Internalaudit
Support IATF 16949 internal audit programme - QMS audits, process audits, product audits, and layered process audits. Covers audit planning, checklists, findings, and corrective actions. USE WHEN user says 'internal audit', 'audit checklist', 'process audit', 'product audit', 'QMS audit', 'audit finding', 'nonconformance', or 'LPA'. Integrates with AutomotiveManufacturing and A3criticalthinking skills.
What this skill does
# Internal Audit
## When to Activate This Skill
- "Plan internal audit programme"
- "Create audit checklist for [process/area]"
- "Conduct process/product/QMS audit"
- "Document audit findings"
- "Write nonconformance report"
- "Plan layered process audit (LPA)"
- "Prepare for IATF 16949 certification audit"
## IATF 16949 Audit Requirements
### Clause 9.2.2.1 - Internal Audit Programme
The organization shall:
- Maintain documented internal audit programme
- Cover all QMS processes over audit cycle (typically 3 years)
- Include customer-specific requirements (CSRs)
- Consider process risk and previous audit results
- Define audit criteria, scope, frequency, methods
### Types of Internal Audits
IATF 16949 **requires three types** of internal audit (clauses 9.2.2.2–9.2.2.4):
| Audit Type | Focus | Frequency | Reference |
|------------|-------|-----------|-----------|
| QMS Audit | Management system conformance to IATF 16949/ISO 9001 | Annual minimum per clause | 9.2.2.2 |
| Process Audit | Manufacturing process effectiveness (process approach) | Based on risk, min annual | 9.2.2.3 |
| Product Audit | Product conformance at production/delivery stages | Per control plan, min annual | 9.2.2.4 |
> **Note:** Layered Process Audits (LPA) are **not** a standalone IATF 16949 requirement. They are a **customer-specific requirement (CSR)** from certain OEMs (e.g., GM, Ford, Stellantis). They must be implemented when required by customer CSRs but are separate from the three IATF-mandated audit types above.
---
## QMS Audit (9.2.2.2)
### Purpose
Verify conformance to IATF 16949/ISO 9001 requirements and organization's QMS.
### Scope
All clauses of IATF 16949 over the audit cycle:
- Context of organization (4)
- Leadership (5)
- Planning (6)
- Support (7)
- Operation (8)
- Performance evaluation (9)
- Improvement (10)
### Approach
- Clause-based checklist
- Interview management and staff
- Review documented information
- Verify implementation and effectiveness
### Output
- Completed checklist
- Finding report (NCRs, OFIs)
- Audit report
---
## Process Audit (9.2.2.3)
### Purpose
Evaluate effectiveness of manufacturing processes using process approach.
### Scope
Each manufacturing process including:
- Inputs and outputs
- Process controls
- Operator competence
- Equipment capability
- Work instructions compliance
### Approach - Turtle Diagram Method
```
INPUTS OUTPUTS
↓ ↑
Materials, specs Products, data
↓ ↑
┌─────────────────────────────┐
│ │
WITH → │ PROCESS BEING │ → METRICS
WHAT? │ AUDITED │ KPIs met?
│ │
└─────────────────────────────┘
↑ ↑
WHO? HOW?
Competent? Per procedure?
```
### Key Questions
- Are inputs conforming?
- Are process parameters controlled?
- Are operators competent and trained?
- Is equipment maintained and capable?
- Are work instructions followed?
- Are outputs conforming?
- Are KPIs being met?
---
## Product Audit (9.2.2.4)
### Purpose
Verify product conformance at appropriate stages of production and delivery.
### Scope
- Dimensional verification vs. drawing
- Functional testing vs. specification
- Appearance vs. standards
- Packaging and labeling
- Documentation/traceability
### Approach
- Select sample per Control Plan
- Measure against all drawing requirements
- Verify special characteristics
- Check packaging and identification
- Document all measurements
### Frequency
- At defined stages (per Control Plan)
- All special characteristics covered annually
- After process changes
---
## Layered Process Audit (LPA)
### Purpose
Standardized process verification at multiple organizational levels.
### Structure
| Level | Auditor | Frequency | Scope |
|-------|---------|-----------|-------|
| Level 1 | Team Leader | Daily | Key process steps |
| Level 2 | Supervisor | Weekly | Process area |
| Level 3 | Manager | Monthly | Department |
| Level 4 | Plant Manager | Monthly | Multiple areas |
### Key Characteristics
- Same checklist at all levels
- Focus on standardized work
- Quick (10-15 minutes)
- Immediate corrective action
- Trend tracking
---
## Audit Planning
### Annual Audit Schedule
Consider:
- All QMS processes over cycle (max 3 years)
- All manufacturing processes annually
- Risk-based frequency (high risk = more frequent)
- Previous audit results
- Customer complaints
- Internal quality performance
- Changes to processes
### Audit Plan Elements
| Element | Description |
|---------|-------------|
| Audit number | Unique identifier |
| Date | Scheduled date |
| Scope | What will be audited |
| Criteria | Requirements to audit against |
| Auditor(s) | Qualified auditor assignment |
| Auditee | Process owner/department |
| Duration | Expected time |
---
## Auditor Qualification
### Requirements (per 9.2.2.2)
- Understanding of automotive process approach
- Customer-specific requirements knowledge
- ISO 19011 audit principles
- Core tools knowledge (FMEA, SPC, MSA)
- IATF 16949 requirements knowledge
### Independence
- Auditors shall not audit their own work
- Cross-functional audit teams encouraged
- External auditor for sensitive areas
### Training Path
1. Internal training on QMS and IATF 16949
2. Core tools training
3. Audit technique training
4. Shadow audits (observe experienced auditor)
5. Supervised audits
6. Independent auditor status
---
## Conducting the Audit
### Opening Meeting
- Confirm scope and schedule
- Explain audit method
- Confirm resources and access
- Answer questions
### Evidence Collection
- Interview personnel
- Review documents and records
- Observe processes
- Take notes with objective evidence
### Audit Techniques
- Open-ended questions (How? What? Why?)
- Request evidence for claims
- Follow the trail (traceability)
- Verify vs. specification
- Compare to procedure
### Closing Meeting
- Present findings
- Confirm accuracy with auditee
- Agree on corrective action timelines
- Thank participants
---
## Finding Classification
### Major Nonconformance
**Definition:** Absence or complete breakdown of system to meet requirement, or situation likely to result in shipping nonconforming product.
**Examples:**
- No documented procedure when required
- Consistent failure to follow procedure
- Pattern of nonconforming product
- Missing required records
**Action:** Requires root cause analysis, corrective action, and verification before certification.
### Minor Nonconformance
**Definition:** Single lapse in meeting a requirement; does not affect product quality or system integrity.
**Examples:**
- Isolated instance of missing signature
- Minor record-keeping gap
- Single deviation from procedure
- Incomplete training record
**Action:** Requires correction, may require root cause and corrective action.
### Opportunity for Improvement (OFI)
**Definition:** Not a nonconformance, but improvement recommendation.
**Examples:**
- Better organization possible
- More efficient method available
- Good practice from other areas
- Proactive enhancement
**Action:** Optional implementation, tracked for consideration.
---
## Corrective Action Process
### Timeline Requirements
| Finding | Initial Response | Corrective Action | Verification |
|---------|------------------|-------------------|--------------|
| Major | 24-48 hours | 30 days max | Within 90 days |
| Minor | 5 business days | 60 days max | Within 90 days |
| OFI | 30 days | As appropriate | As appropriate |
### Corrective Action Elements
1. **Containment**: Immediate action to contain impact
2. **Root Cause**: Analysis to determine true cause (5-Why, Fishbone)
3. **Corrective Action**: Action to eliminate root cause
4. **Implementation**: Execute corrective action
5. **Verification**: Confirm effRelated in Security
mac-ops
IncludedComprehensive macOS workstation operations — diagnose kernel panics, identify failing drives, audit launchd startup items, decode wake reasons, triage TCC permission denials, manage APFS snapshots, recover from no-boot. Use for: Mac is slow, slow bootup, won't boot, kernel panic, kernel_task hot, mds_stores CPU, photoanalysisd, cloudd, login loop, gray screen, sleep wake failure, drive failing, IO errors, APFS snapshots eating space, Time Machine local snapshots, Spotlight indexing, launchd, LaunchAgent, LaunchDaemon, login items, TCC permissions, Full Disk Access, Screen Recording denied, Gatekeeper, quarantine, com.apple.quarantine, app is damaged, helper tool, /Library/PrivilegedHelperTools, pmset, wake reasons, dark wake, sysdiagnose, panic.ips, DiagnosticReports, configuration profile, MDM profile, remote diagnostics over SSH.
a11y-audit
IncludedRun accessibility audits on web projects combining automated scanning (axe-core, Lighthouse) with WCAG 2.1 AA compliance mapping, manual check guidance, and structured reporting. Output is configurable: markdown report only, markdown plus machine-readable JSON, or markdown plus issue tracker integration. Use this skill whenever the user mentions "accessibility audit", "a11y audit", "WCAG audit", "accessibility check", "compliance scan", or asks to check a web project for accessibility issues. Also trigger when the user wants to verify WCAG conformance or map findings to a specific standard (CAN-ASC-6.2, EN 301 549, ADA/AODA).
erpclaw
IncludedAI-native ERP system with self-extending OS. Full accounting, invoicing, inventory, purchasing, tax, billing, HR, payroll, advanced accounting (ASC 606/842, intercompany, consolidation), and financial reporting. 413 actions across 14 domains, 43 expansion modules. Constitutional guardrails, adversarial audit, schema migration. Double-entry GL, immutable audit trail, US GAAP.
assess
IncludedAssesses and rates quality 0-10 across multiple dimensions (correctness, maintainability, security, performance, testability, simplicity) with pros/cons analysis. Compares against project conventions and prior decisions from memory. Produces structured evaluation reports with actionable improvement suggestions. Use when evaluating code, designs, architectures, or comparing alternative approaches.
spring-boot-security-jwt
IncludedProvides JWT authentication and authorization patterns for Spring Boot 3.5.x covering token generation with JJWT, Bearer/cookie authentication, database/OAuth2 integration, and RBAC/permission-based access control using Spring Security 6.x. Use when implementing authentication or authorization in Spring Boot applications.
code-hardcode-audit
IncludedDetect hardcoded values, magic numbers, and leaked secrets. TRIGGERS - hardcode audit, magic numbers, PLR2004, secret scanning.