Building a multi-site audit evidence register
An organisation with several sites can have plenty of documents and still struggle to answer a basic audit question: which site has the current evidence, who owns it and what remains unresolved? A shared register should make records retrievable without flattening genuine local differences. It is an index and decision trail, not a certificate that every location is compliant.
This guide covers an operational evidence register for UK organisations with multiple locations. It is distinct from a general audit checklist and from the separate pre-acquisition property audit. The HSE's managing-for-health-and-safety guidance describes planning, monitoring and review as part of management. The ICO's documentation guidance applies where the register or linked records process personal data. Neither source prescribes one universal evidence register layout.
Decide which question the register must answer
Start with the actual audit request or management decision. Does the organisation need to find training evidence for a role, inspection records for an asset class, contractor approval for a site or closure of identified hazards? List the evidence categories and the business owner for each. Avoid collecting every document “just in case.” A giant folder with no ownership or status can be slower than a smaller, well-maintained register.
Distinguish a source record from a summary. The register should point to the actual report, certificate, action or decision and explain its scope. If the source is held by a contractor or local team, record how it will be retrieved and who can request it. A link that only the original uploader can open is not a useful audit link.
Give sites a common structure with local fields
Use a consistent site identifier, address, business unit, evidence category, document or record ID, coverage period, owner, last review date, next action and exception status. Add a field for the local rule, permit, building type or contract condition where relevant. Do not force a uniform deadline on sites with different statutory or operational requirements. A central field can show “next action due,” but the reason for that date should remain visible.
Version records carefully. A current inspection report may supersede an older one while the older report still explains a defect that was repaired. Do not delete history merely to keep the dashboard tidy. Show which version is current for operations, which earlier version is retained as evidence and whether a corrective action remains open.
Make exceptions first-class entries
Use clear states such as verified current, awaiting review, missing source, adverse finding, remedial work open and not applicable with reason. “No document” and “document contains a defect” are different problems. Identify who assessed the exception, when they assessed it and what interim control or escalation applies. A document uploaded yesterday should not automatically switch a case to green if no one read its findings.
If a site says an item is not applicable, require a short reason and reviewer. This is especially important when the same evidence type appears at other sites. A change in asset, activity or jurisdiction can make a former exception relevant. Review such decisions when the site changes, not only at the next audit.
Protect sensitive evidence
Training, incident and contractor records can contain personal data. Apply role-based access and retention policies to the source, not only to the register screen. The ICO's documentation guidance explains the value of documenting processing purposes, sharing, retention and security. Do not use “auditor access” as a blanket reason to expose every worker record across the organisation. Provide the minimum evidence needed for the question and keep a record of external sharing where appropriate.
Plan for personnel changes. A site manager's departure should not break every link or leave actions unowned. Use organisational roles where useful, but still name the person accountable for the next decision. Test retrieval from a reviewer account that did not upload the source.
Check the record against the physical site
A register can be internally consistent and wrong. Sample a source document and confirm that it identifies the right site, asset or worker and matches current operations. Walk one process at a site: find the inspection, the defect, the repair and the return-to-use decision. Compare the register state with the physical condition. If the register says an action is closed but the condition recurs, reopen it and investigate the status process.
Use a risk-based sample across sites. Include a site with many open actions, a new location and one that reports everything green. Compare how local teams interpret the fields. A central audit will be unreliable if one team marks “complete” at upload while another waits for verification.
Worked example: shared equipment category
Five depots hold lifting accessories. A central register shows current inspection evidence for four, while one depot has a PDF with no asset numbers and an old open defect. The auditor marks that depot as “scope unverified,” asks the local manager to match the PDF to the actual accessories and keeps any affected item under the appropriate local control pending competent review. A later document upload does not close the exception until the asset match and defect resolution are verified. The central view can now show a useful exception rather than a misleading five-of-five document count.
The same approach applies to training or contractor evidence: connect the record to the person, site and task it actually covers. A certificate for a worker at one location does not necessarily prove authorisation for a different activity at another location.
Review the register as a management system
Track retrieval failures, stale owners, repeated evidence gaps and overdue decisions. Ask whether the register helps managers correct the underlying process or merely prepares an audit response. HSE's Plan, Do, Check, Act approach treats monitoring as part of active management. The register should therefore lead to changes in the work and a later check that they worked.
For a current-product discussion, see Complys training matrix software as one relevant evidence category and ask for a demonstration of site-level access and exception ownership using your own sample. This article does not assert that Complys automatically verifies documents, supplies an auditor export or guarantees compliance across sites.