For quality managers
Evidence recorded as it happens, not reconstructed after
When the auditor asks when a decision was taken and who approved it, the answer either was written down at the time — or it has to be rebuilt from memory, in the four weeks before the visit. SecondBrain 365 is an AI agent inside your Microsoft 365: invite it to your reviews and quality meetings, and it records every decision with its date, author and source meeting.
See how SecondBrain 365 supports quality managers, in the months before the auditor arrives rather than the weeks.
The auditor's time is regulated to the half-day. Yours is not measured at all.
IAF MD 5 fixes exactly how long a certification audit lasts, and every accredited body follows it. What nobody has ever put a number on is the weeks your team spends beforehand, collecting evidence for decisions taken months ago.
9 days
of audit for an organisation of 176–275 people — 4 days at 26–45, 15 days at over 1,550. Surveillance is about a third, recertification two thirds.
IAF MD 5:2023, QMS table 1 — binding on all accredited bodies
78%
of certified companies had at least one audit finding; 40% had at least one classified as severe.
DNV, audits of 1,700+ certified companies worldwide, 2018 data
101,426
active ISO 9001 certificates in Italy — second in the world, 6% of the global total.
ACCREDIA, data at 31 December 2024
We are not going to tell you what audit preparation costs your company: no published research measures it, and the figures circulating on vendor pages do not survive a check. You already know what it costs.
What the standard actually asks
Maintain and retain are two different jobs
ISO 9001 distinguishes information you keep current from information you freeze as evidence. Most quality systems handle controlled documents well. What slips through is the decisions taken in meetings: they never become a record, and meanwhile the written procedure falls behind how the work is actually done.
Maintain
A living document, kept current
The procedure as it is followed today. This is the one that drifts: the process changes in a meeting and the document does not, and the gap only surfaces when an auditor reads one and watches the other.
Retain
A record, frozen as evidence
What was decided, when, by whom. Clause 7.5.2 asks for date and author plus review and approval; clause 10.2.2 asks you to retain evidence of the nature of a nonconformity, the action taken and the result.
In ISO's own words: “ISO 9001 requires a ‘Documented quality management system’, and not a ‘system of documents’.” ISO/TC 176/SC2/N1286, guidance on documented information
A concrete case
The corrective action nobody could prove
In the meeting — A nonconformity is discussed, a cause is agreed, someone takes the action and a review date is set. Everyone leaves knowing what was decided.
Eleven months later — The auditor asks for evidence: what was the cause, who owned the action, when was effectiveness verified. The meeting happened — the record of it did not.
With the agent in the room — Each of those becomes a dated record with the minute it came from. On the right: the source on one side, the records on the other, each linked back.
Quality review — Q3
Transcribed · 11 Sep
NC-14: two batches shipped without the final inspection record.
Cause: the checklist step was removed when the line was re-laid out in June.
Anna to restore the step and retrain the two operators by 30 Sep.
Effectiveness to be verified at the November review.
Pick a record to see where it came from.
Nature of the nonconformity, action taken, result to be verified — with the date and the meeting attached. That is what clause 10.2.2 asks you to retain.
What goes in, what comes out
The meetings and threads where quality decisions are actually taken — not a separate compliance tool your team has to remember to open.
In
- Management reviews and quality meetings
- The threads where nonconformities get discussed
- Approval conversations, with who approved
- Procedure documents and their revisions
Out
- Decisions with a date and an author
- A trail from the procedure to the evidence
- Corrective action records, with the verification date
- Alerts when a record contradicts a procedure
⚠️ This is not a compliance product and does not certify anything. It records what was decided, with the date and the source — which is the raw material your evidence is made of, not a substitute for your quality system.
Why the record matters more than the binder
A major has a clock on it
If corrective actions are not verified within six months of the last day of stage 2, the body has to repeat stage 2 — and a suspended certificate is temporarily invalid.
It survives the quality manager
Quality knowledge concentrates in one or two people. What they decided, and why, does not have to leave with them.
Surveillance stops being a project
Recertification is roughly two thirds of the initial audit, every three years — on a record that was kept rather than rebuilt.
The six-month rule is ISO/IEC 17021-1:2015, the standard your certification body itself is accredited against.
FAQ
Questions quality managers ask
No, and anything that claims to should worry you. Compliance is your management system and your auditor's judgement. What this does is narrower and more useful: it keeps decisions with their date, their author and the meeting they came from, so the evidence exists before you go looking for it. Clause 7.5.2 asks for date and author; 10.2.2 asks you to retain the nature of a nonconformity, the action and the result. This produces that material as a by-product of the meetings you already hold.
The record is not really AI-generated: it is what was said in your meeting, with the source attached, and a person approves it if you turn approval on — which for a quality workspace is the setting we would suggest. What you get is closer to a well-kept minute than to a generated document, and it carries the traceability back to the transcript it came from.
Keep them there. Controlled documents under version control are the “maintain” side, and that is a job your DMS does properly. The gap this fills is the “retain” side: the decisions taken in meetings and threads that never become a controlled document at all, and that you end up reconstructing before the audit.
It does not classify anything as a nonconformity — that is your call and the auditor's. It flags when two pieces of content disagree and asks which one holds, the same way it does everywhere else. Deciding whether a difference is a nonconformity, an observation or nothing at all is exactly the part that needs a quality manager.
In your own Microsoft 365 tenant: a SharePoint site under the quality team's Teams group, with your retention rules applying because it is not a separate system. That matters for evidence, which has to be available and protected for as long as your own retention policy says.
Need it for something else?
Same agent, same mechanism. What changes is the rules you write in the context file.
Project management
Stop chasing people for updates: the agent asks, and the plan stays current
Product management
Why the product is the way it is — written down while you decide it
HR
The answer your team already wrote, found by the next person who asks
IT service desk
Forward the reply you just sent. That is the whole documentation step
RFP & bids
The tender's deadlines pulled out of the pack, and the chasing done for you
Onboarding & offboarding
What leaves with a person becomes smaller — and it is honest about the rest