Knowella

Customer Audit Record

A customer audit record captures a visit conducted by a customer or second party, where the consequence runs through the commercial relationship rather than a certification decision. Its recurring failure is answering a customer finding with the same tone as a certification one: a customer finding can end a listing next month, and a technically correct but defensive response reads as the bigger problem.

KnowComplyRecordCMP-04452 fields across 6 sectionsFull researchSee the form

Reviewed by Siddarth SinghCSPLast reviewed 16 August 2026

Basis
BRCGS cl.3.4
Workspace
KnowComply
Form type
Record
Raised
One record per customer audit, in the form CAR-2026-000
Owned by
Technical, because the response is read as much as the fix

The short version

  • A customer audit carries commercial consequences a certification audit does not: a poor result can affect a listing or contract directly, without any certificate being suspended.
  • The response is read as evidence of competence as much as correction. A technically adequate but slow or defensive answer can do more damage than the original finding.
  • Repeat findings from the last audit and findings the site had already identified itself are both tracked, because a customer notices whether the same issue keeps recurring more than it notices the issue's technical severity.
  • Completeness Percent exists because a high score on a half-finished form is not a high score; the record should show how much of the audit was actually assessed, not just the result on what was covered.

What this is

What is a customer audit record?

What is a customer audit record?

A customer audit record documents an audit conducted by a customer or second party against a site, covering how the visit was conducted, the quality and grading of the findings raised, the response given, and the commercial outcome. It sits alongside, but is not the same instrument as, a certification body's external audit.

How is this different from an external audit record?

External Audit Record is the generic instrument for any outside audit, including one by a certification body or scheme owner. This template is specifically for a customer's own audit, where a poor result can affect the commercial relationship directly rather than a certification decision.

Who owns the response to a customer audit?

Technical, because the response is read by the customer as evidence of competence, not only as a fix. The tone of the corrective action matters alongside its content, in a way a certification body's process does not usually weigh.

Scope

When is a customer audit record required?

This record is one step in a larger programme, and its most common misuse is standing in for a step that belongs to a neighbouring template covering readiness, the written response, or the certification body itself.

Use this template when

  • A customer or second party has conducted, or is about to conduct, an audit of the site
  • Findings from that audit need grading, evidence and a proportionate response captured against a deadline
  • The commercial impact of the visit, from none through to significant, needs recording alongside the technical outcome
  • The internal audit programme needs checking against what a customer found, particularly where it was something internal audit had not caught
  • A linked response record needs this one to exist, since it references the customer audit it was written against

Do not use it for

  • External Audit Record, used for a certification body, scheme owner or other second-party visit where the consequence runs through a certification decision rather than a commercial one
  • Unannounced Audit Readiness Check, which checks whether the site would pass an audit arriving today, ahead of any visit rather than as its record
  • Audit Non Conformance Response Record, which holds the formal written correction, root cause and corrective action in full, referenced from this record rather than repeated in it
  • Certification Body Performance Review, which reviews a certification body's own conduct across a cycle of visits, not a customer's
  • Anything outside KnowComply, which belongs in the workspace that owns that process

Compliance mapping

Which BRCGS cl.3.4 requirements does this satisfy?

No single clause defines a customer audit itself; what BRCGS and equivalent schemes require is that a site's own audit and response discipline extend to what a customer finds, not only to what a certification body finds.

ClauseRequirementWhere it lands
ISO 19011 cl.6Audit conducted as a defined sequence, with scope understood in advance and the correct people available to answer questionsConduct
ISO 19011 cl.6Findings evidence-based, understood and agreed at the time, with grading explained rather than merely statedFindings quality
BRCGS cl.3.4Internal audit programme required to reflect issues found through any route, including a customer's own audit, not only the site's own scheduled checksRelated records
BRCGS cl.3.6Corrective action addressing root cause, not only the specific instance found, submitted with supporting evidenceResponse
ISO 19011 cl.6Repeat findings against the prior audit tracked explicitly, as a signal distinct from the finding's own severityFindings quality
BRCGS cl.3.4Audit outcome, including a completeness measure, recorded so a partial audit is not read as a full oneOutcome

What it does not cover

  • External Audit Record, used where the auditor is a certification body, scheme owner or other second party and the consequence runs through a certification decision.
  • Unannounced Audit Readiness Check, which checks readiness ahead of a visit rather than recording one that has happened.
  • Audit Non Conformance Response Record, which holds the full formal correction, root cause and corrective action referenced from this record.
  • Certification Body Performance Review, which assesses a certification body's own conduct across a cycle of visits.
  • Certification Gap Analysis, which identifies what is missing before a first certification attempt, not what a customer found on a live audit.

Global

Customer Audit Record requirements by country

A customer audit is contractual rather than statutory in most places; what varies is how much a scheme or regulator expects a site's own audit programme to absorb what a customer finds.

United States

Buyer-specified audit protocols, typically GFSI-recognised or customer-authored

No federal duty to permit or act on a customer audit; it is a term of the commercial relationship.

The record's real weight is contractual: a poor result affects the listing or contract before it affects anything statutory.

United Kingdom

Retailer and brand-owner audit protocols, layered on top of BRCGS certification

Major UK retailers frequently run their own second-party audits in addition to, not instead of, scheme certification.

A site can be fully certified and still lose a listing on a customer's own audit, since the two assessments answer different questions.

International

GFSI-benchmarked scheme requirements for supplier and second-party assurance

GFSI-recognised schemes expect audit and corrective action discipline to extend to findings from any credible source, including customers.

A customer finding is not a lesser category of evidence; a scheme auditor can ask how it was closed.

How to complete it

How to complete a customer audit record, step by step

The template captures grading, response and commercial impact. What decides whether the record reads well on the next visit is judgement the fields alone do not enforce.

Match the response's tone to what is actually being assessed

A customer rereads the response to the last audit before starting the next one. A minimal answer, even to a minor finding, reads as a supplier who does not take the relationship seriously, and that impression outlasts the finding it was written for.

Treat a repeat finding as the real result of the audit

Repeat Findings From Last Audit says more about the site than the current visit's grading does. A customer who sees the same issue twice starts asking why the previous corrective action did not hold.

Report completeness honestly, not just the score

Completeness Percent exists because Score Percent alone can flatter a partial audit: a high pass rate on half the scope is not the same claim as a high pass rate on the whole scope. Both figures belong in the record.

Separate commercial impact from the finding's technical grade

Commercial Impact is a judgement about the relationship, not a restatement of finding count or severity. A site can have few findings and a significant impact if the customer's confidence was shaken by how the audit was conducted.

What auditors find

Most common customer audit record findings

The findings below concern whether the record reflects what actually happened on a customer visit, and whether the response matched the relationship at stake rather than only the technical finding.

FindingClauseWhat fixes it
Response delivered on time but written in a tone that reads as defensive or minimal.BRCGS cl.3.6Review the response for tone before submission, not only for technical adequacy; a proportionate, evidenced answer protects the relationship.
Repeat finding from the last audit not flagged as such.ISO 19011 cl.6Compare each new finding against the prior audit's list before the record is closed, and mark repeats explicitly.
Root cause superficial or not provided for a finding graded higher than minor.BRCGS cl.3.6Require a root cause beyond the immediate correction wherever the finding was more than an observation.
Score Percent reported without Completeness Percent, so a partial audit reads as a full pass.BRCGS cl.3.4Report both figures together; a score on an incomplete scope is not comparable to one on a complete scope.
Commercial Impact recorded as none despite a significant finding, with no reasoning given.BRCGS cl.3.4Require a short justification whenever Commercial Impact is recorded as lower than the finding grading would suggest.
Internal audit programme unchanged despite a finding a customer caught that internal audit had not.BRCGS cl.3.4Track findings the customer identified that internal audit missed, and require a programme change wherever that figure is not zero.

Case in point

Case in point: the audit that was passed on paper and lost on relationship

A major retail customer audited a co-packer, scoring 94 percent against its own protocol, with three minor findings on labelling traceability. The response was submitted on time: each finding corrected within a week, with photographic evidence attached. Score Percent read as a strong result, and the record was closed as passed.

The retailer did not renew the listing at the next contract review. The account team later explained the reason had little to do with the findings themselves: the response read as a checklist exercise, with no acknowledgement that the same traceability gap had also appeared, in smaller form, on the previous year's audit. What the retailer had actually been testing was whether the supplier learned between visits, and the record showed a good score with no sign that question had been answered.

The template

The template, field by field

The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.

52fields
6 sections
Reference
CMP-044
Archetype
Record
Record ID
CAR-2026-000
Scoring
Findings closed
Direction
High is good
Singleton
Yes
Basis
BRCGS cl.3.4
Links
Links Findings, CAPA, Customer register
Tags
Audits, Customer
Sections
6
Fields
52
Follow up fields
3
Repeating sections
0
Links out
4
Field typesOwn ID, generated on saveCase thread and parentPick list from a registryLinked to another templateFollow up, dashed outlineScored

Header

13 fields
Text

Record ID*

Generated on save

Auto sequence. Format CAR-2026-000.

The record's own ID. Other templates point at this value.

Single Choice

Status*

Scored

Drives who this goes to next.

  • Planned2 pts
  • In progress2 pts
  • Complete3 pts
  • Deferred0 pts
  • Open0 pts
  • Closed3 pts
  • Overdue0 pts
Date & Time

Date and Time*

Users

Completed By*

Pick List

Site*

From FDN-001 Site NameFilter: Status is Active
Text

Site ID*

Linked

Format SITE-000.

Links to FDN-001 Site ID

Text

Customer*

Single Choice

Audit Type*

Scored
  • Announced1 pt
  • Unannounced3 pts
  • Penetration style test4 pts
Text

Audit Dates*

Text

Auditor Name

Optional
Single Choice

Announced Or Unannounced*

Scored
  • Unannounced3 pts
  • Announced1 pt
Numeric Answer

Days On Site

OptionalScored
Info

Commercial Consequences Certification Findings Do Not Have

A customer finding can remove a listing next month. That makes the response quality and the tone of it as important as the technical fix.

Conduct

6 fields
Single Choice

Scope Understood In Advance*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Requested Documents Provided Promptly*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Correct People Available*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Single Choice

Site Presentation Acceptable*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Workers Able To Answer Questions*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Closing Meeting Held*

Scored
  • Yes3 pts
  • No0 pts

Findings quality

6 fields
Single Choice

Findings Evidence Based*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Findings Understood And Agreed*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Findings We Had Already Identified*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Repeat Findings From Last Audit*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Findings Beyond Standard Requirements*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Grading Explained*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts

Response

6 fields
Single Choice

Response Submitted On Time*

Scored
  • Yes3 pts
  • Late0 pts
Single Choice

Root Cause Provided*

Scored
  • Yes3 pts
  • Superficial1 pt
  • No0 pts
Single Choice

Corrective Actions Proportionate*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Evidence Supplied*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Response Accepted*

Scored
  • Yes3 pts
  • With clarification2 pts
  • Rejected0 pts
Single Choice

Verification Visit Required*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator

Related records

2 fields
Text

Customer Register ID

OptionalLinked

The customer whose audit this was.

Links to FDN-021 Register ID

Text

Response Record ID

OptionalLinked

The formal response to the findings raised.

Links to CMP-046 Record ID

Outcome

19 fields
Single Choice

Audit Outcome*

Scored
  • Passed3 pts
  • Passed with actions2 pts
  • Conditional1 pt
  • Failed0 pts
Numeric Answer

Findings Raised*

Scored
Single Choice

Versus Last Audit*

Scored
  • Improved3 pts
  • Same2 pts
  • Worse0 pts
Single Choice

Commercial Impact*

Scored
  • None3 pts
  • Minor1 pt
  • Significant0 pts
Single Choice

All Findings Closed*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Date & Time

Next Audit Expected

Optional
Numeric Answer

Items Assessed*

Excludes anything marked N/A.

Numeric Answer

Items Failed*

Numeric Answer

Score Percent*

Scored

Calculated on submission. High is good. N/A items leave the denominator.

Single Choice

Result Band*

Scored
  • Pass3 pts
  • Caution1 pt
  • Fail0 pts
Numeric Answer

Completeness Percent*

How much of the template was actually answered. A high score on a half completed form is not a high score.

Single Choice

Action Required*

Scored

Raise the action record, then enter its reference here.

  • No2 pts
  • Yes0 pts
Single Choice

Priority

OptionalScoredShows if Action Required equals Yes
  • High0 pts
  • Medium1 pt
  • Low3 pts
Text

CAPA ID

OptionalLinkedShows if Action Required equals Yes

Format CAPA-2026-00000.

Links to FDN-014 CAPA ID

Users

Action Owner

OptionalShows if Action Required equals Yes
Users

Technical*

Signature

Signature*

Users

Site Manager*

Signature

Second Signature*

CMP-044 · record IDs look like CAR-2026-000 · Links Findings, CAPA, Customer register

Open in Knowella

Run it with agents

From a document you fill in to a programme that runs itself

The audit itself is a single visit. What determines whether the relationship survives it is how the response is written, whether a repeat finding gets noticed, and whether the next visit's outcome is anticipated rather than reacted to.

KnowComply

Holds the customer audit record against the customer register and CAPA, and flags a repeat finding against the prior visit automatically.

KnowQuality

Cross-checks a customer finding against internal audit history, so a gap the internal programme missed is visible when it is raised.

Ella
Ella

Drafts the response for review against the tone and evidence the last audit suggests the customer is watching for, before it goes out.

This template lives in KnowComply — audit and governance. Audit programmes, legal register, management review, risk and certification.

Meet KnowComply→

Glossary

Customer Audit Record definitions and key terms

Second party
An organisation with a direct commercial interest in the site, typically a customer, conducting its own audit rather than relying only on third-party certification.
Commercial impact
The effect of an audit result on the customer relationship itself, ranging from none to significant, distinct from the technical grading of the findings raised.
Completeness percent
The proportion of the audit's intended scope that was actually assessed, reported alongside the score so a partial audit is not read as equivalent to a full one.
Repeat finding
A finding raised again from a prior audit, tracked separately from the current finding's own grade because it signals whether previous corrective action actually held.
Root cause
The underlying reason a finding occurred, as distinct from the correction, which fixes only the specific instance a customer found.

FAQ

Frequently asked questions about customer audit record

What is a customer audit record?+

It documents an audit conducted by a customer or second party: conduct, evidence-based findings, the response given and the commercial outcome, kept distinct from a certification body's external audit.

How is this different to an external audit record?+

External Audit Record covers any outside audit body, including certification bodies and scheme owners, where a poor result runs through a certification decision. This template is specifically for a customer's own visit, where the consequence runs through the commercial relationship instead.

Does a repeat finding matter more than a new one?+

In practice, yes. A repeat finding tells a customer that the previous corrective action did not hold, which raises a question about the whole response process rather than about one instance of noncompliance.

Why record completeness alongside the score?+

Because a high score on half the intended scope is not the same claim as a high score on the whole scope, and reporting only the score without the completeness figure can misrepresent how thoroughly the site was actually assessed.

Should the response differ from one written to a certification body?+

Technical content, root cause and evidence should not be weaker, but tone matters more here: a customer reads the response as evidence about the relationship, not only as a technical correction.

What if internal audit already knew about a finding a customer raised?+

Record it against the internal audit comparison anyway. A customer finding that internal audit had already caught shows the internal programme working; one it had not shows a gap worth acting on before the next visit.

Keep going

Related templates and programmes

Siddarth Singh

Written and reviewed by

Siddarth Singh

Founder & Chief Executive Officer, Knowella

Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.

  • Certified Safety Professional (CSP), Board of Certified Safety Professionals
  • MBA, University of Chicago Booth School of Business
  • MS and BS, The Ohio State University, Industrial and Systems Engineering
  • Six Sigma Black Belt
Verify with BCSP →

Sources and last review. Reviewed 16 August 2026 against:

  • BRCGS Global Standard Food Safety, clause 3.4, Internal audits
  • BRCGS Global Standard Food Safety, clause 3.6, Corrective and preventive action
  • ISO 19011:2018, Guidelines for auditing management systems
  • GFSI Benchmarking Requirements, supplier and second-party assurance provisions

This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.

Start in Minutes, Not Weeks

Launch a Ready-Made Template and Customize It Your Way

Every template is fully editable. Adjust fields, workflows, and branding to match your processes, then deploy to your team instantly.