The Question That Changes the Room
You are sitting in a witness audit. The accreditation body assessor has been reviewing your files for the past hour, cross-referencing documents, checking dates, and verifying signatures. Then they look up and ask:
"Show me the communication trail for this client's Stage 1 postponement."
Or: "Show me the signing order for this committee decision. Who signed first, and when did each member sign?"
Or: "Show me when this nonconformity was closed and what evidence was submitted by the client."
These questions are not trick questions. The assessor is doing their job: verifying that your certification body follows its own processes and can demonstrate compliance with ISO/IEC 17021-1:2015. But the way you answer determines whether the conversation moves on smoothly or turns into a finding.
The Paper Trail Scramble
At CBs running on email, spreadsheets, and shared drives, these questions trigger a familiar scramble. The quality manager opens their email client and searches for the client's name. They scroll through threads trying to find the specific communication about the Stage 1 delay. They find three separate email chains, two of which include different stakeholders with different context. They are not sure which chain contains the actual postponement decision.
For the committee signing question, they open the shared drive, navigate to the certification file, and find the signed decision form. It shows all signatures, but the form is a scanned PDF. The timestamps are whatever the scanner recorded, not the actual signing times. The signing order is not evident from the document.
For the NC closure, they search email for the evidence submission. The client sent it as an attachment to an email thread that includes six other topics. The auditor's closure decision was communicated in a reply to a different thread two days later.
None of this is fabricated. It is real. But it is scattered, disorganized, and difficult to verify. The assessor cannot confirm the sequence of events. The CB cannot demonstrate that its process was followed in a clear, auditable way. This is how findings are born.
What the Assessor Actually Needs
Accreditation assessors are not looking for perfection. They are looking for evidence that the CB's management system functions as described in its procedures. They want to see:
- •Sequence: Events happened in the right order. The committee reviewed after the report was finalized, not before. The NC was closed after evidence was reviewed, not simultaneously.
- •Timing: Actions happened within required timeframes. The client responded to the NC within the allowed period. The committee decision was made within a reasonable time after the audit.
- •Attribution: Specific people performed specific actions. The lead auditor submitted the report. A qualified committee member made the certification decision. The client uploaded the corrective action evidence.
- •Completeness: All required steps were performed. Every NC was addressed. Every committee member signed. Every required document was generated and approved.
Certiva's In-App Audit Trail
Certiva records every significant action within the system as an immutable, timestamped entry in the audit trail. This is not a separate log that someone maintains manually. It is an automatic record generated by the system as users perform their work.
Stage 1 Postponement Example
When a planner reschedules a Stage 1 audit, the system records: who changed the dates, what the original dates were, what the new dates are, and exactly when the change was made. If the client requested the postponement through the client portal, that request is also recorded with its own timestamp. The assessor does not need to search through email. They open the audit record and see the complete history of scheduling changes, in order, with timestamps and user attribution.
Committee Signing Order Example
When committee members review a certification file in Certiva, each member's action is recorded individually. The system records when each member opened the file, when they completed their review, and when they applied their signature. The signing order is enforced by the system and recorded in the audit trail.
When the assessor asks who signed first, the answer is in the record: "Member A signed at 14:22 on March 12. Member B signed at 09:15 on March 13. Member C signed at 11:47 on March 13." The sequence is unambiguous, the timestamps are server-generated (not user-reported), and the record cannot be altered after the fact.
NC Closure Example
When a nonconformity is issued, the audit trail records the issuance. When the client uploads corrective action evidence through their portal, the upload is timestamped. When the auditor reviews the evidence and submits their closure decision, that action is recorded with a timestamp. The entire NC lifecycle, from issuance through evidence submission through closure decision, is documented as a sequence of timestamped, attributed events.
The assessor can see at a glance: the NC was issued on February 3, the client submitted evidence on February 18, the auditor reviewed and accepted the evidence on February 20, and the NC was marked as closed on February 20. Every step is accounted for.
Immutable and Timestamped
Two properties of Certiva's audit trail matter for accreditation:
Immutability. Once an event is recorded, it cannot be edited or deleted. The trail is append-only. If a mistake is made and corrected, the correction is a new entry — it does not overwrite the original. This means the assessor can trust that the record reflects what actually happened, not what someone wanted it to show after the fact.
Server-side timestamps. Timestamps are generated by the server at the moment the action occurs. They are not entered by the user, not derived from the user's local clock, and not editable. This eliminates questions about timestamp accuracy or manipulation.
The Confidence Factor
The real value of a comprehensive audit trail is not just compliance. It is confidence. When an accreditation assessor asks a question about process, the CB's quality manager does not need to scramble. They open the audit record, navigate to the relevant section, and show the assessor the timestamped history.
The interaction changes from "Let me search my email for that" to "Here is the complete record." The assessor sees a system that captures process evidence by design, not a collection of artifacts assembled after the fact. This changes the tone of the entire assessment.
A CB like "Vanguard Certification" that previously spent two days preparing documentation packages for accreditation assessments now opens Certiva and walks the assessor through the records in real time. The information is always current, always complete, and always accessible.
Ready to answer the assessor's questions before they finish asking?
Book a demo at getcertiva.com and see how Certiva's timestamped audit trail provides instant proof of process.