How to use AuditCore

Step-by-step guidance for every part of the platform — from onboarding to BRC-aligned reporting. Use the search or navigate by section.

Platform overview

AuditCore is a cloud-based compliance and internal audit management platform engineered for food manufacturing and processing. It aligns with BRC Global Standard Issue 9 and other GFSI-recognised schemes including FSSC 22000, IFS, and SQF.

AuditCore centralises the entire audit lifecycle — from risk-based scheduling to verification of corrective actions — giving you a single, timestamped record for BRC audit day.

Who uses AuditCore

Quality & Technical

Define the annual audit programme, oversee NC trends, and generate evidence-led reports for management review.

Auditors & Site Managers

Execute shopfloor GMP inspections and structured system audits with photo evidence and clause references.

Operations & Production

Primary owners of the CAPA process — responsible for immediate corrections and root cause investigations.

Senior Management

Monitor real-time site health via the Risk Heatmap to satisfy BRC Clause 1.1.2 resource and management review requirements.

Pre-loaded audit standards

The following standards are available from the moment your site is created:

  • BRC Global Standard for Food Safety Issue 9
  • FSSC 22000 v6
  • IFS Food v8
  • ISO 22000:2018
  • SQF Edition 9

Organisations & sites

AuditCore uses a strict three-level hierarchy to maintain data integrity and clear segregation of duties across complex business units.

Hierarchy

  • Organisation — the top-level legal entity. Subscription settings and master GMP templates are managed at this level.
  • Site — a physical factory or warehouse. All data (audits, NC registers, risk scores) is scoped to a specific site.
  • Areas — specific locations within a site (e.g. "High-Care Packing" or "Raw Material Intake") used to pinpoint where an observation or failure occurred.

Site profile

During onboarding each site must complete a profile which informs the risk assessment engine and report headers.

FieldDescription
Site NameUnique identifier, e.g. "BAKM — Manchester Bakery"
Production AreasTotal count of defined functional zones within the facility
Employee CountStaffing levels used to contextualise the scale of operations
High-care FlagBoolean indicator of whether the site contains high-care or high-risk production environments

Managing production areas

Areas are managed via Settings → Sites → [Site Name] → Areas. Precise area definition is critical for the evidence trail required by auditors.

  • Area types: Production, Storage, Despatch, Welfare, Utilities, or Other
  • High-care status: A toggle to identify zones requiring enhanced hygiene and segregation controls
  • Status & order: Admins can set areas to Active/Inactive (hiding defunct areas without losing historical data) and adjust sort order for auditor efficiency

User roles

AuditCore uses an additive permission model. Each successive role inherits all permissions of the roles below it, ensuring a clear chain of command and data security.

RolePrimary permissionsKey restrictions
site_user View dashboard and My Work; conduct assigned GMP/system audits; complete assigned CAPA phases; log Proactive Actions Cannot raise NCs manually; cannot edit programmes or access site/org settings
site_manager All site_user permissions plus: raise/edit NCs; schedule/reassign audits; verify and close NCs; view site-specific reports Permissions restricted strictly to their assigned site(s)
org_admin All site_manager permissions plus: access all sites; manage users (invite/deactivate); configure Programme Builder; run manual risk assessments Cannot access data from other organisations (multi-tenancy lock)
super_admin All org_admin permissions plus: support-level access; log in on behalf of users; global organisation management Reserved for AuditCore technical service team only
When a user leaves the organisation, deactivate rather than delete their account. This preserves the full audit trail — their name remains on all historical audits and NCs they conducted or verified.

Onboarding & setup

New accounts start with a 14-day full-access trial. The onboarding wizard guides you through the four steps required to configure your first site.

Onboarding wizard

  1. Name first site — enter the site name that will appear on all reports and NC references
  2. Complete site profile — production area count, employee count, high-care flag
  3. Define production areas — add the specific locations used during inspections
  4. Select primary audit standard — choose from BRC Issue 9, FSSC 22000, IFS, ISO 22000, or SQF

Account states

  • Trial — 14-day full-access period for new registrations
  • Active — live paid subscription; full platform access
  • Expired — subscription lapsed; login blocked until renewed
  • Suspended — account suspended based on payment status

GMP inspections

GMP inspections are checklist-based evaluations of Prerequisite Programmes — hygiene, maintenance, pest control, and so on. Each checklist item is assigned a Risk Weight (1–5) that determines its impact on the overall inspection score.

Conducting an inspection

  1. Select the GMP template for the area you are inspecting
  2. Mark each item as Pass, Fail, or N/A
  3. For any failure: add notes and up to 5 photos as evidence
  4. Record the Area, Shift, and Product Reference in the metadata fields
  5. On failing an item, use the Auto-NC button to immediately raise a linked Non-Conformance

Offline support

AuditCore uses Service Workers and local caching to support audits in Wi-Fi dead zones — cold stores, external yards, or areas with poor signal.

The Ready Offline badge confirms the template and site data are cached to your device. Responses save locally and sync automatically once a stable connection is restored.

System audits

System audits evaluate the facility against the full breadth of a certification standard, clause by clause. They can be scheduled via the Audit Programme or raised as one-off or triggered audits.

Audit lifecycle

  1. Schedule — create manually or let the Audit Programme generate it automatically
  2. Execute — work through clauses using the Audit Mode: Desk, Shopfloor, Interview, or Combined
  3. Report — on completion a PDF generates automatically with overall compliance score, embedded photo evidence, and a summary NC table

Audit modes

ModeUse case
DeskDocument review — procedures, records, HACCP plans
ShopfloorPhysical walkthrough of the production environment
InterviewStaff competency and awareness checks
CombinedMixed approach covering all of the above in a single audit session

Triggered audits

Outside the routine plan, triggered audits are initiated by specific events:

TriggerExample case
Customer ComplaintSignificant complaint requiring a deep-dive audit response
Product RecallAudit conducted as part of a formal recall or withdrawal
Post-IncidentConducted following a food safety incident or near-miss
Process ChangeTriggered by new line installations or process modifications
Supplier FailureTargeted audit following a significant supplier non-conformance
Audits can be flagged as Unannounced to help meet BRC Issue 9 requirements for unannounced internal audit proportions.

NC & CAPA process

Every Non-Conformance in AuditCore follows a mandatory two-phase CAPA workflow. Unlike Proactive Actions — which are simple improvement logs requiring no formal verification — every NC must complete a structured, multi-stage process.

NC reference format

Each NC is assigned a unique reference following the format: NC-{SITE}-{YEAR}-{SEQUENCE} (e.g. NC-BAKM-2026-0001). The site code is automatically generated from the first four characters of the site name, uppercase, no spaces.

NC source types

SourceDescription
System AuditAuto-raised during internal audits against certification clauses
External AuditFindings from third-party or certification body visits
GMP InspectionAuto-raised from a failed shopfloor inspection item
Customer ComplaintFormal feedback requiring a technical response
IncidentFood safety incidents or near-miss events
Non-Conforming ProductProduct failing specification or release criteria
Product Safety Point FailureFailure of a CCP, OPRP, or other HACCP control
Cleaning FailureDocumented failure of cleaning and disinfection protocols
Supplier IssueNon-conformance regarding delivery or supplier performance
Internal (Other)Internally identified issues not covered by other sources
Manual / Ad HocA manually created record for miscellaneous compliance failures

Severity levels & due dates

SeverityDefinitionDue date
CriticalImmediate risk to safety or legalitySame day
MajorSubstantial failure or potential risk3 days
MinorFailure not posing significant immediate risk14 days
ObservationWeakness or area for improvement30 days

The three-step CAPA workflow

  1. Phase 1 — Immediate correction. Document what was done immediately to prevent harm (e.g. "Batch isolated and quarantined"). Assign a Corrective Action Owner.
  2. Phase 2 — Root cause investigation & prevention. Record a Root Cause Analysis using methods such as the 5 Whys or Fishbone diagram. Then document the Preventive Action Plan that addresses the root cause finding.
  3. Verification & closure. A different person from the submitter must verify the actions taken. They may close the NC or return it for rework if evidence is insufficient.
The verifier must be a different person from the submitter to maintain independence and satisfy BRC requirements for CAPA integrity. The only exception is single-person organisations.

Programme builder

AuditCore separates the library of audit requirements from the execution of the schedule. The Programme Builder defines what needs to be audited and how often. The Annual Plan puts those requirements on the calendar.

Programme builder vs annual plan

ToolPurposeAnswers
Programme BuilderThe master library of Audit EventsWhat needs auditing, how often, and at what baseline risk level
Annual PlanThe site-specific 12-month calendarWhen each audit event is actually scheduled throughout the year
You do not need to set up Programme Builder before you can audit. You can schedule a one-off system audit directly from the System Audits page. Programme Builder is recommended for managing a structured, risk-adjusted annual programme.

Using the annual plan view

The Annual Plan View displays a 12-month grid. Quality Managers use it to schedule specific instances of Programme Builder events, ensuring even distribution of workload and audit coverage across the year.

Risk assessment engine

In accordance with BRC Clause 3.4, AuditCore automatically calculates compliance risk at the section level — rated High, Medium, or Low — using a multi-factor scoring model.

Risk weighting factors

FactorImpact on score
Recent compliance scoreThe primary driver of current section risk
Number of open NCsIncreases risk based on volume of unresolved issues
Overdue NCsSignificant negative factor indicating lack of control
Repeat NCsHigh-priority flag — triggered when the same clause fails in two or more consecutive audits
Time since last auditRisk increases linearly as the duration since the last check grows
The Risk Heatmap on the dashboard provides an early warning system, allowing management to increase audit frequency for sections flagged as High Risk before the next BRC visit.

Reports & exports

AuditCore generates two primary reports designed to meet BRC Issue 9 evidence requirements and support management review.

Management review report

Directly supporting BRC Issue 9 Clause 1.1.2, this report provides Senior Management with the data required to review the effectiveness of the Food Safety Quality Management System.

  • NC trends by severity
  • Open vs. closed rates
  • Average time to close
  • Repeat NC list
  • Audit completion rates
  • Risk score trends over time

NC register export

The full NC register can be exported in two formats:

  • CSV — for internal data manipulation and trend analysis
  • PDF — a professionally formatted register suitable for direct submission during certification audits

System audit PDF

Generated automatically on audit completion. Includes the overall compliance score (percentage of compliant non-N/A responses), all embedded photo evidence, and a summary NC table.

Video walkthroughs

Short screencasts covering the key workflows in AuditCore. More videos will be added as the product develops.

Building and Scheduling the Audit Programme
How to use the Programme Builder to define audit events and the Annual Plan to schedule them across the year.
5 min · Programme Builder & Annual Plan

FAQ & troubleshooting

Common questions from Technical Managers getting started with AuditCore.

No. You can schedule a one-off system audit directly from the System Audits page. Programme Builder is recommended when you want to manage a structured, risk-adjusted annual programme with automatic scheduling and frequency controls.
Only in single-person organisations. In all other cases, the verifier must be a different person from the submitter. This is a BRC requirement for CAPA integrity and AuditCore enforces it at the point of verification.
The platform works offline. When you open a GMP inspection template on a device with a connection, the template and site data are cached locally. If you lose signal mid-inspection, your responses continue to save to the device. Data syncs automatically once a stable connection is restored.
BRC Global Standard for Food Safety Issue 9, FSSC 22000 v6, IFS Food v8, ISO 22000:2018, and SQF Edition 9. All are available from the moment your site is created.
No. Deactivate the account rather than deleting it. This preserves the full audit trail — their name remains attributed to all historical audits and NCs they conducted or verified, which is required for BRC evidence purposes.
Each NC is assigned a unique reference in the format NC-{SITE}-{YEAR}-{SEQUENCE}. For example, NC-BAKM-2026-0001. The site code is automatically generated from the first four characters of the site name (uppercase, no spaces). Sequence numbers increment per calendar year.
A Proactive Action is a simple log for continuous improvement observations — it does not require formal verification or a two-phase CAPA workflow. An NC is a formal non-conformance that requires immediate correction, root cause investigation, preventive action, and independent verification before it can be closed.
The Risk Heatmap on the dashboard shows compliance risk rated High, Medium, or Low at the BRC section level. Risk is calculated from five factors: recent compliance score, open NC count, overdue NCs, repeat NCs, and time since last audit. Sections flagged High Risk should be prioritised for increased audit frequency before the next BRC visit.

Try AuditCore free for 14 days.

No credit card. No demo. Full access from day one.

Start Free Trial