With Certa, the assistant that asks your auditors first
Every certification body problem, solved in one system.
Man-days, multi-country offices, tailored checklists, competence, scheduling, NCs, client history and document review. CABAMS handles the rules, records and reminders; its assistant prepares drafts; your auditors decide.
- Man-day calculation
- Multi-country offices
- Industry-tailored checklists
- Client information once
- Auditor competence
- Auditor scheduling
- NC management
- Client audit history
- Document assessment
- Reports and accreditation
- Client applicationsScope, sites, headcount
- Auditor poolCompetence, codes, availability
- Scheme rulesISO/IEC 17021-1, IAF MDs
- Multi-site clientsSite lists and risk
- Audit historyPast findings and cycles
- Contracts and financeFees, currencies, terms
- Duration rules
- Competence checks
- Stage 1 review
- Draft findings
- Quotations and contractsCalculated, reviewed, signed
- Audit plans and teamsCompetence-matched
- Reports and NCsLinked to evidence
- Certification decisionsWith full review trail
- Certificates and invoicesIssued and registered
The problems every certification body knows
And how CABAMS solves each one.
- 1
Man-day calculation
Durations worked out in spreadsheets, adjustments undocumented, and assessors asking why.
Durations from your approved rules (IAF MD 5 and scheme rules), every adjustment justified and approved before the quotation.
- 2
Offices in several countries
Local offices drift apart on rules, rates and templates, and head office can't prove it stays in control.
One rule set for every office, local currencies and languages, with certification decisions and oversight kept with the legal entity, as ISO/IEC 17021-1 and IAF MD 12 expect.
- 3
Checklists that fit the client
Generic questionnaires that miss what matters in a dairy plant or a hospital.
Audit questionnaires tailored by industry, sub-industry, IAF code and technical code.
- 4
Client information, again and again
The same scope, sites, shifts and headcount re-typed for every audit.
Collected once through the client portal and reused for every audit, with justified non-applicable clauses.
- 5
Auditor competence
Qualifications, codes, witness audits and expiry dates spread across folders.
One competence record per auditor, checked automatically before every assignment, with training and evaluations.
- 6
Auditor scheduling
Calendars in email; the right auditor booked twice or not at all.
Schedules built from competence, availability, location, language, rotation and impartiality.
- 7
NC management
Findings in reports, client responses in inboxes, closures hard to prove.
Temporary NCs drafted for the auditor, graded by the auditor, answered in the client portal and verified to closure.
- 8
Client audit history
Previous reports and open NCs hard to find when the surveillance auditor arrives.
Every audit, report, NC and change for a client in one history, attached to each new audit automatically.
- 9
Document assessment
Stage 1 document reviews done by hand, clause by clause.
Client documents mapped to the clauses, with a draft stage 1 report for the auditor to approve.
- 10
Reports and accreditation
Days spent assembling records for the accreditation body.
Audit reports from your templates, and the CB's own records kept ready for office and witness assessments.
Assistant Built into CABAMS
Meet Certa. It prepares the audit. Your auditor decides.
Certa reviews stage 1 documents against the standard, drafts the stage 1 report, turns field notes into temporary NCs and checks reports for gaps. Every draft waits for a competent auditor to approve, edit or reject it.
- Drafts only. Certa never raises, grades or closes a finding, and never reviews or decides on certification.
- Approval on record. Each draft shows who approved it, what they changed and when.
- Private. No client or auditor data goes to any outside AI service.
- Your choice. Switch Certa off for one scheme, one office or the whole certification body.
See CABAMS at work
Sample screens from a certification body with four offices. Client and personal details are masked, as they are for any user who doesn't need them.
Needs attention today
- Assignment blocked: Clie••• Foods stage 2 has no auditor qualified for code 03 in the Mumbai office.
- Competence expiring: 3 auditors' ISO 45001 qualifications lapse this month.
- Surveillance window: 11 audits must happen within 12 months of the last one.
- Ready for decision: 5 technical reviews complete.
Auditor utilization this month
Inputs · Clie••• Foods · ISO 9001 + ISO 14001
- Effective personnel140
- Shifts2 (night shift: 30)
- Sites3 (multi-site, sampled)
- EMS complexityMedium
- Integration levelHigh (one system)
- Rule setCB-DUR-07 v4 (IAF MD 5)
Calculation, step by step
| ISO 9001 base, 140 people | 7.0 |
| ISO 14001 base, medium complexity | 8.0 |
| Integrated audit reduction (−20%) | −3.0 |
| Multi-site: sampled sites added | +1.0 |
| Adjustment: low process variety (−5%) | −0.6 |
| Initial audit total | 12.4 days |
| Stage 1 / stage 2 split | 3.0 / 9.4 |
| Each surveillance (about one third) | 4.1 |
Every adjustment needs a written reason. The reviewer approves before the quotation is issued.
Multi-site sampling · Clie••• Logistics · 12 sites
| Site | Activity | Risk | Last audited | This audit |
|---|---|---|---|---|
| Central function | Head office | Med | 2025 | Always |
| Site 04 | Cold storage | High | 2024 | Selected · risk |
| Site 07 | Cross-dock | Low | Never | Selected · not yet visited |
| Site 09 | Warehouse | Low | 2025 | Random pick |
| Site 11 | Warehouse | Low | 2023 | Selected · random |
Sample size from the square root of the number of sites, raised for risk and findings, per IAF MD 1. Every site is visited at least once in the certification cycle.
Competence matrix · ISO 9001 technical areas
| Code 03 Food | Code 17 Metals | Code 28 Construction | Code 33 IT | Lead auditor | |
|---|---|---|---|---|---|
| A. R••• | Qualified | Qualified | – | In training | Yes |
| L. C••• | Qualified | – | Qualified | – | Yes |
| M. O••• | Witness due | Qualified | Qualified | – | No |
| S. P••• | – | – | Expires 30 Oct | Qualified | Yes |
Evaluated from qualifications, audit log, witness audits, CPD and annual performance reviews. Screening of new auditors: CV and evidence check, interview, training, witnessed audit, approval by the competence committee.
Stage 2 · Clie••• Foods · 14–18 Apr
- A. R•••: code 03 qualified, lead auditor Competence
- No consultancy or employment with client in 2 years Impartiality
- Not more than 3 cycles with this client Rotation
- Available 14–18 Apr; Arabic and English Calendar
- M. O•••: witness audit for code 03 still due Competence
Team
- Lead auditor: A. R•••Declaration of no conflict signedConfirmed
- Auditor: L. C•••Declaration signedConfirmed
- Technical expertNot required for this scope–
Documents received · Clie••• Foods · ISO 22000
| Clause | Document found | Certa's note |
|---|---|---|
| 4.3 Scope | FSMS Manual §2 | Covers both sites |
| 8.2 PRPs | PRP-01 to PRP-09 | Complete |
| 8.5.2 Hazard analysis | HACCP plan v3 | Allergen hazards not assessed for line 3 |
| 9.2 Internal audit | None uploaded | No internal audit record in 12 months |
| 9.3 Management review | Minutes, Mar 2026 | Inputs 9.3.2 c and e missing |
Draft stage 1 report
3 areas of concern that could become NCs at stage 2, and 1 scope note.
Prepared by Certa from the client's uploads. Not sent to the client until approved.
Clause 7.1.5 Monitoring and measuring resources. Calibration register sampled: 12 of 48 gauges. Two gauges past due date. Photo 14, 15
Temporary NC (draft by Certa): Calibration not maintained for two gauges used for product release. Awaiting lead auditor
Clause 8.4 External providers. Supplier evaluations current for all critical suppliers. Record SUP-2026
Lead auditor decides
Report completeness check
- All clauses in the audit plan covered
- Every finding has a clause and evidence
- Sampled sites match the programme
- Opening meeting attendance not attached
After approval, the NC goes to the client portal with the response deadline and automatic reminders.
Technical review checklist
- Audit duration matches the approved calculation
- Team competent for scope and codes
- Reviewer was not part of the audit team
- Major NCs closed; minor NC plans accepted
- Scope wording matches the activities audited
Decision
Made by an authorized decision-maker, independent of the audit.
Impartiality
- Impartiality risk register14 risks · reviewed quarterlyCurrent
- Impartiality committeeNext meeting 12 NovScheduled
- Annual auditor declarations29 of 31 signed2 due
Complaints, appeals and accreditation
- CMP-019 client complaintHandled by staff not involvedIn review
- APL-004 appeal against decisionPanel independent of decisionClosed
- Accreditation body office assessmentRecords pack prepared18 Nov
Tailored to every client, from the first question
One classification drives everything after it: the checklist the auditor sees, the competence needed, the man-day risk level and the clauses that may not apply.
- IndustryFood and beverage
- Sub-industryDairy processing
- IAF code03 · Food products
- Technical code3.1 Dairy
- DrivesChecklist · auditor competence · man-day risk · applicable clauses
Client input, once
Sites, shifts, headcount, processes, outsourced activities and documents are collected through the client portal and reused for every audit in the cycle.
Non-applicable clauses, justified
Exclusions such as design and development are recorded with the client's justification and the reviewer's acceptance, only where the standard allows them.
Industry checklists
Clause checklists carry sector-specific prompts, so an auditor in a dairy plant sees what matters in a dairy plant.
The whole certification cycle, in one place
Every step is recorded against one client history, from the first enquiry to the third surveillance audit and recertification.
- Application
Client applies online with scope, sites and documents.
Client portal - Contract review
Codes, competence available, man-days by your rules, exclusions justified, quotation issued.
Your rules - Agreement and payment
Agreement, proforma and payment tracked; audits released when terms are met.
Reminders - Programme and plan
Three-year programme, audit plan and formal intimation to the client: dates, team, agenda, documents needed.
Client notified - Team assignment
Competent, trained, impartial auditors, checked before the team is confirmed.
Checked - Stage 1
Document review against every clause, with a draft stage 1 report and readiness for stage 2.
Certa draftsAuditor approves - Stage 2
Offline checklist on site. Field notes become temporary NCs for the auditor to confirm and grade.
Certa draftsAuditor grades - NC follow-up
Client submits root cause, correction and evidence through the portal; reminders run until the auditor verifies closure.
Client portalAuditor verifies - Report
Built from the approved checklist in your template, checked for completeness.
Certa checks - Review and decision
Independent technical review and a decision by authorized staff.
People only - Certificate
Issued, published to the register and verifiable online; suspension and withdrawal handled.
Public register - Surveillance and recertification
Every later audit, including special and transfer audits, starts with the full history and open NCs attached.
Reminders
Certa drafts prepared for review · Auditor decides a person's decision, always · Your rules calculated from your approved rules · Client client communication and reminders
Keep your own house in order, too
Accreditation bodies assess the certification body, not just its audits. CABAMS keeps the CB's own system current and ready.
CB documentation
Manual, procedures and forms under version control, updated when standards or IAF documents change.
Auditor competence
Screening, qualification, codes, witness audits and annual evaluation for every auditor and reviewer.
Training
Training plans, CPD, calibration sessions and records, linked to the codes each person can audit.
Impartiality
Risk register, committee, declarations and rotation, checked before every assignment.
Complaints and appeals
Handled by people not involved, with every step recorded.
Internal audit and review
The CB's own internal audits and management reviews, with actions tracked.
Records and retention
Every client record kept for the required period, findable in seconds.
Accreditation assessments
Office and witness assessment packs prepared from live records.
How it works, step by step
Scroll through the 5 steps. The panel shows what CABAMS does at each one.
- 1 Step 1 of 5
Application and contract review
Clients apply online or through your team. CABAMS checks scope, sites and technical areas, then flags anything your reviewer needs to confirm.
- 2 Step 2 of 5
Man-days and audit programme
Audit duration is calculated from headcount, complexity and sites using the IAF rules, with every adjustment recorded. The three-year programme builds itself.
- 3 Step 3 of 5
Planning and team assignment
Auditors are matched on competence, codes, language, impartiality and availability. Plans go to the client for confirmation in their own language.
- 4 Step 4 of 5
Audit, findings and corrective actions
Auditors work from a live checklist, raise findings on the spot and attach evidence. Clients answer nonconformities with root cause and proof through their portal.
- 5 Step 5 of 5
Technical review, decision and certificate
The review file assembles itself: report, evidence, findings, competence records and duration checks. The certification decision stays with your reviewer, and the certificate is issued and registered.
- Legal entity verifiedDone
- Scope: food processingDone
- 3 sites declaredCheck
- Technical area competenceAvailable
- Contract review sign-offPending
- Base duration, 140 staff6.5 days
- Integrated system reduction-10%
- Multi-site sample (3 of 3)+1.0 day
- Stage 1 / stage 2 split2.0 / 5.0
- Reviewer approvalPending
- Lead auditor: A. R•••Code 03 qualified
- Auditor: L. C•••Code 03 qualified
- Technical expertNot required
- Impartiality checkClear
- Plan sent to clientConfirmed
- NC-01 Calibration records, 7.1.5Minor
- NC-02 Supplier evaluation, 8.4Closed
- OFI-01 Internal audit scopeNoted
- Corrective action planAccepted
- Evidence of closureUnder review
- Audit duration matches calculationPass
- All major NCs closedPass
- Reviewer independent of audit teamPass
- Decision: certifyApproved
- Certificate issued and registeredDone
- Rules you can showMan-days and sampling from your approved rule sets
- One client historyEvery audit, NC and change linked across the cycle
- Draft, then approveThe assistant prepares; auditors decide
- Accreditation readyThe CB's own records kept current
A closer look at each module
Use them together or start with the one you need most.
Applications and contract review
Online applications with scope, sites, headcount and shifts, checked before anyone quotes.
- Application review checklist with reviewer sign-off
- Technical area and code assignment
- Transfer and scope-change requests
Man-days and audit programme
Durations and three-year programmes from your rule sets, with every adjustment justified.
- Rule sets per standard and scheme, versioned
- Integrated audits, shifts and multi-site sampling
- Quotation generated from approved man-days
Auditor competence and screening
From first application to annual evaluation, every auditor's competence in one record.
- Screening: CV and evidence check, interview, training, witnessed audit
- Codes, qualifications, CPD and expiry alerts
- Annual performance and witness audit plan
Assignment and scheduling
Teams built from competence, impartiality, rotation, language and availability.
- Conflict of interest check before every assignment
- Calendar across offices and external auditors
- Audit plan sent to the client for confirmation
Audit reports and nonconformities
Auditors work from the checklist, online or offline, and the report builds itself from it.
- Offline tablet app with photos and evidence
- Report from your approved template
- NC responses from the client portal, tracked to closure
Review, decision and certificates
Independent technical review and decision, then the certificate and public register.
- Review checklist covering duration, team and scope
- Decision by authorized, independent staff
- Certificate templates, register and suspension handling
CB management
The certification body's own obligations, kept ready for accreditation assessments.
- Impartiality risks, committee and declarations
- Complaints and appeals handled independently
- Accreditation body assessment records
Offices and finance
Several offices on one set of rules, each with its own team, currency and invoices.
- Office-level views with group oversight
- Rates, quotations, invoices and payments
- Multi-language reports and certificates
Everything on one screen
The overview your managers open every morning.
Certification operations
Audit mix by standard
Auditor utilization
- A. R•••92%
- L. C•••78%
- M. O•••64%
- S. P•••55%
Agent activity
- Man-days recalculated after scope change, Clie••• Plastics6 min ago
- Report built from checklist for Clie••• Foods31 min ago
- Certificate issued, Clie••• Logistics ISO 450011 h ago
- Reminder sent: 3 NC responses due this week2 h ago
What's included
Rule-based man-day calculation
Durations from headcount, shifts, complexity and sites, with every adjustment justified.
Multi-site sampling
Sample sizes and site selection by your rules, every site covered in the cycle.
Auditor competence matrix
Codes, qualifications, witness audits, CPD and expiry dates in one place.
Auditor screening
Application, evidence check, interview, training and witnessed audit before approval.
Impartiality checks
Conflict of interest, rotation and declarations checked before every assignment.
Offline audit app
Checklists, photos and findings on a tablet, with or without a connection.
Certificate register
Certificates issued, suspended, withdrawn and published for verification.
Multi-office operations
Regional offices with shared rules, their own currencies and central oversight.
Built for
- Certification bodies
- Multi-country CB networks
- Inspection and verification bodies
- Personnel certification bodies
Two ways to run it
Start on a subscription and move to your own installation whenever you need to.
Cloud subscription
Monthly or annual, priced by users and by what you run: standards in AMS, offices, schemes or auditors in CABAMS. Hosted in the region your data law requires.
- Start with what you need, add users or standards any time
- Updates, backups and support included
- Encrypted, masked and fully audited
Dedicated to your organization
Your own installation, hosted for your organization only: in a private cloud in your chosen region, or on your own servers.
- Single-tenant: no data shared with any other customer
- Your security rules, single sign-on and integrations
- A named success manager and agreed service levels
Connects to what you already use
- Email and calendar
- Accounting software
- Payment gateways
- SMS and WhatsApp
- Single sign-on
- REST API and webhooks
- Spreadsheet import and export
- Document storage
Security and deployment
- Cloud hosted, private cloud, or on your own servers
- Role-based access for every screen and record
- Full audit trail of who changed what and when
- Encryption in transit and at rest, with daily backups
- Interface in each user's language, including right-to-left scripts
Built for confidential certification work
CABAMS is built and run under our own ISO/IEC 27001, ISO/IEC 42001 and ISO 9001 certified management systems, with the same protection as all our products.
- ✦AI that assists, auditors decide
Certa only prepares drafts. Findings, grading, reviews and certification decisions are made by your people, no client or auditor data goes to any outside AI service, and you can switch the assistant off completely.
- 🔒Encrypted everywhere
Encrypted in transit and at rest, including backups. Encryption keys are managed separately from the data.
- 🌍Stored where your law requires
Choose the hosting region, or run it on your own servers, so you can meet local data protection laws such as GDPR, India's DPDP Act and Gulf PDPL rules.
- ◐Masked by default
Names, contact details and other personal data are masked for every role that doesn't need them, on screen and in exports.
- ≡Fully audited
Every view, change, export and approval is logged with who, what and when, and can be reviewed by your auditors.
- ⚿Your data stays yours
You own your data. Export it any time, and it is deleted on exit, with written confirmation.
- ⊟Separate by design
Each certification body's data is isolated. Derasar Designs staff can't open it without your written, time-limited permission.
Questions teams ask us
Something else on your mind? Ask us directly
Does CABAMS use AI?
Only as an assistant, and only if you switch it on. Certa prepares stage 1 document reviews, report text and temporary NCs as drafts. Nothing is issued until a competent auditor approves, edits or rejects it, and findings, grading, reviews and certification decisions are always made by your people. No client data goes to any outside AI service, and you can switch the assistant off for any scheme or the whole CB.
How are surveillance and recertification audits linked?
Every audit for a client sits in one history: scope, sites, man-days, previous NCs and their closure, changes and complaints. A new surveillance or recertification audit starts with all of it attached, and open NCs carry forward automatically.
Can offices in different countries work in one system?
Yes. Every office works to the same approved rules and templates, with its own currency, language and team. Head office keeps oversight of all activities, and certification decisions stay with authorized people of the legal entity, as ISO/IEC 17021-1 requires.
How is CABAMS priced?
As a subscription, monthly or annual, priced by the number of auditors and users, offices or schemes. Enterprise gives your certification body a dedicated installation hosted for you only, in your region or on your own servers.
Is CABAMS aligned with ISO/IEC 17021-1?
Yes. Workflows, records and approvals follow ISO/IEC 17021-1 and the IAF mandatory documents, including audit duration (IAF MD 5) and multi-site sampling (IAF MD 1), so your records are ready for accreditation assessments.
Can auditors work without internet?
Yes. The auditor app works offline on a tablet or laptop and syncs findings, photos and evidence when back online.
Does Derasar Designs see our certification data?
No. CABAMS is software only. Each certification body's data is kept separate, and you can host it on your own servers. Derasar Designs does not certify, and never links certification to any consulting or software we provide elsewhere.
Does CABAMS help us manage impartiality?
Yes. Keep your conflict of interest register, impartiality risk assessment, committee records and auditor declarations in CABAMS, and check them automatically before every audit team assignment.
Can we configure our own man-day rules?
Yes. Base durations, adjustments and multi-site sampling rules can be configured per scheme, with every change recorded.
Can clients log in?
Yes. Clients can submit applications, confirm audit plans, respond to nonconformities and download certificates through their portal.
In your team's language
Every user chooses their interface language, and documents and reports can be produced in each site's language. Right-to-left scripts are supported.
See the live language demo- English
- Español
- Français
- Deutsch
- Português
- Italiano
- العربية
- हिन्दी
- 中文
- 日本語
- Türkçe
- Bahasa Indonesia
- Русский
- 한국어
- Tiếng Việt
- ไทย
- Polski
- Nederlands
- বাংলা
- Kiswahili