Key takeaways
Five things, in roughly this order. The critical equipment list, and how you decided what is on it. The preventive maintenance plan for those assets, with intervals and their justification. Completion against that plan for a defined past period, including anything overdue and why. Calibration and inspection status for measuring and safety-related equipment, with certificates in date. And then the one that decides the day: the complete record for a single machine the auditor picks, usually while walking the floor and usually the oldest or dirtiest thing they see.
The test is not whether the records exist. It is how long they take to produce. An auditor who watches someone open four systems and phone a colleague has learned what they came to learn. Fabrico holds documents and full history per machine, tracks planned against completed work with dates and the named person, supports custom fields for criticality and certificate expiry, records part consumption against work orders, keeps an audit log, and exports to Excel, which is the format an audit pack is assembled in.
Certification bodies audit against a standard. They are looking for conformity with a documented system, they follow a defined scope, and their sanction is a finding with a corrective action deadline.
A customer auditing a supplier is doing something else. They are deciding whether to keep giving you work. Three consequences follow.
They go where they want. A second party auditor is not bound by a certification scope. If your process is fine and the compressor feeding it looks neglected, they will follow the compressor, because their interest is continuity of supply rather than conformity of a system.
They ask about your risk, not your paperwork. The question behind every maintenance question is "will this line still be running when I need my order". A perfect plan with poor completion answers that question badly, and an imperfect plan with honest, complete records and a clear backlog answers it well.
The sanction is commercial and immediate. There is no ninety day corrective action window if the outcome is that a new programme goes elsewhere. That asymmetry is why audit readiness is a purchasing decision rather than a quality department preference.
The specific standard varies by sector. Automotive customers audit against the expectations behind IATF 16949, food retailers and brand owners against BRCGS, FSSC 22000 or their own supplier standard, pharmaceutical clients against GMP expectations, and aerospace primes against AS9100 style requirements. The maintenance questions are strikingly similar across all of them.
1. The critical equipment list. A good answer is a list you can filter, with a written method behind it, where criticality is a field on the asset rather than a separate document. The common failure is a list maintained in a Word file that no longer matches the plant. Our guide to asset criticality analysis covers the methods; for an audit, what matters most is that the method is written down and applied consistently.
2. The preventive plan. Tasks, intervals, and where the interval came from, which is normally the manufacturer's recommendation or a documented decision to change it. Auditors probe justification more than content. "It has always been monthly" is a weak answer; "manufacturer says monthly, we reviewed it in March against two years of data and kept it" is a strong one, and it takes one field to record.
3. Completion against the plan. Preventive maintenance compliance for a defined period, on the critical assets, with overdue items visible rather than hidden. Do not present 100 percent. An auditor who sees 100 percent looks harder, because plants do not run at 100 percent, and finding one uncompleted job after being shown a perfect number is worse than showing 91 percent with the gaps explained.
4. Calibration and inspection status. Measuring equipment, safety devices, pressure systems and lifting equipment each carry their own regime. The answer is a register with expiry dates and in-date certificates attached. The classic finding here is an inspection report with observations that generated no work, so make sure findings from external inspections create tasks in the same system.
5. The machine the auditor picks. Full history: scheduled jobs and completions, breakdowns with causes, parts fitted, documents, and any condition readings. This is where the day is won or lost, and it is entirely a function of whether your records are per-asset or per-period. A system organised by week cannot answer a question asked by machine.
You cannot create history you did not record, and attempting to is both obvious and far more damaging than the gap. What you can do in eight weeks is real and it is worth doing.
Weeks 1 to 2. Fix the critical equipment list. Walk it with production and quality, agree what is critical, record it as a field, and write down the method on one page. This is the item most often out of date and the easiest to repair.
Weeks 2 to 4. Rebuild the calibration and statutory register. Every certificate, its expiry, attached to the asset. Anything expired gets scheduled now rather than discovered on the day. Any external inspection findings that were never actioned become work orders with honest dates.
Weeks 3 to 6. Close what can honestly be closed, and record what cannot. Overdue preventive work on critical assets gets done or gets a written, dated deferral with a reason and an owner. A documented deferral is a functioning control. An overdue job with no explanation is a finding.
Weeks 6 to 8. Rehearse. Have someone outside maintenance pick three machines at random and ask for their history, timed. Whatever takes more than a few minutes is the thing to fix, and it is almost always a data organisation problem rather than a missing record.
Throughout: prepare to be straight about the gap. If your records genuinely start four months ago because that is when the system went in, say so on the first slide, show the before and the after, and show the plan. Auditors have seen every version of this and they respond far better to a dated, evidenced transition than to a story that unravels at the third question.
Question 5 is the audit question disguised as an admin one. A system that silently reschedules erases the very control an auditor is trying to verify, and you will not discover that until someone asks.
The relevant capabilities are a machine registry with documents, files and full history per asset; an annual preventive maintenance plan with recurring templates, conditional tasks and approval workflows; custom fields for criticality and certificate expiry; planned against completed tracking with dates and the named person; part consumption tied to work orders; an audit log; analytics covering downtime, MTTR and MTBF, task distribution and top problem machines; and Excel export for assembling a pack. Role based access control covers giving a visitor a limited view. Where the customer is auditing multiple of your sites, multi-plant views and cross-plant benchmarking apply.
Practically, the constraint on getting ready is your data rather than the software. Fabrico quotes 3 days of Fabrico-side setup for the CMMS layer covering configuration, users, roles and bulk import, with bulk-import support, so an eight week runway is comfortable for the system itself. What takes the eight weeks is agreeing the critical equipment list and rebuilding the certificate register, and no vendor can do that part for you.
Certifications held: ISO 27001, ISO 9001 and ISO/IEC 20000-1, with hosting in an AWS EU region, which occasionally matters because customer auditors increasingly ask where supplier data sits. There is no SOC 2 report, so if your customer's own questionnaire requires one, flag it early.
A tier supplier is audited by an automotive customer. The maintenance section runs 90 minutes. The plan and the critical equipment list are reviewed at a desk in 20 minutes and pass without comment.
Then the auditor walks the floor and stops at a 1990s press that is not on the critical equipment list, because it runs a legacy part for a customer that is not this one. They ask for its history.
The weak version: it is not in the plan, its records are in a folder, and the last documented work is a breakdown repair eighteen months ago. The finding written is not about the press. It is that the criticality method is not applied consistently, which puts every other answer of the day back in question, including the ones already accepted.
The strong version: the press is in the system, marked low criticality with the reason recorded, on a reduced inspection interval, with its last three jobs visible and one open backlog item for a guard replacement scheduled next month. Nothing about that is impressive maintenance. It is completely ordinary. But it demonstrates that the method covers the whole plant and produces a defensible answer even for the equipment nobody cares about, and that is exactly what the auditor is testing.
The lesson generalises: auditors probe the edges, not the centre. Your best line is well documented because it matters. Readiness is decided by what happens at the machine that does not.
Show the system, with a prepared operator and a defined scope, and have exports ready as backup. Working live demonstrates the records are real and current, which a printed pack cannot. Do a dry run first, because navigating unfamiliar screens under observation looks like disorganisation even when the data is perfect. If read-only limited access is available, it is worth configuring in advance.
The true one. High nineties on critical assets with explained exceptions reads as a controlled operation. A flat 100 percent invites scrutiny and rarely survives it. What genuinely matters to the auditor is whether the exceptions were noticed, decided on, and recorded, because that is the difference between a system with a gap and no system at all.
It is a manageable one if you handle it openly. State the implementation date at the start, show what exists before it and in what form, and show the completeness of everything since. Auditors assess trajectory as well as state, and a supplier that visibly improved its control twelve months ago is a better risk than one that has been flat for a decade. Concealing the boundary is what turns it into a real problem.
Not directly, and volunteering an OEE dashboard as an answer to a maintenance question can read as deflection. Where it helps is indirectly: machine-recorded downtime with causes is stronger evidence than a handwritten log, and a demonstrable link from a recurring stoppage to a work order to a resolved problem is exactly the closed loop an auditor wants to see. Use it as evidence of the loop, not as a headline.
The evidence overlaps almost entirely; the emphasis does not. A certification auditor checks conformity with your documented system and stays inside the agreed scope. A customer auditor is assessing supply risk and will go wherever their concern leads, including to equipment your own scope excluded. Prepare the same records, and additionally prepare for the plant walk, because that is where a second party audit actually happens. For the formal asset management view, see CMMS software for ISO 55001, and for insurer-facing evidence, which asks similar questions for different reasons, see maintenance records your machinery insurer will ask for.
If an audit date is already in the calendar, the fastest useful step is the timed rehearsal described above. Book a demo and ask to see the single-asset history export, which is the artefact the day turns on.
Last updated: 7 August 2026.