Quality Management
Audits, corrective actions, processes and approvals in one quality system, organised around ISO 9001.
Plan and run your internal audits, drive every finding to a verified corrective action, map how work should happen and prove it did, and sign off records with a real electronic signature - one quality system, organised around ISO 9001.
A quality system your auditor can navigate
The Quality Management module brings your audits, corrective actions, processes, approvals and records into one system, organised around the ISO 9001 clause structure - so an audit finds what it expects, where it expects it. ComplyTrain structures the QMS around the standard; that describes how the software is organised, not a certification of your company or ours. The scaffolding is ours; the evidence and the audit stay yours.
Run your whole internal audit programme
Plan the programme, schedule the audits, run the fieldwork and act on what you find - all in one place. Higher-risk areas are scheduled more often, audits are generated automatically when they fall due, and auditors capture observations as they go, elevating the significant ones into findings mapped to the exact clause they touch. Pull approved procedures, records and training positions straight in as version-pinned evidence, so what you show is exactly what was in force at the time. When the certification body comes round, curate the evidence you choose and hand over a single verified package - no portal, no login, nothing exposed to the internet.
- A risk-based audit schedule that runs itself, with independence rules that keep auditors off their own areas
- Findings mapped to real clauses in the standards you hold, turned into corrective actions in one step
- Evidence imported from across ComplyTrain and pinned to the version that was live
- A certification-readiness score and cross-audit insights that surface problems repeating across audits
Close every problem the way an auditor expects
A corrective and preventive action in ComplyTrain is a real record, not a to-do with a label. Each CAPA carries its source, a structured root-cause analysis, typed containment, corrective and preventive actions, the evidence behind them and its full history. Severity sets the clock, so a critical issue gets a tighter containment and analysis deadline automatically. And a CAPA cannot reach closure until it has passed the gates your process defines - a comment, the supporting evidence, an electronic signature and, where you require it, a management review. Completing an action and verifying it are two separate acts by two people, so "we finished it" can never stand in for "someone checked it worked". AI can suggest a root cause or a corrective action; a person always commits it.
- Structured root-cause analysis - 5 Whys, Fishbone and more - not a free-text box
- Start from a ready-made CAPA process modelled on how regulated industries work, then shape it to yours
- Closure gated by the evidence, sign-off and review your own procedure demands
- A complete history of every transition, approval and signature on the record
Map how work should happen - and prove it did
Describe a process in plain English and let AI draft the swimlane map; refine it in a structured editor with a live diagram you can export as an image or PDF. Once the definition is approved and version-pinned, you can run it: real people are cast onto each lane, every step captures its evidence as the work is done, and completing the run leaves a numbered, locked record. A documented process shows you know how work should happen; a completed run is dated proof that it actually did.
- AI drafts the swimlane map from a plain-English description; you refine and approve it
- Version-controlled, approved process definitions with a review cadence and an append-only history
- Run a process with a named owner on every step and evidence captured as work happens
- Each completed run leaves a numbered, locked record of exactly what was done
Approvals a person makes, records that hold still
Approval in ComplyTrain is a deliberate act by a named person, not a box anyone with a login can tick. When a step calls for a signature, the approver signs with a fingerprint, face or security key on their own device, backed by a signing certificate issued by your organisation’s own certificate authority - and if the signature fails, nothing moves. You decide who is allowed to sign off at each step, and approval can be held back until that person has completed the training the document requires; let a certification lapse and they are gated again. Only a human can sign: AI can draft and propose, but every AI suggestion has to be accepted or rejected by a person before a document can be approved at all. Approved records are locked and filed, and every action across the system is written to a tamper-evident, hash-chained audit trail that one click verifies end to end.
What it looks like

Placeholder - the QMS dashboard. Upload the real screenshot in the admin.
Use cases
First-time ISO 9001
A supplier standing up a quality system for the first time gets the clause structure, the record types, the audit cadence and the approval routes out of the box - not a blank SharePoint.
Surveillance without the scramble
Findings, corrective actions and their evidence are already linked and version-pinned, so the annual surveillance audit is a walk through live records, not a fortnight of retrieval.
From finding to fix, on the record
An internal audit raises a finding; one step turns it into a corrective action with a structured root cause, verified by a second person and closed only once it has passed your gates - the whole chain traceable end to end.
Sign-off you can prove
Approvals are captured as electronic signatures against a specific version, made on the approver’s own device and held back until their training is current - the evidence is on the record, not in an email you have to find.
One quality system, built around the standard
Audit programme
Plan, schedule and run your internal audits, map findings to real clauses, and turn each one into a corrective action in a single step.
Corrective actions (CAPA)
Structured root-cause analysis, typed actions and a separate verification step - closure gated by the evidence and sign-off your process demands.
Signed approvals & records
Electronic signatures on your own certificates, approval gated on current training, and a tamper-evident audit trail you can verify in one click.
