The auditor’s question is not “do you have a matrix” but “how do you know this person is competent”. A single PDF covers ISO 9001:2015 and ISO 45001:2018 clause 7.2 with criteria, evidence and current status; every change is logged as who · when · old→new.
Compliance report — one PDF
The report brings together the framework (how many competencies, how many mandatory, how many job profiles), current proficiency, expired and expiring records, and a training summary.
Auditor link — no sign-in, time-limited
An administrator generates a link valid for 7-180 days. The auditor opens only the compliance report without signing in. The link is signed: it stops working when expired or tampered with.
Audit trail — who, when, from what to what
Score changes, definition updates, deletions and restores are recorded with user, timestamp and old→new value. Records are filterable and exportable.
KVKK: soft delete and retention
Deleting does not destroy a record: it moves to the recycle bin, stamped with who deleted it. A per-organization retention period (default 30 days) governs permanent cleanup.
Who is this module for?
Quality and HSE staff preparing for an ISO 45001 or ISO 9001 audit
Teams that spend weeks collecting records before an audit
Anyone who must answer who changed what and when in competency data
Frequently asked questions
Which clauses does the report address?
ISO 9001:2015 clause 7.2 and ISO 45001:2018 clause 7.2 (“Competence”): the criterion, the evidence that a person meets it, and the action closing the gap.
Is the auditor link secure?
The link is HMAC-SHA256 signed, time-limited and bound to one organization; it opens only the compliance PDF. Expired, tampered or invalid links return nothing.
How far back does the audit trail go?
Records are not purged; every change since day one remains. Assessment history is preserved the same way.