A Finding Is Not a Verdict: How to Write One That Actually Gets Fixed

A couple of years ago I found an internal audit finding that said, in its entirety: “Supplier management is weak.” That was it. No requirement, no evidence, no record number. Just a verdict, handed down like a citation for vibes.

The quality manager did what any reasonable person does when handed a verdict with no evidence: he argued with it. And he won, because there was nothing to argue against. Three months later the same gap showed up in a notified-body audit, this time with a clause number attached, and nobody was arguing anymore.

Here’s the thing about a finding. It is not an opinion of the quality system. It is not a performance review of the person who runs the process. It’s a small, boring, factual object that says: here is a requirement, here is what I saw, and the two don’t match. Get that object right and it gets fixed. Get it wrong — vague, editorial, or misfiled — and it either dies in a spreadsheet or comes back to haunt you at the worst possible time.

The three parts of a finding that actually works

A good finding has exactly three moving parts, and ISO 19011 (the guidance auditors are trained on) will back me up on all three. A finding is evidence measured against a requirement, full stop.

1. The requirement. Name it. Clause 7.4.1. Your own SOP-042, section 5.3. The customer spec. Whatever it is, a finding without a requirement is just an auditor being grumpy. If you can’t point to the thing that was supposed to happen, you don’t have a finding — you have a feeling.

2. The objective evidence. What did you actually see? A record, a date, a part number, a purchase order. “Supplier X appears on the Approved Supplier List (rev 8) but no supplier evaluation record was located” is evidence. “Purchasing seems disorganized” is a mood. If you covered the difference between showing and telling in your last audit, this is where it pays off — you write down what you were shown, not what you were told.

3. The gap — and nothing else. State that the evidence doesn’t meet the requirement. Then stop. Do not diagnose the root cause. Do not prescribe the fix. Do not speculate about whose fault it is. That’s the process owner’s job during corrective action, and if you do it for them in the finding, you’ve pre-committed everyone to a theory before anyone has investigated.

Put those together and you get something like: “ISO 13485 §7.4.1 requires suppliers be evaluated before selection, with records retained. Supplier X (PO-2025-0342) is on the ASL but no evaluation record was found.” Nobody argues with that. There’s nothing to argue with. It’s just true, and now it gets fixed.

Editorializing: the fastest way to lose a finding

The most common way I see good findings go bad is editorializing. “The purchasing team clearly doesn’t understand the procedure.” “This is sloppy.” “Someone dropped the ball here.”

Every one of those hands the audited party a reason to make it about tone instead of substance. Now you’re in a meeting about whether you were fair, not about the missing record. And — smaller point, bigger consequence — those records are FDA-readable now. Under the QMSR, your internal audit reports lost the old §820.180(c) exemption. An inspector can read your findings. “Operator was careless” is not the sentence you want a federal investigator reading back to you. (More on that in why your internal audit is now a confession.)

Nonconformity, observation, or OFI — and why mislabeling hurts

Once you’ve written the finding, you have to classify it, and this is where people quietly make trouble for themselves. The three buckets:

Nonconformity. A requirement is not met. Full or partial non-fulfillment. This one must go into your finding lifecycle — correction, root cause, corrective action, effectiveness check. Many organizations further grade these as major (a systemic breakdown, or an absent/collapsed process) versus minor (a single lapse in an otherwise working process).

Observation. Not a nonconformity — the requirement is met — but something you want on the record. A trend heading the wrong way, a single lapse that isn’t (yet) a pattern, a “this worked, but only because Dave remembered.” It’s a note to your future self.

Opportunity for improvement (OFI). The requirement is fully met — there’s just a smarter way to do it. An OFI is a suggestion, not a failure. It is never mandatory, and it should never carry a due date.

Here’s the trap. Mislabel a real nonconformity as an “observation” because it felt awkward to write up, and you’ve just excused it from the CAPA process. Nobody has to fix it. Nobody tracks it. It sits there, un-actioned, until an external auditor finds the same thing and writes it up properly — and now you’re explaining why you saw it first and called it a shrug. I have watched this exact movie more than once, and it never ends with the manufacturer looking good.

Go the other way — label every OFI a nonconformity — and you drown your CAPA system in busywork, train everyone to dread audits, and bury the findings that actually matter under a pile of “you could use a better spreadsheet.” The label isn’t bureaucratic hair-splitting. It decides what gets fixed, what gets watched, and what gets thanked-and-shelved.

What to do today

Pull your last internal audit report and read the findings cold. For each one, ask: Can I point to the requirement? Can I point to the evidence? Did I stop before diagnosing the cause? Is the classification honest? If a “finding” is missing the requirement or the evidence, it’s not a finding — it’s a note, and you should either finish it or delete it. If an “observation” is actually a requirement not being met, reclassify it now, while it’s cheap.

This is also exactly the kind of discipline a system of record keeps honest for you. When every finding has to carry its requirement, its evidence, and its classification before it can be logged — and when the trend of what you’re finding is visible instead of buried in last quarter’s PDF — the vague verdict has nowhere to hide. That’s a lot of what we do at Red Hen Admin through the Candor platform: make sure a finding is a real, fixable object before it ever becomes a problem someone with a badge writes up for you.

Write the finding, not the verdict. Name the requirement, show the evidence, and then — this is the hard part — stop talking. The fix is the process owner’s to find. Your job was just to tell the truth about what you saw, in a way nobody can argue with. And yes, the auditor noticed.

Leave a Comment

Scroll to Top