Audit Readiness, Evidence

The 80-Document Trap: Procedures Are Not Executed Evidence

A complete index of approved procedures feels like readiness. It is not. An auditor will pick one procedure and ask to see the records it produced last quarter, and that is where most quality systems come apart.

July 2026 6 min read Bob Jordan

A quality manager sends a spreadsheet before the first call. Eighty rows. Document number, title, revision, approval date, owner. Every row populated. It represents months of genuine work, and the message accompanying it is usually some version of: we think we're in reasonable shape, we just want a second opinion before the audit.

The spreadsheet is real and the work was worth doing. But it answers a question the auditor is not going to ask.

An index of approved procedures proves you decided how the work should be done. It proves nothing about whether the work was done that way.

Two categories that get filed together

Every quality system contains two fundamentally different kinds of document, and most document indexes list them in a single undifferentiated column.

Controlled documents state intent. Procedures, work instructions, specifications, drawings, forms, templates, the quality manual. They are approved, revision-controlled, and describe what is supposed to happen. There is normally one current version of each.

Executed records are evidence. A completed inspection sheet with a real measurement and a real initial. A signed device history record for lot 24-A. A calibration certificate for the specific gauge used on the line last Tuesday. A training record showing an operator was qualified before they performed the operation. These are generated continuously, they are never revised, and there are thousands of them.

A procedure without its records is an unkept promise. Records without a procedure are activity without control. An auditor examines both, but spends most of the visit on the second, because that is where the truth is.

How the audit actually goes

Inspections are not conducted by reading your document index top to bottom. They sample, and they follow threads. A realistic sequence:

  • The pick The auditor selects a shipped lot, often one you did not anticipate, sometimes one connected to a complaint.
  • The record "Show me the device history record for this lot." Now the question is whether that record exists, is complete, and is signed by people who were authorized to sign it.
  • The trace inward The DHR references an inspection. Show the inspection record. It cites a gauge. Show that gauge's calibration status on the date of use. An operator initialed a step. Show their training record, dated before that shift.
  • The trace outward The lot used a critical component. Show incoming inspection for it. Show the approved supplier record. Show the specification the component was accepted against.
  • The comparison Now the procedure comes out, not to be read on its own but to be compared against what the records show actually happened.

Every step of that chain is an executed record. The document index contributes exactly one item, at the end, and only as a reference point for judging the records.

The failure modes, in order of frequency

The procedure describes a process nobody follows

Frequently the procedure is more rigorous than reality, written by someone thorough, describing three approval signatures where the line collects one. This is a finding against your own document, and it is self-inflicted. The procedure should describe the process you actually run and can defend, not an aspirational one.

The records exist, at the factory, in an inaccessible form

Very common in outsourced manufacturing. The factory maintains excellent production records, in Chinese, in paper binders, structured around its own system. They exist. You cannot produce them in the room, cannot read them quickly, and have never verified they contain what your specifications require. An auditor asking a U.S. specification owner for evidence is not satisfied by knowing the evidence exists somewhere.

The form was approved but never issued

The inspection form is in the index at revision 2. The line is still using a photocopy of revision 1, or a locally made Excel version with different fields. The document index is accurate about the document and wrong about reality.

Records exist but the chain does not connect

Individually complete records with no linkage. A DHR that does not identify the component lot. An inspection record with no traceable link to the units inspected. Each document is fine; the chain from finished device back to material and process cannot be walked.

Signature and date discipline

Blank fields. Initials without dates. A single signature applied to a month of production in one sitting. Corrections without attribution. These read as small housekeeping issues and are treated as serious, because they undermine confidence in every other record you produce.

Reclassifying your index

The exercise is short and uncomfortable. Take the spreadsheet and add three columns.

Column What it asks
Type Controlled document, or executed record? Most indexes turn out to be almost entirely the first.
Evidence produced For each procedure: what record does it generate? Name it specifically. If the answer is "none," the procedure describes an activity that leaves no trace.
Last instance Can you produce the most recent example of that record, this week, without calling the factory? Not "does it exist," but can you produce it.

The third column is where most of the reality lives. An eighty-row index typically reduces to a handful of record types anyone can actually retrieve, and that shortfall is your real audit exposure.

What to fix first

Do not start at the top of the list. Order the work by what an auditor is most likely to pull and what carries the most risk if it is wrong:

  1. Device history records for recent shipped lots. The most likely first request and the thread everything else hangs from.
  2. The records supporting your highest-severity risk controls. If a safety feature is verified by a production test, that test's records matter more than anything else on the list.
  3. Calibration and training records for the operations in those DHRs. The two most common places a good record chain breaks.
  4. Incoming inspection and supplier approval for critical components.
  5. Complaint and CAPA records, including complaints that were closed without investigation, a pattern auditors look for specifically.

Only after those does it make sense to work on procedures, and by then you will know which procedures need rewriting because you will have seen what the records actually show.

Making the difference visible

The reason this problem persists is that a folder tree cannot tell you which of its contents are promises and which are proof. Both are files. Both have dates. Both look complete in a directory listing.

A system that separates the two, and that knows a validation section with no executed evidence is blocked rather than merely empty, surfaces the gap months before an auditor does. That is the distinction the readiness view in our workspace is built around: not how many documents you have, but which requirements have evidence behind them and which do not.

The eighty-document index is not wasted work. It is the raw material. It just is not the answer, and the difference between those two is usually discovered at the worst possible moment.

Working through this on a real product?

We help U.S. medical device companies control outsourced development and manufacturing in Asia: evidence, design transfer, and on-site supplier readiness. A short call is usually enough to tell whether we can help.

Book a discovery call Medical device services
Bob Jordan

Bob Jordan, Founder & CEO, AsianOPS

25+ years across product design, engineering, sourcing, manufacturing and operations, including Class II and Class III medical device programs and ten years living and working in Shenzhen. Previously PRTM Management Consultants, Cardinal Glass, Guardian Industries and BASF. MBA, University of Virginia Darden School of Business.