REAV

Use case

A quality system that survives
the third audit.

Most operations pass their first ISO 9001 audit on effort. The third one is passed on evidence that accumulated by itself - which is a question of where the evidence is created, not of how hard anyone prepared.

The job

The evidence is scattered, so the review is annual.

The difficulty in a repair workshop is rarely the standard. It is that the evidence lives in four places at once.

Indicators in the ERP, problems in a shared file

Procedures on a drive, competence in HR. Nothing is missing; nothing is together.

So management review is assembled by hand

Clause 9.3 lists its inputs explicitly, and the list is long. Assembling it once a year is why the review tends to describe a system nobody has examined in between.

And documentation ages faster than anything else

In refurbishment the models change, so the gap between the written procedure and the practised one is the single most common audit finding.

What the module holds

Clause by clause, in one place.

This is the quality module already detailed on the GustAV page, mapped to the clauses it serves.

  1. 01

    Improvement register (PDCA / CAPA)

    Non-conformities and corrective actions handled as records with a cause and a verification step, not as tickets that close on the day they open.

  2. 02

    Tamper-proof audit log, chained by hash

    Each entry carries a fingerprint of the previous one, so a later alteration breaks the chain and is detectable.

  3. 03

    Segregation of duties

    So a trail does not show the same person raising, approving and closing an action.

  4. 04

    Management review (9.3) and risk register (6.1)

    The review inputs come out of live data instead of being reassembled, and risks and opportunities are held where the actions against them are.

  5. 05

    Skills matrix (7.2)

    Who is qualified to do what, at what level, with a date - kept next to the procedures it covers.

  6. 06

    Live quality KPIs and audit exports

    Indicators that exist between reviews, and CSV / PDF exports for the auditor.

What this is not

The boundaries, stated plainly.

  • No tool makes an operation ISO 9001 certified. Certification is issued by an independent body after an audit of your system.
  • REAV holds no certification of its own, and this module does not transfer one. The certificate is yours.
  • ISO 9001 covers the management system, not the products. A client asking for R2v3 or WEEELABEX is asking something narrower, which this does not answer.
  • A register only reflects what people report. If reporting a problem creates work for whoever reports it, no software fixes that - it is a management question.

FAQ

Common questions.

Not necessarily. You choose your level: your teams run it, REAV steps in on documentation and quality handling, or REAV carries the day-to-day workload inside the tool. Management keeps the decisions at every level, and the exact scope is defined during scoping.
It holds the register, the log, the competence matrix and the procedures in one place. What your system contains remains yours to define.
CSV and PDF exports, and a trail they can sample: dated entries, identifiable procedure versions, and approvals separated from execution.
It is tamper-evident, which is the accurate word: entries are chained by hash, so an alteration after the fact breaks the chain and can be detected. No log can prevent someone with sufficient access from acting.

← Back to GustAV

Bring the findings from your last audit.

The most useful demo is against real findings. Tell us what came up last time and we will show where each one would be handled, and what the auditor would have seen instead.