Independent and not affiliated with the FDA, MHRA, ISPE, PDA, or any agency. Get the appgoutham@madhadi.com
madhadi.comData Integrity & GxP Quality
Browse all topics → Articles Templates & Procedures Learning paths GlossaryScenariosToolsRegulatory ReferencesLearning PathsTopics About Start here
Form Plug-and-play starting point Audits & Inspection

Form: Audit Finding Record

A plug-and-play form for documenting a single GxP audit finding with the four defensible parts (requirement, condition, objective evidence, consequence), the grade and its rationale, spread, and response commitment, with field definitions and a filled specimen.

Document type: Form

Read and copy the template below into your own quality system. It is a generic starting point for your own internal use, provided as is, with no warranty; see the Terms and License. Adopting it does not by itself create compliance.

This is a ready-to-use finding record. One form per finding. Replace every <<FILL: ...>> placeholder, route it through your audit report and CAPA process, and keep it with the audit file. A field-definition table and a filled specimen follow so both the empty and completed shapes are visible. This content is educational reference, not legal or regulatory advice; verify cited requirements against the current source.

Form control

FieldEntry
Form titleAudit Finding Record
Form number<<FILL: FRM-ID, e.g. FRM-QA-021-01>>
Parent SOP<<FILL: SOP-ID for finding classification, e.g. SOP-QA-021>>
Version<<FILL: version>>

The finding record

FieldEntry
Finding ID<<FILL: unique ID, e.g. INT-2026-019>>
Audit reference<<FILL: audit ID / report number>>
Audit type<<FILL: internal / supplier / self-inspection / for-cause>>
Date observed<<FILL: date>>
Area / process / system<<FILL: department, process, or system>>
Auditor<<FILL: name>>
Requirement (criteria)<<FILL: specific clause, standard section, or SOP number + step + version>>
Condition (what was found)<<FILL: factual, verifiable observed state with identifiers>>
Objective evidence<<FILL: artifacts with identifiers: doc/version, batch/lot, page/line, timestamp, system/equipment ID, audit note ref>>
Consequence / risk<<FILL: link to patient/subject safety, product quality, or data reliability>>
Spread assessed<<FILL: number sampled / number affected; isolated or pattern>>
Aggregation?<<FILL: N/A, or references to constituent minor findings rolled up>>
Grade<<FILL: Critical / Major / Minor / Observation>>
Grade rationale (decision path)<<FILL: why this tier and not the ones above/below it>>
Auditee acknowledgement of condition<<FILL: acknowledged / condition corrected to: ...>>
CAPA / response reference<<FILL: CAPA number or N/A>>
Response due date<<FILL: date per grade>>
Finding owner (CAPA)<<FILL: name / role>>
Lead auditor review<<FILL: name, date>>
QA review (critical/major)<<FILL: name, date, or N/A>>

Field definitions

FieldFormat / ruleWho entersWhen
Finding IDUnique, sequential per programAuditorAt draft
RequirementMust cite a clause, section, or SOP step + version, not a principleAuditorAt draft
ConditionFactual and relocatable by a second person; no adjectives of judgmentAuditorAt observation
Objective evidenceIdentifiers sufficient to relocate; verbal statements corroborated before grading majorAuditorAt observation
ConsequenceTies to one protected interest; the grade must follow from itAuditor / SMEAt draft
GradeOne of the four tiers; no looser than regulatory definitionLead auditorAt draft, confirmed at review
Grade rationaleReferences the decision path (critical, then major, then minor)Lead auditorAt draft
QA reviewMandatory for critical and major before issueQABefore report issue

Retention: keep with the audit file for not less than <<FILL: retention period>>.

Instructions

  1. Complete one record per finding. Do not merge two distinct nonconformities into one record.
  2. Fill the four core fields (requirement, condition, evidence, consequence) before assigning the grade; the grade is the output, not the input.
  3. Where several related minors aggregate into a major, raise the major on its own record and list the constituent findings in the aggregation field.
  4. Do not write proposed corrective actions into the condition or consequence; the auditee owns the fix through CAPA.
  5. Route critical and major records to QA for review before the report issues.

Filled specimen

FieldEntry
Finding IDINT-2026-019
Audit referenceINT-AUD-2026-04 (QC laboratory)
Audit typeInternal
Date observed2026-06-04
Area / process / systemQC chromatography data system, audit trail review process
AuditorA. Patel
RequirementEU GMP Annex 11 paragraph 9 and site SOP-QC-114 v4 step 6.2 require audit trail review prior to batch disposition.
ConditionIn 3 of 4 sampled finished-product batch records (lots A231, A239, A241), the CDS audit trail review was documented on a date later than the disposition decision.
Objective evidenceDisposition signatures 2026-03-02, 2026-03-09, 2026-03-15; review checklists FRM-114-01 dated 2026-03-04, 2026-03-11, 2026-03-18; confirmed on screen in the CDS audit trail; audit note AN-07.
Consequence / riskA required release control operated after the release decision it informs, across most of the sample; the release-control process is not functioning as designed. No patient harm demonstrated.
Spread assessed4 sampled, 3 affected; pattern, not isolated.
Aggregation?N/A (single systemic finding, not a roll-up).
GradeMajor
Grade rationaleNo falsification and no direct patient harm shown, so not critical; systemic failure of a release control across the sample, so major; not isolated, so not minor.
Auditee acknowledgementCondition acknowledged by QC Manager at closing meeting.
CAPA / response referenceCAPA-2026-0231
Response due date2026-07-04 (30 days)
Finding owner (CAPA)QC Manager
Lead auditor reviewA. Patel, 2026-06-05
QA reviewR. Gomez, 2026-06-06

The completed record shows a finding that is hard to argue with: every field points at a relocatable artifact, and the grade follows from the consequence. An auditee can fix it; they cannot wave it away.

Common inspection findings this form prevents

  • Findings recorded as conclusions (“data integrity concerns”) with no requirement, evidence, or consequence.
  • A grade with no rationale, so no one can tell why it was not a tier higher or lower.
  • Corrective actions pre-written into the finding, letting the auditee skip a real root cause.
  • Verbal assertions graded major without corroboration against a record.
  • No QA review of critical and major findings before the report issued.

How to adapt this form

  1. Set your form number and parent SOP in the control block.
  2. Match the retention period to your records retention schedule.
  3. If your CAPA system assigns IDs automatically, align the CAPA reference field to that format.
  4. Keep the four core fields in this order; the ordering is the discipline that makes the grade defensible.
Use madhadi.com as an app Full screen, works offline, one tap from your home screen.