Programme design
Build a risk-based schedule that justifies frequency, depth, and coverage across processes, systems, sites, and the quality system itself.
Internal audit & self-inspection
Self-inspection is a regulatory obligation almost everyone meets on paper. Whether it works depends on something a procedure cannot supply: the willingness to write down what you found.
Perspective
Internal audit fails quietly, and always in the same ways. The auditor reports to the person whose area is being audited. The sample is the one that was offered. The finding is downgraded because everybody knows the team is stretched. None of this looks like a failure until an inspector applies the same scope and reaches a different conclusion.
Independence principle
An auditor’s integrity is not the control. The control is that they do not report to the area under audit, do not depend on it for their objectives, and can escalate past it. Where the organization cannot supply that internally, it has to come from outside.
Capabilities
Scope is tailored to the engagement; these are the core areas in which QA4Tech can contribute.
Build a risk-based schedule that justifies frequency, depth, and coverage across processes, systems, sites, and the quality system itself.
Conduct audits and self-inspections as a genuinely external party, where internal independence cannot be demonstrated.
Reach the areas a generalist internal auditor usually cannot: validation, data integrity, audit trails, cloud, security, and AI-enabled processes.
Grade findings on risk and evidence, and resist the downgrade pressure that makes an internal programme worthless.
Test whether corrective actions address cause, and verify closure with evidence rather than a completed form.
Turn audit output into the trends, decisions, and escalations senior management is expected to act on.
Programme coverage
Most programmes audit processes thoroughly and everything else occasionally. The gaps below are where inspection findings concentrate, precisely because the internal cycle rarely gets to them.
The core activities, audited against the procedures as written and as actually performed — which are frequently two different things.
Validation status, configuration and change control, access, and whether the system in use still matches the system that was validated.
Audit trails and their review, corrections, transfers, spreadsheets, and the end-user computing nobody has inventoried.
Your oversight of suppliers and partners — not the supplier’s own controls, but whether you are genuinely watching them.
Deviation, CAPA, change control, training, and document control audited as processes rather than assumed to be sound.
Whether last cycle’s corrective actions held, and whether the same root cause is reappearing under a different heading.
A rehearsal under realistic pressure: can the organization find, explain, and defend its evidence in the time available?
What makes it credible
An inspector will form a view on your self-inspection programme within minutes, and it will shape everything that follows. These are the things that view is based on.
Approach
A clear sequence keeps the work rigorous while avoiding unnecessary process.
Establish what is covered, how findings are graded, where independence is compromised, and what an inspector would conclude.
Re-base coverage on risk, with a written rationale for frequency and depth that stands up without the author present.
Execute with the same discipline applied to an external party, including the samples nobody offered.
Verify effectiveness, surface repeat causes, and feed trends into management review as decisions rather than information.
Deliverables
A programme the organization runs itself, and audit records that hold up when someone external reads them.
Reference frameworks
The self-inspection requirement is explicit in GxP and in the ISO management-system standards. The criteria are drawn from whichever apply to the activity in scope.
These are examples, not a complete list. The frameworks and criteria that apply to a particular engagement are identified and agreed as part of defining its scope.
Typical applications
Start a conversation
Begin with a focused discussion about context, risk, evidence, and the outcome you need.