Compliance & quality management
Your QMS is not a folder of spreadsheets.
But right now, it probably is.
Okuda gives SMEs a compliance system that's versioned, owned and traceable by design — so the week before an audit is a formality, not an archaeology project.
The problem
Audit theatre isn't a quality system.
Most SMEs don't fail audits because they don't do the work. They fail — or scrape through white-knuckled — because the evidence of that work is scattered across spreadsheets, inboxes and shared drives that nobody fully controls. The week before an audit becomes an archaeology project: digging for the version that was actually approved, chasing who signed off on what, reconstructing a history that should have existed all along.
That's not a quality system. That's audit theatre.
If it isn't versioned, owned and traceable, it doesn't count.
What's inside
Modules you can use on day one.
Okuda isn't a blank canvas you have to configure into something useful. Each module is a working application — built on the same engine, so everything it records is versioned, owned and traceable whether you ever open the designer or not.
Live now
Legal Register
Know which laws apply to you, and prove you're meeting them — with evidence, not assertions.
Learn more → LiveDocument Control
Controlled procedures with an owner, a version history, a signed approval and a record of who has read them.
Learn more →CRM
Companies, contacts and deals on a configurable pipeline board, with per-lane checklists, a unified activity timeline and outreach email sent from your own mailbox with replies captured back onto the deal. Built because we needed it ourselves — Maly runs its own pipeline on it.
In development
Time Tracking
Projects, timers and hours per person per project — deliberately stripped back, with invoicing to follow.
Planned
Specified and sequenced, but not yet built. We'd rather list them honestly here than put them on a features grid and let you assume they're waiting behind a login.
NCR & CAPA
Raise, investigate and close nonconformities so closure means something.
What we're planning →Risk & Opportunity Registers
Structured risk identification and treatment, tied back to your management system.
Skill & Competence Matrices
Prove your people are competent to do the jobs you've assigned them, with evidence attached.
Where the compliance modules sit against ISO 9001
| Module | ISO 9001 clause | Status |
|---|---|---|
| Legal Register | Compliance obligations | Shipped |
| Document Control | 7.5 — Documented information | Shipped |
| NCR & CAPA workflows | 8.7 & 10.2 — Nonconformity & corrective action | Planned |
| Risk & Opportunity Registers | 6.1 — Actions to address risks & opportunities | Planned |
| Skill & competence matrices | 7.2 — Competence | Planned |
Electronic signature and the field-level audit trail underpin every module and are live today — they're part of the platform, not a module you wait for.
What's underneath
Traceability isn't a feature. It's the engine.
Every module runs on the same process engine. A procedure isn't approved because someone changed a dropdown — it's approved because a defined step, owned by a defined role, was signed by a named person, and the record of that can't be edited afterwards. That's why "versioned, owned and traceable" is a claim we can stand behind rather than a line on a brochure.
Versioned processes
Processes are drawn in a visual designer and published as immutable versions. A job in flight stays pinned to the version it started on, so changing a procedure never rewrites history.
Electronic signature
Any step can require a signature. The signer re-authenticates, the statement they signed is stored with the record, and a failed authentication produces no signature at all.
Field-level audit trail
Not "record modified". Every individual field change is logged with the old value, the new value, who changed it and why. Audit records are append-only — nothing in the product can update or delete one.
Your own data shapes
Define the entities your business actually deals in — suppliers, products, sites — and reference them from process forms, so data is picked from a controlled list rather than retyped.
Integration built in
A process step can call an external API or send an email as part of the flow. Credentials are encrypted at rest and never shown again after saving.
Dashboards and retention
Role-assigned dashboards report on live process data, and retention policies delete or anonymise records on a schedule — because keeping everything forever is its own compliance problem.
Okuda is multi-tenant SaaS running on Microsoft Azure, with per-tenant data isolation enforced in the platform rather than left to each screen to remember.
The other differentiator
Most SaaS onboarding is abandonment with extra steps.
We train your key people to run Okuda themselves, so the capability lives in your business — permanently. No dependency on us to keep your own system running.
How we onboard →Questions
Straight answers, no jargon.
What is Okuda?
Okuda is compliance and quality management software built for SMEs. It replaces the spreadsheets, shared drives and email trails that most quality systems actually run on with a single versioned, owned and traceable record. It's not a document dump — it's a system of record.
Who is Okuda for?
SMEs who have to demonstrate compliance — to ISO auditors, regulators or customers — but don't have a dedicated quality team to babysit a heavyweight enterprise QMS. If your quality manager is also doing three other jobs, Okuda is built for you.
Is Okuda just for ISO 9001 certification?
ISO 9001 is where most of our customers start, and Okuda's compliance modules map directly onto its clauses. But the underlying discipline — versioned, owned, traceable records — holds up for any framework that expects you to prove what happened, when, and who signed off on it.
What is the difference between the Okuda platform and an Okuda module?
The platform is the engine: versioned process templates, a visual flow designer, typed forms, electronic signatures, a field-level audit trail, business objects and dashboards. A module is a ready-built application on top of it — the Legal Register, Document Control — so you get a working system on day one rather than a blank designer. You buy modules; the platform is what makes them traceable.
What is a Legal Register and why do I need one?
A Legal Register is your record of the laws and regulations that apply to your business, and evidence that you're meeting them. Auditors ask for it, and most SMEs answer with a spreadsheet nobody has opened since it was created. Okuda keeps it live, owned, backed by evidence you can produce instantly, and fed by a nightly sync against legislation.gov.uk so new legislation reaches you instead of surprising you.
What does Document Control do?
It is a controlled register of the documents your management system depends on — procedures, policies, work instructions — each with an owner, a version history, a review interval and a signed approval before it can be published. It also tracks who has read and acknowledged the current version. It is deliberately not a general file store: it controls the documents that have to be controlled.
How is Okuda different from a folder of spreadsheets or a generic QMS tool?
Spreadsheets don't version, don't own, and don't trace — anyone can edit anything, silently. Generic QMS tools are often built for enterprises with dedicated administrators. Okuda is built specifically for SMEs: opinionated enough to enforce discipline, simple enough that your team will actually use it.
How long does onboarding take?
Long enough to train your key people to run Okuda themselves, not just click through a demo. Most SaaS onboarding is abandonment with extra steps — ours is a train-the-trainer process, so the capability stays in your business permanently.
What is still being built?
Legal Register, Document Control and the CRM module are live. Time Tracking is in development. NCR & CAPA, Risk & Opportunity Registers and Skill & Competence Matrices are planned and specified, but no code has been written against them — we'd rather say that plainly than announce a module we can't show you.