Skip to content

The working checklist

Operations Audit Checklist: The 8 Areas the Best Operators Examine

Most operations audit checklists are listicles — forty shallow questions that produce a tidy document and no decisions. A real audit examines fewer areas, harder. These are the eight I examine in every diagnostic, each with what good looks like and the warning signs — usable on your own operation this week, before you pay anyone anything.

An operations audit answers one question: where is the operating model straining, and what is the strain costing? Not whether people are busy — they always are — but whether the system that converts promises into delivered work and collected cash is sound. The checklist below covers the eight areas where the answer lives: flow, ownership, quality, cadence, measurement, capacity, cash and scale-readiness. Each entry gives you the test to run, what good looks like, and the warning signs that show up earliest. The areas are sequenced deliberately: the early ones expose the facts of the operation; the later ones expose whether the company is able to act on facts.

Method matters more than the list. Audit evidence, not opinions: walk one real order from signature to cash and timestamp its stops; pull the actual numbers rather than the reported ones; sit in one operating meeting and count the decisions closed. Interview the people who do the work, not only the people who describe it — the distance between those two accounts is itself a finding. And score honestly: each area below is either sound, strained or broken, and the discipline of choosing one forces the conversations that matter. An audit that ends with everything amber has measured politics, not operations. Two focused weeks beat two exhaustive months.

This checklist is the one I actually run. Nineteen years inside operations — most recently Senior Director, Business Excellence at Publicis Groupe, owning quality and standards across 500+ clients and 2,000+ teams — taught me that operations fail in patterns, and the patterns cluster in these eight areas. The same checklist, applied as a paid diagnostic, is how my fractional COO engagements begin: two to four weeks, evidence-first, ending in a written read with baselines and a fix sequence. Use it yourself first. If what you find is uncomfortable, the checklist has worked — and the next decision, who fixes what in which order, will be far better informed.

In depth

What you need to know.

Area 1: Flow — sale to delivery to cash

The test: take one real, recent order and walk it from signed deal to cash received, timestamping every handoff, approval and queue. What good looks like: elapsed time is dominated by actual work; handoffs are few and clean; anyone senior can say how long the journey takes and where it slows, and their answer matches the data. Warning signs: nobody can name the end-to-end time; a two-day piece of work sits inside a five-week elapsed cycle; approvals add days and no judgement; every order takes a different path depending on who touches it; expediting is a permanent role rather than an exception. Flow is first on the checklist because it is the X-ray — most of what is wrong with an operation shows up somewhere as time, and time is measurable this week.

Area 2: Ownership and decision rights

The test: pick five recurring decisions — pricing exceptions, hiring approvals, scope changes, quality escalations, vendor spend — and ask three leaders, separately, who closes each one. What good looks like: the answers match; each critical process has one named owner; the owner has real authority rather than coordination duty; and decisions close at the lowest level that has the relevant facts. Warning signs: the answers differ by person — that is not ambiguity, it is the finding; everything above a trivial threshold routes to the founder; committees own things, which means nobody does; decisions reopen after being made because someone senior was not in the room. Unclear decision rights are the most common root cause I find in founder-led companies, and no process redesign survives them. Fix ownership before optimising anything downstream of it.

Area 3: The quality system

The test: ask for the written definition of quality for your main deliverable, then check whether anyone applies it at the point of work. What good looks like: the standard is defined per deliverable, measurable, and checked where errors are born rather than where clients catch them; every failure feeds a loop that fixes causes, not just cases; quality holds on bad weeks. Warning signs: quality means whatever the founder would have wanted; checking happens at final review, so errors are caught expensively late; the same failure recurs monthly with a fresh apology; standards exist in a document nobody doing the work can quote. At scale, quality is a system property — moving a network from 95% to 99% across 2,000+ campaigns was standards and checkpoints, not exhortation. Without the system, growth simply multiplies defects.

Area 4: Operating cadence

The test: sit in the main weekly leadership meeting and count two things — decisions closed, and items that also appeared last week. What good looks like: a fixed rhythm — weekly operating review, monthly deep dive, quarterly reset; an agenda built on the scorecard rather than round-the-room reporting; every deviation leaving with an owner and a date; the meeting finishing early because the system did the work. Warning signs: meetings are status theatre — everyone reports, nothing closes; the same issues roll week to week under new phrasing; urgent topics displace important ones every single time; decisions made in the meeting are relitigated outside it within days. Cadence is where an operating model becomes visible to an auditor. A company with no honest weekly rhythm is not being managed; it is being narrated.

Area 5: Measurement and the single source of truth

The test: ask finance, sales and delivery for last month’s revenue and on-time performance, and compare the three answers. What good looks like: one agreed source; a handful of metrics with one-line definitions and named owners; leading indicators sitting next to lagging ones; leaders who trust the numbers enough to act without a verification ritual. Warning signs: parallel spreadsheets that disagree, and meetings that open by reconciling them; metrics without definitions, so every review starts with what does this actually count; forty KPIs and no thresholds; a dashboard project eighteen months old standing in for measurement discipline. The tell is behavioural — when leaders argue with the number instead of the problem, measurement is broken, whatever the tooling cost. Fix definitions before dashboards; it is cheaper, faster and permanent.

Area 6: Capacity and rework

The test: estimate what share of total effort last quarter went into doing things again — corrections, revisions beyond scope, re-approvals, chasing. Few companies know; the estimating exercise is itself the audit. What good looks like: rework is measured, priced and falling; capacity planning is arithmetic — demand forecast against available hours — rather than instinct; utilisation leaves headroom, because a system loaded past ninety percent queues everything; overtime is an exception with a cause, not a culture. Warning signs: rework is invisible because nobody logs it; hiring is the reflex answer to every backlog while a fifth of existing capacity quietly burns on corrections; heroics are celebrated monthly — heroism is unpriced rework; nobody can say what spare capacity exists for next quarter’s growth. Rework is the most expensive line item that never appears on a P&L.

Area 7: Cash and the billing cycle

The test: measure elapsed time from work delivered to invoice raised, and from invoice raised to cash received — then find where the days actually go. What good looks like: billing follows delivery in days, not weeks; approval chains are short and add judgement; disputes are rare because scope and rates were unambiguous upstream; someone owns the end-to-end cycle rather than fragments of it. Warning signs: unbilled work worth weeks of revenue sits in a queue nobody measures; approvals bounce between entities or systems; every dispute traces back to a sloppy handoff months earlier; finance chases operations for paperwork monthly. This area rewards auditing fastest — compressing a billing approval cycle from roughly two months to fifteen days across 75 entities released working capital no financing could have matched. Operations traps cash; audits find where.

Area 8: Scale-readiness

The test: assume next year’s plan lands — half again more volume — and ask which process breaks first. Good operations know their next bottleneck by name. What good looks like: the operating model is documented enough that new leaders inherit systems, not folklore; critical processes have depth beyond one irreplaceable person; the constraint is known, sized and scheduled for relief; leadership could absorb an acquisition, a new market or a surge without redesigning everything live. Warning signs: the honest answer to what breaks first is silence; every prior growth spurt was survived by heroics and remembered as trauma; key-person risk is discussed only when the key person resigns; the plan assumes capacity that simple arithmetic says is absent. Scale-readiness is the forward-looking area — the previous seven describe today; this one prices tomorrow.

Questions

Common questions.

A structured examination of how a business actually operates — how work flows from sale to delivery to cash, who owns decisions, how quality is enforced, what the numbers really say — with findings expressed as evidence and baselines rather than impressions. It differs from a financial audit, which verifies the records of what happened; an operations audit examines the machine that makes things happen, and what its strain costs. Done properly it ends in a short written read: where the operating model is sound, where it is strained, what that costs, and what to fix first.

Use the eight areas on this page, and audit evidence rather than opinions. Walk one real order end to end with timestamps. Ask three leaders who closes five common decisions, separately, and compare answers. Pull the actual quality, rework and billing numbers instead of the reported ones. Sit in the weekly meeting and count closed decisions. Score each area sound, strained or broken — no fourth option. Two focused weeks is enough for a fifty-to-five-hundred-person company. The self-audit’s limit is candour about the founder’s own role; that is usually where an outside eye earns its fee.

For a company between fifty and five hundred people, two to four weeks of focused work: a few days of data and document review, a week of walking real work and interviewing the people who do it, a few days of analysis, and a working session where leadership argues with the findings before they harden. Longer engagements usually signal scope creep into implementation — a different, later phase. My own diagnostic runs on exactly that clock, fixed-fee, ending in a written, board-ready read with baselines and a fix sequence. Speed matters: audits that run for months describe a company that no longer exists.

Both can work; the failure modes differ. Internal audits know where the bodies are buried but struggle to say so — especially when findings implicate the founder’s own habits, which they usually do. External auditors bring pattern recognition across companies and the licence to be blunt; the best ones audit against scale they have personally run, not against a template. A practical rule: self-audit annually using a checklist like this one, and bring in an outside operator when the findings would be awkward internally, when the numbers are disputed, or when the audit must justify investment to a board.

Five recur across almost every company I examine. Decision rights that differ depending on whom you ask — the single most common root cause. Elapsed time dominated by queues and approvals rather than work. Quality checked at final inspection instead of at the point where errors are born. Parallel spreadsheets that disagree, so meetings reconcile numbers instead of closing decisions. And rework running unmeasured — often a double-digit share of capacity — while hiring plans assume it does not exist. None of these is exotic. Their cost comes from being invisible, which is precisely what an audit is for.

A light self-audit annually, and a serious one at inflection points: before a funding round or acquisition, before committing to a step-change growth plan, after a leadership change in operations, or whenever the symptoms cluster — quality wobbling, cash cycle stretching, the founder’s calendar becoming the constraint. Frequency matters less than consequence: an audit whose findings enter the operating cadence with owners and dates compounds; an audit that produces a document produces a document. If the last audit changed nothing, the next one should examine why — that is a finding about governance, not about auditing.

Three things. Evidence over assertion: the best audits walk real orders, pull real numbers and observe real meetings, rather than scoring a questionnaire. Judgement over coverage: eight areas examined hard beat eighty questions answered politely, and the auditor’s scale experience decides whether findings carry the right altitude for your board. And consequence over documentation: findings priced in money and time, sequenced into a fix order, and injected into the operating cadence with owners and dates. A template exercise produces a maturity score. A real audit produces decisions — and usually returns its fee inside the first fix.

Sequence, then cadence. Findings get priced and ordered — cash leaks and quality risks first, structural work second, optimisation last — because fixing everything at once fixes nothing. Each fix gets an owner, a date and a measure, and enters the weekly operating review so progress is examined rather than hoped for. Some companies run the sequence themselves; others want the auditor to stay and install — which is where my own diagnostic often becomes a fractional COO engagement. Either path is legitimate. The only wrong outcome is the binder on the shelf, which is why the audit’s last deliverable should be a working session, not a PDF.

The next step

A short conversation settles most of this — and a fixed-fee diagnostic settles the rest.