SmartCheck
Sharing evidence with an auditor
How to show certified material to an outsider so they can verify it themselves.
Certifying is not much use if, on the day you have to show it, the only option is emailing the file and asking people to take your word for it. What makes evidence useful is the other side being able to check it without depending on you.
Sharing a single piece of evidence
This is the common case: the auditor asks about one specific record. From the evidence you generate a link you can email. Whoever opens it sees the document and its certification details — what was certified, when, and with what fingerprint — without an account and without seeing the rest of your folder.
Public verification
This is the strongest of the three mechanisms, because it does not depend on a link you generated. Anyone holding the document can check on the public verification page whether it corresponds to a registered certification and from what date. That is what you give a lawyer or a court when they want to confirm it themselves.
Worth knowing
If the document has been altered by even one character, verification does not match. That is what makes it worth something: it is not a decorative seal.
The downloadable certificate
A separate, human-readable document summarising what was certified, when, and with what fingerprint. Useful for attaching to a file or a report without having to send the original document, which is sometimes confidential.
The audit dossier
When what they ask for is not one record but "everything from the third quarter", you export the folder dossier: a package with the evidence and its certification details, ready to hand over in one go. It is the difference between spending an afternoon compiling and settling it in five minutes.
Frequently asked questions
›Does whoever opens the link see the rest of my folder?
No. The link is for that specific piece of evidence. It gives access to nothing else in your organisation.
›Does the auditor need an account?
No. Neither for the shared link nor for public verification. That is precisely the point.
›Can I tell whether someone opened the link?
Accesses are logged along with the rest of your organisation's traceability.
›What if I want to show the date but not the content?
That is what the downloadable certificate is for: it attests what was certified and when, without handing over the original document.
A real case
The situation
An external auditor asks for a whole quarter's quality evidence — eighty records.
What you do
- Exports the dossier for the quarter's folder
- Hands it over in a single delivery
- Points them at the public verification page in case they want to check any independently
What you get
The auditor validates whatever they like without coming back to you, and you never had to hunt down eighty files.
The situation
An auditor wants to verify an evidence record themselves.
What you do
- Points them to the verification page
What you get
They verify without depending on you.
The situation
A screenshot is sent to them.
What you do
- Provides the document and its seal reference
What you get
They can verify rather than believe.
The situation
The auditor asks for the whole file and only one item is needed.
What you do
- Shares only the relevant evidence
What you get
What was asked for is delivered, and nothing more.
The situation
A record is needed of what was shown to them.
What you do
- Records what was shared and when
What you get
The handover is demonstrable afterwards.
The situation
The auditor does not know what the verification means.
What you do
- Explains exactly what the seal asserts
What you get
The proof is not credited with more than it says.
This article answers
- how do I show evidence to an auditor
- share a certified document with a third party
- export the audit dossier
- public verification of a document