Use case
A quality system that survives
the third audit.
Most operations pass their first ISO 9001 audit on effort. The third one is passed on evidence that accumulated by itself - which is a question of where the evidence is created, not of how hard anyone prepared.
The job
The evidence is scattered, so the review is annual.
The difficulty in a repair workshop is rarely the standard. It is that the evidence lives in four places at once.
Indicators in the ERP, problems in a shared file
Procedures on a drive, competence in HR. Nothing is missing; nothing is together.
So management review is assembled by hand
Clause 9.3 lists its inputs explicitly, and the list is long. Assembling it once a year is why the review tends to describe a system nobody has examined in between.
And documentation ages faster than anything else
In refurbishment the models change, so the gap between the written procedure and the practised one is the single most common audit finding.
What the module holds
Clause by clause, in one place.
This is the quality module already detailed on the GustAV page, mapped to the clauses it serves.
-
01
Improvement register (PDCA / CAPA)
Non-conformities and corrective actions handled as records with a cause and a verification step, not as tickets that close on the day they open.
-
02
Tamper-proof audit log, chained by hash
Each entry carries a fingerprint of the previous one, so a later alteration breaks the chain and is detectable.
-
03
Segregation of duties
So a trail does not show the same person raising, approving and closing an action.
-
04
Management review (9.3) and risk register (6.1)
The review inputs come out of live data instead of being reassembled, and risks and opportunities are held where the actions against them are.
-
05
Skills matrix (7.2)
Who is qualified to do what, at what level, with a date - kept next to the procedures it covers.
-
06
Live quality KPIs and audit exports
Indicators that exist between reviews, and CSV / PDF exports for the auditor.
What this is not
The boundaries, stated plainly.
- No tool makes an operation ISO 9001 certified. Certification is issued by an independent body after an audit of your system.
- REAV holds no certification of its own, and this module does not transfer one. The certificate is yours.
- ISO 9001 covers the management system, not the products. A client asking for R2v3 or WEEELABEX is asking something narrower, which this does not answer.
- A register only reflects what people report. If reporting a problem creates work for whoever reports it, no software fixes that - it is a management question.
FAQ