With Certa, the assistant that asks your auditors first

Every certification body problem, solved in one system.

Man-days, multi-country offices, tailored checklists, competence, scheduling, NCs, client history and document review. CABAMS handles the rules, records and reminders; its assistant prepares drafts; your auditors decide.

  • Man-day calculation
  • Multi-country offices
  • Industry-tailored checklists
  • Client information once
  • Auditor competence
  • Auditor scheduling
  • NC management
  • Client audit history
  • Document assessment
  • Reports and accreditation
  • Client applicationsScope, sites, headcount
  • Auditor poolCompetence, codes, availability
  • Scheme rulesISO/IEC 17021-1, IAF MDs
  • Multi-site clientsSite lists and risk
  • Audit historyPast findings and cycles
  • Contracts and financeFees, currencies, terms
CABAMS · Certa + rules
  • Duration rules
  • Competence checks
  • Stage 1 review
  • Draft findings
Working onMan-days for ISO 9001 + 14001, 140 staff, 3 sitesRule set CB-DUR-07 v4 applied, every adjustment justified
  • Quotations and contractsCalculated, reviewed, signed
  • Audit plans and teamsCompetence-matched
  • Reports and NCsLinked to evidence
  • Certification decisionsWith full review trail
  • Certificates and invoicesIssued and registered

The problems every certification body knows

And how CABAMS solves each one.

  • 1

    Man-day calculation

    Durations worked out in spreadsheets, adjustments undocumented, and assessors asking why.

    Durations from your approved rules (IAF MD 5 and scheme rules), every adjustment justified and approved before the quotation.

  • 2

    Offices in several countries

    Local offices drift apart on rules, rates and templates, and head office can't prove it stays in control.

    One rule set for every office, local currencies and languages, with certification decisions and oversight kept with the legal entity, as ISO/IEC 17021-1 and IAF MD 12 expect.

  • 3

    Checklists that fit the client

    Generic questionnaires that miss what matters in a dairy plant or a hospital.

    Audit questionnaires tailored by industry, sub-industry, IAF code and technical code.

  • 4

    Client information, again and again

    The same scope, sites, shifts and headcount re-typed for every audit.

    Collected once through the client portal and reused for every audit, with justified non-applicable clauses.

  • 5

    Auditor competence

    Qualifications, codes, witness audits and expiry dates spread across folders.

    One competence record per auditor, checked automatically before every assignment, with training and evaluations.

  • 6

    Auditor scheduling

    Calendars in email; the right auditor booked twice or not at all.

    Schedules built from competence, availability, location, language, rotation and impartiality.

  • 7

    NC management

    Findings in reports, client responses in inboxes, closures hard to prove.

    Temporary NCs drafted for the auditor, graded by the auditor, answered in the client portal and verified to closure.

  • 8

    Client audit history

    Previous reports and open NCs hard to find when the surveillance auditor arrives.

    Every audit, report, NC and change for a client in one history, attached to each new audit automatically.

  • 9

    Document assessment

    Stage 1 document reviews done by hand, clause by clause.

    Client documents mapped to the clauses, with a draft stage 1 report for the auditor to approve.

  • 10

    Reports and accreditation

    Days spent assembling records for the accreditation body.

    Audit reports from your templates, and the CB's own records kept ready for office and witness assessments.

Assistant Built into CABAMS

Meet Certa. It prepares the audit. Your auditor decides.

Certa reviews stage 1 documents against the standard, drafts the stage 1 report, turns field notes into temporary NCs and checks reports for gaps. Every draft waits for a competent auditor to approve, edit or reject it.

  • Drafts only. Certa never raises, grades or closes a finding, and never reviews or decides on certification.
  • Approval on record. Each draft shows who approved it, what they changed and when.
  • Private. No client or auditor data goes to any outside AI service.
  • Your choice. Switch Certa off for one scheme, one office or the whole certification body.

See CABAMS at work

Sample screens from a certification body with four offices. Client and personal details are masked, as they are for any user who doesn't need them.

app.derasardesigns.com/cabamsMasked view
Northstar Certification / All officesCerta · drafts onlyDubaiMumbaiLondonRiyadh
Audits this month48+9 vs last month
Man-days scheduled13218 unassigned
NC responses overdue9across 6 clients
Certificates expiring in 90 days27recertification due

Needs attention today

  • Assignment blocked: Clie••• Foods stage 2 has no auditor qualified for code 03 in the Mumbai office.
  • Competence expiring: 3 auditors' ISO 45001 qualifications lapse this month.
  • Surveillance window: 11 audits must happen within 12 months of the last one.
  • Ready for decision: 5 technical reviews complete.

Auditor utilization this month

  • A. R•••92%
  • L. C•••78%
  • M. O•••64%
  • S. P•••41%

Tailored to every client, from the first question

One classification drives everything after it: the checklist the auditor sees, the competence needed, the man-day risk level and the clauses that may not apply.

  1. IndustryFood and beverage
  2. Sub-industryDairy processing
  3. IAF code03 · Food products
  4. Technical code3.1 Dairy
  5. DrivesChecklist · auditor competence · man-day risk · applicable clauses

Client input, once

Sites, shifts, headcount, processes, outsourced activities and documents are collected through the client portal and reused for every audit in the cycle.

Non-applicable clauses, justified

Exclusions such as design and development are recorded with the client's justification and the reviewer's acceptance, only where the standard allows them.

Industry checklists

Clause checklists carry sector-specific prompts, so an auditor in a dairy plant sees what matters in a dairy plant.

The whole certification cycle, in one place

Every step is recorded against one client history, from the first enquiry to the third surveillance audit and recertification.

  1. Application

    Client applies online with scope, sites and documents.

    Client portal
  2. Contract review

    Codes, competence available, man-days by your rules, exclusions justified, quotation issued.

    Your rules
  3. Agreement and payment

    Agreement, proforma and payment tracked; audits released when terms are met.

    Reminders
  4. Programme and plan

    Three-year programme, audit plan and formal intimation to the client: dates, team, agenda, documents needed.

    Client notified
  5. Team assignment

    Competent, trained, impartial auditors, checked before the team is confirmed.

    Checked
  6. Stage 1

    Document review against every clause, with a draft stage 1 report and readiness for stage 2.

    Certa draftsAuditor approves
  7. Stage 2

    Offline checklist on site. Field notes become temporary NCs for the auditor to confirm and grade.

    Certa draftsAuditor grades
  8. NC follow-up

    Client submits root cause, correction and evidence through the portal; reminders run until the auditor verifies closure.

    Client portalAuditor verifies
  9. Report

    Built from the approved checklist in your template, checked for completeness.

    Certa checks
  10. Review and decision

    Independent technical review and a decision by authorized staff.

    People only
  11. Certificate

    Issued, published to the register and verifiable online; suspension and withdrawal handled.

    Public register
  12. Surveillance and recertification

    Every later audit, including special and transfer audits, starts with the full history and open NCs attached.

    Reminders

Certa drafts prepared for review · Auditor decides a person's decision, always · Your rules calculated from your approved rules · Client client communication and reminders

Keep your own house in order, too

Accreditation bodies assess the certification body, not just its audits. CABAMS keeps the CB's own system current and ready.

  • CB documentation

    Manual, procedures and forms under version control, updated when standards or IAF documents change.

  • Auditor competence

    Screening, qualification, codes, witness audits and annual evaluation for every auditor and reviewer.

  • Training

    Training plans, CPD, calibration sessions and records, linked to the codes each person can audit.

  • Impartiality

    Risk register, committee, declarations and rotation, checked before every assignment.

  • Complaints and appeals

    Handled by people not involved, with every step recorded.

  • Internal audit and review

    The CB's own internal audits and management reviews, with actions tracked.

  • Records and retention

    Every client record kept for the required period, findable in seconds.

  • Accreditation assessments

    Office and witness assessment packs prepared from live records.

How it works, step by step

Scroll through the 5 steps. The panel shows what CABAMS does at each one.

  1. 1 Step 1 of 5

    Application and contract review

    Clients apply online or through your team. CABAMS checks scope, sites and technical areas, then flags anything your reviewer needs to confirm.

  2. 2 Step 2 of 5

    Man-days and audit programme

    Audit duration is calculated from headcount, complexity and sites using the IAF rules, with every adjustment recorded. The three-year programme builds itself.

  3. 3 Step 3 of 5

    Planning and team assignment

    Auditors are matched on competence, codes, language, impartiality and availability. Plans go to the client for confirmation in their own language.

  4. 4 Step 4 of 5

    Audit, findings and corrective actions

    Auditors work from a live checklist, raise findings on the spot and attach evidence. Clients answer nonconformities with root cause and proof through their portal.

  5. 5 Step 5 of 5

    Technical review, decision and certificate

    The review file assembles itself: report, evidence, findings, competence records and duration checks. The certification decision stays with your reviewer, and the certificate is issued and registered.

Application reviewClie••• Foods
  • Legal entity verifiedDone
  • Scope: food processingDone
  • 3 sites declaredCheck
  • Technical area competenceAvailable
  • Contract review sign-offPending
Man-day calculationISO 9001 + ISO 14001
  • Base duration, 140 staff6.5 days
  • Integrated system reduction-10%
  • Multi-site sample (3 of 3)+1.0 day
  • Stage 1 / stage 2 split2.0 / 5.0
  • Reviewer approvalPending
Audit teamStage 2, 14 to 18 April
  • Lead auditor: A. R•••Code 03 qualified
  • Auditor: L. C•••Code 03 qualified
  • Technical expertNot required
  • Impartiality checkClear
  • Plan sent to clientConfirmed
NonconformitiesClie••• Foods, stage 2
  • NC-01 Calibration records, 7.1.5Minor
  • NC-02 Supplier evaluation, 8.4Closed
  • OFI-01 Internal audit scopeNoted
  • Corrective action planAccepted
  • Evidence of closureUnder review
Certification decisionReady for review
  • Audit duration matches calculationPass
  • All major NCs closedPass
  • Reviewer independent of audit teamPass
  • Decision: certifyApproved
  • Certificate issued and registeredDone
  • Rules you can showMan-days and sampling from your approved rule sets
  • One client historyEvery audit, NC and change linked across the cycle
  • Draft, then approveThe assistant prepares; auditors decide
  • Accreditation readyThe CB's own records kept current

A closer look at each module

Use them together or start with the one you need most.

Applications and contract review

Online applications with scope, sites, headcount and shifts, checked before anyone quotes.

  • Application review checklist with reviewer sign-off
  • Technical area and code assignment
  • Transfer and scope-change requests

Everything on one screen

The overview your managers open every morning.

app.derasardesigns.com/cabamsAvailable in 12+ languages

Certification operations

Audits this month48+9 vs last month
Man-days scheduled13218 still unassigned
Open nonconformities379 overdue
Certificates this quarter6412 renewals due

Audit mix by standard

  • ISO 900141%
  • ISO 1400118%
  • ISO 4500114%
  • ISO 2700117%
  • Other10%

Auditor utilization

  • A. R•••92%
  • L. C•••78%
  • M. O•••64%
  • S. P•••55%

Agent activity

  • Man-days recalculated after scope change, Clie••• Plastics6 min ago
  • Report built from checklist for Clie••• Foods31 min ago
  • Certificate issued, Clie••• Logistics ISO 450011 h ago
  • Reminder sent: 3 NC responses due this week2 h ago

What's included

  • Rule-based man-day calculation

    Durations from headcount, shifts, complexity and sites, with every adjustment justified.

  • Multi-site sampling

    Sample sizes and site selection by your rules, every site covered in the cycle.

  • Auditor competence matrix

    Codes, qualifications, witness audits, CPD and expiry dates in one place.

  • Auditor screening

    Application, evidence check, interview, training and witnessed audit before approval.

  • Impartiality checks

    Conflict of interest, rotation and declarations checked before every assignment.

  • Offline audit app

    Checklists, photos and findings on a tablet, with or without a connection.

  • Certificate register

    Certificates issued, suspended, withdrawn and published for verification.

  • Multi-office operations

    Regional offices with shared rules, their own currencies and central oversight.

Built for

  • Certification bodies
  • Multi-country CB networks
  • Inspection and verification bodies
  • Personnel certification bodies

Two ways to run it

Start on a subscription and move to your own installation whenever you need to.

Subscription

Cloud subscription

Monthly or annual, priced by users and by what you run: standards in AMS, offices, schemes or auditors in CABAMS. Hosted in the region your data law requires.

  • Start with what you need, add users or standards any time
  • Updates, backups and support included
  • Encrypted, masked and fully audited
See plans

Connects to what you already use

  • Email and calendar
  • Accounting software
  • Payment gateways
  • SMS and WhatsApp
  • Single sign-on
  • REST API and webhooks
  • Spreadsheet import and export
  • Document storage

Security and deployment

  • Cloud hosted, private cloud, or on your own servers
  • Role-based access for every screen and record
  • Full audit trail of who changed what and when
  • Encryption in transit and at rest, with daily backups
  • Interface in each user's language, including right-to-left scripts

Built for confidential certification work

CABAMS is built and run under our own ISO/IEC 27001, ISO/IEC 42001 and ISO 9001 certified management systems, with the same protection as all our products.

  • ✦AI that assists, auditors decide

    Certa only prepares drafts. Findings, grading, reviews and certification decisions are made by your people, no client or auditor data goes to any outside AI service, and you can switch the assistant off completely.

  • 🔒Encrypted everywhere

    Encrypted in transit and at rest, including backups. Encryption keys are managed separately from the data.

  • 🌍Stored where your law requires

    Choose the hosting region, or run it on your own servers, so you can meet local data protection laws such as GDPR, India's DPDP Act and Gulf PDPL rules.

  • ◐Masked by default

    Names, contact details and other personal data are masked for every role that doesn't need them, on screen and in exports.

  • ≡Fully audited

    Every view, change, export and approval is logged with who, what and when, and can be reviewed by your auditors.

  • ⚿Your data stays yours

    You own your data. Export it any time, and it is deleted on exit, with written confirmation.

  • ⊟Separate by design

    Each certification body's data is isolated. Derasar Designs staff can't open it without your written, time-limited permission.

Questions teams ask us

Something else on your mind? Ask us directly

Does CABAMS use AI?

Only as an assistant, and only if you switch it on. Certa prepares stage 1 document reviews, report text and temporary NCs as drafts. Nothing is issued until a competent auditor approves, edits or rejects it, and findings, grading, reviews and certification decisions are always made by your people. No client data goes to any outside AI service, and you can switch the assistant off for any scheme or the whole CB.

How are surveillance and recertification audits linked?

Every audit for a client sits in one history: scope, sites, man-days, previous NCs and their closure, changes and complaints. A new surveillance or recertification audit starts with all of it attached, and open NCs carry forward automatically.

Can offices in different countries work in one system?

Yes. Every office works to the same approved rules and templates, with its own currency, language and team. Head office keeps oversight of all activities, and certification decisions stay with authorized people of the legal entity, as ISO/IEC 17021-1 requires.

How is CABAMS priced?

As a subscription, monthly or annual, priced by the number of auditors and users, offices or schemes. Enterprise gives your certification body a dedicated installation hosted for you only, in your region or on your own servers.

Is CABAMS aligned with ISO/IEC 17021-1?

Yes. Workflows, records and approvals follow ISO/IEC 17021-1 and the IAF mandatory documents, including audit duration (IAF MD 5) and multi-site sampling (IAF MD 1), so your records are ready for accreditation assessments.

Can auditors work without internet?

Yes. The auditor app works offline on a tablet or laptop and syncs findings, photos and evidence when back online.

Does Derasar Designs see our certification data?

No. CABAMS is software only. Each certification body's data is kept separate, and you can host it on your own servers. Derasar Designs does not certify, and never links certification to any consulting or software we provide elsewhere.

Does CABAMS help us manage impartiality?

Yes. Keep your conflict of interest register, impartiality risk assessment, committee records and auditor declarations in CABAMS, and check them automatically before every audit team assignment.

Can we configure our own man-day rules?

Yes. Base durations, adjustments and multi-site sampling rules can be configured per scheme, with every change recorded.

Can clients log in?

Yes. Clients can submit applications, confirm audit plans, respond to nonconformities and download certificates through their portal.

In your team's language

Every user chooses their interface language, and documents and reports can be produced in each site's language. Right-to-left scripts are supported.

See the live language demo
  • English
  • Español
  • Français
  • Deutsch
  • Português
  • Italiano
  • العربية
  • हिन्दी
  • 中文
  • 日本語
  • Türkçe
  • Bahasa Indonesia
  • Русский
  • 한국어
  • Tiếng Việt
  • ไทย
  • Polski
  • Nederlands
  • বাংলা
  • Kiswahili

Let's look at your operation together

A 30-minute call. Tell us how you work today and we'll show you the product that fits, configured around your process.