Audit-readiness isn't a pre-audit sprint — three daily habits from a quality engineer's notebook
Auditor: "Show me training records for SOP-014, revision F." Me: "Sure." Me, twenty minutes later: "...this revision was effective eleven months ago and there's no re-attestation on file." That gap is real. It cost me a
Auditor: "Show me training records for SOP-014, revision F."
Me: "Sure."
Me, twenty minutes later: "...this revision was effective eleven months ago and there's no re-attestation on file."
That gap is real. It cost me a finding that should have been impossible, because the revision was approved, the SOP was effective, and the training matrix showed the old revision as current. Nothing in the system lied to me — but the system also didn't connect the dots for me.
That's when "audit-readiness" stopped meaning "binder I scramble to build the week before." It started meaning three boring daily habits that make audits feel like any other Tuesday. Here's what those look like in my Class II setup — names of tools and clauses are real, the rest isn't worth naming.
Map your SOPs before you trust them
Every controlled document in an eQMS — Greenlight Guru in our case, after a long evaluation cycle — exists in a web of references. Your complaint SOP cites your CAPA SOP. Your CAPA SOP cites your risk management procedure. Your risk procedure cites ISO 14971. Your DHF index cites the design input specs. The whole set is a graph, and almost nobody treats it like one.
What changed for me was drawing the graph. Not architecturally — operationally. When a document goes through change control, I now ask three questions before approval:
- What upstream documents does this cite, and are those citations still valid?
- What downstream documents cite this one, and have they been notified of the change?
- Which training records attach to this revision, and how do they get re-attested?
ISO 13485:2016 §4.2.4 doesn't use the word "graph." But the spirit of the clause is exactly this — the document set has to be coherent, not just individually controlled. 21 CFR 820.40 says the same thing in different words.
The practical habit: before I approve any document change, I open the linked records list in our eQMS and click through each one. It takes about ten minutes. It has caught more drift than any pre-audit prep ever did.
Verify the links, don't assume them
Mapping and verifying are different jobs. Mapping tells you what should be connected. Verifying tells you what actually is.
The failure modes I keep seeing:
- A form gets retired but the reference in the parent SOP isn't updated.
- A document ID gets reissued after a platform migration, and old DHF entries still point to the retired ID.
- A CAPA closes, but the SOP it produced never gets linked back to the originating non-conformance.
- A training record attaches to an SOP revision that was superseded six months ago.
None of these are dramatic. All of them are findings waiting to happen.
What I do now is a weekly twenty-minute sweep: open the recently changed documents list, and for each one, check three things — the linked records render correctly, the revision on the training matrix matches the active revision, and any retired IDs are cleaned out of historical references. It's boring work. It's the only work that prevents surprises.
If you're rebuilding these habits from scratch, this YouTube walkthrough from qmsWrapper is a decent companion — practical, "do it today" framing rather than textbook. Worth pairing with what's above: https://www.youtube.com/watch?v=O2Iwcj_OgiM
Automate the approvals that don't need a human decision
The third habit is the one I underestimated. Not every approval in a QMS is a judgment call. A lot of them are routing steps — "QA lead acknowledged," "training triggered," "document now effective" — that exist because a workflow template says they should.
If your eQMS supports it (Greenlight Guru does, and most modern tools do), automate the ones that don't require human judgment. Specifically:
- Auto-route to the next approver when the previous one signs.
- Auto-trigger training re-attestation when a controlled doc with linked training goes effective.
- Auto-flag approval steps that have been open longer than your internal SLA.
- Auto-notify the document owner when a linked record changes revision.
The reason this matters for audit-readiness: auditors don't just ask "did the approval happen." They ask "show me the timestamp, the approver, and the delegation chain." When those are wired into the system and surfaced by default, the question answers itself. When they're emails in someone's inbox, you're reconstructing history under pressure.
What I'm still working on
The habit I'm worst at is the third one. We've automated maybe 60% of our routing. The rest still has human-in-the-loop steps I think we could probably remove — but I haven't been brave enough yet, because some of those approvers are also our internal auditors, and I want a paper trail of their acknowledgment.
That's the tension I'm sitting with. More automation means less visible human evidence. Less automation means more places for a timestamp to go missing.
How much of your approval workflow would you actually trust to run without a human in the loop — and what guardrails do you keep around the parts you won't automate?
Disclosure: I work on qmsWrapper.
Originally published by Dev.to AI. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.