R2 Audit Preparation 11 min read

R2 Audit Document Package: What to Have Ready

J

September 15, 2026

Most R2v3 nonconformities I see don't come from a facility doing something wrong on the floor. They come from a facility doing the right thing and being unable to prove it fast enough when the auditor asks. The R2 Code of Practice (COP) is direct about this: records must be accessible to the auditor, and for certification and recertification audits, the auditor is required to take copies of specific documents and attach them to the audit report. If your package isn't organized before the opening meeting, you're building it in real time while the clock the auditor bills against keeps running.

This is a walkthrough of what actually needs to be staged, organized around the R2v3:2020 structure itself rather than a generic "have your paperwork ready" list. If you know which Core Requirement or Appendix a document supports, you know where it lives in your folder structure and you know exactly what to hand over when it's asked for.

What "Document Ready" Means Under the R2 Code of Practice

R2v3 splits into two tiers: ten Core Requirements that apply to every certified facility, and Process Requirements (Appendices A through G) that apply only to the specific activities a facility actually performs — data sanitization, test and repair, materials recovery, brokering, photovoltaic module handling, and so on. Your scope statement determines which Appendices get audited, and every Appendix in your scope gets reviewed at every audit in the certification cycle, not just at recertification.

The COP also sets two rules that directly shape what you stage before the auditor arrives.

First, a complete cycle of internal audits has to be reviewed at the certification or recertification audit, and any nonconformity from your internal audit that's still open when the CB auditor shows up gets written up as a CB-level nonconformity. Closing your own findings before the external audit isn't just good practice — it's the difference between an internal issue and an external one on your certificate history.

Second, one surveillance audit per certification cycle can be conducted remotely, but only at the certification body's discretion and only if your documents are genuinely accessible electronically. If you're hoping for a remote surveillance year, your digital document package needs to already function as a real audit package, not a folder of scanned paper.

The Ten Core Requirements and the Evidence Behind Each

Every R2v3 audit works through all ten Core Requirements regardless of what Appendices apply. Here's what an auditor expects to see behind each one.

Core Requirement What It Covers Documents to Have Staged
CR1 — Scope What's actually audited and certified Current scope statement, facility site list, process/material list matching real operations
CR2 — Hierarchy of Responsible Management Strategies Reuse-first evaluation before recycling Reuse evaluation procedure, REC (R2 Equipment Categorization) records showing reuse-first decisions
CR3 — EH&S Management System The management system foundation EHS policy, EHSMS manual, objectives and targets, management review minutes
CR4 — Legal and Other Requirements Compliance plan, import/export legality, worker treatment Legal register, permits, import/export documentation, worker treatment policy
CR5 — Tracking Throughput Inbound, in-process, and outbound material tracking Throughput records, inventory reconciliation, aging reports for negative-value streams
CR6 — Sorting, Categorization and Processing REC-based routing of every item REC procedure, sorting records, evidence of the reuse-first hierarchy applied at the item level
CR7 — Data Security Chain of custody and sanitization method Data security procedure, device-level sanitization or destruction records, chain-of-custody logs
CR8 — Focus Materials Identification and downstream handling of hazardous streams FM Management Plan, downstream vendor verification for each FM stream, downstream flowchart
CR9 — Facility Requirements Site conditions, insurance, closure planning Facility risk assessment, insurance certificates, closure plan
CR10 — Transport Packaging, handling, and legal shipping Packaging procedures, shipping documentation, transporter qualification records

Note that CR5 carries a specific, checkable threshold: negative-value streams — the ones that cost the facility money to process — cannot sit in storage longer than one year. If your inventory aging report shows anything past that mark, expect a question about it before the auditor even gets to your EHS files.

Process Requirement Documents: Match Them to Your Actual Scope

This is where I see facilities over-prepare or under-prepare most often. You only need documentation for the Appendices in your certified scope, but you need all of it for those. That list now runs through Appendix G — Photovoltaic Modules was added under R2v3.1, effective January 2024, so it belongs in the table below alongside A through F for any facility that handles, processes, or brokers PV modules.

Appendix Applies To Core Documents
A — Downstream Recycling Chain Any facility transferring R2 Controlled Streams to a downstream vendor Downstream vendor qualification files, tracking of material flow through the chain, pollution liability insurance if managing negative-value streams
B — Data Sanitization Facilities performing logical sanitization or enhanced physical sanitization Sanitization method validation, device-level sanitization records, competency records for staff performing the work
C — Test and Repair Facilities testing or repairing devices for reuse Reuse plan, test records, product safety plan, quality management system certificate (RIOS or ISO 9001)
D — Specialty Electronics Reuse Facilities verifying specialty/industrial electronics for reuse Appendix C documentation plus specialty verification records for equipment that can't undergo full functional testing
E — Materials Recovery Facilities dismantling or refining recovered material streams Additional risk assessments specific to dismantling/smelting operations, pollution liability insurance
F — Brokering Facilities sourcing equipment shipped directly supplier-to-vendor Quality management system certificate, full downstream chain verification under Appendix A qualifications
G — Photovoltaic Modules Facilities handling, processing, or brokering PV modules (added under R2v3.1, effective January 2024) PV module handling and testing procedures, downstream vendor verification specific to PV streams, module-specific risk assessment documentation

One detail that trips up test-and-repair operations: Appendix C requires equipment and components to be processed within one year of receipt. That's a hard clock, and it shows up in the same throughput records CR5 already requires you to maintain — so build one tracking system that satisfies both instead of running parallel logs.

Facilities that stop downstream tracking at the first R2v3-certified vendor in the chain — which the COP allows, since that vendor has already been through its own certification audit — still have to register that downstream chain with SERI. Bring the registration confirmation, not just the vendor's certificate, or the auditor has no way to verify you actually stopped tracking where you're claiming to.

Internal Audit and Corrective Action Records Come First, Not Last

I'd put your internal audit file at the top of the stack, not the bottom, because it's the first thing that tells the auditor how the rest of the audit is going to go. The COP requires a complete internal audit cycle covering the certification period, and any open nonconformity from that cycle becomes a certification-body nonconformity the moment the external auditor sees it's still open. That reclassification is entirely avoidable — close your own findings with documented corrective action before the CB shows up, and the auditor is reviewing history rather than opening new files.

Have ready:

  • The internal audit schedule and evidence it was followed
  • Internal audit reports covering every Core Requirement and applicable Appendix
  • Corrective action records showing root cause and verification of effectiveness
  • Management review minutes showing internal audit results were actually discussed at the leadership level

A management review that never mentions the internal audit results is its own kind of gap.

The COP also names four things it treats as automatic major nonconformities, regardless of how minor they might look in isolation:

  • Failing to identify a Focus Material stream in the FM Management Plan
  • Failing to list a downstream vendor in the recycling chain flowchart
  • Ineffective due diligence on a shipment of Controlled Streams
  • Letting your SERI Licensing Agreement lapse

Check all four before the auditor does — they cost disproportionate audit time to close relative to how quickly they're caught in a five-minute document review.

Building the Package: A Structure That Survives Stage 1 and Stage 2

Whether you're preparing for a documentation-focused Stage 1 or the operational verification of Stage 2, the package should be organized the same way, because the auditor is going to ask for the same evidence at both — just at different depth. I generally recommend mirroring the standard's own numbering rather than inventing your own categories: a folder for each Core Requirement 1 through 10, a folder for each applicable Appendix, and a separate folder for internal audit and management review records that sits outside both because it touches everything.

Inside each Core Requirement folder, keep three things: the procedure or plan itself, the records that prove it's being followed, and — this is the one people skip — a one-page index listing what's inside and where the underlying raw data lives if it's too large to print or attach (throughput databases, sanitization logs, chain-of-custody systems). The COP requires the auditor to pull copies of certain records into the audit report itself, so anything that can't be handed over as a standalone document slows the audit down even when the underlying practice is sound.

A Practical Prep Timeline

30 days out:

  • Pull your scope statement and confirm it still matches what you actually do — new equipment types, new Appendices, or a discontinued process all need the scope updated before the audit, not discovered during it.
  • Close any open internal audit corrective actions.

14 days out:

  • Assemble the folder structure above and do a dry run: pick five documents at random from your own Core Requirement list and time how long it takes to produce each one.
  • If any take more than a couple of minutes to locate, that's your list of what to fix before audit day.

Day of:

  • Have management review minutes, the FM Management Plan, the downstream flowchart, and your internal audit file physically staged and ready to hand over first.
  • Those four show up early in most audits because they're the fastest way for an auditor to gauge whether the rest of the system is going to be well-organized or a scavenger hunt.

The Gaps That Show Up Most in Document Review

A few patterns repeat often enough to call out directly. Downstream flowcharts that list vendors the facility used two years ago but dropped since then. FM Management Plans that cover the Focus Materials a facility processes routinely but miss an occasional stream — old alkaline batteries mixed into a lot, for instance — because it wasn't the primary business line. Insurance certificates that have renewed but the updated certificate never made it into the audit file. None of these are operational failures. They're document-hygiene failures, and they're exactly the kind of finding a facility could catch itself with a quarterly file review instead of learning about it from a nonconformity report.

If your facility is still building out its documentation set rather than just staging it for an audit, our guide to R2v3 documentation requirements walks through what belongs in each procedure before you ever get to the audit-prep stage. And if you want a second set of eyes on the package itself before your certification body sees it, that's the exact gap our R2 audit preparation work is built to close.

Frequently Asked Questions

What documents does an R2v3 auditor ask for before Stage 1? At minimum: the current scope statement, EHSMS documentation (policy, manual, management review minutes), the legal compliance register, throughput tracking records, the Focus Materials Management Plan with downstream vendor verification, data security/sanitization records, and the complete internal audit file for the certification period. Which Appendix-specific documents get added depends entirely on your certified scope.

How far in advance should I send documents to my certification body? Most certification bodies request a document package two to four weeks before Stage 1 so they can review it before scheduling on-site time. Confirm the exact window and format with your CB directly — the COP sets minimum audit-preparation expectations but leaves timing and submission format to each certification body's own procedure.

What happens if my internal audit still has open nonconformities when the auditor arrives? Per the R2 Code of Practice, any nonconformity from your internal audit cycle that's still open at the time of the certification or recertification audit gets written up as a nonconformity by the certification body auditor. Closing internal findings before the external audit keeps them off your certification history.

Do I need separate documentation for every Appendix, or just my Core Requirements? Just the Appendices in your certified scope — but all of them, at every audit in the cycle, not only at recertification. R2v3.1 runs from Appendix A through Appendix G (Photovoltaic Modules, added effective January 2024), so confirm your scope statement reflects the full current list rather than whichever appendices applied when you first certified. A facility certified only to Appendix A (Downstream Recycling Chain) doesn't need Appendix B (Data Sanitization) records unless it's actually performing sanitization in-house.

Can a remote surveillance audit replace staging a physical document package? One surveillance audit per certification cycle can be conducted remotely, but only at the certification body's discretion and only if the facility meets the COP's criteria for electronic document accessibility. A disorganized digital folder doesn't meet that bar any better than a disorganized filing cabinet does — the standard for accessibility is the same either way.

Last updated: 2026-09-15

J

Jared Clark

Principal Consultant, Certify Consulting

Jared Clark is the founder of Certify Consulting, helping organizations achieve and maintain compliance with international standards and regulatory requirements.

Need R2 Certification Help?

Whether you’re starting your R2 certification journey or preparing for your R2v3 upgrade, our team is here to help. Schedule a free consultation to discuss your goals and get a realistic roadmap.