The recorded audit: the full concept

3 minInternal auditorCompliance manager
The auditor's visit
says: the day I visited
2026-07-28
The live compliance board
says: now
one clause tree
Valid extinguishers
Emergency plan
Calibration log
Change management
Valid extinguishers
Emergency plan
Calibration log
Change management
A
Parity report — fixed snapshot
2 alerts · 1 reservation · 1 aligned
⚠ Claim exceeds reality — extinguishers
⚠ Excluded yet assessed — change mgmt
Platform stricter — calibration log
Next visit — a new snapshot
fewer lines: the witnesses converge
🔔 Owner & manager notified
evidence ✓
A dated snapshot — never edited
Two witnesses of one tree: the board says "now", the audit says "the day I visited" — their meeting at the seal births the parity report.

If the compliance board is a mirror reflecting your work right now — its colors shifting as your reality shifts — the recorded audit is something else entirely: a dated visit. An auditor walks the very same standard clauses one by one, judges each with their own eyes, and then the visit is sealed and frozen. The board says "now"; the audit says "the day I visited" — together they are two witnesses of one clause tree.

A visit that seals, not a state that breathes

An audit card moves through a governed path: draft → fieldwork → submission → completion (with an honest cancel exit for a visit that never happened). Submission parks the record at a review gate; completion seals it: a server-side closure stamp, a final score, and a record no longer editable — changes go through the governed reopen only. The score is computed, never asked: compliant earns the full share, partial half, non-compliant zero, and "not applicable" leaves the denominator entirely; serious work accidents deduct from the raw score. Nobody types the number by hand.

Answering clause by clause

Every clause carries a four-way answer and two written fields — objective evidence and notes. The auditor's notes are not a footnote here: they are quoted verbatim in the parity report, and they decide its language. Clauses submitted unanswered count as non-compliant — the platform warns you before submission.

Auditing follows commitment

The standards list in the audit form is filtered to what your management has activated from the compliance page — no audit is born on a standard your organization never committed to. goiso's ladder is: learn → commit → track → operate; if your standard is missing from the list, activation is the compliance manager's responsibility, from the compliance page.

The parity report: where the witnesses meet

At the moment of sealing, the thing all of this was built for happens: the platform recomputes the live board and takes a fixed snapshot comparing the auditor's verdict with each clause's color, classifying the hard contradictions in both directions:

  • Alert — the claim exceeds reality: the board shows green, the auditor said non-compliant. The report's most dangerous line: your data claims what the field denied.
  • Alert — excluded yet assessed: a clause you excluded with a written justification, which your auditor deemed applicable and assessed anyway.
  • Reservation — the platform is stricter: the board shows red, the auditor found the clause fine. The remedy lives inside the platform: the evidence exists outside it — bring it in so the board can see it.

The report is a short text that lands as a notification with the owner and the compliance manager (and the auditor), written in the language of the auditor's own notes. It is a fixed, dated snapshot: the board keeps changing afterwards and the report never does — re-completing after a reopen births a second snapshot, never an edit of the first. And with every new visit the disagreement lines grow shorter: the witnesses converge — that is continual improvement, practised.

What a visit gives birth to

Nonconformities are raised against clauses with their classification (major, minor, observation, opportunity), and a major automatically births its corrective action on the CAPA board — the loop closes with independent verification (the corrective-action lesson). Certification visits (stage 1, stage 2, surveillance) attach to a certification cycle managed from its own page, and granting is blocked while a major stays open (the certification journey).

Who uses it

The board's audience is the internal auditor and the compliance manager — not the owner. The separation is deliberate: whoever performs the work does not audit it, and whoever audits does not perform (the internal-audit lesson). The external certification body reads the visits and annotates without ever touching them.

The rule you carry with you: the board says now, the audit says the day I visited — and their meeting at the seal is goiso's truth detector.

Read next

More in this collection