Menu
Maintenance Records for a Customer Audit: 2026 Readiness Guide

Maintenance Records for a Customer Audit: 2026 Readiness Guide

A second party auditor asks five things and times your answer. What they request, what a good answer looks like, and what to fix with eight weeks notice.
Maintenance Records for a Customer Audit: 2026 Readiness Guide

Key takeaways

  • A customer audit is a second party audit, and it is stricter than a certification audit in one specific way: the auditor has a commercial interest in the answer and can act on it immediately.
  • Auditors do not ask to see your CMMS. They ask a question and watch how long the answer takes. Time to evidence is the real test, and it is the thing a spreadsheet fails.
  • Five requests come up in almost every maintenance section: the critical equipment list, the preventive plan, completion against that plan, calibration status, and the record for one specific machine chosen by the auditor.
  • You cannot retrofit history. With eight weeks' notice, fix the critical equipment list, the calibration register and the ability to produce a per-asset export, and be straight about the rest.
  • The finding that hurts most is not a gap in the work. It is a plan that says one thing and records that say another, because that reads as a control failure rather than a resource problem.

Our customer is auditing us and maintenance is in scope. What will they ask for?

Five things, in roughly this order. The critical equipment list, and how you decided what is on it. The preventive maintenance plan for those assets, with intervals and their justification. Completion against that plan for a defined past period, including anything overdue and why. Calibration and inspection status for measuring and safety-related equipment, with certificates in date. And then the one that decides the day: the complete record for a single machine the auditor picks, usually while walking the floor and usually the oldest or dirtiest thing they see.

The test is not whether the records exist. It is how long they take to produce. An auditor who watches someone open four systems and phone a colleague has learned what they came to learn. Fabrico holds documents and full history per machine, tracks planned against completed work with dates and the named person, supports custom fields for criticality and certificate expiry, records part consumption against work orders, keeps an audit log, and exports to Excel, which is the format an audit pack is assembled in.

Why a customer audit is different from a certification audit

Certification bodies audit against a standard. They are looking for conformity with a documented system, they follow a defined scope, and their sanction is a finding with a corrective action deadline.

A customer auditing a supplier is doing something else. They are deciding whether to keep giving you work. Three consequences follow.

They go where they want. A second party auditor is not bound by a certification scope. If your process is fine and the compressor feeding it looks neglected, they will follow the compressor, because their interest is continuity of supply rather than conformity of a system.

They ask about your risk, not your paperwork. The question behind every maintenance question is "will this line still be running when I need my order". A perfect plan with poor completion answers that question badly, and an imperfect plan with honest, complete records and a clear backlog answers it well.

The sanction is commercial and immediate. There is no ninety day corrective action window if the outcome is that a new programme goes elsewhere. That asymmetry is why audit readiness is a purchasing decision rather than a quality department preference.

The specific standard varies by sector. Automotive customers audit against the expectations behind IATF 16949, food retailers and brand owners against BRCGS, FSSC 22000 or their own supplier standard, pharmaceutical clients against GMP expectations, and aerospace primes against AS9100 style requirements. The maintenance questions are strikingly similar across all of them.

The five requests, and what a good answer looks like

1. The critical equipment list. A good answer is a list you can filter, with a written method behind it, where criticality is a field on the asset rather than a separate document. The common failure is a list maintained in a Word file that no longer matches the plant. Our guide to asset criticality analysis covers the methods; for an audit, what matters most is that the method is written down and applied consistently.

2. The preventive plan. Tasks, intervals, and where the interval came from, which is normally the manufacturer's recommendation or a documented decision to change it. Auditors probe justification more than content. "It has always been monthly" is a weak answer; "manufacturer says monthly, we reviewed it in March against two years of data and kept it" is a strong one, and it takes one field to record.

3. Completion against the plan. Preventive maintenance compliance for a defined period, on the critical assets, with overdue items visible rather than hidden. Do not present 100 percent. An auditor who sees 100 percent looks harder, because plants do not run at 100 percent, and finding one uncompleted job after being shown a perfect number is worse than showing 91 percent with the gaps explained.

4. Calibration and inspection status. Measuring equipment, safety devices, pressure systems and lifting equipment each carry their own regime. The answer is a register with expiry dates and in-date certificates attached. The classic finding here is an inspection report with observations that generated no work, so make sure findings from external inspections create tasks in the same system.

5. The machine the auditor picks. Full history: scheduled jobs and completions, breakdowns with causes, parts fitted, documents, and any condition readings. This is where the day is won or lost, and it is entirely a function of whether your records are per-asset or per-period. A system organised by week cannot answer a question asked by machine.

What to do with eight weeks' notice

You cannot create history you did not record, and attempting to is both obvious and far more damaging than the gap. What you can do in eight weeks is real and it is worth doing.

Weeks 1 to 2. Fix the critical equipment list. Walk it with production and quality, agree what is critical, record it as a field, and write down the method on one page. This is the item most often out of date and the easiest to repair.

Weeks 2 to 4. Rebuild the calibration and statutory register. Every certificate, its expiry, attached to the asset. Anything expired gets scheduled now rather than discovered on the day. Any external inspection findings that were never actioned become work orders with honest dates.

Weeks 3 to 6. Close what can honestly be closed, and record what cannot. Overdue preventive work on critical assets gets done or gets a written, dated deferral with a reason and an owner. A documented deferral is a functioning control. An overdue job with no explanation is a finding.

Weeks 6 to 8. Rehearse. Have someone outside maintenance pick three machines at random and ask for their history, timed. Whatever takes more than a few minutes is the thing to fix, and it is almost always a data organisation problem rather than a missing record.

Throughout: prepare to be straight about the gap. If your records genuinely start four months ago because that is when the system went in, say so on the first slide, show the before and the after, and show the plan. Auditors have seen every version of this and they respond far better to a dated, evidenced transition than to a story that unravels at the third question.

Eight questions to ask a CMMS vendor if audits are the driver

  1. Show me the full history of one asset for two years, on screen, in under a minute.
  2. Can that be exported as a document, with dates, the person, and the linked procedure?
  3. Can criticality be a field on the asset that we can filter and report on?
  4. Can we report preventive compliance for a chosen period and a chosen set of assets, not just plant-wide?
  5. When a job is deferred, are the original due date, the reason and the approver retained?
  6. Can certificates be attached with an expiry date that generates a task before it lapses?
  7. Does an audit log show edits to completed records, and can we show it to an auditor?
  8. Can an auditor be given read-only access to a limited scope, or do we export instead?

Question 5 is the audit question disguised as an admin one. A system that silently reschedules erases the very control an auditor is trying to verify, and you will not discover that until someone asks.

Where Fabrico fits

The relevant capabilities are a machine registry with documents, files and full history per asset; an annual preventive maintenance plan with recurring templates, conditional tasks and approval workflows; custom fields for criticality and certificate expiry; planned against completed tracking with dates and the named person; part consumption tied to work orders; an audit log; analytics covering downtime, MTTR and MTBF, task distribution and top problem machines; and Excel export for assembling a pack. Role based access control covers giving a visitor a limited view. Where the customer is auditing multiple of your sites, multi-plant views and cross-plant benchmarking apply.

Practically, the constraint on getting ready is your data rather than the software. Fabrico quotes 3 days of Fabrico-side setup for the CMMS layer covering configuration, users, roles and bulk import, with bulk-import support, so an eight week runway is comfortable for the system itself. What takes the eight weeks is agreeing the critical equipment list and rebuilding the certificate register, and no vendor can do that part for you.

Certifications held: ISO 27001, ISO 9001 and ISO/IEC 20000-1, with hosting in an AWS EU region, which occasionally matters because customer auditors increasingly ask where supplier data sits. There is no SOC 2 report, so if your customer's own questionnaire requires one, flag it early.

Worked example: the machine the auditor picked

A tier supplier is audited by an automotive customer. The maintenance section runs 90 minutes. The plan and the critical equipment list are reviewed at a desk in 20 minutes and pass without comment.

Then the auditor walks the floor and stops at a 1990s press that is not on the critical equipment list, because it runs a legacy part for a customer that is not this one. They ask for its history.

The weak version: it is not in the plan, its records are in a folder, and the last documented work is a breakdown repair eighteen months ago. The finding written is not about the press. It is that the criticality method is not applied consistently, which puts every other answer of the day back in question, including the ones already accepted.

The strong version: the press is in the system, marked low criticality with the reason recorded, on a reduced inspection interval, with its last three jobs visible and one open backlog item for a guard replacement scheduled next month. Nothing about that is impressive maintenance. It is completely ordinary. But it demonstrates that the method covers the whole plant and produces a defensible answer even for the equipment nobody cares about, and that is exactly what the auditor is testing.

The lesson generalises: auditors probe the edges, not the centre. Your best line is well documented because it matters. Readiness is decided by what happens at the machine that does not.

Frequently asked questions

Should we show the auditor the system directly or export reports?

Show the system, with a prepared operator and a defined scope, and have exports ready as backup. Working live demonstrates the records are real and current, which a printed pack cannot. Do a dry run first, because navigating unfamiliar screens under observation looks like disorganisation even when the data is perfect. If read-only limited access is available, it is worth configuring in advance.

What preventive maintenance compliance figure should we aim to show?

The true one. High nineties on critical assets with explained exceptions reads as a controlled operation. A flat 100 percent invites scrutiny and rarely survives it. What genuinely matters to the auditor is whether the exceptions were noticed, decided on, and recorded, because that is the difference between a system with a gap and no system at all.

Our records only start when we implemented the CMMS. Is that a problem?

It is a manageable one if you handle it openly. State the implementation date at the start, show what exists before it and in what form, and show the completeness of everything since. Auditors assess trajectory as well as state, and a supplier that visibly improved its control twelve months ago is a better risk than one that has been flat for a decade. Concealing the boundary is what turns it into a real problem.

Does the auditor care about OEE?

Not directly, and volunteering an OEE dashboard as an answer to a maintenance question can read as deflection. Where it helps is indirectly: machine-recorded downtime with causes is stronger evidence than a handwritten log, and a demonstrable link from a recurring stoppage to a work order to a resolved problem is exactly the closed loop an auditor wants to see. Use it as evidence of the loop, not as a headline.

How is this different from preparing for an ISO certification audit?

The evidence overlaps almost entirely; the emphasis does not. A certification auditor checks conformity with your documented system and stays inside the agreed scope. A customer auditor is assessing supply risk and will go wherever their concern leads, including to equipment your own scope excluded. Prepare the same records, and additionally prepare for the plant walk, because that is where a second party audit actually happens. For the formal asset management view, see CMMS software for ISO 55001, and for insurer-facing evidence, which asks similar questions for different reasons, see maintenance records your machinery insurer will ask for.

If an audit date is already in the calendar, the fastest useful step is the timed rehearsal described above. Book a demo and ask to see the single-asset history export, which is the artefact the day turns on.

Last updated: 7 August 2026.

Latest from our blog

Define Your Reliability Roadmap
Validate Your Potential ROI: Book a Live Demo
Define Your Reliability Roadmap
By clicking the Accept button, you are giving your consent to the use of cookies when accessing this website and utilizing our services. To learn more about how cookies are used and managed, please refer to our Privacy Policy and Cookies Declaration