Goolean

Compliance platform · Available now

Audits, policies, training and certificates in one system of record. AI does the first pass; people sign off.

CAM (Compliance and Audit Management) is Goolean's AI-powered compliance platform. It runs vendor and internal audits end to end, carries policies through review and approval, trains and tests staff, and tracks every licence and certificate to expiry. Goolean hosts and operates it as a cloud service.

How CAM runs

Hosted
Goolean-hosted SaaS. We run, patch and monitor it; your teams and vendors sign in from a browser.
Your frameworks
Audit templates, question groups, scoring models and framework coverage are configured per organisation — CAM doesn't assume one standard.
Enforced access
Role defaults plus named per-user permissions, organisation and vendor-company scopes, and separation of duties the system refuses to bypass.
Every record moves through a defined lifecycle
Audit
  1. Draft
  2. In progress
  3. Under review
  4. Closed
Policy
  1. Draft
  2. Under review
  3. Pending approval
  4. Active

Modules

Six modules, one audit trail.

Audit Management

Build audit templates, question groups and scoring models. Assign audits to internal teams or vendor companies, review responses, set risk scores, log findings, evidence and CAPAs, and close with digital sign-off and PDF or Excel reports.

Scoring modelsFindings & CAPAsDigital sign-off

Vendor responses

Vendors see only the audits assigned to their company. They answer, attach evidence, fix rejected answers and talk to the auditor in threads. Once an assignment is completed it locks.

Company-scopedRemediationThreads

Manage Policies

Draft, review, approve and publish versioned policies. A named reviewer and a separate approver sign off, and approved policies reach every user in scope — and CAM's AI knowledge base — immediately.

VersioningReviewer → ApproverDistribution

Training & SOPs

Publish training documents and SOPs, build question banks, and assign timed tests with pass thresholds, shuffling and retry limits to staff or vendor companies.

CBT testsQuestion banksPass thresholds

Licenses & Certificates

Record licences and certificates with expiry dates and renewal frequency, define your own certificate types, approve and archive. Vendors can view and download their own company's certificates.

Expiry trackingCustom typesApproval

User Management

Organisation users and vendor-company users, invitations, activation and offboarding. Company admins manage their own people and nobody else's.

Named permissionsCompany adminsInvites

AI in CAM

Where the AI works — and where it stops.

AI in CAM drafts, checks and retrieves. Accepting a response, approving a policy or passing a test stays a human decision with a name on it.

Response review

Auditors run an AI review across vendor responses before they accept, reject or ask for clarification.

Compliance review

Approvers run an AI compliance review on a completed assignment before giving final approval.

Policy knowledge base

Approved policies enter CAM's AI knowledge base the moment they're approved; archived policies are removed from it.

Question generation

CBT questions are generated from an approved training document, then approved like any other question before they reach a test.

Roles

Everyone in the audit, each seeing only their part.

Compliance officers
Own audit programmes, policies, training and certificates; approve and report.
Auditors
Review responses, set risk scores, log findings and CAPAs, collect evidence, sign off.
Reviewers & approvers
Read the policy in front of them and approve or reject it, with comments.
Staff
Read approved policies, take assigned tests, see their own results.
Vendors
Answer assigned audits, remediate rejections, see their own certificates — nothing else.
Company admins
Manage users inside their own company, and only there.
Controls CAM enforces, not just records
  • A policy's creator can't approve it — the system refuses the request.
  • Super-administrators can't act as policy approvers.
  • Completed audit assignments lock against further changes.
  • Vendors see only their own company's audits and certificates.
  • Deleted certificate files are retained for the audit trail.

See CAM on one of your audits.

A walkthrough built around a real audit template or policy of yours. We host it; your team just signs in.

Request a demo