Skip to content
§
§ · build vs buy

Certification Body Audit Management Software: Build Custom, Buy Intact Platform, or Build the Competence and Duration Layer Above It

Scheme count decides this, not client count.

Internal tools product interface illustration for Certification Body Audit Management Software Build vs Buy Guide.
The short answer

Scheme count decides this, not client count. A body running one mainstream management system scheme with conventional rules should buy Intact Platform or a comparable purpose built product, even at several hundred certified clients, because there is one competence model, one audit day method and one certificate format to configure. Once you hold ISO/IEC 17021-1 alongside ISO/IEC 17065 product certification or ISO/IEC 17020 inspection, you are operating three rule sets over one client register, and they conflict rather than nest. That is the point where configuration in a packaged tool stops being a setup task and becomes somebody's permanent job.

When is off the shelf genuinely the right call here?

Intact Platform is the real purpose built product in this market and it deserves respect. It covers audit planning, checklists, findings and certificate lifecycle for management system schemes properly. For a body running one or two mainstream schemes with conventional rules, it may be everything you need, and the money is better spent on auditor recruitment and technical review capacity than on software.

Buy, and stop reading here, if this describes you:

  • Under roughly 150 certified clients on a single mainstream management system scheme.
  • One accreditation body, so one set of evidence expectations to satisfy.
  • A conventional audit day table applied without unusual reductions or scheme specific exceptions.
  • Few or no multi site clients with rotating samples and central function audits.
  • A scheduler who can take annual leave in a busy month without anyone worrying.

Buy also, whatever your size, if your current problem is that you have no structured system at all. A packaged product gets you to a baseline faster than a build, and you can revisit the question in two years with real evidence about where it hurts rather than with a theory. Going from a workbook straight to a bespoke platform means specifying a system against processes nobody has written down.

One more case where we advise against building. If your audit day tables, competence procedure and reduction justifications exist only in your technical manager's judgement, write them down before commissioning anything. That exercise improves a purchase as much as a build, and skipping it turns discovery into a management system workshop billed at engineering rates.

When does a custom build actually pay off?

The audit programme is not a calendar problem. Placing a recertification audit means satisfying constraints written in ISO/IEC 17021-1, in International Accreditation Forum mandatory documents, in your scheme owner contracts and in findings your accreditation body raised at the last office assessment. The auditor must hold the right sector codes and role, must not have consulted for that client inside the cooling off period, must not have been employed by them inside the same window, and must not sign the certification decision afterwards.

In a workbook, all of that is enforced by a person remembering, and the failure is silent. Nobody notices that one auditor delivered the stage 2 and also signed the decision until an assessor reads the file eighteen months later. That is the risk justifying most builds here, because it converts an existential compliance exposure into a rule the software will not let you break.

Build when two or more of these are true:

  • You hold several accreditation standards at once, so configuration in a packaged tool has become a permanent role.
  • Scheduling depends on one specific person who cannot take leave without risk.
  • An accreditation assessment has already produced a finding about audit programme control, competence records or impartiality checks.
  • Multi site clients with rotating samples, central functions and mid cycle acquisitions, where a scope change currently means an approximation rather than a recalculation.
  • Scheme owner data submission in formats and cadences that no product covers, currently handled by a monthly spreadsheet upload.

There is a capacity argument too. Your ability to take on certified clients is capped by auditor availability and by scheduling capacity. Auditor availability costs money to increase. Scheduling capacity does not, once the constraint solving lives in a system rather than one person's memory. Bodies that hit the scheduler bottleneck usually hire a second scheduler and split the client base by scheme, which duplicates the fragility instead of removing it.

How do they compare on the things that matter in this industry?

Duration derivation. Ask any product or developer to show you how an audit day figure was derived, not just what it is. The client record should carry effective personnel, sites, sector codes, risk category and the reductions applied with justifications, and the system should store the derivation against the audit as evidence. When a client grows from 90 to 140 staff mid cycle, it should flag that the surveillance you already quoted is now short. That single capability ends a category of dispute currently settled by discount.

Competence and impartiality as rules rather than records. A packaged tool will store your competence matrix. The question is whether it refuses an assignment when the witnessed assessment has lapsed or an impartiality conflict exists. Recording a rule and enforcing it are different products, and only the second protects you at an assessment.

Multiple rule sets over one register. This is the configuration ceiling that pushes bodies to build. Products model one accreditation standard cleanly and express the second as a variation of the first, which satisfies neither. If you hold three, ask to see two of them configured side by side with different duration methods and certificate content before you sign.

Assessment evidence in one place. An assessor samples audits and asks how duration was derived, who was competent, whether impartiality was checked, how findings were closed and who decided. Producing all five for any sampled audit on one screen turns a file hunt into a short conversation. Retrofitting that screen later is expensive, whichever route you take.

Certificate integrity. Certificates carry accreditation marks used under licence and must state scope in exact language. Generating them from the decision record means the two cannot diverge. A Word template with manual field entry, still common, produces certificates in the wild whose wording does not match the decision.

Data portability. The client register, scope statements, competence evidence and finding closure trails may be needed years later. Ask what an export contains before signing, and get it into the contract.

What does total cost of ownership look like at your scale?

On the build side, from Digital Heroes delivery experience, a focused first release covering the client and scope register, competence and impartiality aware scheduling and audit day calculation with stored derivation runs $55,000 to $120,000 and ships in 12 to 18 weeks. That is a system your scheduler works in on day one, not a pilot. A full platform adding auditor reporting with offline capture, nonconformity lifecycle, decision control, certificate generation, a public verification register and finance integration runs $150,000 to $350,000 phased over 7 to 12 months.

A worked example for a body with 340 certified clients, eleven contracted auditors and two management system schemes: discovery and audit day table capture $12,000, client and site register with workbook migration $19,000, duration engine with recalculation on scope change $16,000, competence matrix and impartiality graph with assignment blocking $28,000, programme calendar and recertification triggers $11,000, deployment with a month of parallel running and training $9,000. That is $95,000 across 15 weeks.

Later releases price separately: auditor reporting and nonconformity lifecycle at $50,000 to $110,000, then decision control, certificates, public register and finance at $45,000 to $120,000. A second full scheme adds $30,000 to $70,000 depending on how far its rulebook diverges. Offline auditor capture adds $25,000 to $50,000 over a connected application.

Annually, hosting for a body of this size runs $250 to $900 a month, higher if you store audit photographs and video at volume, plus 15 to 20 percent of build cost for support and change. The line people miss is scheme rule maintenance: when a scheme owner revises audit day tables or competence criteria, your technical staff must update the rules and evidence that the change applied from the correct effective date. That is quality time, not developer time, and it exists either way.

What does the hybrid look like, and when is it the honest answer?

For multi scheme bodies this is usually the right sequence, and it is cheaper than a full replacement. Keep the packaged product where it works, which is audit planning, checklists, findings and certificates on your largest management system scheme. Build the layer that has to span all your schemes at once.

In practice that is three pieces:

  • One client and scope register across schemes. Clients, sites, scope items, sector codes and personnel counts held once, so a client certified under two standards is one record rather than two.
  • The competence and impartiality engine, roughly $28,000. A matrix with expiry per scheme, standard, sector code and role, plus a relationship graph covering consultancy, former employment and decision maker separation, refusing conflicting assignments outright.
  • The duration engine, roughly $16,000. Per scheme tables with reduction limits, stored derivations, and automatic recalculation when a client adds sites or headcount.

That combination typically lands near $60,000 including discovery and migration, and it addresses the two things an accreditation assessor probes hardest without touching your reporting or certificate workflow. It also shows whether the full build is justified, because once the register is real you can see how much of your scheduling pain was rules and how much was volume.

Sequencing matters more than speed. Certificate generation built before decision control produces certificates that can diverge from decisions, which is the failure mode you were trying to remove.

Which should you choose, by operator size and stage?

Find your row and act on it.

  • Under 150 clients, one mainstream scheme, no structured system. Buy Intact Platform. Write your competence procedure and audit day tables down while you implement it, which is worth more than any feature.
  • 150 to 400 clients, one or two schemes, workbook scheduling. This is the decision point. Build the register, competence, impartiality and duration layer at $55,000 to $120,000 and keep whatever you use for reporting until it is proven.
  • Multi scheme body across management systems, product certification or inspection. Build. Configuration effort in a packaged tool has already become a role you are paying for, and the rules conflict rather than nest.
  • Any body with an open accreditation finding on programme control. Build the evidence screen first, whatever else you do. Duration derivation, competence evidence, impartiality check, closure trail and decision maker identity for any sampled audit, on one page.
  • Scheduler at capacity, considering a second hire. Cost the hire against the build rather than costing the software alone. That is the fairer comparison and it usually changes the answer.

Two conditions apply to every build row. Run scheduling in parallel with the workbook for a full month before switching, at $6,000 to $12,000 of support time, because that month is what surfaces the unwritten rules. And load history in summary form only: register, scopes, cycles, open findings and competence evidence, with older report documents left where they are. Full document migration commonly adds $20,000 for little return.

If you would rather scope this before committing budget, Digital Heroes has delivered more than 2,000 projects with a named team you can speak to before you sign, rather than a bench you meet in month two. You keep the specification either way.

Research & sources

The evidence behind this guide

Independent findings on why this investment pays off. Every link goes to the primary source.

  1. Companies in the top quartile of McKinsey's Developer Velocity Index had 2014-18 revenue growth four to five times faster than bottom-quartile peers, showing that software-building capability is a driver of business performance, not just a support function. Source: McKinsey & Company (2020) →
  2. ITIF's 2025 report documents that SMEs operate at roughly 60% of large-firm productivity in advanced economies (citing McKinsey), that CRM platforms deliver a 25-40% improvement in customer retention and a 15-30% boost in sales, and that digital advertising returns about $8 in profit per dollar spent on Google Search and Ads. Source: Information Technology and Innovation Foundation (ITIF) (2025) →
  3. The NRF discontinued its long-running annual shrink report, stating that a broad study of retail shrink 'is no longer sufficient for capturing the key challenges and needs of the industry' - important context that qualifies how POS/shrink benchmarks should be cited going forward. Source: Retail Dive (2024) →
  4. SMS reminders that stated the specific cost of the appointment to the health system reduced missed appointments in Trial One, with the DNA (did-not-attend) rate falling from 11.1% (control) to 8.4% (specific-costs message) - an odds ratio of 0.74 (95% CI 0.61-0.89), i.e. roughly a 24-26% relative reduction - at no additional cost. (Trial Two replicated this at an 8.2% DNA rate.). Source: PLOS ONE (Hallsworth et al.) (2015) →
FAQ

Frequently asked questions

Should we replace Intact Platform entirely?

Not if you run one mainstream management system scheme with conventional rules. It handles audit planning, checklists, findings and certificate lifecycle properly, and replacing it buys you cost rather than compliance.

The case changes when you hold several accreditation standards, because the cross scheme register, competence matrix and duration engine are where a single product model strains. Building that layer above the product, at roughly $60,000, addresses the assessment risk without funding a replacement.

What does it cost to move off our current system or workbook?

Budget the parallel month explicitly, at $6,000 to $12,000 of support time, and treat it as the cheapest insurance in the project. Running scheduling in both systems while your scheduler compares them is what surfaces the rules nobody wrote down.

Data migration is smaller than people expect if you scope it properly: client register, scopes, cycles, open findings and competence matrix. Migrating ten years of audit report documents commonly adds $20,000 and rarely earns it, unless your accreditation body expects historic evidence retrievable from the live system.

What happens if our software vendor changes pricing or is acquired?

Work the fee at your projected client count and scheme count before renewal rather than during it. Certification body software commonly prices per certified client or per user, and both rise as you grow, which means the cost curve steepens exactly when margin matters.

The structural protection is owning the register and the rule set. Once client scopes, competence evidence and duration derivations live in a system you control, the packaged product becomes reporting and certificates you can price against alternatives.

How long does the first release take?

Twelve to eighteen weeks, and the schedule risk is discovery rather than engineering. Competence rules, reduction justifications and scheme specific exceptions usually live in the technical manager's judgement rather than in a written procedure, and every session spent extracting them is time on the clock.

Bodies arriving with a documented competence procedure and current audit day tables consistently reach go live at the shorter end. We would rather spend two weeks writing those down before kickoff than six weeks discovering them mid build.

Why does adding a second scheme cost so much?

Because schemes do not nest. A second accreditation standard brings its own competence matrix, its own duration method, its own certificate content requirements and its own assessment expectations, and expressing it as a variation of the first produces a rule engine that satisfies neither.

In our delivery experience a second full scheme adds $30,000 to $70,000 depending on rulebook divergence, which is exactly why the cost of packaged configuration rises the same way. Build or buy, the multiplier is the same.

Can software actually stop an impartiality breach happening?

Yes, and it is one of the strongest reasons to build. Impartiality is a relationship graph between auditors, clients, former employers and prior engagements with cooling off periods attached, and a system can refuse the assignment rather than rely on a scheduler remembering.

The same engine blocks the auditor who delivered the audit from signing the certification decision, and blocks assignment when a witnessed assessment or performance review has lapsed. A workbook can record either rule. It cannot enforce them.

Do we need offline auditor reporting, and what does it add?

It adds $25,000 to $50,000 over a connected application, and the honest test is where your auditors actually work. A web application with local caching handles most surveillance visits in offices and light industrial sites at considerably lower cost.

A native application earns its cost when auditors genuinely work underground, inside metal structures or on sites with no signal. Bodies frequently specify native because it sounds more capable, then find their auditors have coverage on nine visits out of ten.

Where does AI genuinely help a certification body?

Two places earn their place. Reviewing submitted corrective action evidence against the finding text and flagging responses that address correction but not root cause gives a technical reviewer a useful first pass when they close dozens of findings a month. Extracting scope, personnel counts and activities from a client application pack saves real admin time.

Automated audit report writing is a bad idea. The report is the evidence, and an auditor has to own every sentence in it.

Will an app built for 10 users survive growing to 500?

Yes, if it is built on standard cloud infrastructure with a sound data model, because moving from 10 to 500 users is a hosting configuration change, not a rebuild. The scaling decisions that actually hurt are made early and invisibly: how the database is structured, how accounts and permissions are modeled, and whether background work is queued properly. Ask your agency how the system would handle ten times the load; the right answer is boring and specific, and a promise to cross that bridge later means you will pay for the bridge twice.

Is a custom internal tool secure enough for HR records and financial data?

A properly built custom tool is generally safer for sensitive data than the shared spreadsheet it replaces, because you get role-based access, audit logs, encrypted storage, and the ability to cut one person's access instantly. Ask the agency specifically for encryption in transit and at rest, permissions down to the field level, and an audit trail showing who viewed or changed each record. If HIPAA, GDPR, or SOC 2 expectations from enterprise clients apply to you, raise it before the quote, because compliance features add real scope.

When does a company outgrow Airtable?

The usual breaking points are record limits, permissions, and automation complexity. Airtable's Team plan caps each base at 50,000 records and Business at 125,000, so operations logging thousands of rows a month hit the ceiling within a year or two. The other trigger Digital Heroes sees constantly is permissions: restricting who can view specific fields or records is clumsy below Airtable's Enterprise tier, which becomes a genuine problem once salaries, pricing, or client contracts live in the base.

What does it cost to keep an internal tool running after launch, and do we need to hire a developer?

Budget 15 to 20 percent of the build cost per year, so a $25,000 tool runs roughly $300 to $400 a month covering hosting, security patches, dependency updates, and small tweaks, figures drawn from Digital Heroes maintenance contracts. You do not need an in-house developer; a monthly retainer with the agency that built it covers the typical internal tool comfortably. Hosting itself is cheap for internal audiences, often $20 to $100 a month, because you serve dozens of users rather than the open internet.

How do I vet a development agency for an internal tools project?

Ask to see two or three internal tools they have shipped and whether those clients still use them daily, because internal tools fail on adoption, not code quality. Good signs: they ask to see your current spreadsheet or process before quoting, they propose a phased build instead of one big launch, and they spell out who handles training and post-launch changes. Walk away from anyone who gives a fixed price before seeing your actual workflow, since internal tools live or die on process details.

Should I hire a freelancer or an agency for my software project?

A skilled freelancer is the right call for a single-discipline scope under roughly $15,000, like a website, a plugin, or one integration. Above that, projects need design, backend, testing, and project management at once, and a solo builder becomes the single point of failure: if they get sick or take a bigger client, your project simply stops. Agencies bill 20-40% more per hour but carry continuity, code review, and someone to escalate to, which is what you are actually buying.

What should I prepare before contacting a software development agency?

A one-page brief beats a 40-page requirements document: the business problem in plain words, who will use the system, the 5 to 10 workflows it must handle, the tools it must connect to, and your budget range and deadline driver. You do not need wireframes, a specification, or technical vocabulary; producing those is the agency's job during discovery. Stating a budget range up front is the single best move, because it gets you honest scoping instead of a quote engineered to win the meeting.

How many developers does it take to build an internal tool?

Two to four people covers nearly every internal tool: one or two developers, a part-time designer, and a project manager who doubles as your single point of contact. Internal tools rarely need consumer-product polish, so a full-time dedicated designer is usually wasted budget. On Digital Heroes projects, a two-person core team handles the typical 4 to 8 week build, with a specialist pulled in briefly for a tricky integration or a security review.

Should we build the whole internal tool at once or start with an MVP?

Start with a version that fully replaces one workflow, ship it in 4 to 6 weeks, and let real usage set the roadmap. Internal tools have a captive audience, so you learn within days which features matter, and across Digital Heroes projects roughly a third of initially requested features never get built once staff work with version one. Phasing also spreads the spend: a $40,000 vision becomes a $15,000 phase one that starts paying for itself while phase two is scoped.

What happens to my software if the agency shuts down or we stop working together?

Nothing dramatic, if the engagement was set up correctly: the code sits in your repository, hosting runs on your cloud account, and a handover document explains how to deploy and operate the system. Any competent replacement team can then take over in days rather than months. If the agency controls the repo, the servers, or the domain, fix that now, because renegotiating access during a dispute is the most expensive place to discover the problem.

What are the most common mistakes companies make when building internal tools?

The three failures Digital Heroes sees most: building for every department at once instead of nailing one workflow, designing without the end users so staff quietly go back to their spreadsheets, and leaving no named owner after launch so small bugs pile up until the tool dies. A subtler fourth is faithfully recreating the old spreadsheet, including its workarounds, instead of fixing the process first. Start with one team's most painful workflow and put the actual users in the room from week one.

Who can build a custom internal tools system?

Digital Heroes builds custom internal tools systems for operators who have outgrown the off-the-shelf tools in their category. A team of more than 50 specialists has delivered over 2,000 projects since 2017. Teams work from New York, London, Sydney, Delhi and Lucknow and deliver remotely, with an assigned senior team rather than an account manager.

Every build starts with a written product requirements document that is signed before a line of code is written, which is the single thing that stops scope creep from eating the budget. Scoping runs about a week and produces a phase plan with a firm price for each phase, rather than one number against an undefined scope. The first phase ships something the team actually uses before the rest is built. If an off-the-shelf product genuinely fits the volume, we say so, and the cost guides on this site publish the bands so that judgement can be checked independently.

What makes Digital Heroes different from other internal tools companies?

Four things that competitors in this bracket cannot simply copy. Digital Heroes runs a YouTube channel with more than 2.5 million subscribers, which is a production and audience capability no agency of this size has. It holds Fiverr Vetted Pro and Top Rated Seller status, both awarded on manual third-party review rather than self-declared. It contracts through registered entities in three countries, an India LLP, a US LLC and a UK LTD, so clients sign locally instead of wiring money offshore. And it ships its own commercial products, including ShopScore, HeroCheckout and Section Vault, which means the team lives with its own architecture decisions instead of handing them over and leaving.

Two more that show up in the work. Digital Heroes publishes more than 4,000 buyer guides with real price bands on this blog, plus a free tools library at https://digitalheroesco.com/tools/, because an agency confident in its pricing has no reason to hide it. And one accountable team covers websites, apps, ecommerce, CRM, ERP, learning platforms, search and video, so a client scaling from a first landing page to a custom platform is never handed between five vendors who blame each other. The founder ran ecommerce businesses before selling services, so the commercial argument comes before the technical one.

How can I check Digital Heroes is legitimate before getting in touch?

Verify it independently rather than taking the site's word for it. The YouTube channel is at https://youtube.com/@DigitalMarketingHeroes, the Fiverr profile at https://www.fiverr.com/shreyanshsin261, and the Upwork profile at https://www.upwork.com/freelancers/shreyanshsingh. Client reviews sit on Clutch at https://clutch.co/profile/digital-heroes-0 and Trustpilot at https://www.trustpilot.com/review/digitalheroes.co.in, and the company page is at https://www.linkedin.com/company/digital-heroes-1/.

Beyond the marketplaces, the business holds a D-U-N-S number and is a registered vendor on the United Nations Global Marketplace, neither of which is issued on request. Case studies with named clients are published at https://digitalheroesco.com/case-studies/. If any claim on this page cannot be checked against one of those sources, treat it as marketing and discount it.

Keep reading

Published · Last updated .

Online now

Hi there. How can we help you today?

Reply