Directed, for-cause & due diligence

The audits nobody scheduled.

Something happened, or something is about to be signed. Either way the ordinary audit calendar is irrelevant and the question is narrow, urgent, and consequential.

A signal spike rising from a quiet baseline, triggering a narrow focused beam that converges on one area of a wider field.

Perspective

These audits are different in kind, not just in timing. The atmosphere is rarely cooperative, the evidence may be at risk, the findings may be read by lawyers or regulators, and the answer usually has to be delivered before anyone is comfortable giving it. Scope discipline and evidence handling matter more here than anywhere else.

Investigative principle

Establish what happened before deciding what it means.

Pressure to reach a conclusion arrives immediately and from every direction. Separating the sequence of events from the interpretation of them — and documenting both separately — is what makes the conclusion defensible afterwards.

Capabilities

Specialist support, connected to the whole system.

Scope is tailored to the engagement; these are the core areas in which QA4Tech can contribute.

01

For-cause audits

Respond to an incident, a signal, or a pattern with a focused audit that establishes scope, cause, and exposure.

02

Directed audits

Narrow scope to one process, system, study, site, or control where an oversight question has become urgent.

03

Data-integrity investigation

Examine audit trails, records, and system behaviour where the integrity of data itself is in question.

04

Allegation follow-up

Handle whistleblower reports and complaints with the confidentiality, proportionality, and evidence discipline they require.

05

Quality due diligence

Assess quality-system maturity, validation state, data integrity, and regulatory exposure ahead of an acquisition or major contract.

06

Regulatory response support

Establish an evidenced position after an inspection observation, and test whether the proposed response actually covers it.

Triggers

Six reasons this audit is happening now.

Each trigger sets a different scope, a different pace, and a different audience for the report. Naming it explicitly at the start prevents the audit from drifting into a general assessment nobody asked for.

01

A data-integrity signal

Audit trail anomalies, unexplained corrections, or backdating indications that need to be characterized before anyone can judge impact.

02

A serious incident

A failure, loss, breach, or product or subject impact where the organization needs an independent view of scope and cause.

03

A pattern

Deviations, complaints, or repeat findings that individually looked minor and collectively no longer do.

04

An allegation

A whistleblower report or complaint requiring confidential, proportionate examination that neither dismisses nor presumes.

05

A regulatory observation

An inspection finding that has to be answered with evidence, on a deadline, without overcommitting the organization.

06

A transaction

An acquisition, merger, partnership, or major contract where quality and technical risk transfers on signature.

What changes

Why these audits are run differently.

The method is the same craft, but the constraints are not. Getting these wrong is how an investigation ends up unusable at exactly the moment it is needed.

  • Evidence preservation comes first, before anyone starts interpreting it
  • Scope is fixed narrowly and in writing, because it will be pushed in both directions
  • Records are secured against routine deletion, retention cycles, and system change
  • Confidentiality is planned deliberately: who knows, who cannot know, and why
  • Observation is kept strictly separate from interpretation in every working note
  • Legal exposure is anticipated, and the report is written knowing who may read it
  • For transactions, findings are expressed as risk, cost, and remediation effort

Approach

Context first. Evidence throughout.

A clear sequence keeps the work rigorous while avoiding unnecessary process.

  1. 01

    Secure the evidence

    Identify and preserve relevant records, audit trails, and system state before anything is examined or discussed widely.

  2. 02

    Fix the question

    Agree a narrow, written scope and the decision it has to support, so the work does not expand into a general assessment.

  3. 03

    Establish the sequence

    Build a factual chronology from source evidence, separating what is documented from what is asserted.

  4. 04

    State the exposure

    Set out impact, cause, and residual risk in terms the audience — quality, executive, legal, or acquirer — can act on.

Deliverables

What the engagement produces.

Investigation-grade output, built on the assumption that it will be read by someone unsympathetic.

  • A written scope and evidence-preservation plan agreed before work begins
  • A factual chronology traceable to source records
  • Findings separating observation, interpretation, and reviewer judgment
  • An impact and exposure assessment, including data and product or subject impact
  • An evidence pack suitable for a quality investigation or regulatory response
  • For transactions, a risk register with remediation effort and indicative cost

Reference frameworks

The expectations behind the investigation.

Criteria are fixed to the activity in question and stated before analysis begins, so the conclusion cannot be characterized as reverse-engineered.

PIC/S PI 041
Data management and integrity expectations, including how integrity failures are characterized and assessed.
21 CFR Part 11 & EU Annex 11
Electronic records, signatures, and audit trails as the evidentiary basis for most integrity investigations.
ICH Q9(R1)
Quality risk management applied to impact assessment, and to the formality the investigation itself warrants.
ICH E6(R3)
Serious breach handling, data governance, and sponsor responsibilities in clinical research.
ISO 19011
Evidence, sampling, and objectivity discipline, applied where the conclusion is likely to be contested.

These are examples, not a complete list. The frameworks and criteria that apply to a particular engagement are identified and agreed as part of defining its scope.

Typical applications

Where this work can apply.

  • For-cause audits after an incident or data-integrity signal
  • Directed audits of a specific system, study, site, or control
  • Confidential follow-up of an allegation or whistleblower report
  • Independent support for an inspection response
  • Pre-acquisition and pre-merger quality and technical due diligence
  • Assessing a target or partner’s validation and data-integrity state

Start a conversation

Bring the right level of assurance to the next decision.

Begin with a focused discussion about context, risk, evidence, and the outcome you need.

Discuss an Urgent Audit