Three years per certificate A handbook that lives Evidence from the work itself

Custom HKZ quality manual and audit file development

An HKZ certificate requires not only a quality manual, but proof that work is actually carried out according to that manual. At most organisations the manual lives in a folder on the shared drive, and the evidence is gathered together six weeks before the audit. Appfront builds the system in which the manual and the evidence belong together.

Where HKZ gets stuck in practice

HKZ stands for Harmonisatie Kwaliteitsbeoordeling in de Zorgsector and has dozens of standards, each for a specific sub-sector: residential care and home care under one standard, care for people with disabilities, mental health care, youth care, and so on down to small practices. The scheme sets out which subjects you must have under control. Your manual describes how you do that; the audit checks whether it matches practice. The certificate is valid for three years, with interim assessments during that period and a recertification at the end. That rhythm shapes your file more than anything else: at recertification the auditor looks back over three years, and what counts is whether you documented it at the time. It touches your care compliance, which covers legal frameworks such as NEN 7510 and the Wkkgz; HKZ is a voluntary certificate with its own scheme and its own certifying body. The overview of standards is on hkz.nl.

That difference is where things go wrong, and the HKZ scheme puts its finger precisely on that spot. It asks not only for documented processes but for the PDCA cycle around them: an internal audit programme, management review, measurements of client satisfaction, and demonstrable follow-up of complaints and incidents. That is work which should be spread across the whole three-year period. In practice, the management review gets written in one afternoon, internal audits are planned but not carried out, and the improvement points from the previous external audit sit in a report nobody opens again.

The auditor at your certifying body sees that in the dates. Four internal audit reports written in the same week tell them more about your quality system than anything written in them.

Where it really goes wrong is in the link to the three-year cycle. A finding from the interim assessment in year one should still be traceable at recertification in year three, along with what you did about it and whether it worked. In an organisation with several locations and several standards, the same improvement is tracked separately in three places, so at recertification no one has the overall picture any more.

The mandatory submission of quality indicators has its own rhythm and its own source. That is covered on the page about the indicator registration app on the ward.

How we build your HKZ system

Your manual and your scheme are the starting point and remain yours. What belongs in them is for you and your quality officer to decide; we build the system that keeps it alive.

1
Setting the manual and the scheme side by side

Which parts of your scheme touch which processes, and where there is nothing. This overview is usually the first thing that delivers value, even apart from software: it shows where the manual describes subjects that nobody actually carries out.

2
Recording the links

A procedure hangs off a part of the scheme, an audit hangs off a procedure, a finding hangs off an audit and an action hangs off a finding. Without those links it stays a collection of documents.

3
The manual first

Everyone works from it, so that is where the build starts: one valid version, findable on the shop floor. Your quality officer takes part and checks every sprint against the scheme.

4
Mock audit and handover

We walk through a scheme item the way an auditor would and look for where you cannot get the evidence out of the system. That is the test that counts, and we run it before the real auditor arrives.

What the system does in practice

Going from a collection of documents to a working quality system takes these six steps. For one location and one scheme you need four; for several of both, all six.

Manual with version control

Each procedure has one valid version, with earlier versions kept and a clear record of who changed what and when. Staff always see the current version, because an outdated document on the shared drive is a finding at audit.

Integration with your scheme

Every part of your HKZ scheme is linked to the procedures and records that give it substance. Where nothing depends on it, that is immediately visible rather than only coming to light during the audit.

A self-maintaining audit year plan

Internal audits, management review, evaluations and review intervals on an annual plan with alerts. A missed internal audit stays open rather than quietly disappearing.

Finding with action and verification

A finding is only closed once there is an action, an owner, a deadline and confirmation that it worked. That last part is what an auditor checks the following year, and what most systems leave out.

Reports from the frontline

Incidents, complaints and improvement suggestions come in where the work happens and land in the same system. While they arrive through three separate routes, nobody sees that the same cause keeps coming back.

Audit file per scheme component

The evidence is arranged the way the auditor looks at it, with the records, audits and follow-up brought together and organised by your scheme. If you need a system that plans and carries out audits of any kind, audit software is the broader answer; this page is about the file that one specific HKZ scheme requires.

Who we build for

The number of locations determines whether a central manual reaches the shop floor, and the number of schemes determines how much gets recorded twice. Four situations.

Home care and domiciliary care

Many locations and teams working independently, so a central manual quickly drops out of sight. Here it matters that the current procedure can be found on a phone, not on the office shared drive.

Mental health and youth care

Heavier file documentation and more overlap with other supervisory frameworks. The temptation is to build a separate system for each framework, so the same record exists three times, separate from your WMO and youth care software.

Care for people with disabilities and small-scale living

Small teams across many locations, with a quality officer who often handles this alongside other duties. In that case usability matters more than completeness; a system that asks too much will not be filled in.

Organisations with multiple certificates

HKZ alongside ISO 9001, or alongside an additional scheme per service. A quality management system is generic and follows the ISO structure; an HKZ scheme is written per sub-sector and contains requirements that are not in that structure. The benefit is that a single record is linked to both, rather than duplicated.

Not yet sure about a large project?

Test your idea first: a working prototype in 1 day

With OneDayBuild, we turn your idea into something tangible in one day for €1,150, so you can see whether further development is worth the investment. Decide to go ahead with the full build? Then we credit the full cost.

Explore OneDayBuild →

Technology and integrations

One design requirement comes first, and it is not technical: the system must be usable for people who are not quality officers. They supply the evidence, and anything that asks too much will not get filled in.

If you want to record the definition, source and sign-off for each indicator, see our software for the quality indicator submission file.

Node.js / Python / .NET PostgreSQL Version control on documents Schema structure as a configurable component Linking procedures to schema components Audit planning and monitoring Findings with corrective action and verification Mobile reporting Roles by location and by team Search across the entire file Export for the auditor Audit logging of changes Integration with your EHR or HR system EU hosting

Why Appfront

Evidence is created in the work

An audit file assembled after the fact is exactly what an auditor recognises. We make sure records are created where the work happens and organise themselves automatically.

A finding only closes after verification

Most systems let a finding be closed as soon as someone writes down an action. We also ask whether it worked, because that is what gets checked the following year.

Built around your own scheme

HKZ has dozens of schemes and they differ. We take yours on as a configurable structure rather than imposing a standard layout that doesn't fit.

Honest about our role

We are not quality consultants and we do not write your manual. We build the system that keeps the manual alive and gathers the evidence; the substantive assessment remains with you and your certifying body.

Security and privacy

A quality system in healthcare almost always involves client data. An incident report describes what happened to a specific person; a complaint contains a name. That falls under both the GDPR and medical professional confidentiality, which means an improvement file cannot be open to the entire organisation. We separate the report from the analysis: those working on improvements usually do not need to know to whom it relates.

The same applies to audits. An auditor may inspect files, but exporting your entire system to a folder that then remains in place is a risk nobody needs. We set up the audit as temporary, limited access to what is being checked. Furthermore, the records are tamper-proof: a correction is visible as a correction, because a finding that can be removed from the system afterwards renders the whole file worthless. How we handle security ourselves is set out in our information security policy; reports from outside come through our vulnerability disclosure policy.

Frequently asked questions about HKZ software

No. Deciding what belongs in your procedures is specialist work for your quality officer or consultant, and we cannot take that over. We build the system the manual lives in: with version control, linked to your schema, and connected to the evidence that work is being carried out as documented. If you do not yet have a manual, that is the first step, not the software.

Yes, and that is usually where the biggest gains are. HKZ alongside ISO 9001, or several HKZ schemes for different services, overlap considerably. We link a procedure or record to every requirement it addresses rather than duplicating it. When a schema changes, you can see straight away what is affected.

Because there is only one valid version and it is findable where the work takes place, including on a phone. Old versions are kept for the record but are not what someone encounters when searching. When a revision is made, you can see who has viewed the new version, which for important changes makes the difference between sending and actually reaching people.

It receives an action, an owner and a deadline, and it is only closed once it has been established that the action worked. That last step is exactly what is missing in most systems and what an auditor checks the following year. Findings from internal audits, external audits, incidents and complaints follow the same route, so you can see whether a cause recurs.

Often, yes, through integrations, and with a limited scope: counts and signals, not client records. The benefit is that incident reports from the primary process land in the quality system automatically rather than being retyped by someone. What can be connected depends on your supplier; we establish that before committing to anything.

Transferring documents is usually the smallest part. The real work lies in establishing the links: which procedure corresponds to which element of the scheme, and which record is the evidence for it. That is work you do with your quality officer, and it delivers value in itself, because it shows where nothing hangs under a subject.

We can restructure this without making the accumulated history worthless. We build the schedule structure as a configurable component and keep a record of which version applied in each period, so an old audit can still be read against the requirements of the time. That's why we don't hard-code it into the software.

That depends on the number of locations, the number of schemes and whether integrations with your EHR or HR system are needed. The manual with version control and the audit planning are usually quick to put to use and deliver the most value; integrations cost more. We provide a reasoned estimate after the discovery phase.

Building an HKZ system?

Bring the findings report from your last external audit. It usually shows straight away which part of your file was compiled after the fact and which part kept pace with the work. We build this as a standalone system or as part of a broader custom software project. If you run a childcare organisation, staffing runs separately; see BKR software.

Edit content