Book a demo Get Started

An ISO Audit Is Really One Question: Who Is Responsible for This?

Nathan Evans

Most of the stress around an audit comes from scrambling to prove who owns what. When every role and its responsibilities are written down and kept current, the answer is already sitting there.

Imagine a company called Roncieux. It is a Swiss workshop that machines tiny, high-precision parts for medical devices. Work like that is regulated, so once a year an auditor visits to check the company runs the way the rules require. Roncieux holds an ISO 13485 certificate, the quality standard for medical device work, and keeping it is not optional. Lose it, and customers walk.

Ask anyone who has sat through one of these audits what the hard part is. It is almost never the work itself. Roncieux makes excellent parts. The hard part is proving, on the day, that someone is clearly responsible for each thing the standard cares about, and that the work is actually being done.

That is what an audit comes down to. Underneath the paperwork, it is one question asked over and over: who is responsible for this, and how do you know it is happening?

Why that question is harder to answer than it should be

In most companies, the answer lives in three places, and none of them is much help under pressure.

There are job descriptions, often written when the person was hired and untouched since. There is a quality manual that describes the ideal, which few people have read end to end. And there is an org chart of boxes and titles, which tells you who reports to whom and nothing about who is accountable for what.

So when the auditor asks “who signs off the final release of a batch?”, people look at each other. Everyone sort of knows. Nobody can point to the one role that owns it. The scramble that follows is the part everyone dreads, and it has nothing to do with the quality of the actual work.

What the auditor is actually looking for

For each requirement in the standard, an auditor wants three simple things:

  • One clear owner. Not a department, a role that a specific person holds.
  • A plain description of what that role is accountable for.
  • Evidence that it happens.

A title like “Quality Engineer” answers none of these. It does not say who owns the regulatory file, who talks to the notified body, or who keeps the technical documentation current. Those are the things an auditor asks about, and a job title cannot carry them.

How a living map answers it in seconds

Roncieux keeps its structure as a living map instead of a slide. Every role on it carries a purpose and a written list of responsibilities. So the answer to “who is responsible for this?” is built into the map itself.

Search for “regulatory” and you land on the Regulatory Affairs circle. Its purpose is written plainly: keep the company compliant on its markets. Inside it sit named roles, each one held by a person: the MDR technical file, the FDA registrations, regulatory monitoring, vigilance, and relations with the notified body. Each role lists what it is accountable for.

The Regulatory Affairs circle on the Roncieux map, showing its purpose and named roles for the technical file, registrations, and monitoring.

When the auditor asks “who keeps the technical file up to date?”, nobody goes hunting. You point at the role whose job that is, and at the person who holds it. The same is true for every other requirement, because every responsibility is attached to a role, and every role is attached to a person.

You can explore the Roncieux map yourself at peerdom.org/roncieux and click any circle or role to see its purpose and responsibilities.

The part that matters between audits

An audit is a snapshot, but compliance is a continuous thing. A slide deck of the org chart is out of date the week after it is drawn, which is why so many teams rebuild theirs in a panic the month before the auditor arrives.

A living map is kept current by the teams themselves, as part of normal work. When someone takes on a new responsibility, it goes on the map that week, not next audit season. So on the day the auditor walks in, the structure already reflects how the company actually works. There is nothing to reconstruct.

The full Roncieux map, the whole company visible at once as nested teams and roles.

What to do if audits are a scramble for you

  1. For each requirement in your standard, name one role that owns it. One, not a committee.
  2. Write down what that role is accountable for, in plain words a newcomer could follow.
  3. Give the role to a real person, and make sure everyone can see who holds it.
  4. Keep it current as part of everyday work, so there is nothing to rebuild before the auditor arrives.

None of this makes the standard itself any easier. It makes your answer to it obvious, and a clear answer is most of what an audit is testing.

Common questions

We already have job descriptions. Isn’t that enough? Job descriptions describe a person’s job in general terms. An audit asks who owns a specific responsibility today. If your descriptions are two years old or sit in a folder nobody opens, they will not answer that fast. A living map ties each responsibility to a current role and a current person.

What is a living org chart? It is a map of your organisation that shows roles and their responsibilities, not only names and titles, and that teams keep up to date themselves. Because it reflects how the company works right now, it answers “who is responsible for this?” without a scramble.

Does this only help with ISO 13485? No. Any audit or certification that asks who is accountable for what benefits from the same setup: clear roles, written responsibilities, one owner each, kept current. Quality, safety, information security, and financial controls all ask the same underlying question.

Can an auditor look at the map directly? Yes. You can walk an auditor through the live structure, open a role, and show its purpose, its responsibilities, and who holds it. That is often faster and more convincing than handing over a binder.

Roncieux is an illustrative example, not a real Peerdom customer. It stands in for the kind of regulated manufacturer that lives with annual audits, so the pattern is easy to follow.

Keep reading