Most companies do not fail their ISO audit. What happens is a report with findings in it, and a certificate that waits until the important ones are closed. These are the findings we raise most often.
How the report actually works
There is no pass mark. We assess your management system against the standard, and everything we find is classified in the report.
A major non-conformance has to be closed before a certificate is issued, and where a company is already certified it can mean suspension or withdrawal. A minor non-conformance is a lapse rather than a breakdown, although more than five minors in one report counts as a major. An observation does not stop a certificate and is picked up again at the next surveillance visit. An opportunity for improvement needs no response at all, and a commendation is exactly what it sounds like. Response times are agreed case by case rather than fixed.
So the real question is not whether you fail. It is how much work sits between the audit and the certificate. What happens during an ISO audit sets out the visit and the report in full.
Objectives that cannot be measured, or never were
This is the finding we raise more than any other, and it comes in two versions.
The first is an objective that is not quantifiable. "Improve customer satisfaction" and "reduce waste" cannot be audited, because there is nothing to audit against. An objective needs a number and a date: what is being measured, what the target is, and by when.
The second is an objective that was written properly in January and never looked at again. Setting the objective is only half the requirement. The other half is measuring it and reviewing whether you got there, which is why objectives come up again under management review.
If you do one thing before your audit, take your objectives, check that each one has a figure and a deadline attached, and write down where each of them actually got to.
The system describes a company that does not exist
Somebody buys or inherits a set of procedures, the procedures describe a sensible way of working, and nobody in the building works that way.
One of the three things we assess is whether you follow your own documented procedures. A procedure you do not follow is worse than no procedure, because you have written your own non-conformity and handed it to us. If the document does not match the practice, the usual fix is to change the document, not the practice.
Internal audit and management review have not happened
Both are required, and both are activities rather than documents. You cannot write an internal audit report for an audit you did not carry out, and management review needs to be documented and relevant.
A system based on the ISO standard rather than your business cannot evidence either of them, and that is the real reason certification takes some organisations months rather than weeks. It is covered in how long ISO certification takes.
Intentions without evidence
Where the standard asks you to retain documented information, the record is the requirement, and "we do that, we just do not write it down" is a finding rather than a defence. The records most often missing are training and competence, equipment calibration, supplier evaluation, and what happened to complaints and incidents after they were logged.
Corrective action that treats the symptom
Something went wrong, somebody fixed it, and nobody asked why it happened. The instance is closed and the cause is untouched.
We notice this at surveillance, because the same thing has happened again in a different department. A corrective action that does not change how the process works is not a corrective action.
Legal and regulatory compliance is not demonstrated
Compliance with statutory and regulatory requirements within your scope is one of the audit objectives, and it is the section that catches people out on ISO 14001 and ISO 45001 in particular.
What we look for is that you know which legislation applies to you, that you have it written down somewhere current, and that you have evaluated your compliance with it rather than assumed it. If you would like a pre-audit review of legal compliance please get in touch - there is no additional charge for this service.
How to avoid most of this
Send us your documentation before the audit. We review it free of charge, and the review exists precisely so that the findings above surface at a point where fixing them costs you a fortnight rather than a certificate.
Findings at a first audit are normal, and a report with nothing in it is rarer than you would think. What matters is whether the system is real and whether you can show us that it runs.
If you want to talk it through, tell us what standards you are going for and roughly where you have got to.