I have stood in plants where the audit binder was pristine — every signature in place, every control plan current, every training matrix glowing green — and walked onto the floor to find operators running a process that bore almost no resemblance to what the documentation described. Not because anyone was dishonest. The audit certified the paper, not the process. Manufacturing Today ran a piece this week by Christina Hoefer on exactly this disconnect — compliance that looks perfect in the binder and fails at the machine. Good article. But the framing is too generous to the audit itself. The problem is not that compliance sometimes fails. Audit methodology was never designed to detect capability drift in the first place.
What your auditor actually verified
A clean audit score certifies that the PFMEA exists and was reviewed within the required cycle. The control plan lists every characteristic, every reaction plan, every measurement frequency. The training matrix shows every operator on every shift signed off on the relevant work instructions. Calibration records are current. The nonconformance log is maintained. The 8D register is up to date. All of this is real. None of it proves the process is capable.
The auditor verified that a system exists. Whether that system is working — whether the Cpk on the critical bore diameter is still 1.67 or has drifted to 1.12 over six months as tooling wore and nobody updated the capability study — that question is almost never asked inside an audit. The standard says you must have a control plan. It does not say the auditor must verify that the control plan reflects what is happening at the machine at 02:30 on a Wednesday.
When I built the greenfield QA/QC department for over 900 employees at SNOP, I had seen enough immaculate binders covering broken processes that I designed the internal audit system to test capability, not just documentation. An auditor who finds nothing and a customer who finds a nonconformance on the same part number in the same week — that is not bad luck. The audit measured the wrong variable.
The compliance–capability gap
Cpk does not hold still. Tooling wears. Fixtures loosen. Material lots vary. Environmental conditions shift between the morning audit and the night shift that produces the parts your customer actually receives. The process that was capable during the last PPAP submission is not the same process today — and the gap between those two states is where escapes live. Audits measure in snapshots. Capability drifts on a continuous curve. That structural mismatch is the flaw, not an implementation detail.
At Witte Automotive I saw this directly. We ran QRQC — quick response quality control — with daily rapid-response logs capturing deviations, near-misses, and first-time-through failures in real time. Those logs surfaced drift that quarterly audits had missed for months. Not because the auditors were incompetent. Their methodology sent them to the filing cabinet instead of the machine. The QRQC data was telling us the process was shifting every week. The audit was telling us the paperwork was in order. Both correct. Only one useful.
A clean audit certifies that you wrote down what you intended to do. It says nothing about whether what you are doing still works.
Redesigning the audit to test effectiveness
The fix is not to add more checkboxes. It is to change what the audit interrogates. At SNOP, I built the internal audit around a simple principle: every finding had to be backed by live data, not a signed form. If the control plan says you measure a characteristic every fifth part, the auditor pulls the actual measurement log from the last three shifts and checks whether the frequency was maintained. If the PFMEA lists a detection rating of 2 on a critical characteristic, the auditor asks to see the last capability study and checks whether the data supports that rating.
This sounds obvious. It is not standard practice. Most audit checklists are still built around does the document exist? rather than does the document describe reality?
Three things make this work:
- Live data walls — visibility boards showing capability indices, first-time-through rates, and QRQC open issues by cell, refreshed at least per shift. If the data is not visible to the people running the process, the auditor will not see it either.
- QRQC triggers tied to capability indices — when Cpk drops below a defined threshold on a critical characteristic, that is a QRQC event. Not a trend to monitor. An event that demands containment and an A3 within the same day.
- A3 reviews that interrogate the control plan against shift data — the A3 is not a reporting format. It is a structured way to ask why the process is drifting and what in the control plan needs to change to reflect the new reality.
None of this requires a new standard. IATF 16949 already asks for effective process control. AS9100 already demands that you monitor process capability. The standards are adequate. The audit methodology that reduces them to a documentation checklist is not.
Key takeaways
- A clean audit score certifies documentation, not capability. Treat the two as the same and you will be blindsided by a customer escape that was already visible in your own data.
- Capability drift is continuous; audits are periodic. The gap between reviews is where nonconformances are born — and where QRQC and live data walls do the work the audit cannot.
- Redesign internal audits to interrogate live shift data, not signed forms. If the auditor cannot find evidence of drift, they are looking at the wrong source of truth.
- If your audit finds nothing and your customer finds something on the same process in the same quarter, the audit measured the wrong variable. Fix the methodology, not the auditor.
When I started at SNOP, the temptation was to build a QA/QC department that would pass any audit cleanly. I built one that makes audits uncomfortable — because an audit that finds nothing on a quietly drifting process is not a success. It is a failure wearing a clean score.