Simple | Smart | Certification Services
Get a quote
An audit tests what you said you do against what you actually do

Most people picture an ISO audit as someone arriving with a clipboard to hunt for mistakes. What actually happens is more useful than that, and knowing the shape of the day in advance takes most of the worry out of it.

Before the audit

We audit in one visit rather than splitting it into two stages. Before that visit we will review your documentation if you want us to, at no charge, so anything obviously missing is found while there is still time to do something about it rather than on the day.

The audit itself can be carried out on site, remotely, or as a mix of the two, depending on what suits the organisation and the standards involved. How quickly the whole thing can happen is covered in how long does ISO certification take.

What the audit is trying to establish

Three things, and it is worth knowing all three because the second one surprises people.

The first is whether your management system conforms to the requirements of the standard. The second is whether the system is effective and suitable, and whether you are following your own documented procedures. The third is whether the operations covered by the scope are meeting the statutory and regulatory requirements that apply to them.

That middle objective is the one that catches organisations out. You are measured against your own documents as well as against the standard. A procedure describing an approval step nobody takes is a finding, even though the standard never asked you to have that step in the first place. It is also the easiest kind of finding to avoid, by writing down what you actually do.

How the day runs

It opens with a meeting to confirm the scope, the standards being audited and who is available. If this is a surveillance audit, the findings from last time are reviewed first and closed out where the evidence supports it.

From there the audit works through the system. The general requirements first, meaning your management system documentation, how documented information is controlled and backed up, the documented scope, your context and interested parties, and your legal and contractual obligations. Then leadership and planning, covering policies, roles and responsibilities, objectives, risks and opportunities, and management review. Then resources and support, which is training, competence, awareness, equipment, premises and communication. Then your operational processes, from enquiries and sales through purchasing and outsourced services to the control of operations and how changes are managed. Then monitoring and improvement, which takes in customer satisfaction, control of nonconforming outputs, corrective action, your internal audits and continual improvement.

Where you hold ISO 14001, ISO 45001 or ISO 27001, there are further sections covering what those standards ask for beyond the common requirements.

Auditing is sampling, and we say so

An audit is based on evidence viewed on the day, drawn as a sample from what is available. There is always an element of uncertainty in that, and we state it plainly in every report rather than implying we have seen everything.

It cuts both ways. A clean report is not a guarantee that every record in the building is perfect. It is evidence that the system worked everywhere it was tested, which is what certification has ever meant.

What the findings mean

Findings are classified, and the labels matter because they carry different consequences.

A major non-conformance is evidence of something significant, such as a legal compliance issue or a complete failure of the system to meet a requirement of the standard. It has to be addressed and closed before a certificate can be issued, and where certification already exists it may be suspended or withdrawn until it is resolved.

A minor non-conformance is a finding that has to be addressed and closed out, but does not stop a certificate. Worth knowing: more than five minor non-conformances in the same report amounts to a major one.

An observation is something that may need attention and could become a non-conformance later, where there was not enough evidence to say so with certainty on the day. There is no limit on how many can be raised, they do not usually need an immediate response, and they are reviewed at the next surveillance audit.

An opportunity for improvement is advice. It needs no response and nothing is held against you for leaving it, and it may fall outside the audit scope entirely.

A commendation records something managed exceptionally well. We use it because an audit report that only lists problems is a poor description of most organisations.

Where a response is required, the time to respond is agreed case by case, according to what the finding actually needs.

The findings we raise most often, and how to avoid them, are set out in common reasons companies fail their ISO audit.

The report

You receive a full report setting out the evidence viewed and any findings, section by section, along with the auditor's recommendation. It also carries feedback and guidance where the auditor has something useful to offer, including suggestions for simplifying documentation. If there is a more straightforward way to run something, we would rather say so than leave it unsaid.

After the audit

Ongoing certification depends on an annual surveillance audit, scheduled around the anniversary of your initial certification.

You can hold a one year certificate and decide each year whether to carry on, or agree a multiple year term, which brings a lower renewal rate. At the end of a three year term it is your choice whether to continue with surveillance at the discounted rate or return to a one year certificate. Current prices and terms are set out in full on the certification costs page.