How to Write an Audit Checklist
A practical guide to writing an audit checklist with scope, evidence, findings, actions, closure review, sample language and operational criteria.

An audit checklist is a working tool for checking evidence against agreed criteria. It is not a memory aid full of vague prompts, and it is not a compliance certificate by itself. A useful checklist tells the reviewer what is being audited, what evidence to inspect, how to record findings, what actions are required and how closure will be verified.
Use this scenario: a consulting firm wants to audit the quality of a completed strategy review before issuing the final recommendations report. The firm needs to check that the approved scope was followed, interview notes are stored correctly, assumptions are marked, client approvals are recorded and follow-up actions have owners. The checklist should help a reviewer inspect actual records, not merely ask whether the team "did good work."
Define audit scope and criteria
Start with the audit objective. What decision should the checklist support? For the consulting scenario, the objective might be to confirm that the engagement file supports the recommendations report and that open delivery risks have been assigned before client handoff.
Then define the scope:
- Engagement name and client
- Time period covered
- Work products included
- Systems or folders included
- People or roles included
- Exclusions
- Reviewer and review date
Next, define criteria. Criteria are the requirements used to judge evidence. They may come from the statement of work, internal quality procedure, client instructions, regulatory requirement, standard operating procedure or approved project plan.
Draft language:
Audit objective: determine whether the Northstar strategy review file contains sufficient evidence to support the recommendations report and whether unresolved delivery risks are recorded before final handoff. Scope includes discovery interviews, analysis workbook, recommendation slides, decision log and client approval records dated 1 August to 15 September 2026. Criteria are the signed statement of work, consulting quality procedure QP-04 and the client-approved engagement closeout requirements.
The EPA describes technical audits as systematic and objective examinations to determine whether activities and results comply with planning documents, are implemented effectively and are suitable to achieve goals (EPA quality management tools for projects). That definition is useful beyond environmental work: an audit checklist should connect objective review to defined criteria.
Identify evidence to inspect
Once scope is set, list evidence for each criterion. "Interview process complete" is not evidence. Interview schedule, signed attendance record, notes stored in the correct folder and client-approved interview guide are evidence.
For each checklist item, include:
- Requirement or criterion
- Evidence to inspect
- Sample size or selection method
- Reviewer notes
- Result
- Finding classification
- Action required
Draft checklist item:
Criterion: Client interviews were conducted using the approved interview guide. Evidence: final interview guide, calendar record, interview notes for sampled participants and decision log entry approving any changes. Sample: five interviews, including at least one sales, one operations and one finance participant. Result: conforming / nonconforming / improvement opportunity / not applicable.
Sampling matters. If you review one file and declare the whole engagement clean, the checklist overstates what happened. If you review every file when a sample would be enough, the audit may become too heavy to repeat. State the sample method so the result can be understood later.
EPA guidance on quality project planning emphasizes that quality plans describe activities needed to satisfy performance and acceptance criteria, and the EPA quality program materials include checklists as review tools (EPA QAPP guidance). The practical lesson is to decide what evidence would show that the criterion was met before the reviewer begins.
Write checklist questions that test behavior
Good checklist questions are specific, observable and tied to evidence. Avoid questions that invite unsupported opinion.
Weak question:
Was the project managed well?
Better question:
Does the decision log show client approval for each scope change affecting the recommendations report?
Weak question:
Are files organized?
Better question:
Are final client-provided data files stored in the approved engagement folder with restricted access and a version date?
Include space for notes. A yes/no field is too thin for most audits. The reviewer should be able to record evidence inspected, limits and context.
Draft language:
Checklist result: Partially conforming. Evidence inspected: decision log entries DL-04 to DL-07 and email approval from client sponsor dated 5 September. Limitation: approval for the pricing sensitivity appendix was verbal and is not yet recorded. Required action: engagement lead to obtain written confirmation or remove the appendix before final issue.
This makes the checklist useful to the team that must fix the gap.
Record findings and actions
Findings should connect three elements: requirement, evidence and effect. A finding that says "documentation missing" is less useful than one that says which requirement was not met, what evidence was absent and why it matters.
Finding categories may include:
- Conforming
- Nonconforming
- Observation
- Improvement opportunity
- Not applicable
- Not inspected
Draft finding:
Finding F-02: The statement of work requires client approval for material scope changes. Evidence inspected shows written approval for the additional margin analysis but no written approval for the added pricing sensitivity appendix. Effect: the final report may include advice outside the approved scope. Action: engagement lead to obtain written approval or remove the appendix before issue.
Actions need owners and verification evidence:
Action A-02: Engagement lead to obtain client sponsor approval for the pricing sensitivity appendix or remove the appendix from the report. Due: 18 September 2026. Verification evidence: approval email stored in decision log or revised report showing appendix removed. Closure reviewer: quality lead.
Do not close findings because a meeting was held. Close them when the required evidence exists.
Build closure review into the checklist
The last section should not be an afterthought. Closure review confirms whether findings are resolved, accepted with risk or escalated.
Closure criteria:
- Every finding has an owner.
- Every required action has a due date.
- Verification evidence is defined.
- Open risks are accepted by an authorized person.
- The reviewer records limitations.
- The final checklist is stored with the audited records.
- The process owner receives the result.
Draft approval language:
Closure review: The quality lead confirms that findings F-01 and F-03 are closed with evidence attached. Finding F-02 remains open and blocks final issue until client approval is recorded or the appendix is removed. The engagement partner accepts no other limitations. Checklist approved for closeout review on [date].
EPA Region 1 guidance for quality project plans asks organizations to describe how assessment findings and corrective actions are documented and communicated, who responds and how actions are tracked to completion (EPA Region 1 QAPP guidance). That is the heart of closure review.
Prepare the checklist for reuse
Before you turn the audit checklist into a standard form, test it on one real file. Mark unclear questions, missing evidence fields and items that produce opinions instead of findings.
Operational review criteria:
- The scope tells reviewers exactly what is in and out.
- Criteria are named and current.
- Evidence fields are specific enough to inspect.
- Sampling rules are stated.
- Results allow more than a bare tick.
- Findings connect requirement, evidence and effect.
- Actions include owner, due date and verification evidence.
- Closure cannot happen without authorized review.
For a Word starting point, the consulting audit checklist template includes editable sections for objective, scope, criteria, evidence, sampling, findings, actions, verification and approval. Use it as a drafting structure, then adapt the checklist to your own criteria and records.
A strong audit checklist makes the review repeatable. It does not replace judgment; it gives judgment a documented path to follow.
Last updated: September 26, 2026
Frequently Asked Questions
Related Articles
Audit Checklist Best Practices
Best practices for audit checklists, including scope, evidence, findings, actions, closure review, failure modes and sample wording.
Audit Checklist Checklist: Review Your Audit Form Before You Use It
A practical audit checklist checklist with decision gates for scope, evidence, findings, actions and closure review.
Audit Checklist Examples: Scope, Evidence, Findings and Closure
Audit checklist examples for consulting work, covering audit scope, evidence to inspect, findings and actions, closure review and practical draft wording.
Business Continuity Plan Best Practices for Consulting Teams
Business continuity plan best practices for consulting teams, including critical services, recovery priorities, communications, exercises and review criteria.
Business Continuity Plan Checklist for Consulting Teams
A practical business continuity plan checklist for consulting work, covering critical services, recovery priorities, communications, exercises and review criteria.
Business Continuity Plan Examples: Consulting Scenarios and Recovery Priorities
Business continuity plan examples for consulting teams, with critical services, recovery priorities, communications, exercises and review criteria.