The Witness Audit You Thought You Were Ready For
The accreditation body assessor arrives for a scheduled witness audit. Your lead auditor is conducting a Stage 2 at a food packaging company. The audit itself goes smoothly. Your auditor is competent, thorough, and professional. But the assessor is not just watching the audit -- they are reviewing your entire file.
And they find four problems that your internal processes did not catch.
Problem 1: Unsigned Impartiality Declarations
The assessor opens the audit file and checks the impartiality declarations. Every auditor and technical expert assigned to an audit must sign an impartiality declaration confirming they have no conflict of interest with the client. It is a basic requirement of ISO/IEC 17021-1:2015.
Your lead auditor signed hers. But the technical expert who participated on day two never signed his. His declaration form is in the file, but the signature line is blank. Nobody noticed.
How Certiva prevents this. In Certiva, impartiality declarations are part of the audit workflow. Each team member is prompted to complete and sign their declaration within the platform. The audit cannot advance to the next phase until all assigned team members have signed. It is not a reminder or a checklist item -- it is a gate. If the technical expert has not signed, the system blocks progression. The unsigned declaration is impossible to miss because the workflow will not move past it.
Problem 2: A Coverage Gap in the Audit Team
The audit scope includes ISO 22000. Your lead auditor is qualified for ISO 9001 and ISO 22000. Your second auditor is qualified for ISO 9001 only. The audit plan shows both auditors, but the qualification matrix reveals that the second auditor does not hold the EA code required for food safety-related clauses in the scope.
The assessor flags this as a nonconformity. The audit team did not have adequate competence coverage for the full scope.
How Certiva prevents this. When building an audit team in Certiva, the system validates each member's qualifications against the client's scope. It checks standards, EA codes, and scope categories. If the combined team does not cover every required area, the system flags the gap before the audit is scheduled. The planner sees exactly which EA codes are uncovered and can assign an additional team member or replace the unqualified one. The audit plan is not finalized until coverage is complete.
Problem 3: A Nonconformity That Was Never Formally Closed
During the file review, the assessor looks at the previous surveillance audit from ten months ago. A minor NC was raised against Clause 7.1.5 (monitoring and measuring resources). The NC record shows it was issued, and there is a note in the file that says "client sent corrective action evidence by email." But there is no formal closure record. No auditor review. No acceptance or rejection. No date of closure. No evidence linked to the NC record.
The corrective action may have been adequate. But without a formal closure record, the assessor cannot verify it. This generates another finding.
How Certiva prevents this. In Certiva, nonconformity management follows a structured lifecycle. When an NC is raised, it is assigned a due date. The client uploads their root-cause analysis and corrective action evidence through the client portal. The auditor reviews the submission and either accepts it (closing the NC) or rejects it (sending it back for another round). Every action is timestamped and recorded. The NC cannot simply be noted as "done" in a comment -- it must be formally closed through the review process. And critically, if an NC remains open, it gates subsequent workflow steps. An unclosed NC from a previous audit cycle is visible to everyone who opens the client file.
Problem 4: A Report With Misclassified Findings
The assessor reviews the Stage 2 report. In the findings section, there is an entry under Clause 8.5.1 (production and service provision) that reads: "The organization does not have a documented procedure for controlling nonconforming outputs, and three instances of nonconforming product were shipped to customers in the last quarter without detection."
This is classified as an "observation."
The assessor raises an eyebrow. A systematic failure to control nonconforming outputs, with evidence of repeated occurrence and customer impact, is not an observation. It is, at minimum, a minor nonconformity -- and a strong case could be made for a major. The misclassification affects the audit conclusion and potentially the certification decision.
How Certiva prevents this. Certiva's AI report review analyzes the language and substance of each finding against its classification. When a finding describes a failure to meet a requirement -- especially one with evidence of recurrence -- but is classified as an observation rather than a nonconformity, the AI flags it. The review returns typed findings (critical, major, minor, warning) as inline comments, giving the auditor a clear signal that the classification needs reconsideration before the report is submitted. This does not override the auditor's judgment, but it ensures that obvious misclassifications are caught before the report leaves the CB.
The Pattern Behind the Problems
None of these four issues are rare. They are among the most common findings during accreditation assessments. They all share a root cause: the CB's processes rely on people remembering to do things rather than on systems that enforce them.
Certiva does not make these problems impossible. But it makes them visible, flagged, and blocked before they reach the point where an accreditation assessor discovers them. That is the difference between a system that relies on human vigilance and one that enforces compliance by design.