September 7, 2026 · 6 min read
TL;DR: Audits appear in 41 of the bank's answer options: 9 keyed, 32 wrong. The keyed ones all answer the same question, which is why a process produced a bad result. The wrong ones use an audit to measure a problem you already understand, to delay a decision, or to check something that has already been checked.
An audit is a diagnostic instrument aimed at a process, and the exam is strict about that aim. Point it at a deliverable, a schedule, or a decision, and it becomes a distractor.
A process that was supposed to work and did not, where nobody can yet say why. That is the entry condition in every keyed instance.
Weekly progress reports on a shipyard refit are consistently upbeat, but what the project manager sees on the dock does not match them. Keyed: audit the project's reporting process to find and correct the discrepancies. The reasoning is that reports drift from reality for identifiable reasons, such as percentage-complete estimated rather than measured, or progress claimed at the wrong point in the workflow, and an audit is what locates them. Instructing the team to report more accurately leaves the mechanism that produces the optimism untouched.
Second: a risk on a contractor deliverable was recorded with an agreed mitigation, and at final inspection the mitigation did not work. Keyed: audit the procurement process to determine why. Re-evaluating probability and rewriting the strategy adjusts the register without knowing the cause. A change request to apply a response plan that has already been applied and failed repeats the failure.
In both, something was supposed to work, did not, and nobody can say why. That is the entry condition.
When it is aimed at something other than a process: sizing up a problem the stem has already described, certifying a finished product, or re-checking work that is already complete.
| Stem | Audit option | Why it loses |
|---|---|---|
| Supplier quality problem, risk identified earlier with a planned response | Immediate full audit of all supplier deliverables to size the problem | The response was already analysed and approved; execute it |
| Experimental ML product, no stable specification | External audit at the end to certify against standards | Nothing stable to inspect against; build quality into how the work is done |
| Audit findings already flag non-conformances | Ask the sponsor to review the auditor's report | The obligation is to act on the recommended corrective actions |
| Deliverables already validated, accepted and audited | Check with compliance that they passed every audit | Sequence: that is already done, so file the records |
The last row is a pure ordering test. By the final review meeting, the deliverables have been validated, accepted, and audited for compliance, so re-running the compliance check repeats completed work. The keyed answer uploads the lessons learned register and the final report to the organisation's repository.
Common trap: using an audit as a sizing tool. In the supplier item, "request an immediate full quality audit of all supplier deliverables to size up the problem" is a strong-sounding wrong answer, and the bank rejects it because the stem says the supplier risk was identified earlier, which means a response already exists and this is the moment to execute it. A wide audit of everything is what you commission when you do not know where to look. The exam usually tells you where to look in the stem itself.
You act on the findings. An audit produces recommended corrective actions, and the bank keys integrating those into the plan through change control.
An external auditor reports several significant non-conformances that could hit timeline and budget. The keyed answer adjusts the scope to account for them and integrates the recommended corrective actions into the plan, with the explanation noting that this is a scope, schedule, and cost change and goes through change control rather than around it.
The parallel item is a manufacturing audit flagging non-conformances as risks. Keyed: develop and implement corrective actions. The explanation draws a distinction worth memorising, because it is examinable on its own: corrective action addresses the process that produced the non-conformances, which stops the next batch carrying the same defects, and that is a different thing from defect repair, which fixes the units already affected. A serious response usually needs both.
Halting production until every non-conformance is fixed is offered in that item and rejected, which is consistent with how the bank treats stop-work answers generally.
When is a quality audit the keyed answer on the PMP exam? When something has gone wrong repeatedly and nobody knows why the process allowed it. The bank keys auditing the reporting process when reports do not match reality, and auditing the procurement process when an agreed risk mitigation failed.
What do you do with an audit's findings? Act on them. A quality audit's output is a set of findings with recommended corrective actions, and the bank keys integrating those into the plan through change control, not merely monitoring the non-conformances.
Why is commissioning an audit often a distractor? Because it is frequently offered as a way to size up a problem already described in the stem, or to certify a product at the end when the scenario needed quality built in as the work was done.
Is an audit quality assurance or quality control? Assurance. It examines whether the way the work is being done will reliably produce something good, which is why it is aimed at a process. Checking a finished deliverable against a specification is the separate control activity, and one bank item turns entirely on that distinction.
PMP Practice's 2,141 questions are certified against PMBOK 8 and the July 2026 ECO, with every wrong answer explained rather than just marked wrong. Start the free 20-question sample — no card, no signup required to try it.
Related reading: Quality on the PMP Exam: Prevention, Inspection, and the Cost of Getting It Wrong and Project Compliance on the PMP Exam: What the Project Manager Actually Owns. Process tasks are mapped on the Process domain study page.
When is a quality audit the keyed answer on the PMP exam?
When something has gone wrong repeatedly and nobody knows why the process allowed it. The bank keys auditing the reporting process when reports do not match reality, and auditing the procurement process when an agreed risk mitigation failed.
What do you do with an audit's findings?
Act on them. A quality audit's output is a set of findings with recommended corrective actions, and the bank keys integrating those into the plan through change control, not merely monitoring the non-conformances.
Why is commissioning an audit often a distractor?
Because it is frequently offered as a way to size up a problem already described in the stem, or to certify a product at the end when the scenario needed quality built in as the work was done.