What this is
What is an external audit record?
What is an external audit record?
An external audit record documents an audit conducted by someone outside the organisation against a management system standard or scheme: a certification body, a scheme owner, or a second party. It captures scope, conduct, findings by grade, the response required, and the certification outcome.
How is this different from a customer audit record?
Audit Body on this template includes certification bodies, scheme owners and second parties as well as customers, but where the auditor is specifically a customer and the consequence is commercial rather than a certification decision, use the Customer Audit Record instead. This template's outcome fields are built around certificate status; the customer template's are built around commercial impact.
Who decides the grade a finding receives?
The auditor, at the time of the audit, against the scheme's own grading scale. The record captures whether the site agreed with the grade and whether the same issue had already been found internally; it does not give the site a route to downgrade a finding after the visit.
Scope
When is an external audit record required?
This record is the general instrument for an outside audit against a scheme. Its most common misuse is standing in for a step that belongs to a neighbouring template earlier or later in the same programme.
Use this template when
- A certification body, scheme owner or second party has conducted, or is about to conduct, an audit against a management system standard or scheme
- An unannounced or penetration-style visit has occurred and needs the same discipline as an announced one
- Findings need grading, a deadline, and routing into CAPA before the certification body's own clock runs out
- Certificate status, whether issued, maintained, suspended or withdrawn, needs to be recorded against the visit that produced it
- The internal audit programme needs checking against what an outside body actually found, to see whether it missed something
Do not use it for
- Customer Audit Record, used specifically when the auditor is a customer and the consequence is commercial rather than a certification decision
- ISO 45001 Readiness Audit or ISO 14001 Readiness Audit, the internal check run before the body arrives, not the visit itself
- Certification Gap Analysis, which identifies what is missing before a first certification attempt
- Audit Non Conformance Response Record, which holds the formal written response to a finding raised here
- Certification Body Performance Review, which evaluates the body's own conduct across a cycle of visits, not this visit's findings
Compliance mapping
Which ISO 17021 requirements does this satisfy?
ISO 17021-1 binds the certification body, not the site, but its requirements on how an audit is conducted and decided are what this record exists to evidence from the other side of the table.
| Clause | Requirement | Where it lands |
|---|---|---|
| ISO/IEC 17021-1 cl.9.1 | Audit process applied to a defined method regardless of which body, scheme owner or second party is conducting it | Header |
| ISO 19011 cl.6 | Opening meeting, evidence gathering and closing meeting conducted as a sequence, with the workforce able to explain the system under questioning | Conduct |
| ISO 19011 cl.6 | Findings graded against objective evidence, with the auditee's agreement or disagreement recorded at the time | Findings |
| ISO/IEC 17021-1 cl.9.5 | Certification decision taken independently of the audit team, based on the grading and finding record produced | Outcome |
| ISO/IEC 17021-1 cl.9.6 | Corrective action and evidence required within a timeframe the certification body sets, before a certificate is confirmed or maintained | Response and learning |
| ISO 9001/14001/45001 cl.9.2 | Internal audit programme adjusted where an external body finds something the internal programme did not | Response and learning |
What it does not cover
- Customer Audit Record, used where the auditor is a customer and the consequence runs commercial rather than through a certification decision.
- Audit Non Conformance Response Record, which holds the formal correction, root cause and corrective action for a finding raised here.
- Certification Gap Analysis, which identifies what is missing before a first certification attempt, ahead of the audit rather than as its record.
- ISO 45001 Readiness Audit or ISO 14001 Readiness Audit, the internal readiness check, not the external body's own visit.
- Certification Body Performance Review, which evaluates the auditor and body across a cycle of visits rather than any single one.
Global
External Audit Record requirements by country
Nothing compels the certification visit itself in most places; what is binding is how the certification body must conduct and decide it once a scheme is in play.
ISO/IEC 17021-1, applied via accredited certification bodies
No federal requirement to certify to a management system standard; certification is customer or scheme driven.
This record's real audience is commercial and contractual, since nothing in US law compels the audit that produced it.
UKAS accreditation of certification bodies under ISO/IEC 17021-1
Certification bodies operating in the UK are themselves accredited and periodically audited against 17021-1.
How the audit was conducted is itself auditable, which is why opening meeting, closing meeting and grading discipline matter beyond this one visit.
ISO/IEC 17021-1
Sets requirements for bodies providing audit and certification of management systems, wherever the site sits.
The obligation travels with the certification body, not the location, so the same process discipline applies across sites in different countries.
How to complete it
How to complete an external audit record, step by step
The template captures grade, deadline and status. What decides whether the record is defensible afterwards is the judgement applied before those fields are filled in.
The grade recorded should match what was evidenced in the room, not a softened version chosen because it reads better internally. The body's own report will confirm the grade it gave; a mismatch costs credibility and time against the deadline.
Response Deadline is fixed by the audit body at the point the finding is raised. Diarise it that day, not when the written report arrives, because the gap between the meeting and the paperwork is time not recovered.
Found By Us Previously distinguishes a finding the internal programme had already caught, which shows the system working, from one it never saw, which is a gap deserving more attention than the finding's own grade suggests.
Response Accepted and All Findings Closed should reflect the body's actual acceptance, including a verification visit where required, not the site's own sense that the response was adequate.
What auditors find
Most common external audit record findings
The record almost always exists after an external visit. The findings concern whether it reflects what was actually said and agreed, and whether it moved fast enough.
| Finding | Clause | What fixes it |
|---|---|---|
| Grade softened between the closing meeting and the written record. | ISO 19011 cl.6 | Complete the grade and description in the closing meeting; treat disagreement as a matter to raise with the body, not to edit. |
| Response submitted after the deadline the certification body set. | ISO/IEC 17021-1 cl.9.6 | Diarise the response deadline the day the finding is raised, not the day the written report arrives. |
| Root cause not required on a finding that repeated from the previous audit. | ISO 19011 cl.6 | Flag repeat findings for mandatory root cause and compare against the prior audit's finding list before closing. |
| Certificate status change not reflected until well after the decision letter arrived. | ISO/IEC 17021-1 cl.9.5 | Update certificate status the day the decision letter arrives, not at the next scheduled review. |
| Internal audit programme unchanged despite the external body finding something it missed. | ISO 9001/14001/45001 cl.9.2 | Record findings missed by internal audit as its own figure and require a programme change wherever that figure is not zero. |
| Action marked required with no CAPA reference entered against it. | ISO/IEC 17021-1 cl.9.6 | Require the CAPA ID before the record can be marked complete whenever Action Required is Yes. |
Case in point
Case in point: the grade that was softer on paper than in the room
A site's ISO 45001 surveillance audit ran two days. In the closing meeting, the auditor described a finding on permit-to-work records as a major nonconformity, tied to overdue hot work permits found in three files. Writing up the external audit record afterwards, the compliance lead recorded it as a minor observation, reasoning that the grade would likely soften once a corrective action plan was offered.
The written report arrived a week later and confirmed the major grading, with a fixed evidence deadline that had already lost most of a week to the softened record. The gap between what was said and what was written cost the site its response window, and it repeated at the next visit because nothing stopped a grade being rewritten on the way in. The fix was procedural: grade and description are now completed in the closing meeting, before anyone leaves the room, in the auditor's own words.
The template
The template, field by field
The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.
5 sections
- Reference
- CMP-021
- Archetype
- Record
- Record ID
- EAR-2026-000
- Scoring
- Finding count by grade
- Direction
- High is bad
- Singleton
- No
- Basis
- ISO 17021
- Links
- Links Clause, Vendor; feeds CAPA
- Tags
- Certification, Audit
- Sections
- 5
- Fields
- 56
- Follow up fields
- 3
- Repeating sections
- 1
- Links out
- 3
Header
12 fieldsRecord ID*
Auto sequence. Format EAR-2026-000.
The record's own ID. Other templates point at this value.
Status*
Drives who this goes to next.
- Planned2 pts
- In progress2 pts
- Complete3 pts
- Deferred0 pts
- Open0 pts
- Closed3 pts
- Overdue0 pts
Date and Time*
Completed By*
Site*
Site ID*
Format SITE-000.
Links to FDN-001 Site ID
Audit Body*
Certification body, customer, second party, or scheme owner.
Standard Or Scheme*
Audit Type*
- Announced1 pt
- Unannounced3 pts
- Penetration style test4 pts
Audit Dates*
Lead Auditor Name
Announced Or Unannounced*
- Unannounced3 pts
- Announced1 pt
Conduct
9 fieldsScope Audited*
Days On Site
Shifts Covered
Documents Produced Promptly*
- Yes3 pts
- Delayed1 pt
- No0 pts
Workers Interviewed
Workers Able To Explain The System*
- Yes3 pts
- Partly1 pt
- No0 pts
Opening Meeting Held*
- Yes3 pts
- No0 pts
Closing Meeting Held*
- Yes3 pts
- No0 pts
Findings Explained Clearly*
- Yes3 pts
- Partly1 pt
- No0 pts
Findings
Repeats10 fieldsFinding Reference*
Clause
Grade*
- Critical0 pts
- Major1 pt
- Minor2 pts
- Observation3 pts
- Opportunity for improvement3 pts
Finding Description*
Agreed With Finding*
- Yes3 pts
- Partly1 pt
- No0 pts
Found By Us Previously*
A finding we had already raised internally shows the system works. One we never saw shows it does not.
- Yes3 pts
- No0 pts
Finding ID
Links to FDN-015 Finding ID
Response Deadline
Root Cause Required*
Owner*
Outcome
9 fieldsCritical Findings*
Major Findings*
Minor Findings*
Grade Or Score Awarded*
- AA or equivalent4 pts
- A3 pts
- B2 pts
- C1 pt
- D or below0 pts
- Not graded2 pts
Versus Last Audit*
- Improved3 pts
- Same2 pts
- Worse0 pts
Certificate Issued Or Maintained*
- Yes3 pts
- Suspended0 pts
- Withdrawn0 pts
Certificate Expiry
Next Audit Due*
Unannounced Next Time
Response and learning
16 fieldsResponse Submitted On Time*
- Yes3 pts
- Late0 pts
Response Accepted
- Yes3 pts
- With clarification2 pts
- Rejected0 pts
All Findings Closed
- Yes3 pts
- Partly1 pt
- No0 pts
Findings Missed By Internal Audit*
Internal Audit Programme Adjusted*
- Yes3 pts
- Not needed3 pts
- No0 pts
Readiness Audit Had Predicted Outcome*
- Yes3 pts
- Partly1 pt
- No0 pts
Results Shared With Workforce*
- Yes3 pts
- Partly1 pt
- No0 pts
Feeds Management Review*
Action Required*
Raise the action record, then enter its reference here.
- No2 pts
- Yes0 pts
Priority
- High0 pts
- Medium1 pt
- Low3 pts
CAPA ID
Format CAPA-2026-00000.
Links to FDN-014 CAPA ID
Action Owner
Compliance Lead*
Signature*
Site Manager*
Second Signature*
CMP-021 · record IDs look like EAR-2026-000 · Links Clause, Vendor; feeds CAPA
Open in KnowellaRun it with agents
From a document you fill in to a programme that runs itself
The visit produces a document. What decides whether it holds up afterwards is whether the grade, the deadline and the certificate status stay attached to the record as they change.
Holds the external audit record against the certification calendar, flags an approaching response deadline, and keeps certificate status current as decisions arrive.
Cross-checks a finding against the internal audit and inspection history, so a repeat or previously missed finding is visible at the point it is raised.

Watches for a response deadline approaching without a submitted response, and raises it to the compliance lead before the certification body does.
This template lives in KnowComply — audit and governance. Audit programmes, legal register, management review, risk and certification.
Meet KnowComply→Glossary
External Audit Record definitions and key terms
- Grade
- The severity tier assigned to a finding, such as critical, major, minor, observation or opportunity for improvement, which sets the response deadline and the risk to certification.
- Certification decision
- The decision to issue, maintain, suspend or withdraw a certificate, made independently of the audit team that raised the findings.
- Scheme owner
- The organisation that owns a certification scheme's rules, such as BRCGS or SQF, distinct from the certification body that conducts the audit under those rules.
- Unannounced audit
- An audit conducted without prior notice, used by several schemes to see conditions as they normally run rather than as prepared for a visit.
- Root cause
- The underlying reason a finding occurred, distinct from the correction, which fixes only the specific instance found.
FAQ
Frequently asked questions about external audit record
What is an external audit record?+
It documents an audit conducted by an outside party, certification body, scheme owner or second party, against a management system standard or scheme, covering scope, conduct, graded findings, response and certification outcome.
How is this different to a customer audit record?+
This template covers any outside audit body. The Customer Audit Record is specifically for a customer's own commercial audit of a supplier, where the consequence runs through the commercial relationship rather than a certification decision, even though a customer can also appear as the Audit Body here.
Who sets the response deadline?+
The certification body or scheme owner, at the time the finding is raised. It is not set internally and does not move because the write-up took longer than the deadline allowed.
What if we disagree with a finding's grade?+
Record the disagreement against Agreed With Finding at the time, and raise it through the certification body's own appeals or clarification route. The record is not the place to quietly downgrade a finding after the visit.
Does an unannounced audit get recorded differently?+
Not structurally; the same fields apply. Announced Or Unannounced and Audit Type are recorded because several schemes track how a site performs without preparation time, and that pattern matters over successive audits.
What if internal audit already knew about a finding the external body raised?+
Record it as Found By Us Previously. That answer matters more than most people expect: it shows whether the internal audit programme is catching what an outside body eventually finds, which is closer to the point of running one.
Keep going
Related templates and programmes
Industries this is written for
Programmes this belongs to
Used together in Internal Audit and Certification
Internal Audit Programme
Sets out what will be audited, when, by whom and against which standard, across the year
Internal Audit Report
Records an internal audit against a standard or process, with findings and evidence
Audit Plan
Sets out the scope, criteria, schedule and people involved for a single audit
Audit Finding Record
Records a single audit finding with its evidence, clause reference and classification
Audit Follow Up Record
Checks whether audit findings have actually been closed and the fixes work
Auditor Competency Record
Records an internal auditor's training, experience and audits performed
More in Cert Readiness
ISO 45001 Readiness Audit
Audits the occupational health and safety management system against ISO 45001 ahead of certification or surveillance
ISO 14001 Readiness Audit
Audits the environmental management system against ISO 14001 ahead of certification or surveillance
Certification Gap Analysis
Identifies what is missing before a first certification attempt

Written and reviewed by
Siddarth Singh
Founder & Chief Executive Officer, Knowella
Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.
- Certified Safety Professional (CSP), Board of Certified Safety Professionals
- MBA, University of Chicago Booth School of Business
- MS and BS, The Ohio State University, Industrial and Systems Engineering
- Six Sigma Black Belt
Sources and last review. Reviewed 16 August 2026 against:
- ISO/IEC 17021-1:2015, Conformity assessment — Requirements for bodies providing audit and certification of management systems
- ISO 19011:2018, Guidelines for auditing management systems
- ISO 9001:2015, ISO 14001:2015 and ISO 45001:2018 clause 9.2, Internal audit
- UKAS accreditation criteria for management system certification bodies
This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.