Software for Elevator Maintenance Tracking and Compliance
By Sumeet Katariya, ElevatorPlus
In short: A maintenance log is not a scheduling tool. It is the evidence an elevator company produces when an inspector, an insurer, a building owner or a court asks what was done, when, by whom and on which unit. A schedule that lives in a technician's head or a WhatsApp group produces nothing under scrutiny. A defensible record names the asset, the person, the date and time, the checks performed, the findings and the actions, signed at the point of work and locked afterwards.
Key takeaways
- The log is the evidence, not the paperwork around the evidence. When something goes wrong, nobody asks whether the work was done well. They ask what you can show, and the record is the whole of your answer.
- Eight elements decide whether a record survives scrutiny. Which asset, who attended, when, what was checked, what was found, what was done, a signature captured at the point of work, and an entry that cannot be silently rewritten afterwards. Miss any one and the entry stops being proof of anything.
- Your local rule sets the interval, and the record has to match it. Statutory maintenance and inspection frequencies differ by country and, in India, by state. The obligation on the software is to hold whatever interval applies to that asset and show it was met.
- Signed at the point of work beats signed at month end. A signature added days later, from an office, by someone who was not on site, weakens the entry it was meant to strengthen.
- Handover and contract loss are where records disappear. The unit stays in the building. If your history leaves with your engineer, the next company starts from zero and so does the owner.
- Retention outlives the contract. Questions about a unit arrive long after the AMC ended, and the only useful answer is a record you still hold.
What this guide covers: why maintenance is a compliance record · what a defensible entry contains · weak records and what they are missing · mapping schedules to the local rule · what to record on breakdowns and callbacks · handover and contract loss · retention · FAQs.
Why is a maintenance log a compliance record and not just a schedule?
Ask an elevator company how it manages planned maintenance and you usually get an answer about routing. Which technician, which building, which day of the month. That is a scheduling answer. It describes intent.
Now change the question. A unit has stopped between floors with passengers inside. An inspector has arrived. An owner is disputing an invoice, or a lawyer has written asking what service the unit received over three years. None of them care about your route plan. They ask one thing: show me what was done.
At that moment the log stops being an operations tool and becomes the only account of your work anyone will accept. Everything else is memory, and memory is contested easily.
This is why a schedule held in a technician's head fails. So does a WhatsApp group, and that case is worth spelling out because so many companies rely on it. Messages are unstructured, so nothing can be pulled by asset. The timestamp records when a message was sent, not when the work happened. Anyone in the group can delete. Photos expire from phones, and people leave and take the history with them. As evidence it is not weak. It is absent.

What makes a maintenance record defensible?
A defensible record is one a stranger can read, two years later, without asking you a single question.
That test is stricter than it sounds. It rules out shorthand only the writing technician understands, "serviced" as a description of work, a checklist ticked in bulk at the end of a week covering eleven buildings, and any entry where the identity of the person who did the work cannot be established.
Here is what separates the two.
| Element | What a defensible record contains | What a weak record is missing |
|---|---|---|
| Which asset | A unique asset identifier tied to that specific unit, not the building. Machine number, controller, capacity, install date, location within the site | Building name only. Two or three units on one site share one history and no one can tell which car was worked on |
| Who attended | Named technician, with their qualification or licence status where the local rule requires one, plus anyone who assisted | A team name, an initial, or a signature nobody can attribute |
| When | Date and time of arrival and completion, captured at the site rather than typed in later | A month. Or a date entered at the office from a paper slip of uncertain age |
| What was checked | The full task list actually applied on that visit, each item marked pass, fail or not applicable | A single line saying routine maintenance carried out |
| What was found | Findings in plain language, including the ones with no action, plus photographs where a condition is visual | Only the items that were fixed. Anything observed and deferred vanishes |
| What was done | Work performed, parts replaced with quantities, anything left open, and the recommendation given to the owner | No distinction between what was repaired, what was advised and what was refused |
| Signature | Technician sign-off and a site acknowledgement, captured at the point of work | An unsigned entry, or one signature covering a batch of visits |
| Integrity after the fact | Entries locked once submitted. Later changes appear as a dated correction with an author, never as a silent overwrite | A spreadsheet anyone can edit, with no history of who changed what |
That last row does more work than any other. A record that can be quietly rewritten proves nothing, because the version you hold cannot be shown to be the version that existed at the time. An editable file is a claim. A locked entry with a visible correction trail is a record. A fix belongs on top of the original entry, dated and attributed, not in place of it.
One point sits alongside it. If a component was flagged and replacement was declined, the note showing you raised it is the thing that matters later.
How should a planned maintenance schedule map to what the rule requires?
There is no single answer to how often an elevator must be serviced or inspected. Requirements are set nationally, and in India they vary between states. Some regimes fix a frequency for statutory inspection and leave maintenance to the contract. Some do the opposite. Some place the duty on the building owner, some on the maintenance provider, some on both. Contract terms then sit on top, often tighter than the legal minimum.
So the rule for the software is simple to state. Your local rule sets the interval, and the record has to match it. This is general guidance, not legal advice.
What that means in practice comes down to four things.
Hold the interval on the asset, not in a policy document. Two units in one building can sit under different obligations if one was installed later or serves a different occupancy. Make the frequency a global setting and the exceptions get managed by hand, then missed.
Separate the statutory clock from the service clock. A planned maintenance visit and a statutory inspection are different events with different actors and different consequences. A system that treats an inspection as just another job type will let a service visit appear to satisfy a requirement it does not. Keep two schedules against one asset, each with its own due date and record. Certificates, outcomes and expiry dates belong with the asset, which is what inspection management is for.
Record the visit that did not happen. A missed or postponed visit with a reason is a stronger position than a gap. Gaps invite the worst interpretation available.
Make the reminder produce a record, not a nudge. A due date that pops up, gets dismissed and leaves nothing behind was decoration. Scheduling exists to generate an auditable trail of what was due, what was done and what was not.
One thing this is not: prediction. Software of this kind does not forecast the next failure and should not be sold as if it does. It holds what was due, what happened, and what remains open. That is a different and more defensible claim.
👉 Wondering whether your due dates would survive an audit?
See how planned maintenance and AMC reminders build the record as they run →
What should a breakdown or callback record contain?
Planned maintenance gets most of the attention. Breakdowns get most of the scrutiny.
A callback record needs everything a maintenance entry needs, and three things more. The time the call was received, separately from the time the technician arrived, because response time is often a contractual obligation. Whether anyone was trapped, and how the release was carried out. And the cause, stated as a cause rather than a symptom. "Door fault" is a symptom. "Door detector edge misaligned after the sill was cleaned" is a cause, and that is what makes the next entry on the unit intelligible.
Link the callback to the asset, not just to the job. Read down a single unit's history and you want maintenance visits and breakdowns interleaved on one timeline. Held separately, they hide the exact thing an inspector or an owner is looking for, which is whether a recurring fault was addressed or repeatedly patched. Breakdown management and the underlying asset register only earn their keep when they share the same asset identity.
What happens to the record at handover or when a contract ends?
Elevator maintenance changes hands constantly. Installation passes to the service team. An AMC is renewed under a different manager, lost to another company, or renegotiated when the building sells. The unit does not move. The history should not either.
At handover from installation to service, what transfers is not just the commissioning certificate. It is the asset identity, the component list, anything modified during installation, the initial inspection outcome, the warranty position and every open item. If service inherits a spreadsheet with a serial number on it, the first year of maintenance history has nothing underneath it.
At contract loss, two separate obligations appear. The building owner is normally entitled to the service history of their own equipment, and failing to produce it on request is a poor look in a dispute already going badly. You also keep your own copy, because later questions concern the period when you held the contract.
This is the failure mode we see most often. Not a company that recorded nothing, but one that recorded plenty in a form tied to individuals rather than assets, and then lost people. The engineer who ran that site for six years left. The photos were on his phone. The schedule was in his head. The customer's account of what was serviced is now the only account that exists.
A record held against the asset, in one system, with structured document handling and a controlled view of who can see and change what, survives all of that. A record held against a person does not.
How long should maintenance records be kept?
Retention periods for equipment and safety records are set by local law, and sometimes by the contract rather than by statute. There is no universal number, and anyone offering you one without naming the instrument it comes from is guessing.
The practical guidance is easier than the legal question. Keep the full record for as long as you have any exposure connected to that unit, which is usually longer than the contract. Keep it retrievable by asset, by date range and by technician, because that is how a request for records is actually phrased. Keep it readable without your software. And keep the integrity trail with it, since a retained record is only worth what its provenance is worth.
The failure here is quiet. Companies rarely destroy records deliberately. They change systems, migrate what looks important, leave the rest on an old server, and find the gap three years later when someone asks.
Frequently asked questions
1. Is a maintenance schedule the same thing as a compliance record?
No. A schedule states what you intend to do. A compliance record shows what was done, by whom, on which asset and when. Only the second one answers a question from an inspector, an insurer, an owner or a court. Most companies manage the first well and the second poorly.
2. Is a WhatsApp group an acceptable maintenance record?
It is not a record in any usable sense. Messages cannot be retrieved by asset, cannot be relied on for the time work was actually performed, can be deleted by participants, and disappear when a person leaves. It may work as coordination. It fails completely as evidence.
3. How often does an elevator legally have to be maintained or inspected?
That depends entirely on where the unit is. Requirements vary widely between countries, and in India they vary between states, with some regimes also placing the duty on the building owner rather than the maintenance provider. Your local rule sets the interval, and your record has to match it. Check the instrument that applies to your jurisdiction.
4. What are the minimum fields a maintenance entry should contain?
Asset identifier, named technician, date and time, the checks performed with their outcomes, findings including any with no action taken, work done with parts used, anything left open, and a signature captured at the point of work. Anything less and the entry cannot stand on its own.
5. Does an electronic signature make a maintenance record valid?
Capturing sign-off digitally at the point of work is stronger operationally than collecting paper slips later, because the signature is attached to the entry, the time and the person. Whether an electronic signature satisfies a particular legal requirement is a matter for the law of your jurisdiction and for your advisers, and it is not a claim any software should make on your behalf.
6. Can a maintenance record be edited after it is submitted?
It should not be silently editable. Corrections belong on top of the original entry, dated and attributed, so both versions remain visible. A record that can be rewritten without a trace cannot be shown to be the record that existed at the time, which is exactly what someone will want established.
7. Who owns the maintenance history when a contract ends?
The building owner normally has a legitimate claim to the service history of their own equipment, and you should be able to produce it. You also need to retain your own copy, because later questions concern the period you were responsible for. Treat these as two separate obligations, not one.
8. Does maintenance tracking software predict failures?
No. ElevatorPlus does not do predictive maintenance, AI forecasting, remote diagnostics or IoT sensing. It records what was due, what was done, what was found and what is still open, and it makes that retrievable by asset. That is the part that has to hold up when someone asks.
📲 Join our WhatsApp channel for compliance tips, updates: ElevatorPlus - Business Automation Tool
Every elevator company already has a maintenance record. The question is only whether it is one you would be comfortable handing over unedited.
The uncomfortable version is scattered. Some in a spreadsheet, some on paper in a van, some in photographs on personal phones, some in the recollection of a technician who knows that equipment better than any document does. It works, right up until the moment it has to be produced.
The defensible version is boring by comparison. One asset register. One history per unit, with maintenance and breakdowns on the same timeline. Entries captured on site, signed at the point of work, locked afterwards, corrected in the open when correction is needed. Due dates that generate a record whether or not the visit happens. Documents attached to the asset instead of to an inbox.
None of that makes the engineering better. It makes the account of the engineering survivable, which is a separate thing and, on the day it matters, the only thing anyone can examine.
The work you did is not the same as the work you can show. Closing that gap is most of what compliance actually asks of a service business.
👉 See what a defensible maintenance record looks like across a whole portfolio. Book a demo →
Related reading
- Planned maintenance and AMC reminders that leave an auditable trail
- Inspection management: certificates, outcomes and expiry dates held against the asset
- Digital signatures captured at the point of work
- Asset management: one identity per unit, one history per unit
- Work order management for service teams
About the author. Sumeet Katariya is the founder of ElevatorPlus, the Elevator Business Operating System used by 200+ elevator companies across 20+ countries.
👉 Follow ElevatorPlus on,
Instagram LinkedIn Facebook YouTube Qoura Substack Twitter