Where the problem comes from
A management system application already holds most of the records. That produces an easy but dangerous idea: since the records are here, let the software mark conformity too. The result is not an audit but a mirror — the system looks at its own records, endorses itself, and everybody scores full marks.
Two separate fields
| Field | Filled by | What it says |
|---|---|---|
| System finding | The software | What the records show: is there a record, is it out of date, are fields missing |
| Auditor verdict | A person | Whether the requirement is actually met |
The auditor verdict is required and may contradict the system. Without an auditor able to look at a training record and say “this training did not cover that hazard”, the software has not supported the audit — it has replaced it.
What software genuinely contributes
- finding the evidence and putting it in front of the auditor — turning search time into finding time,
- flagging expired records and empty fields in advance,
- tying a finding straight to a corrective action and a due date,
- showing history per clause: did this clause carry a finding last year too?
How this stands in Optifora
In an internal audit record the system finding and the auditor verdict are two separate fields; the verdict is mandatory and a nonconformity can be raised against a clause the system treats as satisfied. The product holds 155 clauses across 6 standards and 33 document types; the audit screen shows the clause, the record attached to it, and the auditor's verdict side by side.