Key Points
- Auditors do not review your asset register in general terms. ISO 55001, FDA, OSHA, and insurance auditors each pull different fields, and a register missing their specific data points will fail even if it looks complete on the surface.
- The baseline is the same everywhere: unique asset IDs, accurate locations, criticality rankings, clear ownership, and a maintenance history you can trace to an individual asset in minutes, not days.
- Registers kept in spreadsheets drift out of date between audits. When every work order, inspection, and reading writes itself to the asset it belongs to, which is what a CMMS does automatically, the record stays current on its own.
There is no such thing as a generic audit. An ISO 55001 assessor, an FDA investigator, an OSHA compliance officer, and an insurance underwriter will all ask to see your asset register, but they are not looking for the same thing. Each one arrives with a specific standard, a specific checklist, and a specific set of records they expect you to produce on request.
That is why the question is not whether your asset register is “good.” The question is whether it holds up against the specific audit in front of you. A register that sails through an insurance review can still sink an ISO 55001 certification. A register that satisfies a corporate finance audit can still leave you exposed when OSHA asks for the inspection history of a single pressure vessel.
This guide breaks down what your asset register needs to pass each of the four audits maintenance and reliability teams face most often, and how to close the gaps before an auditor finds them for you.
Why the Asset Register is the First Document Auditors Ask For
Your asset register is the master record of every physical asset your plant owns and operates: what it is, where it is, what condition it is in, and what has been done to it. Auditors start there because it tells them, within the first hour, whether your operation runs on documented facts or on institutional memory.
A complete, current register signals control. Every finding that follows gets weighed against it. An incomplete register signals the opposite, and auditors respond by digging deeper, sampling more assets, and extending the audit. In practice, the quality of your register sets the tone for everything that comes after it.
It also determines speed. When an auditor asks for the maintenance history of a specific compressor, the difference between pulling it up in thirty seconds and reconstructing it from work orders, emails, and a technician’s memory is the difference between a routine audit and a painful one.
The Baseline Every Audit Expects
Before we get into what makes each audit specific, start with the fields every auditor expects to see, regardless of the standard they carry.
Unique asset identification. Every asset needs one ID, used consistently across your CMMS, your financial records, and the physical tag on the machine. Duplicate IDs and orphaned records are among the first red flags auditors look for, because they suggest the register and the plant floor have drifted apart.
Location and hierarchy. Auditors need to find the asset, physically and logically. That means a site, area, and system hierarchy that reflects how the plant is actually laid out, down to the parent-child relationships between equipment and components.
Criticality ranking. A documented criticality analysis shows you know which assets can hurt production, safety, or compliance when they fail. It also justifies your maintenance strategy: why some assets get condition monitoring and others run to failure.
Ownership and accountability. Every asset record should name who is responsible for it. Unowned assets are unmaintained assets, and auditors know it.
Maintenance history tied to the asset. Work orders, inspections, calibrations, and repairs must trace back to the specific asset they were performed on. A pile of completed work orders proves you did work. A history attached to each asset record proves you maintained that asset.
Supporting documentation. Manuals, drawings, certificates, and procedures should be linked to the asset record, not buried in a shared drive folder nobody has opened since commissioning.
Get this baseline right and every audit starts from a position of strength. Now here is where each one gets specific.
What Each Audit Actually Checks
ISO 55001: Prove the Register Supports Decisions
ISO 55001 is the international standard for asset management systems, and its auditors care less about individual records than about whether your asset information actually drives decisions. The standard requires you to identify, manage, and maintain the information needed to support asset management objectives, and your register is the primary evidence.
To pass, your register needs to connect to your Strategic Asset Management Plan. Assessors will pick assets from the register and ask you to show the asset management plan that covers them: the activities, resources, and timescales assigned to that asset or asset class. They will check that criticality rankings in the register match the risk assessments in your documentation, and that performance data, such as MTBF and downtime records, flows back into the register to inform lifecycle decisions.
The most common ISO 55001 failure is a register that exists but does not do anything. If your criticality rankings were assigned once and never revisited, or your maintenance strategies do not reference the register at all, the assessor will find the disconnect. The register has to be a living input to planning, not a spreadsheet you refresh before the certification body arrives.
FDA and GMP Audits: Prove the History is Complete and Traceable
If you operate in pharmaceuticals, medical devices, or food and beverage, FDA investigators and GMP auditors approach your register with one question: can you prove that every piece of equipment touching the product was qualified, calibrated, and maintained according to procedure?
Your register needs equipment qualification status (IQ, OQ, PQ where applicable), calibration records with due dates and results, and a complete maintenance history for every GMP-relevant asset. Traceability is the standard here. An investigator will pick a batch, identify the equipment that produced it, and ask for the maintenance and calibration records of that equipment during that time window. If the register cannot answer that question quickly and completely, you are looking at a finding.
Data integrity matters as much as the data itself. Under 21 CFR Part 11, electronic records need audit trails: who changed what, when, and why. A spreadsheet register fails this test on its face, because anyone can edit a cell without a trace. This is the audit where paper and spreadsheets carry the most risk, and where a validated electronic system does the most work for you.
OSHA Process Safety Management: Prove Mechanical Integrity
For facilities covered by OSHA’s Process Safety Management standard, the mechanical integrity requirements in 29 CFR 1910.119(j) define exactly what your register must contain for covered equipment: pressure vessels, storage tanks, piping systems, relief and vent systems, emergency shutdown systems, controls, and pumps.
For each of these assets, the register needs to show that inspections and tests were performed, that they followed recognized and generally accepted good engineering practices, and that the frequency matched manufacturer recommendations or your own documented experience. Every inspection record needs the date, the inspector’s name, the asset’s unique identifier, a description of what was done, and the results.
OSHA officers audit by sampling. They will select a relief valve or a vessel from your process and ask for its complete inspection history. Deficiencies found and not corrected before further use are citations waiting to happen, so your register also needs to show the loop closed: deficiency found, work order raised, repair completed, asset returned to service. An open deficiency with no documented resolution is one of the most expensive findings in this audit.
Insurance Audits: Prove Values and Protection
Insurance auditors and underwriters read your register through a financial lens. They want an accurate schedule of insurable assets: what you own, where it is, what it would cost to replace, and how well you protect it.
That means your register needs current replacement values, not fifteen-year-old purchase prices. It needs asset locations precise enough to map against flood zones, fire protection coverage, and sprinkler systems. And increasingly, it needs evidence of your maintenance program itself, because underwriters price risk partly on how likely your equipment is to fail catastrophically.
A documented preventive maintenance program, condition monitoring on critical assets, and a clean loss history backed by asset records can directly influence your premiums. Ghost assets cut the other way. If your register carries equipment you scrapped years ago, you are paying to insure metal that no longer exists. If it is missing assets you added, you are underinsured and may not know it until you file a claim.
The Gaps That Fail Audits
Across all four audit types, the same failures show up again and again.
Ghost assets and missing assets. The register says one thing, the floor says another. This single gap undermines every other record you produce, because it tells the auditor the register cannot be trusted as a source of truth.
Histories that live somewhere else. The work was done, but the records sit in email threads, paper binders, or a retired planner’s filing cabinet. If you cannot produce the history from the asset record, the auditor treats the work as undocumented.
Stale data. Criticality rankings from five years ago, replacement values from the original purchase order, calibration due dates that passed without a record of the calibration. Auditors are trained to check dates first.
No audit trail. Records that can be edited without a trace, especially in regulated industries, turn a documentation gap into a data integrity finding, which is a far more serious category.
How to Make Your Register Audit-Ready
Closing these gaps is not a one-week project, but it follows a clear sequence.
Start with a physical verification. Walk the plant, reconcile what exists against what the register says, and resolve every ghost asset and every unrecorded addition. Then standardize your data fields so every asset record answers the baseline questions: ID, location, criticality, ownership, condition, value, and history.
Next, map your register against the specific audits you face. If ISO 55001 certification is on the roadmap, connect the register to your asset management plans. If you are FDA-regulated, confirm calibration and qualification records are attached to each GMP asset. If you are PSM-covered, verify inspection histories for every piece of covered equipment. If your insurance renewal is coming, update replacement values and locations.
Finally, get the register off spreadsheets and into the system where the work actually happens. This is the step that makes audit readiness permanent instead of periodic, because the asset, not a document someone remembers to update, becomes the source of truth. Every completed work order writes itself into the asset's history. Every calibration logs its result against the asset record. Every change carries a timestamp and a user, building a continuous, living picture of asset health that doubles as the audit trail regulated auditors require. Integrating with your CMMS is what ties that picture to the work your team already does. So when the auditor asks for the full history of a specific asset, you are not reconstructing a record. You are reading one the asset has been writing all along, from the same system your technicians use every day.
Pass the Next One Without the Scramble
Audit preparation should not mean three weeks of reconstructing records before the auditor arrives. When you know the real condition and history of every asset you own, and that knowledge lives in one place, preparation mostly means printing the reports.
That is the standard worth building toward: assets that can tell their own story. Each one carries the traceability the ISO assessor tests for, the history the FDA investigator asks about, the inspection record the OSHA officer requests, and the accurate picture your underwriter needs. Not a register you scramble to assemble, but assets whose health and history are already documented, ready for whichever audit walks through the door.
Tractian makes the asset the system of record. Every sensor reading, inspection, and work order lives on the asset it belongs to, building a continuous picture of asset health that doubles as your audit trail, and syncing with your CMMS keeps that history tied to the work itself. Be ready for your next audit, whichever one it is, because your assets already are.
For more on connecting that history to your workflows, read our blog on How a CMMS Simplifies Regulatory Compliance Audits.

