September 8, 2026 · 6 min read
Compliance audit preparation, automated: audit-ready all year
By Sahan, co-founder, systems and delivery
Certification audit prep hurts for a reason that has nothing to do with the paperwork being hard. The paperwork expires. Certificates, calibration records, supplier declarations, training sign-offs and open corrective actions each run on their own clock, and nobody watches those clocks until an auditor picks a date. Automating compliance audit preparation means putting an agent on the expiry dates instead: one job that runs every day, checks what is about to go stale, and raises it as work while there is still time to fix it.
One disambiguation first. This post is about certification audits: ISO 9001, ISO/IEC 27001, FSSC 22000, BRCGS, HACCP, SOC 2. It is not about our own AI operations audit, which maps how work flows through a business and ranks what is worth automating. Same word, different animal.
The audit clock is bigger than most people assume
ISO published its ISO Survey of Management System Standard Certifications for the 2024 reference year in September 2025: 1,474,118 valid ISO 9001 certificates covering 2,321,640 sites, 96,709 certificates for ISO/IEC 27001, and 59,521 for ISO 22000. That edition was the first compiled from IAF CertSearch across 76 accreditation bodies, so it is not comparable with earlier editions. Read it as a snapshot of scale, not a growth rate.
Food schemes tell the same story. BRCGS reported more than 36,000 certificated sites in over 130 countries in its 2024-25 annual report, published June 2025. Foundation FSSC announced in April 2026 that FSSC 22000 had passed 40,000 certified organisations across more than 150 countries.
Every one of those numbers is an organisation on a recurring audit clock. Certification is not an exam you pass once. It is a recertification visit, surveillance audits in between, and under several schemes an unannounced audit you do not get to schedule.
Stale evidence has downstream consequences that are also counted. The European Commission’s 2025 annual report on the EU Alert and Cooperation Network, compiled from the system on 13 January 2026, recorded 10,490 notifications for the year, 11% more than 2024, with alert notifications up 14% and now the second largest category.
The scramble model has a measurable failure rate
Hyperproof’s 2026 IT Risk and Compliance Benchmark Report, published 12 February 2026 from a survey of 1,002 GRC professionals, found that organisations managing risk on an ad-hoc basis reported breaches at 50%, against 27% among those running an integrated and automated approach. That is self-reported vendor-commissioned survey data and Hyperproof does not publish the company-size split, so treat it as directional. The gap is still wide enough to act on.
On time cost, the best figure available is older than anyone would like. Vanta’s State of Trust Report, published October 2024 with Sapio Research and a sample of 2,500 business and IT leaders across the US, UK and Australia, put time spent on manual security compliance tasks at over 11 weeks a year in 2024, up from 10 weeks in 2023. Vanta’s 2025 and 2026 editions do not restate it, so that is a 2024 number and should be quoted as one.
The most useful finding I read this year is qualitative. LRQA, drawing on more than 72,000 BRCGS audits, concludes that recurring non-conformities come mostly from inconsistency in routine human action rather than from badly designed systems. That matches what we see in our own plants. Nobody forgets how to fill in the cleaning log. They forget on a Tuesday in March.
| Audit prep as a project | Audit prep as a background job | |
|---|---|---|
| When the work happens | Four to six weeks before the visit | Every day, in small amounts |
| What triggers it | The auditor’s date | An expiry date getting close |
| Typical failure | Evidence missing on the day | A task somebody has not closed |
| Who notices first | The auditor | The person who owns the record |
| State on audit day | Being assembled | Already current |
How ours runs: one job, every day
We built a certification-evidence agent for our own food manufacturing business, which works toward FSSC 22000, BRCGS, HACCP, organic and halal certification at the same time. It is a tomte, our word for one production agent with one defined job, and this one’s job is to make sure nothing expires quietly.
The mechanics are deliberately boring. One store holds the records: certifications, the audit calendar, non-conformities, documents, trainings, approvals, and the reference material staff actually ask questions about. Access is gated twice, once at sign-in and again against a per-user allow list, so being logged into the company system is not enough on its own to see compliance data.
A single job runs daily. It compares every due date against today and raises exactly three kinds of work into our task backbone: a certificate approaching expiry, an audit coming due, a non-conformity still open. Those tasks close themselves when the underlying record changes, so renewing the certificate resolves the task without anyone tidying up afterwards. A second job chases approvals that have stalled. Uploads, renewals and non-conformity closures all write to an audit trail.
There is also an assistant that answers compliance questions from that same reference material. Most compliance questions are lookups, and a lookup that takes four minutes instead of a day is the difference between a rule being followed and a rule being guessed at.
The pattern generalises past food safety. The same shape works for anything with a renewal date attached, which is why it sits next to the other document-driven work we automate for manufacturers and the same refusal logic we use in export documentation.
Where it is not allowed to act
The refusals are the design. Compliance sign-offs are human-action gates. The system is not permitted to mark a compliance action complete on its own, and it is deliberately excluded from the autonomous performance scoring we apply to the rest of our agent fleet. A person attests, or nothing is attested.
A second agent can propose additions to the reference material but cannot publish them. Proposals land in a staging area and a human compliance staffer promotes them, using their own access rather than the proposing agent’s. Nothing in the system deletes. When sign-on is unavailable, the fallback screen shows an empty shell instead of live records, because showing stale compliance data is worse than showing none.
What it does not do yet
File uploads currently store the filename and metadata, not the file itself, so real evidence storage is still an open item. Some of the newer record types save to browser storage rather than the shared database. There is no one-click evidence pack: evidence lives per module and gets read per module. The approval step for proposed reference material happens directly in the database rather than in a review screen. No automated tests cover this logic yet.
The run history has been clean so far, which we count for very little. A system with no observed failure is not a proven system, it is an untested one. We would rather write that down than publish a case study that quietly implies everything works.
What this costs
Our prices are public, so here they are against this problem. The AI operations audit is $1,900 for ten working days and will tell you whether certification evidence is even your highest-value automation, with a full refund if the answer is that nothing here is worth building. A build of this shape sits in the workforce sprint range, from $9,500, fixed at the written scope.
If you want it run and extended after handover, the fractional AI officer retainer is $2,900 a month, cancellable monthly. You own the code, the data and the accounts from the first day, which is the point. The number to weigh those against is the six weeks your quality manager loses every year, and the risk that the missing record gets found by the auditor instead of by you.
If that is the part of your year you want back, describe it at /start. Start async: no call follows, a written reply arrives within one business day, and you will have a fixed price before you have had a meeting.