A localization provider may have skilled linguists, established client relationships, and a credible technology stack, yet still receive nonconformities during an ISO assessment. The top audit findings in localization rarely result from one major operational failure. More often, they arise when documented procedures, competence evidence, project records, and actual practice do not align.
For language service providers pursuing or maintaining ISO 17100 certification, and for organizations operating post-editing services under ISO 18587, audit readiness must be treated as an operational discipline. Auditors assess objective evidence. A statement that a process is followed is not sufficient if the organization cannot demonstrate who performed it, under what conditions, and according to which controlled procedure.
Why localization audit findings recur
Localization operations are complex because service delivery depends on distributed personnel, varied client instructions, language-specific resources, technology platforms, and tight deadlines. This does not reduce the need for control. It increases it.
Recurring findings usually indicate that the quality management system exists as a set of documents but has not been fully embedded into project delivery. A procedure may define qualified translator selection, independent revision, terminology management, or supplier evaluation, while project records show inconsistent implementation. Certification audits test this connection between policy and evidence.
The following findings are particularly common in localization organizations and should be addressed before a certification, surveillance, or recertification audit.
Top audit findings in localization operations
1. Incomplete evidence of translator, reviser, and post-editor competence
ISO 17100 requires translation personnel to meet defined competence requirements. ISO 18587 also establishes competence expectations for post-editors working on machine translation output. A frequent finding is not that personnel are unqualified, but that the provider cannot present complete, current, and consistently assessed evidence of qualification.
Typical gaps include missing degree certificates, outdated resumes, no documented assessment of professional experience, and unclear records showing whether an individual has been approved for translation, revision, review, or post-editing. Organizations also sometimes confuse supplier registration with supplier qualification. Entering a linguist into a vendor database does not demonstrate that the required competence criteria were evaluated.
A controlled competence file should show the basis for approval, language combinations, service roles, specialist fields where applicable, evaluation results, and periodic re-evaluation. The approval process must be applied consistently to internal staff and external providers.
2. Revision is planned but cannot be evidenced at project level
Independent revision is a central ISO 17100 control. Auditors commonly find that a workflow states revision is mandatory, but the project file contains no reliable evidence that a qualified reviser performed it. A status label in a translation management system may be insufficient if it does not identify the reviser, the task completed, and the relevant project scope.
This issue becomes more significant when exceptions are involved. Some assignments may legitimately have a different workflow because of client direction, service type, or documented risk considerations. The provider must be able to show that the exception was authorized, communicated, and recorded. An undocumented departure from the standard workflow is likely to be treated as a nonconformity.
The appropriate control is not simply adding another checkbox. It is ensuring that project records link the assigned personnel, their approved role, completed workflow stages, and any approved deviations. The system should make it possible to reconstruct what happened without relying on memory.
3. Client requirements are captured inconsistently
Localization projects often include detailed instructions on target markets, terminology, style, file formats, software environments, security, linguistic validation, and delivery acceptance. Audit findings occur when these requirements are received but not formally reviewed, translated into operational instructions, or retained in the project record.
For example, a client may require use of an approved glossary, a specific in-country reviewer workflow, or restrictions on machine translation. If those requirements remain in an email thread and are not reflected in project planning, the provider cannot demonstrate controlled service delivery.
The issue is especially relevant for recurring accounts. Project managers may understand the client’s expectations through experience, but ISO compliance requires institutional knowledge rather than personal knowledge. A documented client profile, project specification, or controlled instruction record should identify applicable requirements and be available to all assigned personnel.
4. Supplier evaluation is periodic in theory, not in practice
External linguists, desktop publishing specialists, localization engineers, and technology vendors can materially affect service conformity. A common audit finding is a supplier evaluation process that was completed during implementation but has not been maintained.
Organizations may retain an approved supplier list without recording ongoing performance, quality incidents, complaints, delivery reliability, confidentiality compliance, or re-evaluation decisions. In other cases, evaluation criteria are too general to support a meaningful decision. A score of “approved” without evidence of performance assessment provides limited audit value.
Supplier management should be proportionate to risk. A high-volume reviser handling regulated content requires more controlled monitoring than an occasional provider of a low-risk ancillary service. The key requirement is that the organization can show a defined method, objective records, and action when performance does not meet expectations.
5. Machine translation post-editing controls are unclear
Providers offering machine translation post-editing under ISO 18587 must distinguish this service from human translation and define the applicable workflow. Audit findings frequently arise where organizations market post-editing services but have not established clear criteria for engine selection, source-content suitability, post-editor competence, quality expectations, or client communication.
A common weakness is treating post-editing as a lower-cost version of translation without documenting the service specification. This creates risk for both conformity and client acceptance. The organization should define whether light or full post-editing is offered, what level of quality is expected, how terminology and client instructions are applied, and how final verification is performed.
Technology governance also matters. Where client content is processed through machine translation tools, the provider should be able to demonstrate authorization, confidentiality safeguards, data handling controls, and any restrictions imposed by the client. The specific controls will depend on the platform and contractual context, but undocumented use of public tools presents a material audit risk.
6. Nonconformities, complaints, and corrective actions do not reach root cause
Many localization companies record client complaints and quality incidents. The audit weakness appears after the record is created. Corrective action is often limited to replacing a linguist, correcting the delivered file, or reminding staff to be careful. These immediate actions may resolve the individual project, but they do not necessarily address the cause of recurrence.
An effective corrective action record identifies the issue, assesses its impact, determines root cause, assigns actions, verifies completion, and evaluates whether the action was effective. If terminology errors recur across projects, for instance, the cause may be inadequate project preparation, unclear ownership of glossary updates, insufficient linguist onboarding, or failure to apply a technical control. The corrective action should address the actual process weakness.
Auditors also examine whether management uses complaint and nonconformity data to identify trends. A single complaint may be isolated. Repeated late deliveries in the same workflow, language group, or service line require management attention and documented improvement action.
7. Internal audits and management reviews are treated as formalities
Internal audits are intended to test whether the management system is functioning before an external auditor identifies failures. A frequent finding is an internal audit program that reviews documentation but does not sample real projects, supplier records, competence files, or corrective-action effectiveness.
Independence is also relevant. An internal auditor should not audit their own work without safeguards. In smaller organizations, complete separation may not be practical, but the organization should define how objectivity is protected, such as using trained cross-functional auditors or an external resource.
Management review records can be similarly weak. Minutes that merely state “the system is effective” do not demonstrate review of required inputs and decisions. Senior management should examine audit results, client feedback, supplier performance, process performance, risks, resources, opportunities for improvement, and follow-up actions. The output should show decisions, responsibilities, and deadlines.
How to prepare without creating unnecessary bureaucracy
The strongest audit preparation is not a document-writing exercise. Begin by tracing a sample of completed projects from client inquiry through delivery and follow-up. For each project, verify that requirements were reviewed, appropriately qualified resources were assigned, required workflow stages were completed, records were retained, and any issue was addressed through the corrective-action process.
Then compare this evidence with the organization’s documented procedures. If practice is effective but the procedure is outdated, revise the controlled documentation. If the procedure is correct but teams are bypassing it, address training, system design, capacity, or accountability. The right response depends on the cause. Requiring more forms can create delay without improving control.
A pre-assessment should also test difficult cases rather than only standard projects: urgent delivery, a client-approved workflow exception, post-editing work, a complaint, a security-sensitive assignment, and a project involving a new supplier. These cases reveal whether the management system is resilient under operational pressure.
Audit findings should be viewed as evidence about system reliability, not as isolated administrative defects. When localization providers maintain traceable records, qualified resources, controlled workflows, and effective corrective actions, certification becomes a credible demonstration of capability for clients, procurement teams, and tender evaluators.





Leave A Comment