PLATFORM MODULE REFERENCE

Zebsoft Compliance Software Modules

Configured Applications of Shared Assurance Capability

This page is the reference index for Zebsoft compliance software modules. It explains how reusable platform capabilities are configured for particular operational purposes and provides direct routes to the relevant module and capability pages.

A module is not a disconnected product or another data silo. It applies shared workflow, permission, evidence and assurance functions to a defined subject such as audit, risk, documents, incidents, people, suppliers, assets or continuity.

Zebsoft compliance software modules platform reference

THE STRUCTURAL DISTINCTION

Module, Capability, Domain and Standard Are Not the Same Thing

These terms describe different layers of the platform. Keeping them separate makes the system easier to navigate and prevents one configurable function being mistaken for a fixed standalone product.

Capability

A reusable platform function such as auditing, risk assessment, document control, training, change or task management. The same capability can support several subjects.

Module

A configured application of capability for a defined purpose. An internal-audit module and supplier-audit module can share the audit engine while using different scope and workflow.

Domain

The responsibility context in which modules operate, such as quality, information security, health and safety, environmental management or supply-chain integrity.

Standard

A requirements framework such as ISO 9001, ISO 14001 or ISO 27001. Standards can draw on multiple modules and capabilities without becoming the operating system themselves.

ONE SHARED OPERATING STRUCTURE

Modules Organise Context Without Breaking the Connection

Organisations often buy separate tools for each compliance activity. Audit data sits in one system, risks in another, documents in SharePoint, actions in email and training in a spreadsheet. Each application may perform its own task, but the relationship between them becomes difficult to see.

Zebsoft modules use shared platform services for identity, permissions, workflow, notification, evidence, review and reporting. The context can change while the operating connection remains available.

What remains connected

  • The requirement, risk, role, site, asset, supplier or process in context
  • The accountable owner and configured authority route
  • The workflow, schedule, communication and evidence request
  • The decision, exception, action and escalation history
  • The human review that verifies whether the expected outcome was achieved
  • The reporting view used across relevant modules and domains

SHARED ENGINE—DIFFERENT CONTEXT

Examples of How Capability Becomes a Module

The module applies classification, questions, responsibilities, permissions and workflow appropriate to the subject. It does not require a new isolated platform for every variation.

Risk modules

Information-security risk, health-and-safety risk, environmental risk, supplier risk and business risk can share the same assessment logic while retaining distinct context, ownership and control expectations.

Audit modules

Internal audits, supplier audits, site inspections and framework-specific audits can use shared planning, evidence, findings and follow-up capability with different programmes and criteria.

Incident modules

Safety events, information-security incidents, complaints, nonconformities and near misses can use shared reporting and investigation functions with different classifications and escalation routes.

MODULE GROUP 01

Audit and Assurance Modules

Plan assurance activity, collect evidence, record findings and connect identified weakness to accountable follow-up.

Audit management

Build programmes, define scope and criteria, assign competent auditors, conduct activity, retain evidence and report the outcome through a controlled audit trail.

Operational checklists

Turn repeatable questions, inspections and verification points into scheduled or triggered activity with ownership, response, evidence and exception visibility.

Findings and nonconformance

Record what did not meet the expected condition, preserve its context and initiate investigation, correction, corrective action or risk review as appropriate.

MODULE GROUP 02

Risk, Controls and Documented Information

Connect what the organisation has decided, the risks that could prevent it and the approved information that directs the work.

Risk management

Maintain structured risk context, assessment, ownership, controls, treatment, review and current status without reducing every risk type to an isolated spreadsheet.

Statement of Applicability

Connect ISO 27001 Annex A control decisions to applicability, justification, implementation context, ownership, supporting evidence and assurance activity.

Document control

Govern authoring, review, approval, publication, access, communication, revision and withdrawal for information that carries operational authority.

MODULE GROUP 03

Incident, Change and Action Modules

Keep events, decisions and required responses visible from initial record through authorised closure and effectiveness review.

Incident management

Capture the event and immediate context, route notification, support investigation, identify contributing causes and connect the outcome to risk, change or improvement.

Change management

Control proposed change through context, impact assessment, review, approval, implementation, communication and verification rather than treating approval as the finish line.

Task and action management

Assign work with an owner, due date, priority, supporting information and evidence requirement. Escalate missed activity and retain the decision trail at closure.

MODULE GROUP 04

People, Competence and Communication Modules

Make approved requirements visible to the people affected and return completion, evidence, questions and exceptions through structured workflows.

Training and competency

Define role requirements, assign learning or evidence, review submitted records, monitor status and expiry and keep competence decisions with authorised people.

Employee communication

Give employees a current view of applicable information, changes, acknowledgements, assignments and required responses while managers retain visibility of exceptions.

Supplier collaboration

Request information and evidence from external parties through a controlled route and return submissions to internal owners for review, decision and continued monitoring.

MODULE GROUP 05

Continuity, Assets and Infrastructure Modules

Apply structured responsibility and evidence to operational resilience, physical or digital assets and the work required to keep them controlled.

Business continuity

Connect impact analysis, critical activity, dependency, plan ownership, exercises, incidents, lessons and improvement actions within a maintained resilience system.

Asset records and maintenance

Maintain asset identity, location, responsible person, inspection, maintenance, certification, condition and supporting records for operational use.

Asset assurance

Connect asset strategy, lifecycle risk, integrity decisions, change, investment and assurance without confusing strategic governance with routine maintenance scheduling.

MODULE GROUP 06

Privacy and External-Party Modules

Structure registers, decisions, due diligence, communication and monitoring where responsibilities extend across personal information or external organisations.

Data protection records

Maintain personal-data and processing context, ownership, lawful basis, retention and supporting information as part of a governed privacy system.

DPIA and privacy governance

Assess change and privacy risk through a controlled impact route, retain competent review and connect approved treatments to evidence and follow-up.

Supplier approval and tendering

Control initial qualification, evidence, evaluation, approval and tender decisions before moving selected suppliers into onboarding and continued assurance.

HOW MODULES CONNECT

A Module Should Lead Into Controlled Work—not End at a Record

The exact route varies by configuration, but the operating principle remains consistent: context enters the platform, required activity is owned and visible, evidence returns to the record and a competent person verifies the outcome.

01

Context

A requirement, risk, incident, document, person, supplier, asset or other governed subject establishes why work is needed.

02

Configured workflow

The applicable module determines questions, stages, permissions, ownership, notifications and required evidence.

03

Operation

The responsible people complete the required activity, communicate, submit evidence or record a decision through the controlled route.

04

Visibility

Current status, missed responses, conflicting information and overdue work remain visible to authorised roles while action is still possible.

05

Human verification

A competent person reviews the information and decides whether it is accepted, rejected, returned, escalated or subject to further action.

06

Assurance

The record retains the operation, evidence, review, exception and outcome so reporting is based on traceable activity rather than reconstructed claims.

CHOOSE THE RIGHT VIEW

Continue Through the Platform Reference

Use the page that matches the question you are trying to answer. The routes below describe the architecture, reusable functions, responsibility contexts and external requirements separately.

System structure

See how the platform, domains, capabilities, portals and ZAP workflows fit together as one connected assurance environment.

Capabilities

Explore the reusable functions that perform audit, risk, document, incident, change, training and action work across the platform.

Domains

See how the platform is applied to quality, information security, health and safety, environment, suppliers, assets and other responsibilities.

Standards

Find framework-specific information for organisations operating recognised standards and regulatory requirements through the platform.

PRACTICAL QUESTIONS

Zebsoft Software Module FAQs

Module availability, naming and workflow depend on the agreed platform configuration. These answers explain the structural principle rather than defining a universal customer setup.

What is a Zebsoft module?

A module is a configured application of shared platform capability for a defined operational purpose. It brings relevant fields, classification, permissions, workflow, evidence and reporting together without requiring an isolated system for every subject.

Is a module the same as a capability?

No. A capability is the reusable function, such as risk management or auditing. A module applies that capability to a context, such as supplier audit, information-security risk or a site inspection.

Is a module the same as a domain?

No. A domain is the responsibility context, such as quality, health and safety or information security. A domain normally uses several modules and capabilities to operate its controls.

Does every customer receive every module?

Not necessarily. The enabled functions, configuration, user roles, portals, workflows and implementation scope depend on the customer’s agreed requirements and subscription arrangement.

Can modules share information and workflows?

Yes, where configured and authorised. An incident can prompt risk review, action, change, document revision, training or audit verification while retaining the relationship between the records.

Does a module guarantee compliance?

No software module guarantees conformity, certification or legal compliance. Zebsoft helps organisations operate approved controls and retain evidence. Competent people remain responsible for requirements, configuration, decisions and assurance.

NEED HELP FINDING THE RIGHT ROUTE?

Start With the Work You Need to Control

If the module name is not obvious, begin with the operational problem: what must happen, who is responsible, what evidence is required and how an exception should be handled. Zebsoft can then show which capabilities and configuration provide the appropriate route.

Explore the connected platform

Bring one real workflow or register to a conversation and we can map it to the relevant modules without assuming that every requirement needs another standalone tool.