The Witness Audit Is Not Just About the Auditor
Most certification bodies think of a witness audit as an assessment of the auditor's performance in the field. The AB assessor sits in on an audit, watches how the auditor conducts interviews, reviews evidence, and documents findings. This is true — but it is only part of what happens.
The assessor also reviews the entire audit file. They check the documentation trail from team assignment through to the certification decision. They look at whether the CB's processes were followed, not just whether the auditor asked good questions. And they look at it all in detail.
A CB that prepares its auditor for the witness but neglects the documentation behind the audit is setting itself up for findings that have nothing to do with auditor competence.
The Checklist the Assessor Works Through
Here is what the AB assessor will typically examine, beyond the auditor's field performance. Think of this as the operational checklist that most CBs wish they had assembled before the assessor arrived.
1. Impartiality Declarations — Signed Before the Audit
The assessor will check whether every team member — lead auditor, technical expert, trainee — signed an impartiality declaration before the audit began. Not "around the time of the audit." Before it.
Common finding: the declaration was signed on the same day as the audit, or worse, after the audit was conducted. This suggests the declaration was a formality completed after the fact rather than a genuine pre-audit assessment of impartiality.
In Certiva, impartiality declarations are auto-generated when the team is assigned and gated — the audit phase cannot proceed until all declarations carry a signed timestamp that predates the audit start.
2. Audit Team Scope Coverage
The assessor checks whether the audit team collectively has the qualifications to cover the scope of the certification. For a multi-EA-code engagement, this means verifying that the lead auditor or technical experts have documented competence in each relevant EA code.
Common finding: the technical expert's qualification records do not demonstrate coverage for one of the EA codes in scope, or the qualification evidence is stored in a separate system that nobody can access during the assessment.
Certiva validates team qualification coverage at the time of assignment. The auditor profile includes all qualified standards and EA codes, and the system flags gaps when the team does not cover the engagement's scope.
3. Audit Time Calculation and Justification
The assessor wants to see the audit time calculation — not just the number of days, but the methodology. How did the CB determine that this client needs four auditor-days for Stage 2? What factors were considered? Were there justifiable reductions or increases from the IAF MD 5 baseline?
Common finding: there is no documented audit time calculation, or the calculation exists but the justification for deviations from the standard table is missing.
Certiva's audit time calculator is part of the engagement record. The inputs — employee count, sites, complexity factors, shift patterns — are documented alongside the calculated result. Any adjustments from the baseline include a rationale field.
4. Signing Order on Documents
The assessor reviews the audit plan, stage reports, and certificate to verify that signatures appear in the correct order. The lead auditor signs the report before the reviewer. The committee members sign before the certificate is issued. The signing dates should reflect a logical sequence.
Common finding: the reviewer's signature date is before the auditor's, or the committee decision date is after the certificate issue date. These inconsistencies suggest that documents were backdated or that the signing process was not properly controlled.
Certiva enforces signing order through role-gated chains. The system presents the document to signers in sequence — the next signer cannot access the document until the previous signer has completed. Timestamps are system-generated and cannot be manually altered.
5. Committee Composition and Qualification
The certification decision must be made by a person or committee that is competent and was not involved in the audit. The assessor checks who made the decision, whether they were qualified for the scope, and whether there was any conflict of interest.
Common finding: the committee member who signed the decision does not have documented qualification for one of the standards in scope, or the same person who conducted the audit also reviewed the decision.
Certiva manages committee assignment with qualification validation. The system checks that assigned reviewers have the required competence for the engagement's standards and scope. It also prevents assigning team members who participated in the audit to the committee review.
6. Nonconformity Closure Evidence
If the audit raised nonconformities, the assessor checks the closure trail. Was the client's corrective action documented? Did the auditor review and accept the response? Is there evidence of verification — either document review or on-site follow-up? Is the timeline consistent with the CB's procedures?
Common finding: the NC record shows the finding and the closure, but the client's actual corrective action response is missing from the file. Or the auditor accepted the corrective action but there is no documented rationale for acceptance.
Certiva tracks NCs as structured records with status progression: raised, responded, reviewed, closed. Each step is timestamped. Client responses are submitted through the portal and attached to the NC record. Auditor review notes are captured when the response is accepted or rejected.
7. Audit Plan Content and Communication
The assessor reviews whether the audit plan was prepared with adequate detail — scope, objectives, criteria, team roles, schedule — and whether it was communicated to the client before the audit. Some ABs also check whether the client had the opportunity to object to team members.
Common finding: the audit plan exists, but there is no record of it being sent to the client, or the plan was sent after the audit started.
In Certiva, audit plans are generated within the engagement record and can be shared with clients through the client portal. Communication records within the platform show when documents were made available.
The Preparation That Actually Works
The witness audit preparation most CBs do looks like this: the week before, someone scrambles through folders pulling together documents, checking for gaps, and printing things the assessor might ask for. It is reactive, stressful, and unreliable.
The preparation that actually works is not preparation at all — it is normal operations. If every audit engagement is managed through a system that enforces declarations before audits start, validates team qualifications at assignment, documents audit time calculations, enforces signing order, tracks NC closure, and stores everything in a structured record, then the audit file is always witness-ready.
When a CB like Sterling Certification uses Certiva, the witness audit preparation meeting is 15 minutes instead of two days. The planner opens the engagement, confirms everything is green, and sends the assessor access to the file. Because the system has been enforcing the requirements all along, there are no surprises to find and no gaps to fill.
The checklist above is not a preparation tool. It is a design specification for how your CB should operate every day. If you only check these things before a witness audit, you are already behind.