What this is
What is a customer audit record?
What is a customer audit record?
A customer audit record documents an audit conducted by a customer or second party against a site, covering how the visit was conducted, the quality and grading of the findings raised, the response given, and the commercial outcome. It sits alongside, but is not the same instrument as, a certification body's external audit.
How is this different from an external audit record?
External Audit Record is the generic instrument for any outside audit, including one by a certification body or scheme owner. This template is specifically for a customer's own audit, where a poor result can affect the commercial relationship directly rather than a certification decision.
Who owns the response to a customer audit?
Technical, because the response is read by the customer as evidence of competence, not only as a fix. The tone of the corrective action matters alongside its content, in a way a certification body's process does not usually weigh.
Scope
When is a customer audit record required?
This record is one step in a larger programme, and its most common misuse is standing in for a step that belongs to a neighbouring template covering readiness, the written response, or the certification body itself.
Use this template when
- A customer or second party has conducted, or is about to conduct, an audit of the site
- Findings from that audit need grading, evidence and a proportionate response captured against a deadline
- The commercial impact of the visit, from none through to significant, needs recording alongside the technical outcome
- The internal audit programme needs checking against what a customer found, particularly where it was something internal audit had not caught
- A linked response record needs this one to exist, since it references the customer audit it was written against
Do not use it for
- External Audit Record, used for a certification body, scheme owner or other second-party visit where the consequence runs through a certification decision rather than a commercial one
- Unannounced Audit Readiness Check, which checks whether the site would pass an audit arriving today, ahead of any visit rather than as its record
- Audit Non Conformance Response Record, which holds the formal written correction, root cause and corrective action in full, referenced from this record rather than repeated in it
- Certification Body Performance Review, which reviews a certification body's own conduct across a cycle of visits, not a customer's
- Anything outside KnowComply, which belongs in the workspace that owns that process
Compliance mapping
Which BRCGS cl.3.4 requirements does this satisfy?
No single clause defines a customer audit itself; what BRCGS and equivalent schemes require is that a site's own audit and response discipline extend to what a customer finds, not only to what a certification body finds.
| Clause | Requirement | Where it lands |
|---|---|---|
| ISO 19011 cl.6 | Audit conducted as a defined sequence, with scope understood in advance and the correct people available to answer questions | Conduct |
| ISO 19011 cl.6 | Findings evidence-based, understood and agreed at the time, with grading explained rather than merely stated | Findings quality |
| BRCGS cl.3.4 | Internal audit programme required to reflect issues found through any route, including a customer's own audit, not only the site's own scheduled checks | Related records |
| BRCGS cl.3.6 | Corrective action addressing root cause, not only the specific instance found, submitted with supporting evidence | Response |
| ISO 19011 cl.6 | Repeat findings against the prior audit tracked explicitly, as a signal distinct from the finding's own severity | Findings quality |
| BRCGS cl.3.4 | Audit outcome, including a completeness measure, recorded so a partial audit is not read as a full one | Outcome |
What it does not cover
- External Audit Record, used where the auditor is a certification body, scheme owner or other second party and the consequence runs through a certification decision.
- Unannounced Audit Readiness Check, which checks readiness ahead of a visit rather than recording one that has happened.
- Audit Non Conformance Response Record, which holds the full formal correction, root cause and corrective action referenced from this record.
- Certification Body Performance Review, which assesses a certification body's own conduct across a cycle of visits.
- Certification Gap Analysis, which identifies what is missing before a first certification attempt, not what a customer found on a live audit.
Global
Customer Audit Record requirements by country
A customer audit is contractual rather than statutory in most places; what varies is how much a scheme or regulator expects a site's own audit programme to absorb what a customer finds.
Buyer-specified audit protocols, typically GFSI-recognised or customer-authored
No federal duty to permit or act on a customer audit; it is a term of the commercial relationship.
The record's real weight is contractual: a poor result affects the listing or contract before it affects anything statutory.
Retailer and brand-owner audit protocols, layered on top of BRCGS certification
Major UK retailers frequently run their own second-party audits in addition to, not instead of, scheme certification.
A site can be fully certified and still lose a listing on a customer's own audit, since the two assessments answer different questions.
GFSI-benchmarked scheme requirements for supplier and second-party assurance
GFSI-recognised schemes expect audit and corrective action discipline to extend to findings from any credible source, including customers.
A customer finding is not a lesser category of evidence; a scheme auditor can ask how it was closed.
How to complete it
How to complete a customer audit record, step by step
The template captures grading, response and commercial impact. What decides whether the record reads well on the next visit is judgement the fields alone do not enforce.
A customer rereads the response to the last audit before starting the next one. A minimal answer, even to a minor finding, reads as a supplier who does not take the relationship seriously, and that impression outlasts the finding it was written for.
Repeat Findings From Last Audit says more about the site than the current visit's grading does. A customer who sees the same issue twice starts asking why the previous corrective action did not hold.
Completeness Percent exists because Score Percent alone can flatter a partial audit: a high pass rate on half the scope is not the same claim as a high pass rate on the whole scope. Both figures belong in the record.
Commercial Impact is a judgement about the relationship, not a restatement of finding count or severity. A site can have few findings and a significant impact if the customer's confidence was shaken by how the audit was conducted.
What auditors find
Most common customer audit record findings
The findings below concern whether the record reflects what actually happened on a customer visit, and whether the response matched the relationship at stake rather than only the technical finding.
| Finding | Clause | What fixes it |
|---|---|---|
| Response delivered on time but written in a tone that reads as defensive or minimal. | BRCGS cl.3.6 | Review the response for tone before submission, not only for technical adequacy; a proportionate, evidenced answer protects the relationship. |
| Repeat finding from the last audit not flagged as such. | ISO 19011 cl.6 | Compare each new finding against the prior audit's list before the record is closed, and mark repeats explicitly. |
| Root cause superficial or not provided for a finding graded higher than minor. | BRCGS cl.3.6 | Require a root cause beyond the immediate correction wherever the finding was more than an observation. |
| Score Percent reported without Completeness Percent, so a partial audit reads as a full pass. | BRCGS cl.3.4 | Report both figures together; a score on an incomplete scope is not comparable to one on a complete scope. |
| Commercial Impact recorded as none despite a significant finding, with no reasoning given. | BRCGS cl.3.4 | Require a short justification whenever Commercial Impact is recorded as lower than the finding grading would suggest. |
| Internal audit programme unchanged despite a finding a customer caught that internal audit had not. | BRCGS cl.3.4 | Track findings the customer identified that internal audit missed, and require a programme change wherever that figure is not zero. |
Case in point
Case in point: the audit that was passed on paper and lost on relationship
A major retail customer audited a co-packer, scoring 94 percent against its own protocol, with three minor findings on labelling traceability. The response was submitted on time: each finding corrected within a week, with photographic evidence attached. Score Percent read as a strong result, and the record was closed as passed.
The retailer did not renew the listing at the next contract review. The account team later explained the reason had little to do with the findings themselves: the response read as a checklist exercise, with no acknowledgement that the same traceability gap had also appeared, in smaller form, on the previous year's audit. What the retailer had actually been testing was whether the supplier learned between visits, and the record showed a good score with no sign that question had been answered.
The template
The template, field by field
The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.
6 sections
- Reference
- CMP-044
- Archetype
- Record
- Record ID
- CAR-2026-000
- Scoring
- Findings closed
- Direction
- High is good
- Singleton
- Yes
- Basis
- BRCGS cl.3.4
- Links
- Links Findings, CAPA, Customer register
- Tags
- Audits, Customer
- Sections
- 6
- Fields
- 52
- Follow up fields
- 3
- Repeating sections
- 0
- Links out
- 4
Header
13 fieldsRecord ID*
Auto sequence. Format CAR-2026-000.
The record's own ID. Other templates point at this value.
Status*
Drives who this goes to next.
- Planned2 pts
- In progress2 pts
- Complete3 pts
- Deferred0 pts
- Open0 pts
- Closed3 pts
- Overdue0 pts
Date and Time*
Completed By*
Site*
Site ID*
Format SITE-000.
Links to FDN-001 Site ID
Customer*
Audit Type*
- Announced1 pt
- Unannounced3 pts
- Penetration style test4 pts
Audit Dates*
Auditor Name
Announced Or Unannounced*
- Unannounced3 pts
- Announced1 pt
Days On Site
Commercial Consequences Certification Findings Do Not Have
A customer finding can remove a listing next month. That makes the response quality and the tone of it as important as the technical fix.
Conduct
6 fieldsScope Understood In Advance*
- Yes3 pts
- Partly1 pt
- No0 pts
Requested Documents Provided Promptly*
- Yes3 pts
- Partly1 pt
- No0 pts
Correct People Available*
- Yes2 pts
- No0 pts
- N/Aexcluded from denominator
Site Presentation Acceptable*
- Yes3 pts
- Partly1 pt
- No0 pts
Workers Able To Answer Questions*
- Yes3 pts
- Partly1 pt
- No0 pts
Closing Meeting Held*
- Yes3 pts
- No0 pts
Findings quality
6 fieldsFindings Evidence Based*
- Yes3 pts
- Partly1 pt
- No0 pts
Findings Understood And Agreed*
- Yes3 pts
- Partly1 pt
- No0 pts
Findings We Had Already Identified*
- Yes3 pts
- Partly1 pt
- No0 pts
Repeat Findings From Last Audit*
- Yes3 pts
- Partly1 pt
- No0 pts
Findings Beyond Standard Requirements*
- Yes3 pts
- Partly1 pt
- No0 pts
Grading Explained*
- Yes3 pts
- Partly1 pt
- No0 pts
Response
6 fieldsResponse Submitted On Time*
- Yes3 pts
- Late0 pts
Root Cause Provided*
- Yes3 pts
- Superficial1 pt
- No0 pts
Corrective Actions Proportionate*
- Yes3 pts
- Partly1 pt
- No0 pts
Evidence Supplied*
- Yes3 pts
- Partly1 pt
- No0 pts
Response Accepted*
- Yes3 pts
- With clarification2 pts
- Rejected0 pts
Verification Visit Required*
- Yes2 pts
- No0 pts
- N/Aexcluded from denominator
Related records
2 fieldsCustomer Register ID
The customer whose audit this was.
Links to FDN-021 Register ID
Response Record ID
The formal response to the findings raised.
Links to CMP-046 Record ID
Outcome
19 fieldsAudit Outcome*
- Passed3 pts
- Passed with actions2 pts
- Conditional1 pt
- Failed0 pts
Findings Raised*
Versus Last Audit*
- Improved3 pts
- Same2 pts
- Worse0 pts
Commercial Impact*
- None3 pts
- Minor1 pt
- Significant0 pts
All Findings Closed*
- Yes3 pts
- Partly1 pt
- No0 pts
Next Audit Expected
Items Assessed*
Excludes anything marked N/A.
Items Failed*
Score Percent*
Calculated on submission. High is good. N/A items leave the denominator.
Result Band*
- Pass3 pts
- Caution1 pt
- Fail0 pts
Completeness Percent*
How much of the template was actually answered. A high score on a half completed form is not a high score.
Action Required*
Raise the action record, then enter its reference here.
- No2 pts
- Yes0 pts
Priority
- High0 pts
- Medium1 pt
- Low3 pts
CAPA ID
Format CAPA-2026-00000.
Links to FDN-014 CAPA ID
Action Owner
Technical*
Signature*
Site Manager*
Second Signature*
CMP-044 · record IDs look like CAR-2026-000 · Links Findings, CAPA, Customer register
Open in KnowellaRun it with agents
From a document you fill in to a programme that runs itself
The audit itself is a single visit. What determines whether the relationship survives it is how the response is written, whether a repeat finding gets noticed, and whether the next visit's outcome is anticipated rather than reacted to.
Holds the customer audit record against the customer register and CAPA, and flags a repeat finding against the prior visit automatically.
Cross-checks a customer finding against internal audit history, so a gap the internal programme missed is visible when it is raised.

Drafts the response for review against the tone and evidence the last audit suggests the customer is watching for, before it goes out.
This template lives in KnowComply — audit and governance. Audit programmes, legal register, management review, risk and certification.
Meet KnowComply→Glossary
Customer Audit Record definitions and key terms
- Second party
- An organisation with a direct commercial interest in the site, typically a customer, conducting its own audit rather than relying only on third-party certification.
- Commercial impact
- The effect of an audit result on the customer relationship itself, ranging from none to significant, distinct from the technical grading of the findings raised.
- Completeness percent
- The proportion of the audit's intended scope that was actually assessed, reported alongside the score so a partial audit is not read as equivalent to a full one.
- Repeat finding
- A finding raised again from a prior audit, tracked separately from the current finding's own grade because it signals whether previous corrective action actually held.
- Root cause
- The underlying reason a finding occurred, as distinct from the correction, which fixes only the specific instance a customer found.
FAQ
Frequently asked questions about customer audit record
What is a customer audit record?+
It documents an audit conducted by a customer or second party: conduct, evidence-based findings, the response given and the commercial outcome, kept distinct from a certification body's external audit.
How is this different to an external audit record?+
External Audit Record covers any outside audit body, including certification bodies and scheme owners, where a poor result runs through a certification decision. This template is specifically for a customer's own visit, where the consequence runs through the commercial relationship instead.
Does a repeat finding matter more than a new one?+
In practice, yes. A repeat finding tells a customer that the previous corrective action did not hold, which raises a question about the whole response process rather than about one instance of noncompliance.
Why record completeness alongside the score?+
Because a high score on half the intended scope is not the same claim as a high score on the whole scope, and reporting only the score without the completeness figure can misrepresent how thoroughly the site was actually assessed.
Should the response differ from one written to a certification body?+
Technical content, root cause and evidence should not be weaker, but tone matters more here: a customer reads the response as evidence about the relationship, not only as a technical correction.
What if internal audit already knew about a finding a customer raised?+
Record it against the internal audit comparison anyway. A customer finding that internal audit had already caught shows the internal programme working; one it had not shows a gap worth acting on before the next visit.
Keep going
Related templates and programmes
Industries this is written for
Programmes this belongs to
Used together in Internal Audit and Certification
Internal Audit Programme
Sets out what will be audited, when, by whom and against which standard, across the year
Internal Audit Report
Records an internal audit against a standard or process, with findings and evidence
Audit Plan
Sets out the scope, criteria, schedule and people involved for a single audit
Audit Finding Record
Records a single audit finding with its evidence, clause reference and classification
Audit Follow Up Record
Checks whether audit findings have actually been closed and the fixes work
Auditor Competency Record
Records an internal auditor's training, experience and audits performed
More in Customer and Scheme Audits
Unannounced Audit Readiness Check
Checks whether the site would pass an audit arriving today, covering records, standards and area condition
Audit Non Conformance Response Record
Holds the formal response to an external finding, with correction, root cause, corrective action and evidence
Certification Body Performance Review
Reviews the certification body on auditor consistency, technical competence, scheduling and value

Written and reviewed by
Siddarth Singh
Founder & Chief Executive Officer, Knowella
Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.
- Certified Safety Professional (CSP), Board of Certified Safety Professionals
- MBA, University of Chicago Booth School of Business
- MS and BS, The Ohio State University, Industrial and Systems Engineering
- Six Sigma Black Belt
Sources and last review. Reviewed 16 August 2026 against:
- BRCGS Global Standard Food Safety, clause 3.4, Internal audits
- BRCGS Global Standard Food Safety, clause 3.6, Corrective and preventive action
- ISO 19011:2018, Guidelines for auditing management systems
- GFSI Benchmarking Requirements, supplier and second-party assurance provisions
This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.