Audit module
Audit management that carries the whole cycle
From the annual audit plan to the documented effectiveness check — without findings disappearing into spreadsheets and email threads along the way.
Why the lifecycle has to stay in one piece
ISO 9001 clause 9.2 requires a documented audit programme and retention of audit results as documented information. What the standard does not prescribe is the toolchain — and that is exactly where things break. In practice the audit plan lives in a spreadsheet, the question catalog in a Word document, the findings in a report, and the actions in yet another list.
Once those four are kept apart, one simple question can no longer be answered reliably: how many findings from the last cycle were actually closed effectively? That is not an academic question — in the management review and in the certification audit it is regularly the first one asked.
What the audit module covers
The audit programme as the structural umbrella. The programme is not a cover sheet but the level at which intervals, scope, audit teams and sites are defined. Every individual audit, every finding and every resulting action stays visibly linked to it.
Question catalogs built from audit criteria. Catalogs are assembled from a hierarchical structure of audit criteria rather than free text. Every question therefore stays connected to its clause and to the findings it produces — the mapping lives in the system, not in someone’s head.
Execution with evidence attached. Responses, ratings and evidence are captured directly against the audit item. Attachments hang off the finding rather than sitting in a parallel folder structure.
From finding to effectiveness check. A finding and its corrective action form one continuous item with a status history, not two separate records. Ownership and due dates sit on the finding, and automated reminders keep actions from stalling without an active status.
An audit-proof history. Every change is logged, so reviews and audits can trace who changed what and when.
Two details that matter day to day
Auditor independence per ISO 19011 6.2.5. The standard requires that auditors do not audit their own area of responsibility. qportal warns automatically when the auditor and the audited org unit coincide — instead of it surfacing during the external audit.
Auditee confirmation. ISO 19011 6.5.5 expects findings to be agreed with the auditee. That step is modelled as its own state in the lifecycle rather than as an informal conversation.

Who this is for
Quality managers and audit managers who own the annual cycle. Auditors who work on the floor and would rather not retype their notes in the evening. Departments that get assigned an action and need to know what is expected of them by when. And leadership, which needs defensible numbers in the management review rather than collected impressions.
Frequently asked questions
- Does qportal cover both internal and external audits?
- Yes. Internal (first-party) audits, supplier (second-party) audits and preparation for certification (third-party) audits all use the same structure of audit programme, question catalog, finding and action — they are distinguished by audit type and audit criteria.
- Do I need SAP to use qportal?
- No. qportal runs on SAP BTP but is also offered as a hosted service. You need neither your own BTP subaccount nor an S/4HANA system.
- How are findings linked to clauses of a standard?
- Through a hierarchical structure of audit criteria, modelled up to three levels deep. Every catalog question hangs off a criterion, and every finding inherits that link — traceability back to the specific requirement emerges automatically instead of being reconstructed by hand.
- Can auditors work on-site from a mobile device?
- Yes. The interfaces are built with SAP Fiori Elements and work on tablets and phones. Findings are captured during the audit rather than transcribed later from paper notes.