Skip to content
intermediate ⏱️ 18 min read

Audit Trail & Compliance Enforcement

Use the QCTO compliance dashboard, enforcement rules, deadlines, waivers, and the immutable audit log to keep your provider audit-ready.

For: Training Providers Administrators

Summary

skillSYMS continuously checks your learner, enrolment, evidence, and assessment data against QCTO compliance rules. This guide shows you how to read the compliance dashboard, turn on enforcement, track submission deadlines, request waivers when you genuinely need an exemption, and use the immutable audit log as evidence during inspections.

Who This Guide Is For

  • Quality assurance and compliance managers
  • Training provider administrators responsible for QCTO readiness
  • Operations staff who monitor the 21-day rule and submission deadlines

Prerequisites

Before you begin, ensure you have:

  • An SDP Admin or Compliance role on your tenant
  • At least one programme with learners enrolled (so there is data to validate)
  • An understanding of which QCTO rules apply to your accreditation

Step 1: Read the Compliance Dashboard

Navigate to Compliance β†’ Dashboard.

The dashboard shows your overall Compliance Score plus six enforcement status cards:

  • Evidence Mapping β€” evidence linked to curriculum outcomes
  • Moderation Gate β€” moderation completed before SoR issuance
  • SoR Coverage β€” Statement of Results coverage requirement
  • 21-Day Rule β€” enrolments submitted within the QCTO window
  • Identity Lock β€” biographical data locked after first submission
  • Export Validation β€” data validated before MIS export

Below the cards, the Compliance Issues table lists each problem with its entity, rule, severity, and a suggested action. Filter by Entity Type (Learners, Enrolments, Evidence, Assessments) and Severity (Blocked, Error, Warning).

Tip: Click Run Validation before any QCTO submission to refresh the score against your current data.

Step 2: Review the Compliance Rules

Navigate to Compliance β†’ Rules.

Rules are grouped by category (Learner Identity, Enrolment, Evidence, Assessment, SoR Issuance, MIS Export). Each rule shows its code (for example QCTO-EN-001), severity, and whether it is Enforced or Monitoring. Click any rule to open its detail panel, which includes the QCTO reference, the error message learners or staff will see, and the remediation steps.

Tip: Use the category filter to focus on one area at a time when you are remediating a backlog.

Step 3: Turn On Enforcement

Navigate to Compliance β†’ Settings.

Enforcement controls whether a failing rule simply warns you or actually blocks the operation. Toggle the rules you want to enforce, such as:

  • Identity Lock (QCTO-ID-008)
  • 21-Day Rule (QCTO-EN-001)
  • Evidence-to-Curriculum Mapping (QCTO-EV-001)
  • Moderation Gate (QCTO-AS-001)
  • Curriculum Coverage for SoR (QCTO-SR-001)
  • Pre-Export Validation (QCTO-EX-001)

Set an Enforcement Effective Date and an optional Grace Period (days) so your team has time to clean up data before blocks take effect. Click Save Settings.

Tip: Start in Monitoring mode, clear the existing issues, then switch to Enforced with a short grace period.

Step 4: Track Deadlines

Navigate to Compliance β†’ Deadlines.

This view summarises deadlines as Overdue, Urgent (1–3 days), Approaching (4–7 days), and On Track. The 21-Day QCTO Rule section visualises each enrolment’s submission timeline so you can see what is pending, submitted, or overdue. Filter by deadline type (Enrolment Submission, SoR Issuance, MIS Export, Moderation).

Step 5: Request a Waiver

Navigate to Compliance β†’ Waivers.

When a rule genuinely cannot be met (for example a legacy record), request a temporary exemption:

  1. Click Request Waiver.
  2. Select the Compliance Rule.
  3. Choose the scope: Entire Organisation or Specific Record (then pick the entity type and ID).
  4. Enter a Reason (minimum 10 characters) and any additional justification.
  5. Submit. An admin reviews and approves or rejects it.

Approved waivers appear under the Active tab with a validity date. Every waiver request and decision is written to the audit log.

Tip: Keep waiver reasons specific and evidence-based β€” auditors will read them.

Step 6: Generate Audit Reports

Navigate to Compliance β†’ Audit Reports.

Use a quick report card (Full Compliance Audit, MIS Export Readiness, or Evidence Mapping) or click Generate New Report to choose a report type, date range, and programme. Generated reports are timestamped, scored, and stored in the Previous Reports table for download.

Step 7: Use the Audit Log

Navigate to Compliance β†’ Audit Log.

The audit log is a complete, immutable activity trail. Filter by date range (24h / 7d / 30d / 90d / custom), action type (Create, Update, Delete, Login, Export, Approve, Reject, Submit), entity type, and user. Click any row to see the full event detail, including actor, IP address, before/after state hashes, and metadata. Use Export CSV to hand a filtered trail to an auditor.

Tip: Audit log entries are retained for seven years to meet QCTO governance expectations. Never rely on deleting records to β€œfix” compliance β€” the trail captures the original action.

Common Mistakes to Avoid

  1. Enforcing before cleaning up β€” switching everything to Enforced with no grace period blocks legitimate work.
  2. Vague waiver reasons β€” β€œdata issue” is not an acceptable justification at audit.
  3. Ignoring warnings β€” warnings become blocks the moment you enforce a rule.
  4. Skipping pre-export validation β€” fix issues before generating MIS exports, not after rejection.
  5. Treating the audit log as optional β€” it is your primary evidence of governance.

Verification Checklist

Before your next inspection, verify:

  • Compliance score reviewed and issues triaged
  • Enforcement rules configured with an effective date
  • No overdue items in the 21-Day Rule timeline
  • All open waivers approved with documented reasons
  • A current Full Compliance Audit report generated
  • Audit log exported for the inspection period

Next Steps