
Introduction
Most quality teams that struggle in GMP audits fail to translate their knowledge into something an auditor can actually see — documented practice, verifiable records, and personnel who can describe their own procedures without reaching for a binder.
That gap between knowing GMP and being genuinely audit-ready is where most nonconformances are written.
This guide is written for quality managers, plant quality leads, and compliance teams in regulated manufacturing — aerospace, general manufacturing, and medical devices. Most GMP audit content targets food and pharma; this one doesn't. If you're running an ISO 9001, AS9100D, or ISO 13485 program and facing any type of audit, here's what this guide covers:
- What GMP is and why it matters
- The types of audits you'll face
- What auditors are actually evaluating
- How to prepare effectively
- The findings that generate nonconformances most often
What GMP Means and Why It Matters in Manufacturing
**GMP stands for Good Manufacturing Practice** — a set of principles and requirements designed to ensure products are consistently produced and controlled to the quality standards appropriate for their intended use.
GMP is not a single global standard. It's a framework embedded across multiple regulations and certification schemes depending on your industry:
| Framework | Application |
|---|---|
| ISO 9001:2015 | Cross-industry quality management, including general manufacturing |
| AS9100D | Aviation, space, and defense supply chains |
| ISO 13485:2016 | Medical device QMS requirements |
| FDA 21 CFR Part 820 (QMSR) | Legally binding device CGMP, effective February 2026, incorporating ISO 13485:2016 |
Regardless of which framework applies to your operation, auditors evaluate compliance through the same lens.
The 5 Pillars of GMP
GMP auditors organize their evaluation around five dimensions, commonly called the "5 Ps":
- People — trained, qualified personnel operating within documented procedures
- Premises — clean, maintained, and fit-for-purpose facilities
- Processes — documented, controlled, and consistently executed manufacturing steps
- Products — quality-controlled incoming materials and finished goods
- Procedures — current SOPs, work instructions, and records that reflect actual practice

Use this framework for self-assessment before any audit. If your team can walk each of the 5 Ps and produce objective evidence for every element, you're in a defensible position.
The Stakes Are Real
GMP compliance is not a background requirement. Following a February–March 2024 inspection, FDA issued a July 2024 warning letter to Globus Medical citing inadequate CAPA procedures and complaint-handling deficiencies — and explicitly stated that unresolved violations could lead to seizure, injunction, or civil money penalties. FDA also issued import alerts covering specified Olympus facilities in Japan, with products subject to refusal at the US border.
At smaller scale, the consequences follow the same pattern:
- Certification suspension
- Customer disqualification
- Contract loss
The stakes are proportional to your industry, not your intent.
Types of GMP Audits You Will Encounter
Internal GMP Audits (First-Party)
Internal audits — also called self-inspections — are conducted by the organization's own quality team to find gaps before external scrutiny arrives. They are not optional. ISO 9001 (Clause 9.2), AS9100D (Clause 9.2), and ISO 13485 (Clause 8.2.4) all require documented internal audit programs at planned intervals — frequency should reflect process importance, prior results, and organizational change, not just a fixed calendar date.
Critically, findings from internal audits must feed into your CAPA process. An internal audit that produces a finding with no corrective action is itself an audit finding.
Second-Party Audits (Customer and Supplier Audits)
Second-party audits are conducted by a customer, brand owner, or prime contractor evaluating a supplier's GMP compliance. These are common in aerospace supply chains, defense manufacturing, and contract manufacturing relationships.
Customer audits typically use proprietary checklists and can directly affect your approved supplier status. Boeing, Lockheed, and other Tier 1 primes audit supply chain compliance as part of ongoing surveillance — not just at onboarding. A weak internal audit program becomes visible quickly when a sophisticated customer auditor arrives.
Third-Party Certification and Regulatory Audits
Two distinct types fall into this category, and the consequences differ significantly:
- Certification audits — conducted by an accredited registrar to award or maintain ISO 9001, AS9100D, or ISO 13485 certification. These are contractual assessments conducted by appointment.
- Regulatory inspections — such as FDA inspections, which exercise statutory authority under federal law. Routine device inspections are generally preannounced; for-cause inspections may not be. FDA classifies inspection outcomes as NAI (no objectionable conditions), VAI (objectionable conditions not currently warranting action), or OAI (action recommended).

Preparation logic for both is the same — but a regulatory finding carries statutory consequences that a certification nonconformity does not.
What GMP Auditors Actually Evaluate
From a practitioner's perspective: auditors are not running through a rigid checklist looking for boxes to tick. They're looking for evidence that quality requirements are embedded in daily operations — not just documented in binders.
An auditor who finds a well-written SOP alongside records that contradict it will score that as a worse finding than no SOP at all. It reveals a system that exists on paper only.
ISO 19011:2018 defines audit evidence as verifiable records, statements of fact, and other information relevant to audit criteria — gathered through observation, measurement, interviews, and document review. A document alone does not establish that the documented practice is consistently implemented.
Personnel and Training Records
Auditors evaluate whether employees performing quality-critical work are trained, qualified, and operating within documented procedures. They will:
- Request training records by employee and role
- Look for role-specific competency requirements
- Speak directly with production staff
An employee who cannot describe their own procedure is an audit finding — regardless of what the training log says.
Facilities, Equipment, and Calibration
Physical environment assessments cover building condition (walls, floors, lighting, pest control), equipment maintenance logs, and calibration records for measuring instruments.
Calibration gaps are among the most consistently cited findings across manufacturing audits. Auditors commonly flag:
- Expired calibration certificates still on file
- Instruments in active use with no documented calibration interval
- Failed instruments with no documented assessment of product impact
Documentation, Records, and Document Control
Auditors evaluate whether documents are current, controlled, and accessible — and whether actual practice matches what the documents say. Common failures include:
- Outdated SOPs still in circulation at workstations
- Incomplete revision histories or missing approval signatures
- Records with blank fields, missing dates, or no trainer identification
Records must be complete, legible, and retrievable. If an auditor has to wait 20 minutes while someone searches through cabinets, that signals systemic weakness before a single record is reviewed.
Process Controls and Nonconformance Handling
Auditors pull nonconformance records to assess whether root cause analysis was actually performed or whether corrective actions only addressed the symptom. This is one of the most visible gaps between a compliant-looking system and a capable one.
Data from DNV's analysis of 25,000+ companies and 250,000 audit results found that more than half of audited organizations had nonconformities in ISO 9001 Chapter 6 (Planning), with Clause 6.1 representing 35.4% of planning-related findings. When CAPA quality is poor, those planning gaps don't get resolved — they get documented, closed on paper, and repeated at the next audit cycle.
How to Prepare for a GMP Audit
Preparation is not a pre-audit scramble. Auditors can tell the difference between records that were recently reconstructed and records that reflect genuine ongoing compliance activity. Teams that start preparing three weeks before an audit are already behind.
Step 1: Conduct a Pre-Audit Gap Assessment
Start with a structured internal review using a checklist mapped to the standard being audited. Walk the facility as an auditor would, score each area against requirements, and document every gap found.
The assessment should be performed by someone independent of the area being reviewed. Any findings must be addressed with documented corrective actions before the audit — not after. An AI Workbench trained on your specific standard (ISO 9001, AS9100D, ISO 13485) can generate clause-specific checklists and gap analysis reports on demand, cutting this step from days to hours.
Step 2: Review and Verify All Documentation
Pull every SOP, work instruction, training record, calibration log, and corrective action file an auditor is likely to request. Verify:
- All documents are current and signed
- Revision histories are complete
- No superseded SOPs are posted at workstations
- Training records reflect the current procedure revision
Document control failures are disproportionately common findings because they signal systemic weakness in the quality system — not just an isolated administrative error.
Step 3: Train and Prepare Your Team
Production floor personnel will interact with auditors, and their answers matter. Before the audit:
- Brief the team on what to expect from auditor questions
- Coach responses: answer what is asked, offer nothing extra, say "I don't know" rather than guessing
- Conduct focused refreshers on the procedures most likely to be observed
Document this briefing with dated records. Those records can serve as objective evidence of pre-audit training activity.
Step 4: Perform a Facility Walk-Through with Fresh Eyes
Walk the facility from the auditor's entry point through each production and support area. Look for:
- Damaged surfaces, improper storage, unlabeled containers
- Calibrated instruments past their calibration interval
- Chemical storage that doesn't match documented procedures
Everything caught in this walk-through is a corrective action on your terms. Everything missed becomes a finding on the auditor's report.
Step 5: Prepare Audit Logistics and Evidence Packages
Audit day logistics signal organizational competence before the auditor reviews a single document:
- Assign escorts for each area
- Designate a quiet space for document review
- Stage key records in retrievable format
- Brief management on the audit agenda
The ability to retrieve any requested record within minutes — rather than searching through file cabinets — makes a measurable impression on how auditors assess the maturity of your quality system. QMS Learning's Manager Dashboard compiles training records, completed scenario logs, and AI-generated compliance artifacts into a single exportable PDF — ready to hand an auditor without a search.

Common GMP Audit Findings and How to Prevent Them
After writing over 1,000 audit findings, Will Trikha — who built QMS Learning from two decades on aerospace audit floors — observed the same categories appearing repeatedly. Not because teams don't know the requirements, but because the systems they build aren't maintained under the pressure of daily production. The five categories below are predictable — and each one has a clear prevention path.
Inadequate or Expired Calibration Records
The finding: Instruments in active use with no current calibration certificate, calibration intervals not defined in a documented schedule, or devices that failed calibration with no assessment of product impact.
Prevention:
- Build a calibration register with defined intervals and assigned ownership per instrument
- Create a quarantine or impact-assessment process for any instrument found out of calibration before it returns to service
- Set calendar alerts for upcoming expiration dates so no certificate lapses during active production
Training Records That Don't Match Current Procedures
The finding: Employees trained to an older procedure version after a revision, training records with no date or trainer identification, or production personnel who cannot accurately describe their current work instruction.
Prevention:
- Link document control directly to your training program — every revision should trigger a retraining flag automatically
- Require new dated records before the updated procedure goes live, not after
- Capture read-and-understand acknowledgments per person, per revision, with timestamps — that's the objective evidence auditors look for
QMS Learning's Document Management System handles this automatically: acknowledgments are logged by person, by revision, with timestamps, so the audit trail builds itself.
Corrective Actions That Address Symptoms, Not Root Causes
The finding: CARs that document what happened and what was immediately fixed, but contain no root cause analysis, no systemic cause identification, and no preventive action to stop recurrence. Auditors treat CAPA quality as a direct read on quality system maturity — weak CAPAs generate findings even when the original nonconformance was minor. Structured methods like 5-Why and fishbone analysis are expected, applied proportionally to severity.
Prevention: Treat every CAPA as an opportunity to demonstrate that your system learns. Document the root cause, the systemic cause, the corrective action, and the effectiveness verification. Auditors look for effectiveness verification with a defined timeline — "closed" without it signals the system corrected the paperwork, not the problem.

Outdated or Uncontrolled Documents in Use
The finding: Superseded SOPs still posted at workstations, documents without revision numbers or approval signatures, or printed records that don't match the controlled master.
This finding tells an auditor the organization doesn't know which version of a requirement is currently being followed.
Prevention: A functioning document control system with retrieval, obsolescence, and distribution controls must prevent an outdated document from staying in active use after a revision is released.
Facility and Equipment Maintenance Gaps
The finding: Missing entries in preventive maintenance logs, damaged surfaces in production areas, equipment running past its scheduled maintenance interval.
Maintenance gaps are damaging in audit context because they suggest the quality system exists independently of actual operations — the facility should not look different on audit day than it does on any other day.
Prevention: Assign ownership for every piece of equipment on the PM schedule. Gaps closed only before an audit are the clearest signal to an auditor that the system isn't functioning — the standard expects year-round compliance, not audit-week sprints.
Building Audit Readiness That Lasts Beyond the Audit Day
There's a meaningful distinction between audit preparation (a point-in-time activity) and audit readiness (a continuous organizational state). Teams that only mobilize before an audit will always be behind. Teams that maintain current documentation, regular internal audits, and trained personnel can walk into any audit with confidence regardless of lead time.
A continuous audit readiness model looks like this in practice:
- A rolling internal audit schedule that covers all QMS elements within a defined cycle
- A live corrective action log with assigned owners and due dates
- Calibration and maintenance schedules that are actively managed rather than retroactively completed
- Training records that reflect current procedures at all times

Maintaining all four elements simultaneously is where most teams struggle. Pulling records from shared drives, reconstructing revision histories, and chasing down training logs is what makes audit preparation feel overwhelming — especially when teams carry obligations across multiple standards at once. A centralized system that connects training records, document control, and CAPA evidence removes that assembly burden before it starts.
QMS Learning's platform is built around that model. Key components include:
- Role-specific training pathways scoped to ISO 9001, AS9100D, and ISO 13485 — built by practitioners, not academics
- AI Workbench that diagnoses compliance problems and generates auditor-ready documentation automatically
- Manager Dashboard that produces a single exportable PDF — training records, completed scenarios, AI-generated artifacts, and timestamped activity — accepted by registrars as objective evidence on first submission
When those components work together, audit preparation stops being a scramble. Quality teams spend less time assembling evidence and more time resolving the gaps that actually matter.
Frequently Asked Questions
What does GMP stand for?
GMP stands for Good Manufacturing Practice — a set of regulatory requirements ensuring products are consistently produced to defined quality standards. It applies across pharmaceutical, food, medical device, and general manufacturing industries through frameworks including ISO 9001, ISO 13485, and FDA 21 CFR Part 820.
What are the 5 pillars of GMP?
The 5 Ps: People (trained, qualified personnel), Premises (clean, maintained facilities), Processes (documented and controlled manufacturing steps), Products (quality-controlled materials and finished goods), and Procedures (standard operating procedures and complete records).
What is the checklist for a GMP audit?
A GMP audit checklist typically covers:
- Personnel training and qualifications
- Facility and equipment condition
- Calibration records and document control
- Process controls, nonconformance handling, and CAPA records
Specific items vary by standard — an ISO 9001 checklist differs meaningfully from an FDA 21 CFR Part 820 inspection checklist.
How much does a GMP audit cost?
Internal audits cost primarily in staff time. Third-party certification audits vary by facility size, scope, and certification body — no registrar publishes a fixed price, but costs scale with audit duration. Regulatory FDA inspections carry no direct fee but can result in significant remediation costs if findings generate formal observations or warning letters.
How long does a GMP audit take?
A single-site internal audit typically runs one to two days. A full third-party certification audit at a larger facility can run three to five days or more. FDA inspections vary widely — they can extend significantly if investigators identify systemic issues worth pursuing.
What happens if you fail a GMP audit?
There's no binary pass/fail in most GMP schemes. Findings are classified by severity: minor findings require documented corrective actions; major or critical findings can result in certification suspension or customer disqualification. FDA inspections can escalate to warning letters, import alerts, or consent decrees depending on the nature and persistence of violations.


