• CAPA actions tracked in spreadsheets with no systematic follow-up or closure verification?

  • Document control done by emailing PDFs with version numbers in the filename?

  • Audit findings managed in a shared folder with no visibility on open versus closed items?

  • Calibration overdue alerts sent by someone who checks a spreadsheet once a week?

Quality Management System Software Development

When CAPA actions live in spreadsheets and document versions travel by email, your quality system is only as reliable as the last person who remembered to update the file. An audit response that should take minutes takes a day because the records are spread across folders and inboxes.

We build custom QMS software for manufacturers who need structured, auditable quality processes. From CAPA and document control through supplier quality and SPC, we build systems that hold up under an auditor's scrutiny and give quality teams visibility they can act on.

  • CAPA management with root cause, action assignment, effectiveness verification, and closure workflows

  • Document control with version management, approval workflows, and controlled distribution

  • Audit management for internal, supplier, and customer audits with finding and corrective action tracking

  • SPC charts and process monitoring with out-of-control alerts for key quality characteristics

A Quality Management System (QMS) is the software layer that manages non-conformances, corrective actions, document versions, audits, and supplier quality in a controlled, auditable way. It replaces spreadsheet-based CAPA tracking and emailed PDFs with structured workflows and a single source of truth. RaftLabs builds custom QMS software for manufacturers, aligned to ISO 9001, IATF 16949, and FDA 21 CFR Part 11 requirements, covering CAPA management, document control, audit management, calibration tracking, and statistical process control.

Vodafone
Aldi
Nike
Microsoft
Heineken
Cisco
Calorgas
Energia Rewards
GE
Bank of America
T-Mobile
Valero
Techstars
East Ventures
Products shipped
100+
Industries served
24+
Cost delivery
Fixed
Week delivery cycles
12-14

Why custom QMS software outperforms generic platforms

Generic QMS platforms are built to cover every industry with a single configuration. The result is a system with screens and fields your team will never use sitting next to gaps that require workarounds for your specific process. Customisation options are limited by what the vendor has exposed, and you pay per user for features you don't use.

A custom QMS is built around your quality processes, your document hierarchy, your audit schedule, and your non-conformance categories. It fits the way your quality team actually works, which means adoption is faster and the data quality is higher. When an auditor arrives, you can pull the records they need in minutes rather than spending the morning reconstructing them.

We build QMS software for manufacturers operating under ISO 9001, IATF 16949, AS9100, and FDA quality regulations. We design the data model and audit trail to meet the evidentiary requirements of your certification standard before development starts.

What we build

CAPA and non-conformance management

Non-conformances are captured at the point of detection, whether on the production line, in incoming inspection, or from a customer complaint. Each NCR triggers a structured CAPA (Corrective and Preventive Action) workflow: containment action with affected lot or batch identification, root cause analysis using the 8D report format with D1 through D8 steps, Ishikawa (fishbone) diagram support, corrective action definition with assigned owner and due date, and effectiveness verification before the CAPA can be closed.

For automotive suppliers operating under IATF 16949, the 8D report structure and required supporting evidence are built into the workflow so the output is directly usable for customer problem submissions via AIAG formats. FMEA (Failure Mode and Effects Analysis) risk register integration links the CAPA to the relevant process FMEA line item, updates the severity, occurrence, and detection ratings, and recalculates the RPN (Risk Priority Number) to confirm the risk has been addressed. Nothing falls through the cracks because the system drives the workflow, sends escalation alerts for overdue actions, and reports open CAPA count by responsible owner so management can see where quality issues are accumulating.

Document control and approval workflows

Documents are created, reviewed, and approved inside the system under an ISO 9001:2015 clause 7.5 compliant document control framework. Version history is maintained automatically with a full audit trail of who made each change and when. When a document is revised, the previous version is superseded and archived with complete traceability so the document state at any past date can be reconstructed without manual record hunting.

Controlled copies are distributed electronically to defined distribution lists with read confirmation required before the acknowledged status is recorded. Training matrices link document revisions to the training records of the personnel who work to those procedures, so the system flags which operators need to be retrained when a procedure changes. No more emailed PDFs with version numbers in filenames, and no more uncertainty about whether the floor is working to the current revision. Audit requests for a specific document version at a specific date are answered in seconds from the version history log rather than requiring a search through a shared drive. For automotive suppliers, the document hierarchy supports IATF 16949 requirements including control plan and PFMEA linkage to the relevant work instructions.

Audit management

Plan and schedule internal audits, supplier audits, and customer audits from a single audit calendar aligned to your ISO 9001:2015 or IATF 16949 audit programme requirements. Audit plans are linked to scope, clause mapping, checklist, and assigned auditors. Checklists can be structured by standard clause or by process, supporting both vertical-slice and horizontal-slice audit approaches required under IATF 16949 process audits.

Findings are recorded during the audit on mobile with severity classification (major non-conformance, minor non-conformance, opportunity for improvement). Each finding above a configurable severity threshold automatically generates a CAPA record with the audit finding as the problem statement, linking the audit and CAPA records so the quality manager can see which CAPAs originated from which audit without cross-referencing two systems. Open findings, closure rates against the audit schedule, and repeat findings -- findings of the same type that have appeared in multiple audit cycles -- are visible in the audit performance dashboard. Repeat findings flag processes where corrective actions have not been effective, which is a key surveillance trigger under both ISO 9001 and IATF 16949 certification bodies.

Supplier quality management

Maintain an approved vendor list (AVL) with supplier classification, approval status, approval expiry date, and rolling performance scores. APQP (Advanced Product Quality Planning) and PPAP (Production Part Approval Process) documentation requirements are tracked per new part submission, with each PPAP element -- design records, control plan, measurement system analysis results, initial process capability study, and sample parts -- tracked for submission and approval status. PPAP level requirements per customer are configurable so the system prompts for the right documentation set for each customer's submission requirements.

Incoming inspection results are recorded by supplier, part number, and lot so defect rates can be tracked at the part-supplier level rather than just at the supplier level. Supplier corrective action requests (SCARs) follow the same CAPA workflow structure as internal non-conformances, with 8D response required from the supplier within a configurable response window. Supplier performance dashboards show incoming defect rate, on-time delivery rate, and SCAR response time on a rolling 12-month basis so supplier reviews and re-qualification decisions are grounded in data rather than the quality manager's memory of recent incidents.

Calibration management

Register every gauge, instrument, and measuring device with calibration interval, responsible owner, calibration procedure, acceptance criteria, and traceability reference to the national measurement standard. The system generates calibration due notices automatically at a configurable lead time before the expiry date, and escalates overdue instruments to the quality manager before they are used in production. Calibration certificates are stored against each calibration event with expiry date tracking so the calibration status of every instrument is immediately visible without a manual spreadsheet check.

Calibration records store the as-found and as-left measurement results, the reference standard used, the calibration method, and the technician who performed the work. MSA (Measurement System Analysis) studies -- gauge R&R repeatability and reproducibility studies -- are tracked in the same instrument record so the calibration status and the measurement system capability are visible together. If an instrument is found out of tolerance at a calibration event, the system automatically flags all measurement records taken since the last in-tolerance calibration for quarantine review, which is the required response under ISO 9001:2015 clause 7.1.5.2 and directly supports the out-of-tolerance investigation workflow.

Statistical process control

Define Shewhart control charts for key process characteristics and enter measurement data at the point of production via the operator interface or import directly from CMM or automated measurement systems via CSV or API. The system plots Xbar-R charts for subgroup data, Xbar-S charts for larger subgroup sizes, and individual-moving range (I-MR) charts for processes where subgrouping is not practical. All charts are evaluated in real time against the full set of Western Electric (WECO) rules -- the eight Shewhart detection rules that cover point outside control limits, runs above or below the centre line, trends, and stratification patterns.

When a Western Electric rule violation is detected, an out-of-control alert is generated immediately rather than waiting for the next supervisor check. The alert includes the rule that triggered it and a link to the process FMEA so the operator knows what investigation steps to follow. Cp and Cpk process capability indices are calculated continuously from the current data set and displayed alongside the control chart. Process capability reports formatted for PPAP submissions or internal capability reviews are generated from the live data without manual charting in Excel -- which eliminates the data re-entry errors and the time lag that are the two biggest problems with spreadsheet-based SPC.

Frequently asked questions

Yes. We map the system modules to your certification clause structure during the requirements phase so that the QMS reinforces your management system rather than creating a parallel administration burden. For ISO 9001:2015, the document control, audit management, and CAPA modules are designed to satisfy the evidentiary requirements of clauses 7.5, 9.2, and 10.2 respectively. For IATF 16949, additional requirements around APQP, PPAP, MSA, SPC, and the customer-specific requirements (CSRs) of OEMs like Ford, GM, Stellantis, and Volkswagen are built in as configurable rule sets.

The audit trail, record retention period settings, and document control workflows are defined during requirements sign-off with your quality manager and, where possible, reviewed against your most recent surveillance audit report to ensure the new system addresses any previous audit observations. We have built QMS systems that have been through successful ISO 9001 and IATF 16949 surveillance and recertification audits. The certification body's requirements are a design input for the system, not an afterthought.

For FDA-regulated manufacturers, we build electronic signature and audit trail functionality that meets the 21 CFR Part 11 requirements for electronic records and electronic signatures. This includes tamper-evident time-stamped audit trails that record who made each change and the reason for the change, individual user authentication with unique user ID and password for every approval action, and electronic signature attribution that binds the signature to the signatory's identity and the specific record version being signed.

We document the 21 CFR Part 11 assessment as part of the validation package so your validation team has a clear statement of which Part 11 controls the system implements and how. The validation approach -- IQ (Installation Qualification), OQ (Operational Qualification), and PQ (Performance Qualification) protocol structure -- is agreed before development starts so the test scripts are written alongside the system build rather than assembled after go-live. Your QA team reviews and approves the protocols before execution, and all executed protocols are stored as part of the validated system record.

Yes. Common integration points include pulling non-conformance triggers from an MES when a quality hold is placed on a work order, syncing the part master, supplier master, and BOM from the ERP so the QMS works from the same reference data without manual maintenance, and pushing inventory quarantine flags back to the ERP when material is placed on quality hold so the ERP reflects the actual usable stock position.

For SPC, the integration can pull measurement data directly from CMM output files, operator entry systems in an MES, or automated gauging systems via CSV drop or REST API, eliminating the manual re-entry step that introduces errors in spreadsheet-based SPC. For PPAP and supplier quality, the integration can sync approved supplier lists and part approval status with the ERP's purchasing master data so the procurement team sees the PPAP approval status when raising purchase orders. Integration capability depends on your ERP's API or file export options, which we assess during scoping and design the connector approach around what is technically available in your system version.

A QMS covering CAPA, document control, and audit management typically takes 14 to 18 weeks from requirements sign-off to go-live. Adding supplier quality with APQP/PPAP tracking and calibration management with certificate storage extends this by four to six weeks depending on the volume of existing calibration records and supplier data to migrate. Adding SPC with Western Electric rule detection and PPAP capability reporting adds two to four additional weeks depending on the number of control charts to configure and whether measurement data import from existing systems is required.

We stage the rollout by module so your quality team can start using CAPA and document control while supplier quality and SPC are still being completed and configured. This means the system is delivering value from week 14 onwards rather than requiring your team to wait for the full scope to be finished before going live. All data migration -- existing CAPA records, calibration history, approved vendor lists -- is included in the project scope and is not charged as additional work after delivery.

What clients say

What our clients say

Three-year average engagement. Founders and operators describing the work in their own words. No marketing varnish.

Gil Nugraha
Gil Nugraha
Indonesia
Founder at UrShipper

I definitely recommend RaftLabs, especially to founders building complex platforms. They were transparent throughout the whole project.

01 / 02

Related services

  • Business Process Automation -- Automate production scheduling, quality inspection workflows, supplier purchase orders, and inventory replenishment
  • AI Agent Development -- AI agents for predictive equipment maintenance, defect detection, and production optimisation
  • Custom Software Development -- Custom MES, ERP modules, and production management platforms built for your manufacturing process

Let's talk about your QMS project

Tell us about your quality processes and the certification standards you operate under. We'll scope a system that works for your auditors and your team.