Home · Solutions · Legal & compliance

Solution · Legal & compliance

The standards audit becomes a review of a file that already exists

Audit-ready for every brand, without the week of panic

Each brand's standards manual runs as a checklist with an owner and an evidence type per item; robots collect what already exists, people photograph the rest, and findings close under a name.

DepartmentalMicrosoft TeamsHuman in the loopDeterministic automation
16standards audits a year, four brands, nine sites, 310 items each: this illustrative dealer group prepares every one of them from scratch.

Executive summary

Challenge

Stop rebuilding the standards file the week before each importer audit and fixing the same finding twice.

What changes

The centre of the design is a register, not a robot.

Business value

Gathering falls from about six minutes an item to a robot check for records, versions and web pages.

Systems involved

standards, readiness and findings registers in Microsoft Lists; evidence libraries and audit files on SharePoint; the importer portal self-assessment where required

Business problem

Brand standards

A dealer contract is a set of standards as much as a right to sell. Each manufacturer's manual says what the showroom must look like, which roles hold which certificates, which special tools the workshop calibrates, which steps and documents a customer receives, and how the site appears on the web. The importer checks all of it through standards audits, mystery shopping and self-assessment, and the score feeds the variable bonus. Where the new-car margin is thin, that bonus is where much of the new-car result is made.

A group with four brands has four manuals, four audit calendars and four definitions of compliant. Proving compliance lands on the same people at every site: the sales, service and parts managers, the marketing coordinator and whoever keeps the training records. None of them has the standards as a job; each has a section of a spreadsheet that surfaces a few weeks before the visit.

What breaks at scale is memory. Nobody reads the differences between manual versions, so the auditor discovers the new items. Findings are answered with an action plan of dates that no one tracks, so the same missing tool appears in two consecutive reports.

How it works today

  1. PersonThe importer's area manager announces the visit; the site director forwards the brand's 310-row checklist to the same five managers and coordinators
  2. PersonEach collects their section: photographs of the facade, showroom and workshop; certificates downloaded one employee at a time from the academy portal; calibration certificates found in a drawer or requested again
  3. WaitingThe self-assessment waits for the slowest contributor; the last week before the visit goes on the items nobody started
  4. Risk of errorItems are ticked from memory: a tool that failed calibration in March, an adviser whose certificate lapsed, a web page still carrying last season's campaign
  5. PersonThe site director keys the self-assessment into the importer portal and spends the audit day walking the auditor through folders
  6. SystemThe score arrives weeks later; the findings report is saved to a folder and answered with an action plan of dates
  7. Risk of errorNobody owns the plan between visits; the same finding is raised again and fixed for the second time in the week before the next audit
PersonWaitingRisk of errorSystem

Why the current process costs more than it appears

Time that disappears before anyone measures it.

  • Evidence is gathered by the most expensive people at the worst moment: the site's managers, in the fortnight before the visit, when the showroom and the workshop need them most.
  • Certificates, calibrations and template versions are checked once a year, so an overdue calibration is found when someone looks, not when it happened.
  • Repeat findings cost twice: the fix, the photograph and the explanation are done again, and the auditor looks for a finding raised once first.
  • None of this time has a cost line; it is booked as manager time, never as the cost of holding a contract.

Cost of inaction

A year of gathering evidence by hand for 16 audits≈ €11,894
Sixteen audit weeks of management time (three managers, two days each, €45 an hour)≈ €34,600
Both, over the three-year life of a standards manual≈ €139,500

Bonus money stays out of this table on purpose. In most dealer contracts the variable bonus depends on volume, customer satisfaction and the standards score together, and no citable figure exists for what a repeat finding costs; the rows price working time only, and the second row is 16 audits, three managers, two days each, 768 hours at €45.

What the rows describe continues quietly: each new manual version adds items nobody reads until the visit, each audit consumes the managers' fortnight, and each finding without an owner returns. The folder cannot show a technician without a current qualification or a tool out of calibration: standards items today, warranty disputes tomorrow.

Illustrative scenario

A plausible organisation with realistic proportions. The figures are there to be recalculated on your data; they are not a client result.

Organisation

A dealer group in Poland: four brands, one of them premium, nine sites, about 620 employees, one DMS per brand, importer portals, Microsoft 365 E3 with Teams on phones in the workshops.

Volume

16 standards audits a year, a sales and an aftersales review per brand and site; about 310 checklist items each, 4,960 a year; roughly 40% documents and records, 35% photographs, 25% confirmations.

Current process

A workbook sent round the site's managers; evidence photographed and scanned into a folder per audit; the self-assessment keyed into the importer portal; findings answered with a dated action plan nobody tracks.

Bottleneck

About six minutes of gathering per item, by managers, in the two weeks before the visit; certificates found lapsed on the day; one finding in four a repeat.

Solution

A register per brand in Microsoft Lists with an owner and an evidence type per item; robots collect weekly what exists, UiPath Test Cloud checks web presence, Action Center tasks in Teams ask for photographs and confirmations, findings close under a name, and the audit file is assembled six weeks ahead.

Potential outcome

In the modelled case, gathering falls from six minutes an item to a robot check for most items and a short task for the rest, lapsed certificates surface within a week, and no finding stays open without an owner, all of it modelled rather than observed at a client.

Proposed solution

The centre of the design is a register, not a robot. Each brand's manual is loaded into Microsoft Lists as one item per requirement: section, wording, evidence type (record, document, version, web check, photograph or confirmation), owner role and check frequency. Each site holds a readiness copy per brand; a new manual version is loaded beside the old one, and the differences become items with an owner.

Robots do the reading. Weekly, on an Orchestrator schedule, they compare certification status per employee and role from the importer's academy portal with the staffing list and the brand's requirement, read calibration due dates from the equipment register on SharePoint, and compare the templates in use with the version the brand publishes. UiPath Test Cloud runs a web test set against each site's pages and brand locator entries: opening hours, address and phone, current logo and campaign, booking links, legal notices.

What a robot cannot see is asked of a person through a UiPath Action Center task in Microsoft Teams: a confirmation from the card, or a photograph from the phone into the item's evidence folder in the site's channel. Findings from the last audit carry an owner, a due date, reminders and an escalation to the site director. No AI is involved; every rule is a row the brand director owns.

Native capabilities used

UiPath Orchestrator time triggers, queues and credential stores; UiPath Integration Service connectors for Microsoft OneDrive & SharePoint and Microsoft Teams; UiPath Action Center tasks with due dates and actionable notifications in Microsoft Teams; UiPath Test Cloud web test cases; Microsoft Lists versioning; SharePoint metadata and Purview retention labels; Power BI as a Teams tab

What we build

The standards data model and version loader, the evidence robots, the digital-presence test sets, the task and escalation logic, the findings register, the audit-file assembly, the Power BI readiness model and the runbook

Custom integration

The importer's academy portal and, where required, the self-assessment in the importer portal, through UI automation where no export exists; a staffing extract from the HR system

How the automated process works

  1. AutomationEach brand's manual is a versioned register in Microsoft Lists; a new version is loaded beside the old one, and the differences become items with an owner and a deadline
  2. AutomationWeekly, robots collect what exists: certification status per employee and role from the academy portal, calibration due dates from the equipment register, template versions, the demo-fleet list; UiPath Test Cloud runs the digital-presence test set against each site's pages; each item turns green, amber or red
  3. PersonItems that need a person reach the owner as an Action Center task in Teams: a confirmation from the card, or a photograph from the phone into the item's evidence folder
  4. AutomationOpen findings from the last audit carry an owner and a due date; reminders before the date, escalation to the site director after it
  5. AutomationSix weeks before the visit the audit file is assembled on SharePoint and the self-assessment exported or keyed into the importer portal; Power BI shows readiness by brand, site and section
  6. PersonThe site director verifies closures, answers the weekly readiness summary in the site's channel and, on the audit day, reviews the file with the auditor; new findings get an owner the same day
AutomationPerson

Human-in-the-loop model

Automation handles

  • Loading each manual version into the register and listing what changed
  • Weekly collection of training status, calibration due dates, template versions, demo lists and web checks
  • Opening, reminding and escalating the tasks for photographs, confirmations and finding closure
  • Assembling the audit file and refreshing the readiness view

People decide

  • Whether a photographed item is compliant; the site director signs the self-assessment
  • Whether a finding is closed: the owner attaches the evidence, the site director verifies it
  • What to spend: a replacement tool, a rebranded facade or a training place is a decision recorded against the item
  • What counts as evidence for each item and who owns it; the register stays with the brand director

Before and after

BeforeAfter
Gathering per itemabout 6 min, by managersrobot check; short task for the rest
Lapsed certificate or calibration foundon the audit datewithin a week
Findings with an owner and a due datean action plan nobody tracksevery finding, from the day the report arrives
Preparation for the visittwo weeks of folders and chasinga file assembled six weeks ahead

Systems and integrations

We do not add technology to make an architecture look serious. Every element below has a specific job in this process.

Inputs

  • the importer's checklist per brand
  • the academy portal
  • the equipment register
  • the template library
  • the group's websites and brand locator entries
  • the last findings report
  • the staffing list per site

Automation layer

  • UiPath Orchestrator
  • UiPath Robots
  • UiPath Integration Service
  • UiPath Action Center
  • UiPath Test Cloud

Target systems

  • standards, readiness and findings registers in Microsoft Lists
  • evidence libraries and audit files on SharePoint
  • the importer portal self-assessment where required
  • Power BI semantic model

Human touchpoints: Action Center tasks in Microsoft Teams; evidence folders in the site's channel; weekly readiness summary; Power BI readiness tab

the importer's checklist per brandUiPath OrchestratorUiPath RobotsstandardsAction Center tasks in Microsoft Teams

Technologies used

UiPath Robots + Orchestrator

weekly evidence collection from the portal, the register and the libraries; schedules, queues, credential store, run log

A
UiPath Integration Service (Microsoft OneDrive & SharePoint, Microsoft Teams connectors)

reads and updates the registers, files evidence, posts the weekly summary

A
UiPath Action Center in Microsoft Teams

photograph, confirmation and finding-closure tasks with owners and due dates

A
UiPath Test Cloud (Test Manager)

web test sets that check each site's pages against the digital standards

A
Microsoft Lists and SharePoint libraries

standards register per brand, readiness copy per site, findings register, evidence folders; certificates and templates with due-date and version columns

A
Power BI

readiness by brand, site and section; open and repeat findings by owner; a tab in each site's Teams channel

A
Averified product capability (vendor documentation)

Illustrative economic model

What it is worth, with the arithmetic shown.

Illustrative model
413 checklist items a month × 6 minutes of evidence gathering= 41 h / month
41 h × €24 fully loaded hourly cost= €991 / month
× 12 months≈ €11,894 / year
Annual capacity released (illustrative)≈ €11,894

Sixteen audits of 310 items make 4,960 items a year, or 413 a month; nothing here was measured at a client. Six minutes an item is gathering alone: a certificate downloaded, a calibration document found, a page checked, a photograph filed. €24 is a fully loaded hourly cost blended across advisers, coordinators and a share of manager time. The rows show capacity released, not positions removed.

Run the numbers on your data

hours released per month
of annual capacity released

An illustrative estimate from your own inputs. It models released capacity; it is not a promise of savings.

Business benefits

  • Gathering falls from about six minutes an item to a robot check for records, versions and web pages; people photograph and confirm only what a robot cannot see
  • Lapsed certificates, overdue calibrations and outdated templates surface within a week; the technician is booked on the course before the auditor asks
  • Every finding has a named owner and a due date from the day the report arrives, and closure is evidenced rather than remembered
  • The audit week is spent on customers: the file exists, and the auditor is walked through exceptions, not cupboards; four brands and nine sites are compared on one readiness scale

The management view

  • Readiness by brand, site and section is a weekly figure the group office sees before the area manager does
  • Standards become a running control, like a calibration schedule, not a project that starts when a date is announced
  • The cost of holding each contract is counted: preparation hours, open and repeat findings, items red for more than 30 days
  • A change of site director carries the file with it; the knowledge sits in the register, not in a leaver's inbox

Board-level KPIs

readiness score per brand and site a week before the auditopen findings older than 30 daysrepeat findings per auditaudit score per brandpreparation hours per audit

Security and governance

Trust in automation is built on the audit trail, not on a promise.

  • The portal robot has its own account with read rights only; its secret sits in a vault connected to Orchestrator, and each run is logged in the EU region of UiPath Automation Cloud
  • Registers, evidence and audit files stay in the group's Microsoft 365 tenant, visible per site to that site's managers, the group office and the brand director; Purview retention labels keep audit files for the period the group's policy requires
  • Training records are personal data: the readiness list stores status and expiry per employee and role; the certificate itself stays in the HR library
  • Whoever fixes a finding cannot close it; the site director verifies, and every reassignment, extension or regrade carries a name and a reason; evidence rules are changed by the group standards owner only

Why now

01

Manuals are changing faster than they used to: electrification brings items on high-voltage training, and battery-electric registrations in Poland rose by more than 160% in 2025 to 43,311 cars (PZPM, January 2026); a register that reads the differences is worth more each year

02

The framework is under review: Regulation (EU) 2023/822 extended the aftermarket block exemption to 31 May 2028, and CECRA, the European dealer association, describes corporate identity and premises as "copious capital expenditures" with "negligible" returns; the modelled €991 a month of gathering is the cheapest part of defending the bonus that pays for them

03

Action Center tasks are completed inside Microsoft Teams, Integration Service connectors read SharePoint lists and post to channels, and UiPath Test Cloud runs web checks on a schedule

Relevant executive roles

Group Managing Director

Four contracts, one readiness number, and audits that no longer pull the site's managers off the floor for a fortnight

Brand Director

The manual becomes a running checklist with owners, and the audit week is a review of a file

Aftersales Director

Calibrations, special tools and technician certifications are checked weekly, which warranty audits and workshop safety need anyway

Group CFO

The cost of holding each contract is counted in hours and findings, and the bonus that depends on the standards score is defended with evidence rather than overtime

Common questions and objections

Each brand's checklist is different and changes every year.

That is what the register is for: one structure, four contents. A new version is loaded beside the old one and the differences become new items with owners; evidence rules are per item type, not per brand.

Our importers' portals have no export.

Most do not, which is why the robot reads them the way a coordinator does: through the screen, with its own account, on a schedule. When a portal changes its layout, one robot is adjusted; nobody's fortnight is.

The auditor still walks the showroom.

And should. The file shows what was checked and when, items that need a person carry last week's photograph, and last visit's findings carry closure evidence; the audit becomes a conversation about exceptions.

When this is not the right solution

  • A single-brand dealer with one or two sites and one audit a year: a well-kept SharePoint library and a calendar are enough, and we will say so
  • The sites have not agreed who owns each section of the standards; a task with no owner is an email with a robot's name on it, so the responsibility matrix comes first
  • The open findings are capital items, a facade or a showroom extension; a tracker does not fund a rebuild, and that decision belongs in the investment plan

A question for the next management meeting

Suppose the premium brand moved next quarter's audit at our largest site forward by a month: what in our file is ready today, what is one photograph away, and which of last year's findings would the auditor see for the second time?

Implementation approach

What we deliver, and what we need from you to start.

We deliver

  • Discovery with the brand director and two sites: manuals, evidence type per item, owners, last findings
  • The standards register per brand in Microsoft Lists, versioned, with a report of differences between versions
  • The evidence robots, the digital-presence test sets in UiPath Test Cloud, and Action Center tasks in Teams with reminders and escalation
  • Audit-file assembly, self-assessment export, the Power BI readiness model and a runbook for site coordinators

We need from you

  • Current manuals and checklists per brand, and the last findings reports from two sites
  • A group standards owner, usually the brand or aftersales director, and a site director for the pilot
  • Service accounts for the academy portal and Teams, the equipment register, the staffing list and the audit calendar per brand

Stages

Discovery

Manuals, evidence types, owners and last findings for one brand and two sites

Design

Register model, evidence rules, task and escalation logic, test sets, permissions

Build

Registers, robots, test sets, Teams tasks, audit-file assembly and the Power BI model

Pilot and rollout

One brand at two sites through a real audit, then the remaining brands and sites in audit-calendar order, with hypercare

Departmental. Effort depends on the number of brands and manual formats, how many evidence sources offer an export, and how far the sites' habits differ.

Four brands, four audit calendars, sixteen files rebuilt from scratch every year.

Send us one brand's standards checklist and the findings report from your last audit at one site. We come back with the share of items a robot can evidence on its own, what still needs a photograph, and a first estimate of the preparation hours released.

Audit one site before the importer does

The neighbouring process usually has the same problem

Industries we deliver this in most oftenAutomotive retail

Browse all 115 solutions