Skip to main content
LMS SystemsBY MULTISYSTEMS

What Auditors Actually Ask For

Auditors do not want your completion dashboard. They want a named person, a date, and proof. The evidence chain that holds up, and four gaps that sink it.

LSLMS Systems TeamJuly 15, 20263 min read742 words

The uncomfortable thing about a compliance audit is how narrow it is. Properties prepare broad summaries: completion percentages, programme overviews, policy documents. Then they get asked something much more specific:

"On March 14th, this person served alcohol. Show me their certification was valid that day."

That's the whole audit, repeated. Not "is your training good," but "prove this person was qualified for the work they did, on the day they did it."

The evidence chain

A defensible record has six parts. Miss any one and the record weakens.

Who — the individual, identified unambiguously and linked to employment records. "Front desk staff completed PCI training" proves nothing about a specific person.

What — the specific course and version. If content was updated in June, an April completion was of the earlier version. Auditors reviewing a post-incident timeline will ask which one.

When — completion timestamp, and the expiry it generated. Both matter: the second is what makes the certification a state rather than an event.

Where — the property. In a portfolio, requirements derive from location, so a record without it can't be checked against the right rule set.

Score — where a passing threshold applies, the result and ideally the attempt count.

How — the delivery and verification method. Increasingly asked when training is remote or mobile.

Six fields. Most properties can produce two or three from memory and reconstruct the rest under deadline pressure, which is where errors, and credibility problems, enter.

The four gaps that sink properties

1. The denominator problem. Compliance reported against everyone who ever had an account, including people who left months ago. Reports 74% when active-staff reality is 96%. The fix is termination events flowing from the HRIS. Otherwise you're diluting your own numbers and can't tell a real gap from a ghost.

2. The transfer gap. An employee moves between states, their required credential set changes, and nothing recalculates. The most dangerous gap because every dashboard stays green.

3. The version gap. An SOP changed; the course built from it didn't; staff were certified against superseded material. Discovered during incident review, which is the worst possible moment.

4. The role-drift gap. Hired as a server, now runs banquets and pours wine on weekends. The system has "server," so alcohol-service certification was never required. The schedule and the record disagree, and the schedule is what an investigator reads.

All four are silent. None produces a red indicator. That's what makes them worth auditing yourself for.

Run the drill before someone else does

Pick five employees at random across properties and roles. For each, produce inside ten minutes:

  1. Required credentials, given current role and property
  2. Current status of each, with expiry dates
  3. Completion certificate with timestamp and content version
  4. What they'd need if transferred to another state tomorrow
  5. Full training history including prior roles

If any takes longer, or requires assembling a spreadsheet, you've found your gap, and you found it on a Tuesday instead of during an inspection.

Retention and export

Two operational details that matter more than they should:

Keep records past employment. A former employee's certification history can be relevant to an incident that surfaces later. Deleting on termination is a mistake; deactivating access while retaining the record is correct. Check what your platform does by default.

Verify export before you need it. "We can export" is not the same as "here is a per-person certification report with versions and timestamps, in a format an auditor accepts, in under an hour." Test it during evaluation, not during an audit.

What good looks like on the day

A property that's genuinely ready doesn't scramble. Someone opens the compliance view, filters to the named person and date, and prints a record with all six fields. It takes two minutes and the conversation moves on.

That outcome isn't produced by working harder in the week before. It's produced by the record being generated automatically at completion time, because the only reliable way to have evidence a year later is to have never needed to assemble it.

The bottom line

Auditors are not evaluating your training programme. They're testing whether you can produce specific, dated, per-person proof on demand.

Build the record so it exists without anyone curating it, close the four silent gaps, and run the five-employee drill quarterly. Then an audit is a search query rather than a fire drill.

See how compliance tracking generates the evidence chain automatically.

See it working on your hotel's own SOPs

Explore the product →

Topics

AuditsComplianceEvidenceRecordkeeping
LS

Written by

LMS Systems Team

The team behind LMS Systems — operators, trainers and engineers building the learning and compliance layer for hotels.

Ready to see your compliance picture?

Book a 30-minute demo and watch your own SOP become a course, a quiz, and an assigned learning path — live.

No credit card required · Setup in minutes · Cancel anytime

Ask about LMS Systems on

Ask an AI assistant or your peers about LMS Systems.