
Okuda — Compliance Management That Survives an Audit
But right now, it probably is. Okuda replaces the spreadsheet sprawl with one auditable system — legal registers, corrective actions, risks and competence, mapped to ISO 9001.
The honest problem
Most SMEs don’t fail audits because they don’t do the work. They fail — or scrape through with findings — because the evidence lives in seventeen spreadsheets, four inboxes and one person’s head. The week before an audit becomes an archaeology project.
That’s not a quality system. That’s audit theatre.
Okuda was built on a simple position: if it isn’t versioned, owned and traceable, it doesn’t count. Every process is versioned. Every step has a named owner. Every field change is in the audit trail. When the auditor asks “who approved this, and when?” — the answer is a click, not a hunt.
What’s in the box
- Legal Register — the legislation that applies to you, screened for applicability, with compliance status you can evidence at any point in time. Not a PDF someone last updated in 2023.
- Non-conformance & CAPA — raise, investigate and close corrective actions through a controlled workflow with electronic signatures. No more “closed” NCRs that were never actually actioned.
- Controlled workflows — versioned process templates with role-based ownership and a visual designer, so your procedures run the way they’re written — not the way people remember them.
Mapped to the standard, not bolted onto it
Okuda’s roadmap is being built clause-by-clause against ISO 9001:
| ISO 9001 clause | Okuda answer |
|---|---|
| 6.1 Risks & opportunities | Risk & Opportunity Registers (in development) |
| 7.2 Competence | Skill & competence matrices (in development) |
| 7.5 Documented information | Document Control (in development) |
| 8.7 / 10.2 Nonconformity & corrective action | NCR & CAPA workflows |
| Compliance obligations | Legal Register |
If a clause needs evidence, Okuda’s job is to hold it.
Onboarding that sticks
Here’s another opinion: most SaaS onboarding is abandonment with extra steps. A login, a help centre link, good luck.
We do it differently. We train your key people to configure and run Okuda themselves, so the capability lives in your business — permanently. When we leave, you’re not dependent on us. That’s the point.
Backed by Maly IT Solutions
Okuda is built and supported in the UK by Maly IT Solutions — real people who understand your processes, not a ticket queue in another timezone.
Jargon buster
Plain-English answers to the terms on this page — no acronyms left unexplained.
A QMS (Quality Management System) is the set of documented processes a business uses to consistently meet customer and regulatory requirements. It covers how work is done, who is responsible, and how problems are found and fixed. ISO 9001 is the international standard a QMS is certified against.
A legal register is a live list of the laws, regulations and other compliance obligations that apply to your business, with a record of whether each one is relevant and how you comply. Auditors expect it to be current, evidenced and reviewed — not a spreadsheet last touched years ago.
NCR stands for Non-Conformance Report. It’s the formal record raised when something doesn’t meet a requirement — a faulty product, a missed process step, a supplier failure. Each NCR should be investigated, actioned and closed with evidence, forming a key input to your corrective action process.
CAPA stands for Corrective and Preventive Action. Corrective action fixes the root cause of a problem that has already happened; preventive action stops a potential problem before it occurs. ISO 9001 requires corrective actions to be tracked to closure with evidence of effectiveness.
A risk and opportunity register records the things that could harm or benefit your business, how likely they are, and what you’re doing about them. ISO 9001 clause 6.1 requires organisations to identify and act on both risks and opportunities — not just threats.
A skill matrix maps the competences each role requires against what each person can actually demonstrate, exposing training gaps. ISO 9001 clause 7.2 requires businesses to determine necessary competence, ensure people have it, and retain evidence — a matrix is the standard way to prove it.
An audit trail is an automatic, tamper-evident record of who changed what, and when, within a system. In Okuda it operates at field level, meaning every individual value change is captured — so compliance history can be evidenced without relying on anyone’s memory.
Audit theatre is our term for the scramble before an external audit: reconstructing records, backfilling spreadsheets and rehearsing answers to look compliant on the day. A working QMS makes it unnecessary — the evidence already exists because it was captured as the work happened.
Stop rehearsing for audits. Start passing them.
The full product, documentation and how-to guides live at okuda.io.