Quality management
Run the whole audit programme, not just the audit
Plan a risk-based programme, run the fieldwork, and follow every finding through to a corrective action that someone verified. The evidence stays pinned to the version that was in force.

The audit workspace
Plan an audit around what actually needs attention
An audit starts from its scope and objectives, and the evidence, observations, findings and sampling each have their own place on the record rather than living in a spreadsheet beside it. The audit above is saved and in planning, which is where a real audit spends much of its life.
Programmes schedule higher-risk areas more often and generate the audit when it falls due. Independence rules keep an auditor off their own area, and that is enforced rather than remembered.
- Internal, external and mock audits in one programme
- Risk-based scheduling, with audits generated when they fall due
- Independence rules that keep auditors off their own areas
- Sampling and observations captured as the fieldwork happens
From programme to verified fix
Programme and schedule
Plan the year, weight it by risk, and let the system raise each audit when it is due.
Evidence pinned to a version
Pull in approved procedures, records and training positions as they were at the time, not as they are now.
Findings that become work
Elevate an observation to a finding against the clause it touches, and turn it into a corrective action in one step.
A trail back to the records
A reviewer can follow any finding to the evidence it came from, which is the question an external auditor actually asks.
Patterns across audits
Cross-audit insight surfaces the problem that keeps recurring in different words.
A package you hand over
Curate the evidence you choose and hand the certification body one verified package. No portal, no login.
