What software keeps audit evidence for IATF 16949 surveillance audits?
A surveillance audit asks to see what you have actually been doing. Folders, audit schedulers and QMS suites each hold part of the answer, and the part they all miss is the operational record the auditor reads.
A surveillance audit is not the certification audit. Nobody is rebuilding the quality system from scratch. The auditor arrives with a smaller and harder question, which is whether the system you were certified on is still the system you are running. So the audit day is spent sampling. Show me this die. Show me the inspection on that part. Show me what you did about the result that fell outside the limit in March. Every one of those samples is answered by an operational record, and every hour spent hunting for one is an hour the audit spends looking at your filing rather than your process. Which is why the software question is worth asking properly, and why the honest answer is not one product category.
What a surveillance auditor is actually asking for
Strip the wording away and a sampled request has four parts. It names a thing, usually a part number, a tool or a gauge. It names a period, usually since the last visit. It asks for the record of what was done, not a description of what is supposed to happen. And it expects the record to be attributable, meaning it shows the site it belongs to, the person who did the work, the date it happened and the released revision or plan it was done against. A procedure document answers none of that. A procedure says what you intend. The auditor is sampling for whether the intent was carried out, and that answer only exists in the records the work itself produced.
The four places audit evidence usually lives
- A shared folder or document archive. Universal, cheap and already in place. But it stores copies, not work, so every record has to be exported and filed by somebody, and that filing step is the first thing dropped in a busy month. An exported document also carries no thread back to the record it came from, so the first follow-up question sends you back to the source system anyway.
- An audit management scheduler. Genuinely good at the audit programme itself, which is the internal audit plan, the findings, the corrective actions and the reminders. It manages the audit. It does not hold the tooling history, the measurement results or the out-of-spec responses that the audit samples, so those are still somewhere else on the day.
- A QMS or eQMS. Strong on the document layer, which is a real and required part of the picture, including controlled documents, change control, corrective action and training records. The gap is usually the shop floor. Each die service, each measurement against a released control plan revision and each disposition of a bad result tend to sit outside it, or arrive as attachments that have already stopped being live records.
- An operational system that produces the evidence as it runs. The toolroom books its job cards, the inspector captures the measurement, and those entries are themselves the record, so nothing has to be filed afterwards. The honest trade-off is scope. A system like this does not replace your document control, your training matrix or the quality system itself, and it should not pretend to.
The first test is whether the evidence is made by the work
This is the test that separates the four categories, and it costs nothing to apply. Ask where a record is born. If a maintenance record exists because a toolmaker completed the service in the system, the evidence is a by-product of the work and it is there whether or not anyone was thinking about the audit. If the record exists because somebody later exported a report and saved it into a folder, the evidence depends on that person having time, and the gaps in it will be exactly the weeks the plant was busiest. Evidence assembled after the fact is the expensive way to answer a surveillance audit, and it is expensive twice, once in the assembling and again when the sample lands on the month nobody filed.
The second test is whether one question can be answered in one place
The second test arrives on the audit day. Take a real request, say every service on this die since the last visit, or the inspection results and the response to the out-of-spec reading on that part in the second quarter. Now count the systems you have to open to answer it, and count the exports you have to reconcile before it reads as one story. A plant can hold every record it needs and still fail this test, because a record that takes forty minutes and three spreadsheets to assemble is not answering the question, it is being reconstructed to look like an answer. What the auditor experiences is the assembling, and a long silence reads as weak control even when the underlying work was sound.
Where VoraSuite sits
VoraSuite is in the fourth category, an operational system for production facilities running tooling, with the evidence falling out of the running. VoraTool holds the toolroom side, where preventive maintenance plans are set in days, weeks, months, years or produced parts, repairs run on job cards that carry a root cause category and detail with who recorded it and when, and critical spares carry minimum quantities against the tooling that consumes them. VoraControl holds the quality side, where a measurement captured against a released control plan writes a context snapshot storing the part number, the revision code, the operation and the specification limits as they stood at that moment, so the result cannot drift when the plan is revised later. Out-of-spec results raise exceptions that carry containment and disposition through to closure. Gauges carry their calibration requirement, last calibration and next calibration due, so the equipment behind a measurement is part of the record rather than a separate list.
How the reporting works, and what it is not
VoraAudit is the reading layer over those records. The Audit Reporter starts from the auditor question itself, and there are eight of them across production tooling, quality control and governance, including tooling history for a part, inspections and capture for a part, out-of-spec and resolution for a part, process capability, the complete evidence file for one part, and site-wide access and user accountability. You pick the question, pick the part or gauge it is about, set the period, and it loads only the records that answer it, ready to read on screen or print. Event records default to the last three months so the report is bounded, while current-state records like tooling and control plans default to all time so a record that simply has not changed recently is never hidden. There is no saved archive and no second copy. The report is a filtered live read of records that already existed, so a follow-up question can be answered by changing the filter rather than by going back to a folder.

The coverage view is deliberately honest about gaps
One more thing is worth naming because most software will not show it to you. VoraAudit carries a coverage matrix that marks each evidence area as covered, partial or roadmap. It is not a score and it is not a readiness rating. It is a plain statement of which evidence areas the system holds records for and which it does not, which matters before an audit for the same reason a stock count matters before a shipment. A tool that only shows you what it does well is not much use for planning the parts it does not.
VoraSuite keeps controlled records of manufacturing work and makes them readable on demand. It does not certify anything, it does not assess your quality system, and whether a surveillance audit goes well rests on how you actually run the plant. No software changes that. So put the same five questions to any candidate. Is the record created by the work, or filed afterwards by a person? Does it carry the site, the date, the person and the released revision it was done against? Can one auditor question about one part or tool over one period be answered without leaving the system? Does the measurement keep the limits that applied on the day it was taken? And will the vendor tell you plainly what it does not cover?
Ask an auditor-style question, get the evidence report from records you already have.
Talk to someone who understands manufacturing control and audit evidence. We do not do generic demos.