Auditors and inspectors are unimaginative in a useful way. Whatever the scheme or the sector, the training part of the visit opens with the same request: show me who was instructed, on what, when, and how you know it landed.
Companies that hold that as a per-person record with a date and a version answer in the room. Companies holding a shared drive full of scanned signature sheets spend two days reconstructing something that ends up being an argument rather than a record.
Four visitors, and the exact documents they want
The VCA auditor. The most literal of the four. Question 4.1, a must question, states the document request word for word: the list of dates and topics discussed, and the attendance lists of the toolboxmeetings. Two artefacts, per site. Chapter 3 adds two more must questions a diploma register does not answer. 3.5 asks for your own VGM information and instruction programme, including the onthaal (structured reception and induction) for new and reassigned workers. 3.6 asks for instruction on the internal rules and procedures at clients' locations, including for temporary workers and subcontractors, before work starts there, demonstrable, with attendance lists. Note how often the word "list" appears. The scheme is telling you the shape of the evidence.
The BRCGS or IFS auditor at a food site. IFS Food version 8, clause 3.3.3, describes the record in full: a participant list with signatures, the date, the duration, the content and the name of the trainer, plus a documented procedure demonstrating effectiveness. That second requirement sits inside the same clause, and an attendance sheet does not address it. BRCGS Food Safety Issue 9, clause 7.1.2, adds documented competency assessment for anyone working with critical control points and control measures, held per person.
The social inspector or the Nederlandse Arbeidsinspectie. No prescribed format at all, which is why this one surprises people. Arbowet art. 8 requires that workers are effectively informed about the work and its risks and that instruction is adapted to their distinct tasks, and lid 4 requires the employer to supervise compliance. The law names no document. That cuts both ways: nobody can reject your record for being the wrong shape, and nobody can help you if you have none.
The FAVV, in Belgian food. Training sits inside the autocontrolesysteem (self-checking system) every operator must establish, apply and maintain under the KB of 14 November 2003. What is inspected is your own system, described in your own documents: your stated training arrangements become the standard you are measured against.
Records that answer the request, and one nobody keeps
Four categories carry almost all the weight.
- The per-person completion record. Name, course, date, version of the material. Everything else is built from this unit, and it is where an auditor drills in when a rollup looks too tidy.
- Version history of the material. What the procedure said in March, what it says now, and when it changed. Without it, "trained on the cleaning procedure" is a topic, not evidence.
- The assignment record. Who was required to do what, from when. It turns a completion list into a coverage statement, because it makes the people who did not complete visible rather than absent.
- The integrity of the record. Whether a completion is a system-generated timestamp attached to a person and a version, or a date somebody typed into a column later.
The fourth is the one nobody keeps, and it decides a contested audit. An auditor who suspects a file was assembled the week before the visit will test it, usually by picking a name and asking for the trace behind it. A record produced by the system that delivered the training survives that. A spreadsheet last modified two days ago does not, and no amount of correct content rescues it.
One site is being audited, but the network is the question
Audits are local. The auditor is standing in one building, asking about the people who work there, and the file that matters is that site's file.
Head office needs the other view. A site at 62 percent completion means one thing if the network sits at 95 and something else entirely if it sits at 64: the first is a site problem, the second is a programme problem, and they call for different responses.
Both views have to exist at once, on the same data. When the site view and the head office view come from different sources, one of them is wrong, and you find out which during an audit.
Audit-ready is a stopwatch, not a filing cabinet
Audit readiness has three parts, and they are not equally hard. The records exist and are current: most organisations manage this. The records leave the system in a form somebody else can read, per person, per site, per version, with the dates intact: many manage this too, after some work. And the export happens while the auditor is still sitting there. Almost nobody manages this, and it is the part that determines the tone of the rest of the visit. An auditor who waits four days for a list does not conclude that your filing is slow. They conclude that the record was not there, and they look harder at everything else.
The design consequence: the record has to be a by-product of delivering the training, not an administrative act performed afterwards by someone with a deadline.
Version-tagged completion, and why the border changes the record
Tie every completion to the version of the document it came from. It costs nothing when the course is generated from the procedure, and it answers the question that decides an incident file: was this person instructed on the method in force that day, or on the one it replaced.
The country you are standing in changes what else the record must contain. In Belgium, one specific document is prescribed. Codex art. I.2-11, second paragraph, 9° requires the employer to organise the onthaal of every starting worker, to designate an experienced worker to accompany them, and requires the designated member of the hierarchical line to sign a document under his own name showing that the necessary information and instructions on welzijn op het werk were given. Per person, signed, named. Group attendance cannot produce it, and this is not a best practice you can argue about: it is a duty to hold evidence.
In the Netherlands there is no prescribed form at all. The Arbowet demands a result, not a document. In practice that makes the record more important rather than less, because art. 8 lid 4 asks you to supervise compliance on a continuing basis, and supervision without data is an assertion. You are free to choose the shape of your evidence, and entirely responsible for having some.
If you operate on both sides of the border, build for the Belgian requirement and the Dutch one is covered. The reverse does not hold.
Four numbers to check before an auditor does
Run a monthly self-audit on the system rather than the content. Four numbers are enough.
Share of sites current on every required topic. Not average completion, which hides the tail. The share of locations with nothing overdue.
Time to export, spot-checked. Pick one site at random, ask for its file the way an auditor would, and time it. It is the only one of the four measured with a clock, and the one that predicts how the visit feels.
Record completeness. The proportion of completions carrying every field you would be asked for: person, date, version, result. A record missing the version is a record you cannot use after an incident.
Onthaal coverage for starters. Every person who started last month, with a per-person record behind their induction. In Belgium that is the I.2-11 document, signed by the designated member of the hierarchical line. Dutch law prescribes no form of proof at all, which is precisely why you need a record of your own: without one there is no way to demonstrate that article 8 was met.
The first number tells you how the programme is doing. The other three tell you how the audit will go.
Setting this up before the request arrives
Four steps, in this order.
Mark which content is compliance content. Separate the material you would be asked to produce (safety instruction, hygiene, allergen procedures, site rules, onthaal) from everything else. Only that set needs the full record discipline. Pretending everything is compliance content is how the discipline dies.
Make completion mean more than opened. Attach a knowledge check, so what you hold per person is a result rather than a signature. That is the difference between the attendance half and the effectiveness half of IFS 3.3.3.
Keep the network export ready as standing output. Person, site, course, version, completion date, knowledge check result. Not a report you build on request, a view you filter.
Let the site produce its own file. When an inspector arrives unannounced, the manager of that location should be able to produce that location's record from their own scoped view, without a call to head office.
In Aristotl that is the ordinary operating state rather than a project. Your existing procedures become courses of three to five minutes finished on the worker's own phone, each with a knowledge check, and completion is recorded per site, per role and per version as a by-product of the training itself. The records export.
Rehearse it with one location
Take the site you are audited on next and one topic you would be asked about. In a demo we build it and show you that site's file, in the form the scheme itself asks for it.