Schedule Meeting

A Practical Nuclear Audit Example for ISO 19443

A Practical Nuclear Audit Example for ISO 19443

A nuclear audit example is most useful when it shows what happens beyond the checklist: how an auditor follows a safety-significant requirement from contract review to the point of manufacture, identifies a control failure, and tests whether corrective action is genuinely effective. For UK nuclear supply-chain organisations, this is the difference between a management-system audit that produces paperwork and one that provides credible assurance.

The worked example below is based on a fictional precision engineering supplier manufacturing valve components for a nuclear new-build programme. It is designed around ISO 19443 requirements and the practical expectations placed on organisations working within the nuclear supply chain. It is not a substitute for an Office for Nuclear Regulation inspection, a nuclear site licence assessment, or a project-specific customer audit.

Nuclear audit example: a supplier manufacturing safety-class components

Northfield Precision Engineering Ltd has secured a contract to machine and inspect safety-class valve bodies. Its customer requires the business to operate a quality management system aligned with ISO 19443, including a demonstrable nuclear safety culture, graded application of controls, traceability, competence management and effective control of externally provided processes.

The internal audit was scheduled six months after contract award and before the first production batch. The audit objective was to determine whether the company could consistently meet the specified nuclear quality requirements, not merely whether its procedures existed.

The audit scope covered contract review, purchasing, receipt inspection, machining, non-conformance control, final release, competence, calibration and records. The audit team consisted of a lead auditor independent of the production department and a technical specialist with machining and material traceability experience.

Establishing the audit trail

Rather than beginning with a broad interview, the auditor selected one valve body from the planned first-off batch and traced its requirements through the organisation. The purchase order, customer specification, manufacturing route card, material certificate, inspection plan and release documentation were sampled as a connected evidence trail.

This approach matters in nuclear work because a process can appear compliant in isolation while the interfaces between departments fail. A controlled procedure for purchasing does not assure quality if the purchasing team has not flowed down the correct safety classification or inspection requirements to the material supplier.

The auditor reviewed whether the contract review had identified nuclear-specific requirements, including customer hold points, notification periods, record retention, right of access, independent inspection and escalation of quality concerns. The contract review record confirmed that these requirements had been captured, but the audit then tested whether they had been transferred accurately into operational controls.

Evidence reviewed during the audit

The audit relied on objective evidence, not assurances that staff understood the process. Records sampled included:

  • the customer order, technical specification and quality plan;
  • the approved supplier list and purchase order for forged material;
  • material certification, goods-in inspection and traceability records;
  • machining route cards, operator authorisations and inspection reports;
  • calibration certificates for measuring equipment;
  • non-conformance reports and corrective action records; and
  • training records for inspectors, production operatives and quality personnel.

Interviews were then used to confirm how people applied the documented controls in practice. The stores supervisor explained the identification method for quarantined material. A quality inspector demonstrated how a material heat number was transferred from the goods-in record to the route card. The production manager described the authority to stop work where a requirement was unclear or a potential safety concern had been identified.

The auditor also checked that personnel could distinguish between a routine production issue and an issue requiring formal escalation under the organisation’s nuclear safety culture arrangements. The aim is not to make every minor deviation a major event. It is to ensure people understand when a defect, uncertainty or procedural departure could affect safety, quality or customer confidence.

The key finding: incomplete flow-down of critical requirements

The principal non-conformity concerned the purchase order issued to the material supplier. The customer specification required material certificates to identify the product, heat number, applicable standard, chemical composition, mechanical properties and authorised release. It also required the supplier to preserve traceability to the original melt and notify Northfield before any proposed use of an alternative source.

The purchase order referred generally to the customer specification but did not list the alternative-source notification requirement or clearly state the required certification content. The approved supplier had supplied compliant material on this occasion. However, the organisation could not demonstrate that the requirements would be consistently communicated for future orders or to a different supplier.

This was recorded as a major non-conformity under the company’s audit procedure because the weakness affected externally provided processes and could compromise material traceability for safety-class work. The classification itself should always follow the organisation’s defined process and contractual requirements. Some businesses use critical, major and minor categories; others record non-conformities without grading them. What matters is that the significance of the issue is assessed proportionately and acted on promptly.

A second, less significant finding related to competence records. Two inspectors had completed visual inspection training and had been authorised locally, but their authorisation records did not state the scope and limitations of the approval. Their experience was appropriate, yet the records did not clearly show whether they were approved for final inspection, in-process inspection or both.

The auditor raised this as a minor non-conformity. The distinction was important: there was no evidence that unsuitable personnel had released product, but the competence control was not sufficiently defined for a nuclear-quality environment.

Root cause and corrective action

A weak response would simply amend the one purchase order and close the finding. That treats the symptom, not the system failure. Northfield’s corrective action process therefore required the quality manager to investigate why the flow-down requirement had been omitted.

The root cause review found that the purchasing template was designed for conventional aerospace and industrial work. It contained a generic specification reference but no mandatory field for nuclear-specific quality clauses, safety classification, traceability conditions or customer notification requirements. Contract review had identified the requirements correctly, but there was no formal verification that purchasing had transferred them to the supplier.

The corrective action plan included three linked measures. The purchasing template was revised to include mandatory nuclear requirement fields. A controlled flow-down matrix was introduced, linking each customer requirement to the purchase order, inspection plan or manufacturing document where it had to be applied. Finally, buyers and quality engineers received targeted briefing on graded application, traceability and supplier notification controls.

For the competence finding, the quality manager revised the inspector authorisation form to define approved activities, product scope, supervision requirements and authorisation expiry or review date. Existing authorisations were reassessed by the quality manager and technical authority.

Verifying effectiveness rather than closing paperwork

Corrective action is not complete when the revised form has been issued. In this nuclear audit example, effectiveness verification was planned for eight weeks after implementation, using a new material order as the test case.

The follow-up auditor selected the new order and confirmed that the applicable material requirements had been taken from the flow-down matrix and included in the purchase order. The supplier acknowledgement confirmed acceptance of the requirements. Goods-in inspection records demonstrated that the material certificate had been checked against the order and that the heat number was carried through to the manufacturing route card.

The auditor also sampled two inspector authorisations. Both now defined the inspection activities permitted and were supported by training, experience and assessment evidence. Interviews confirmed that production staff knew to refer unclear requirements to quality before work progressed.

The major non-conformity could therefore be closed with evidence that the corrected process had worked in operation. The audit report retained a clear trail from finding, through root cause and action, to effectiveness review. That trail is essential when customers, regulators or senior leaders need confidence that a recurring weakness has been controlled.

What this example demonstrates for ISO 19443 readiness

An effective ISO 19443 audit examines the quality management system through a nuclear lens. It tests leadership commitment, safety culture, risk-based thinking, supply-chain control, competence, traceability and the ability to prevent counterfeit, fraudulent or suspect items where relevant. It should also establish whether controls are graded according to the potential impact on nuclear safety.

The required depth depends on the organisation’s role. A manufacturer producing safety-class components will need more detailed product traceability and process validation than a consultancy providing non-safety-significant administrative support. However, every supplier should be able to explain its scope, contractual obligations, competence boundaries and escalation routes.

For organisations preparing for a customer, surveillance or certification audit, the most valuable preparation is often a focused gap analysis using real contract and production records. Evolution Safety Solutions can support this work through ISO 19443 gap analysis, internal audit, corrective action support and workforce competence development.

The strongest audit outcome is not a clean report. It is a workforce that can show, with controlled evidence, how a nuclear requirement is understood, applied, checked and improved before it becomes a safety, quality or delivery failure.

Leave A Comment

Your email address will not be published. Required fields are marked *