Audit day has a rhythm to it.
The binder is ready. The conference room is booked. The quality manager has been preparing for three weeks.
And the team is confident, because the work is good.
That confidence is usually justified. Most operations that get audited are run by people who care about doing the job right.
Here is what catches them anyway.
An auditor is not there to evaluate whether you do good work. An auditor is there to evaluate whether your record proves you did. Those are two different tests, and only one of them is graded.
The finding never lands on the work. It lands on the gap between the work and the evidence.
That gap is where AS9100, NADCAP, ITAR, and ISO findings actually come from. Not from shops that cut corners. From shops that did the job correctly and kept the proof in somebody’s inbox, or in a folder nobody controls, or nowhere at all.
Here are eight of the most common audit gaps in regulated manufacturing, and the shift that closes each one.
1. The Documents Nobody Controls
Every uncontrolled copy of a controlled document on your team’s shared drive is a finding your next auditor already has a template for. The auditor asks which version was used on the job. Your team hunts through folders and inboxes. Nobody can prove it.
A drawing gets emailed to production. Someone saves it to their desktop for convenience. Two months later, engineering releases a revision. The controlled copy in the document system updates. The desktop copy does not. The operator runs from the desktop copy and the part builds to the old revision. Inspection catches it, or the customer does, or the auditor does. The CAPA opens and the root cause gets written as human error. The real root cause is that anyone could keep a copy where control did not reach.
The shift: Deliver the current document to the point of use instead of expecting people to go get it. Retire old versions automatically. Log every access, so the answer is already in the record when someone asks.
A controlled document on somebody’s desktop is not a copy. It is a liability.
2. The Training That Expired Quietly
Every operator running work on a qualification that lapsed last quarter is a finding, a CAPA, and a batch of product your customer gets to question. The auditor picks one traveler, then one operator name on it, then the training record behind that name.
The training happened. The sign-in sheet got scanned and the file went into a folder. Then the revision changed and the requalification interval came due, and nobody got a notification, because a folder does not know what today is. The supervisor assigned the job to the most experienced operator on the shift. That operator is genuinely good at the work. The record just says they were not current. Both things are true, and only one of them is in evidence. Now the auditor does not have an isolated finding, because if that record went stale unnoticed, every record can. The corrective action is not retraining one person. It is proving the other two hundred.
The shift: Tie qualification to the operation instead of to a folder. Flag records before they expire, not after. Block the assignment when currency lapses, so the floor and the record never disagree.
An expired qualification does not mean your operator forgot how to do the job. It means you cannot prove they knew.
3. The Signature That Proves Nothing
Every use-as-is disposition signed without a record of who was authorized to sign it is product your customer can reject after you have already been paid for it. The auditor does not ask whether the part shipped. The auditor asks who accepted it, which approval matrix gave that person the authority, and what evidence they reviewed.
A part comes back out of tolerance on one dimension. Engineering looks at it, the feature is non-critical, the call is use-as-is, and the part ships. That call was probably correct. But the record shows a name and a date. It does not show that the person held disposition authority for that characteristic, or the analysis behind the call, or whether the contract required a concession request first. Eighteen months later the assembly fails in the field. The customer traces it back and does not find a bad decision. They find a decision they have no way to evaluate. So they stop trusting every disposition on the program.
The shift: Record who approved, what authority they held, and what they reviewed, at the moment of the decision. Route approvals to the person the matrix actually names. Keep the basis attached to the part, the job, and the program.
A signature tells you a decision was made. It does not tell you the decision was anyone’s to make.
4. The Gap Between Two Stamps
Every lot that changes hands without a record of the transfer is a lot you cannot bound when a defect surfaces, and what you cannot bound, you contain in full. The auditor traces a serial number. Receiving to first operation, recorded. Final inspection to shipping, recorded. The five moves in between, nothing.
The traveler moves with the parts and every department signs it when the work is done. That is an operation record. It is not a custody record. The lot sat in a staging rack for two days between operations. Half of it ran on second shift. A supervisor pulled four pieces for a hot order. Somebody moved the rest to another cell when a machine went down. None of that is written anywhere. Then a defect shows up at the customer and the failure mode points to handling between operations. You know the parts were made and you know they were inspected. You cannot say who had them, when, or which ones split off. So the containment boundary stops being the lot and becomes everything that could have touched that rack.
The shift: Record the transfer, not just the completion. Capture who took custody, when, and how many pieces. Keep split lots attached to the parent, so the trace narrows instead of widening.
The size of your recall is set by the gaps in your record, not by the size of your problem.
5. The Gage That Drifted
One gage failing its next calibration check turns every part it accepted since the last good check into product you have to re-evaluate at your own cost. The auditor does not ask whether you calibrate. Everyone calibrates. The auditor asks what you did the last time a gage came back out of tolerance.
A caliper goes out for annual calibration and comes back out of tolerance, reading high by three thousandths. Nothing dramatic happened. It drifted. Now the standard asks one simple question. What did that gage accept in the last twelve months? The sticker tells you when it was due. The certificate tells you it failed. Neither one tells you what it measured. So somebody starts pulling inspection records, and the records list the characteristic and the reading, but most of them do not list the gage. The few that do list an asset number that changed when the tool crib re-tagged everything in March. Now you are reconstructing a year of inspection out of memory and hope, and the honest answer to your customer is that you cannot say which parts are affected. Which means all of them are.
The shift: Stamp the gage identity onto every measurement it takes. Flag the interval before it lapses. When a gage fails, pull the affected parts in minutes and scope the customer notification honestly.
When the gage fails, your uncertainty runs back to the last day you can prove it was right.
6. The Requirement That Stopped at the PO
Every customer requirement that stopped at your purchase order is one you are liable for and your supplier never agreed to, on parts already sitting in your building. The auditor reads the contract, then reads your PO, then asks where the record retention clause went.
The contract arrives with fourteen flow-down requirements. Somebody reads them at contract review and somebody understands them. Then the job gets planned and a buyer cuts a PO from the part number and the quantity, not from the contract. The PO goes out clean and the supplier does exactly what it asked for. The supplier did nothing wrong. But your customer requires ten years of record retention and your supplier keeps records for three. Your customer requires approval before any process change, and your supplier moved heat treat to a second source last spring. Your customer requires right of access, and your supplier never agreed to let anyone through the door. None of that is a supplier failure. It is a flow-down failure, and the flow-down was yours. When your customer audits the program, the finding lands on your certificate.
The shift: Tie flow-down requirements to the part and the program instead of a contract nobody reopens. Push them onto every PO automatically. Keep the supplier’s acceptance in the record, next to the requirement it answers.
A requirement you did not flow down is still a requirement you will be held to.
7. The Corrective Action That Corrected Nothing
Every CAPA closed without verifying it worked is a finding you already paid to fix and will pay to fix again, at a higher price the second time. The auditor pulls a corrective action you closed last year, reads the root cause, reads the action, reads the closure signature, and then asks the only question that matters. How do you know it worked?
The finding came in, the investigation ran, the root cause got written, and the corrective action was to retrain the operators and update the work instruction. Both got done and both got signed. The CAPA closed inside 30 days, which is the number everyone reports. Nobody went back at 90 days to look at the defect rate. Nobody pulled the next ten jobs to see whether the new instruction was followed. Nobody asked whether that root cause was a root cause, or the first plausible answer that stopped the questions. Then the same problem comes back, and this time the auditor does not write you up for the defect. They write you up for the system that was supposed to catch it. A repeat finding does not cost twice what the first one cost. It puts every corrective action you have ever closed back on the table.
The shift: Define what evidence of effectiveness looks like before you close anything. Set the check date and keep the record open until the data arrives. Measure recurrence, not closure speed.
Closing a corrective action proves nothing except that somebody stopped working on it.
8. The Drawing Anyone Could Open
Every export-controlled drawing sitting in a folder anyone in your building can open is a potential ITAR violation, and those penalties are counted per violation, not per incident. The auditor does not ask whether the drawing is marked. It is marked. The auditor asks who opened it last quarter, whether all of them were authorized, and where the log is that proves it.
The drawing lives in the engineering folder and the permissions were set up six years ago. Since then, three reorganizations, two IT contractors, and one new engineer on a work visa added to the engineering group on day one so they could get started. Under ITAR, releasing controlled technical data to a foreign person can count as an export, even inside your own building. Nobody shipped anything and nobody emailed anything out. The folder was simply open, and the file server was never configured to record who opened what. So the question is no longer whether it happened. It is whether you can prove it did not. Then add the newest reader of your engineering data, the AI tool your team started using this year. It can read that folder too, on behalf of anyone who asks it a question. If the AI does not respect the same permissions as the folder, it becomes a faster way around them.
The shift: Tie access to the person’s authorization instead of their department. Log every open, every download, and every AI query. Answer who saw this in minutes, with evidence.
If you cannot show who saw it, you cannot show who did not.
The Common Thread
Every one of these eight gaps shares the same underlying pattern.
The work got done correctly, and the evidence of it was left somewhere the operation does not control. The document was current in the system and stale on the desktop. The operator was capable and the record was expired. The disposition was sound and the authority behind it was never captured. The parts were good and the custody chain had holes. The measurement was fine until the gage said otherwise. The requirement was understood at contract review and never reached the buyer. The corrective action was completed and never verified. The data was marked controlled and the folder was open to everyone.
None of those are failures of capability. They are failures of proof.
That distinction matters more than it sounds, because it changes what you fix. You cannot train your way out of an audit gap. The people already know how to do the work. What is missing is a system that captures the evidence while the work happens, instead of asking people to reconstruct it under pressure months later.
The old way is to prepare for the audit. Pull the records, build the binder, chase the signatures, and hope the sample the auditor picks is one of the clean ones.
The new way is to be auditable continuously. The evidence accumulates as a byproduct of doing the work, so any sample the auditor picks is already complete.
That is what KMDProjects was built to do.
Not replace your people. Not add another binder to maintain. Just capture the evidence while the work is happening, tied to the job it belongs to, so the proof is already sitting there when somebody asks for it.
And when the question turns to who is allowed to see controlled data, including what your AI tools can read on someone’s behalf, that is what AIBI was built to do. It runs on your hardware, inside your network, honoring the access rules you already set, and it logs every question against the person who asked it.
The right platform does not make your team work differently. It makes the work prove itself as it happens.
If any of these gaps sound familiar, let’s talk. Not a sales pitch. A conversation about which one would open first if an auditor walked in Monday, and what it would take to close it before they do.
