What your auditor is handed

The audit log is a timestamped record of every event in the certificate lifecycle, written at the moment the event occurs.

One lot, start to finish

Every certificate request. Every follow-up, with its stage. Every escalation. Every document received, with its matching outcome and confidence. Every review decision. Every exception opened.

Each row carries the timestamp, the lot, the supplier, the material, and what happened. Filter to a single consignment and the whole history is there in order.

Audit log TPL-LOT-010

TPL-LOT-010 · TPL-PO-010 · Template Peptides SA · Template Vitamin C Powder

TimestampEventWorkflowOutcomeNotes
2026-07-06 09:02:14 PO Logged WF2 PO Intake success PO TPL-PO-010 logged for Template Peptides SA / Template Vitamin C Powder. Initial COA request sent to [email protected].
2026-07-11 09:00:07 COA Chase Sent WF1 COA Chase Loop success Follow-up 1 sent to [email protected] (chase 1, 5d open)
2026-07-16 09:00:11 COA Chase Sent WF1 COA Chase Loop success Follow-up 2 sent to [email protected] (chase 2, 10d open)
2026-07-23 09:00:09 COA Chase Sent WF1 COA Chase Loop success Final Follow-up sent to [email protected] (chase 3, 17d open)
2026-07-28 09:00:06 COA Escalated WF1 COA Chase Loop success Escalated to [email protected] after 3 chases, 22d open. Exception created. No further automated chasing for this batch.
One consignment, every event, in the order they happened. Each row was written at the moment of the event, not assembled afterwards.

Why written-as-it-happens matters

A report generated at audit time can only contain what survived in the systems it reads. Anything that happened in somebody’s inbox and was never recorded is gone.

A log written continuously contains the events regardless of whether anyone thought they mattered at the time. That includes the events you would rather not have to explain, which is exactly what makes the ones you can explain credible.

What this evidences

Clause 3.5.1.2 requires a documented supplier approval and monitoring procedure. Clause 3.5.1.3 requires ongoing monitoring and review of supplier performance. Monitoring is continuous by definition. Your procedure document proves the intent. The log proves the operation.

Clause 3.5.2.1 requires that acceptance parameters and testing frequency are “clearly defined, implemented and reviewed”. Defined lives in your procedure. Implemented and reviewed live here.

Your data stays yours

The records sit in a database instance belonging to your business. You can export the entire audit log at any time, in full, without asking. If you stop working with Opscera, the evidence does not leave with it.

Book a process review