The Temptation of Generic Tools
It starts the same way at almost every certification body. The operations are growing, the spreadsheets are breaking, and someone on the team suggests a project management tool. "Let's try Monday.com," they say. Or Trello, or Asana, or ClickUp. The tools are polished, affordable, and designed to manage any kind of workflow. Surely they can handle certification management.
The CB signs up, creates boards, builds columns, maps out stages. For the first few weeks, it feels like progress. Everything is visual. Tasks move across the board. People get notifications. It looks organized.
Then reality sets in.
Scenario 1: Phases Need Gates, Not Just Columns
In Trello or Monday.com, a "phase" is just a column or a status label. Moving a card from "Stage 1 Complete" to "Stage 2 Scheduled" is a drag-and-drop action that anyone can perform at any time, with no conditions.
In a real certification workflow, Stage 2 cannot begin until Stage 1 findings have been addressed, the Stage 1 report has been signed, and the audit plan for Stage 2 has been approved. These are not soft guidelines — they are requirements defined in the CB's quality manual and enforced by the accreditation body.
A generic tool has no concept of phase gates. There is no mechanism to prevent a card from moving forward until prerequisites are satisfied. There is no validation that the required documents exist. There is no check that the right people have signed off. The result is that the tool becomes a visual tracker rather than a workflow enforcer, and the actual process enforcement falls back to manual checking — which is what the tool was supposed to replace.
Scenario 2: Signing Chains Are Not Task Assignments
Certification documents require signatures from specific people in a specific order. The lead auditor signs the stage report, then the technical reviewer signs, then the committee chair signs. Each signature carries a different meaning — the auditor attests to the findings, the reviewer validates the technical adequacy, the chair approves the certification decision.
In a generic project management tool, the closest equivalent is a task assigned to a person. But task completion is binary: done or not done. There is no visual signature capture, no signing order enforcement, no timestamp and IP recording, no PDF generation with signatures flattened into the document. The CB ends up managing signatures through email — sending PDFs back and forth — while the project management tool simply tracks whether "the signing step" is marked complete.
Crestview Registrars tried this approach with Asana. They created a subtask checklist for each signing step: "Lead auditor signed," "Technical reviewer signed," "Committee chair signed." But the checklist was just a set of checkboxes. Anyone could check them. There was no actual signature captured. When the AB assessor asked to see signed documents during an office assessment, Crestview had to produce the email thread where PDFs were exchanged — a process the tool was supposed to eliminate.
Scenario 3: Scope Coverage Is Invisible
When a planner assigns an audit team, they must ensure the team collectively covers the client's scope — the EA codes, food chain categories, or technical areas relevant to the certification. This is a matching problem: the client's scope requirements must be compared against the qualifications of available auditors.
No generic project management tool can do this. Trello does not know what an EA code is. Monday.com has no concept of auditor qualifications. The planner looks at the board, sees a card for the audit, and then opens a separate spreadsheet to check which auditors are qualified. The tool manages the timeline but is blind to the most critical planning constraint.
Scenario 4: Audit Time Rules Do Not Fit Custom Fields
ISO certification has specific rules for calculating audit time. IAF MD 5 provides tables based on employee count, complexity factors, and standard-specific adjustments. These calculations determine the minimum number of audit days, and the AB expects the CB to demonstrate that their audit time meets or exceeds the calculated minimum.
In a generic tool, the CB might create a custom field called "Audit Days" and manually enter the number. But there is no calculation engine behind it. There is no validation that the entered number meets the MD 5 minimum. There is no adjustment for multi-site audits, integrated management systems, or standard-specific factors like the K-factor for ISO 50001. The number is just a number in a field — it could be right or wrong, and the tool cannot tell the difference.
Scenario 5: Committee Impartiality Cannot Be Checked
When a certification decision goes to committee, the committee members must be impartial — they cannot have consulting relationships, employment history, or other conflicts with the client. The CB must verify this before assigning committee members.
A generic tool has no conflict-of-interest database. It has no relationship between committee members and clients. The planner assigns committee members based on availability and qualification, trusting that someone remembers to check for conflicts. When nobody remembers — and eventually, nobody does — the CB discovers the gap during an AB assessment, resulting in an accreditation nonconformity.
Scenario 6: Accreditation Requirements Are Foreign Concepts
Accreditation bodies impose requirements on CBs that have no parallel in general project management: witness audit cycles, surveillance date tracking, scope coverage validation, competence management, and impartiality assurance. These requirements are not optional features — they are conditions of the CB's accreditation.
Generic tools are unaware of these requirements. They cannot track witness cycles, calculate surveillance windows, validate scope coverage, or enforce impartiality rules. The CB must build these capabilities manually — typically through spreadsheets and email reminders — alongside the project management tool. The result is a two-system operation where the tool handles the easy parts (task tracking, calendar views) and manual processes handle the hard parts (everything the AB actually cares about).
The Pattern: Tool Adoption, Customization, Abandonment
The lifecycle of generic tool adoption at a CB follows a predictable pattern:
- 1. Adoption: The team sets up the tool with enthusiasm. Boards are created, workflows are mapped, integrations are configured.
- 2. Customization: The team realizes the tool does not handle CB-specific requirements. Custom fields are added, automations are built, workarounds are documented.
- 3. Parallel systems: Despite the customizations, critical functions still require external tools. Spreadsheets persist for scope tracking. Email persists for signatures. A separate calendar tracks surveillance dates.
- 4. Abandonment: The overhead of maintaining the tool alongside the parallel systems exceeds the benefit. The tool becomes an underused dashboard while real work happens in spreadsheets and email.
Atlas Certification Group went through this cycle twice — first with Trello, then with Monday.com — before concluding that they needed purpose-built software.
What Purpose-Built Means
A purpose-built platform for certification body operations is not a project management tool with certification-themed labels. It is a system that understands the domain:
- •Phases have gates with defined prerequisites and document requirements
- •Signing is built in with visual signatures, defined chains, and timestamped records
- •Scope is a first-class concept with qualification matching and coverage validation
- •Audit time is calculated using the applicable rules, not entered manually
- •Committee impartiality is checked systematically before assignment
- •Accreditation requirements are embedded in the workflow, not bolted on
Certiva was built from inside a certification body, by people who understood why generic tools fail. It is not a project management tool adapted for certification. It is a certification operations platform that happens to manage projects as part of a much larger, domain-specific workflow.