How Compliance & QHSE Works
Internal audits, incident reporting, risk register, QHSE training, and how compliance connects to the rest of the platform.
What Compliance does
The Compliance module gives your organisation a structured framework for managing risk, incidents, audits, and health & safety obligations. It is designed for internal governance β tracking what standards you must meet, logging what went wrong, and demonstrating that you are in control.
Core components
Internal Audits Schedule and conduct internal audits against a standard or checklist. Each audit has:
- A scope (what is being audited)
- An auditor and scheduled date
- Findings β observations, non-conformances, or positive notes
- Action points β corrective actions with owners and due dates
Audit findings link to the Risk Register if they expose a new risk.
Incident Reporting Log any incident β near-miss, accident, data breach, equipment failure, client escalation. Each incident record captures:
- What happened, when, who was involved
- Immediate response taken
- Root cause analysis
- Corrective and preventive actions
Incidents integrate with the Service Desk: a major incident can generate a linked ticket for tracking the technical response, while the incident record tracks the governance side.
Risk Register A live register of all identified risks facing the organisation. Each risk has:
- Description and category
- Likelihood and impact scores (1β5)
- A calculated risk rating
- Owner and review date
- Mitigating controls and residual risk rating after controls
The risk register is reviewed on a schedule. Overdue reviews are flagged automatically.
QHSE Training Track which employees have completed which training and when. Each training record has:
- Employee
- Training type / course name
- Date completed and expiry date (if applicable)
- Certificate upload (stored in Documents)
Employees approaching or past training expiry are flagged in the dashboard. This is particularly important for certifications that have legal implications (e.g. first aid, fire safety, GDPR awareness).
Evidence Attach evidence to audits, incidents, or risk controls β documents, screenshots, photos. Evidence is stored in the Documents hub and linked back to the compliance record it supports.
Permits to Work If your operations require formal permits (e.g. for contractors working on-site), manage permit issuance, approval, and validity periods here. Permits can be linked to Field Service work orders.
How Compliance connects to the rest of the platform
Service Desk: Major incidents can generate a linked ticket. Compliance actions can be tracked as tasks.
HCM: Training records are linked to employees. Training expiry appears in the HCM employee dashboard.
Documents: Evidence attached to compliance records is stored in the Documents hub.
Field Service: Permits to Work can be linked to work orders β a technician cannot start a job until the permit is issued.
Reports: Compliance dashboards (audit pass rates, open risk count, incident frequency) are available in Reports.
Where to go next
Was this article helpful?