The audit email on a Tuesday
A client's procurement team emails: their annual supplier audit is in two weeks. They want training records for every operative on their sites, risk assessments and method statements for each site, substance data sheets for all chemicals used, the last twelve months of quality audit results, complaint logs, and proof of insurance.
Your compliance lead starts hunting. Training certificates are in personnel files, some scanned, some paper. Risk assessments are in a shared drive, several versions each. Quality audits are in an app. Complaints are in the account manager's inbox. Two days later there is a folder of files, some of them out of date, and nobody is sure it is complete.
Why evidence is so hard to gather
Our article on safety records looks at keeping those records current. This problem is different: the records may be perfectly good, but finding and assembling the right ones for a specific client, across all their sites, takes days.
Evidence is created by different people in different tools for different reasons. Training records belong to HR, risk assessments to operations, audit results to quality, complaints to account management. Each keeps its own filing system. Nothing links them to the client and site they relate to.
Audit questions also cut across those systems. 'Show us training for everyone who works on our sites' needs a list of who worked where, from the rota, joined to training records, from HR. Nobody holds that join, so it is rebuilt by hand every time.
What the hunting costs
| Cost | Effect |
|---|---|
| Senior staff time | Compliance and operations leads lost for days per audit |
| Incomplete packs | Missing items discovered by the auditor, not by you |
| Out-of-date documents | Old versions submitted because the latest could not be found |
| Tender deadlines | Bids weakened because evidence took too long to gather |
| Repeated effort | The same work done again for the next client |
The incomplete pack is the painful one. A missing record often exists; you just could not find it in time. To the auditor, a record you cannot produce looks the same as a record that does not exist.
How we make evidence findable
- We map the evidence clients and tenders usually ask for against where each type is kept today: shared drives, Microsoft 365 or Google Workspace, HR and rota systems, audit apps and email.
- An evidence index that reads those sources through their APIs or connectors, and records each document's type, date, expiry, site, client and the people it relates to. Documents stay where they are.
- Classification with a language model under business data terms to tag documents that are not already labelled, with a person confirming anything uncertain.
- Joins that audits need: rota data linked to training records, so 'everyone who works on this client's sites' is a query, not a spreadsheet.
- A gap and expiry view, showing missing or soon-to-expire evidence per client, so problems are found before the auditor asks.
- An audit pack builder: choose a client and a list of requirements, review the matching documents, and export a structured folder or PDF bundle with an index.
The index shows what you hold. Whether it satisfies a particular client's requirement is still a judgement for your compliance lead; the tool gives them the material quickly.
The next audit
When the email arrives, the compliance lead selects the client, ticks the requirements, and reviews what comes back. Gaps are already known because the expiry view flagged them weeks ago. The pack goes out with an index, current documents and nothing missing that you actually have.
Tenders get easier too. The evidence for a bid is a search, which leaves more time for writing the parts that win work.
Is this where you are?
- Client audits take days of senior staff time to prepare for
- Evidence is spread across drives, inboxes, apps and paper
- You have submitted an out-of-date document by mistake
- Linking training records to the staff on a client's sites is a manual job
- You find gaps when the auditor asks, not before