Choosing calibration software
Calibration Software With an Audit Trail: What Assessors Actually Want
Full disclosure up front: Axiospec is one of the tools we build, so weigh our take accordingly. This is the plain-language version of what an audit trail actually has to do in a calibration program, and why a spreadsheet quietly fails at it. One thing to say clearly before we start: an audit trail does not make you compliant. It makes your records defensible when an assessor starts asking who changed what, and when.
What an audit trail is, in calibration terms
An audit trail is a running record of every change to a calibration record, tied to a named person, stamped with a time, that cannot be edited after the fact without leaving a trace. That is the whole idea. Not a log you keep for fun, but proof that the record you are showing today is the record as it was entered and approved.
Assessors reduce this to three plain tests. Is each entry attributable to a real user, not a shared login. Is it timestamped, so the sequence of events is clear. Is it tamper-evident, meaning a later change is detectable rather than silent. A record that passes all three tells a story someone can trust. A record that fails any one of them is just data, and data is easy to argue with.
What an assessor opens first
When someone audits your calibration records, they are not testing whether you love metrology. They are testing whether your records tell a consistent story and whether that story can be trusted without taking your word for it. In practice they go looking for a short list of things.
- Traceability: can you show the certificate for the reference standard used to calibrate this instrument, and follow it back toward a national reference.
- Attribution: who performed the calibration, and who reviewed or approved it, as named people rather than initials in a cell.
- Dates: the calibration date, the next-due date, and whether the recall actually happened on time or slipped.
- Change history: if a reading or a due date was corrected, is the original value still visible along with who changed it and why.
- Integrity: can anyone prove that the record on screen today is the record as it was signed, not a quietly edited copy.
Why a spreadsheet fails the test
Spreadsheets are good at math and poor at evidence. Any cell can be overwritten, and nothing in the file records what it used to say or who changed it. Track changes is off by default and simple to strip out. A shared file has no reliable identity behind an edit, so an entry from one person is indistinguishable from an entry from another. There is no built-in link between an instrument and its certificate PDF, so the proof lives in a separate folder that may or may not still match.
None of this means your numbers are wrong. It means you cannot prove they were not changed, and proving that is the entire job of an audit trail. This is why most modern cloud tools stop editing cells in place and instead write every change to a log the user cannot alter. Once the record of the change lives somewhere the person making the change cannot reach, the story holds up.
What tamper-evident actually means
This is where the words matter. Tamper-proof is a marketing word, because you cannot stop a determined administrator from touching a database. Tamper-evident is the honest one: you make any change detectable. Axiospec does this with a hash-chained ledger. Each record is linked to the one before it with a cryptographic hash, so a silent edit breaks the chain and shows up instead of hiding.
The rest is the plumbing an assessor expects. Every change is attributed to a user and timestamped. Records carry electronic signatures. An immutable maker-checker ledger keeps the person who entered a result separate from the person who approved it, so no single account can quietly do both. Calibration certificates attach to each asset, so the evidence travels with the instrument rather than sitting in a folder somewhere. You can log a calibration at the bench from an iOS or Android app by scanning the QR or barcode label on the instrument, and the same rules apply to those entries.
How this maps to the standards
Named standards do not hand you a feature checklist, and no tool can grant you a certificate. What they share is an expectation that records are controlled, attributable, and retrievable. ISO/IEC 17025 leans hardest on measurement traceability and stating uncertainty. AS9100 and ISO 13485 care about record control and approvals. ISO 9001 and IATF 16949 expect calibrated equipment with retained evidence behind it.
Axiospec supports these programs by keeping records audit-ready, but certification depends on your own processes, scope, and assessor. The tool covers the record-keeping side: the hash-chained trail, signatures, attached certificates, and due-date tracking. For an ISO/IEC 17025 program, the 17025 tailoring adds measurement uncertainty and traceability fields, and built-in MSA and Gage R&R help you back up the measurement decisions themselves. What Axiospec does not do is run your process for you, so treat any tool as evidence infrastructure, not a shortcut through the assessment.
What audit-ready looks like day to day
The practical payoff is that on the day an audit is scheduled, you are not rebuilding anything. The trail already exists because it was written as the work happened. When the assessor asks for records, one-click audit-pack export gives you a PDF and CSV with an integrity page, so the proof and the data leave together.
The rest of the week it does quieter work. The system computes the next-due date for each instrument, a Calibration Due Calendar and due-soon and overdue counts show what is coming, and an Audit-Readiness Scorecard tells you where the gaps are before someone else finds them. Reminders keep recalls from slipping, which is the failure most audits actually catch.
If you want to see how the trail reads without signing up, the live demo runs on sample data. Make an edit, then go look at where it was recorded. That is the fastest way to judge whether an audit trail is real or just a label.
Put it into practice
Import your asset registry in an afternoon, log every calibration to a tamper-evident audit trail, and produce records on demand. Prefer to see it first? Take a self-guided tour with sample data, no signup required.
Axiospec is a documentation and workflow tool. It helps you keep clean, traceable, audit-ready records; certification depends on your own processes, scope, and assessor.
More like this, by email
A short series of practical calibration guides like this one. No spam, unsubscribe with one click.