Your learners log in at 6 a.m., on a Sunday, in twenty-minute chunks. And your Qualiopi auditor is asking you for “attendance sheets.” The two seem incompatible, and plenty of training providers end up cobbling together unverifiable spreadsheets or getting backdated PDFs signed. That is exactly what triggers a non-conformity.
Good news: for asynchronous distance learning, the French Labour Code does not require a signature for every half-day. It requires an individualised training protocol and evidence that the training actually took place. That difference completely changes how you organise your day-to-day work.
Below you'll find the four methods that are genuinely used to produce digital attendance records that hold up in front of an auditor, from the most automated to the most manual. For each one: what it really proves, what it costs you in time, and where it falls short. And at the end, the precise list of documents to file in your evidence folder, session by session.
What Qualiopi actually requires in e-learning (and what it doesn't)
In open and distance learning, the expected proof is not a signature at a fixed time: it's a body of traces showing that the learner followed and completed the training.
The framework comes down to two texts. First, article D6313-3-1 of the French Labour Code on Légifrance, which states that a distance learning action follows an individualised protocol covering three elements: the technical and pedagogical support made available to the learner, information about the learning activities and their average duration, and the assessments that punctuate or conclude the action.
Second, the national quality framework set by decree no. 2019-564 of 6 June 2019: 7 criteria, 32 indicators, mandatory since 1 January 2022 for any provider wanting access to public and pooled funding (OPCO, CPF, France Travail, regions, local authorities).
In practice, the auditor is trying to answer three questions:
- Did the learner actually access the content, and over what period?
- Did they produce something (assignments, quizzes, assessments) that proves their activity?
- Did they have access to support, and did that support leave a trace?
What the auditor does not ask for: a handwritten signature every half-day for asynchronous sequences. That would be a fiction, and a well-documented fiction is still a fiction.
Watch out for two nuances. As soon as a sequence is synchronous (virtual classroom, video call, in-person), timed attendance becomes the norm again, and it's almost always required. And above all, your funder can be stricter than the law: the terms and conditions of an OPCO or a regional agreement take precedence over your convenience. Read them before choosing your method. If you want the details indicator by indicator, the article on what auditors really expect when it comes to Qualiopi evidence is a good companion to what follows.
Method 1: a platform that produces the evidence for you
The shortest route is to use an e-learning platform that natively timestamps every login, every completed module and every assessment, then exports the whole thing as one document per learner.
That's the principle behind Skilzy, a French platform for learning and using AI: more than 15 programmes (image creation, UGC videos, ads, faceless channels, avatars and voice-overs, music, automation with n8n, prompt writing, AI-assisted development). A built-in “AI Lab” lets learners use the real tools directly inside the platform, with credits included, so they don't have to pile up subscriptions on their own.
For a training provider, the benefit is twofold. The catalogue is ready to offer, and two certifications registered in France's Répertoire spécifique are state-recognised and eligible for funding: certification RS7439 in AI content marketing and RS6792 in AI and sales. On the compliance side, learner activity is tracked by design: login dates and durations, modules opened and completed, quiz and assessment results, work produced in the Lab, support exchanges.
These elements feed directly into the folder an auditor expects. The compliance offer for training providers sets out the available exports and how to link them to your training agreements.
Two honest caveats. The platform supplies the raw material: building the folder, and keeping it consistent with your quote, agreement and completion certificate, remains your responsibility — nobody can carry that for you. And if you use several tools in parallel, you'll have to consolidate the exports.
As for trying it out, the discovery demo gives you 7 days of access with no credit card, including 1 image, 1 video, 1 music track and 10 messages: enough to check the learner experience before committing to anything. The consumer plan starts at €29.90 per month with no lock-in, and a dedicated offer exists for training providers. If you're still weighing up your technical foundation, first compare the options in the guide on choosing an e-learning platform for your training organisation.
Method 2: your current LMS plus an attendance module
If you already host your content on an LMS such as Moodle, Chamilo, LearnDash or 360Learning, the evidence often already exists in the activity logs: the work is making it readable.
An LMS records logins, time spent per module and assessment results. Content in SCORM or xAPI (also called Tin Can) format additionally reports completion status and score. Many tools offer an attendance module or plugin that turns those logs into a dated, electronically signed record.
Two settings you shouldn't neglect. Connection time is not training time: a tab left open for three hours manufactures false data, and an attentive auditor will notice. Configure an automatic logout after inactivity — 15 or 30 minutes, for example. Then export as a timestamped PDF rather than an editable CSV: a raw spreadsheet file can be tweaked in two clicks, which weakens its evidential value.
Main limitation: raw logs are unreadable for someone discovering your tool. Plan a formatting template, one page per learner, with your organisation's name, the title of the training action and the session dates.
Method 3: a dedicated electronic attendance tool
Specialised solutions (Edusign, Digiforma, Dendreo, Ypareo and equivalents) deliver what an LMS does badly: named, timestamped signatures, especially for synchronous sequences.
The principle is simple: the learner receives a link or a code by email or SMS, signs from their phone, and the tool generates a consolidated sheet per session. The signature relies on the European eIDAS regulation, which distinguishes three levels (simple, advanced, qualified). For attendance purposes, a simple electronic signature is accepted in practice as long as you can demonstrate the signatory's identity, the exact date and the integrity of the document. The qualified level, far more expensive, isn't expected here.
This is the best option for virtual classrooms, group sessions and blended formats. Pricing varies by vendor (per user, per session or as an annual package): check the current rate card, it changes often.
Limitation: this tool proves presence at a given moment, not asynchronous engagement. If your programmes are mostly self-paced, it doesn't replace your platform's activity logs — it complements them. And without a connector to your LMS, you'll be re-entering sessions by hand.
Method 4: the hand-signed PDF, the minimum viable option
Sending an attendance sheet as a PDF, having it printed, signed, scanned and sent back is still possible, but it's the most fragile and most time-consuming method.
It makes sense in one case: low volume, a few sessions a month, with clearly dated synchronous sequences. Beyond that, you'll spend a considerable amount of time chasing learners, and the return rate drops fast.
The risks are real. A scanned signature is worth no more than the paper it came from: nothing indicates the actual date of signing, which opens the door to suspicions of backdating. Sheets signed after the fact all at once, all in the same ink and from the same day, are a classic red flag in an audit. And an unprotected PDF is easy to modify.
If you stick with this method, lock down at least three things: one sheet per session and per date, not a monthly summary sheet; a saved outgoing and incoming email for each one (the message timestamp becomes your proof of date); and systematic, consistent file naming in your archive.
Quick comparison of the four methods
| Method | What it proves | Effort per session | Best suited to |
|---|---|---|---|
| Integrated platform (Skilzy) | Logins, progress, assessments, work produced | Almost none, automatic export | Asynchronous programmes and high volumes |
| LMS plus attendance module | Logins and completion, signature depending on plugin | Low once configured | Providers already running an LMS |
| Dedicated attendance tool | Named, timestamped presence | Low, automated sending | Virtual classrooms and synchronous sessions |
| Hand-signed PDF | Declared presence, uncertain date | High, manual chasing | Low volume, occasional stopgap |
The evidence folder: the checklist to build for each learner
A solid folder contains seven items per learner, all dated, consistent with one another and unambiguously tied to the same person and the same training action.
- The individualised training protocol, provided before the start, listing the activities, their average duration, the support arrangements and the planned assessments.
- The timestamped activity log: login dates, durations, modules opened and completed.
- Assessment results: initial positioning, interim quizzes, final assessment.
- The learner's output: assignments, deliverables, exercises, screenshots of work done in a lab or integrated tool.
- Traces of support: emails, in-platform messages, tickets, meeting notes. This is the item most often forgotten, and one of the most closely examined.
- Signed attendance records for every synchronous sequence, one sheet per date.
- The completion certificate sent to the funder, plus the end-of-training attestation given to the learner.
A few rules that save you trouble. Name your files using a single scheme, for example 2026-03-12_LASTNAME_Firstname_activity-log.pdf: an auditor who can find a document on their own in ten seconds is a reassured auditor. Check that dates line up across the training agreement, the activity log and the completion certificate, because date inconsistencies are the most frequent cause of non-conformity. Keep everything for at least three years, the length of the certification cycle, bearing in mind that an administrative inspection can cover earlier periods; many providers keep five years, with the retention period written into their GDPR records.
The three mistakes that cost you dearly: logs generated en masse the day before the audit, connection times identical to the stated durations (nobody completes a 45-minute module in exactly 45 minutes), and an individualised protocol sent after the training has started. On that last point, if you're building your offer from external content, check that the ready-made AI training catalogue you're using does provide average durations per activity: without them, your protocol is incomplete.
Where to start this week
Take a session that recently ended and try to reconstruct the seven items. Whatever you can't find in under ten minutes is exactly what will be missing on audit day. Then choose your method based on how much of your programmes are asynchronous: an integrated platform if everything is self-paced, a signature tool on top as soon as you schedule virtual classrooms. The rest is a matter of habit, not technology.