The ISO Certification Process Explained Step by Step
What Is ISO Certification?
ISO certification is a formal declaration by an independent certification body (CB) that an organization's management system conforms to the requirements of a specific ISO standard. The certification body audits the organization, evaluates evidence of conformity, and - if satisfied - issues a certificate valid for three years.
It is important to understand that ISO itself does not certify organizations. ISO develops and publishes standards. Certification is performed entirely by external certification bodies operating independently of ISO.
The Certification Journey: 10 Steps
Step 1: Choose Your Standard
Identify which ISO standard applies to your organization's goals. ISO 9001 covers quality management. ISO 14001 covers environmental management. ISO 45001 covers occupational health and safety. ISO 27001 covers information security. Some organizations pursue multiple certifications simultaneously through an integrated management system.
Step 2: Gap Analysis
Compare your current processes, documentation, and controls against the standard's requirements. A gap analysis reveals what you already have in place and what needs to be developed. Many organizations conduct this internally; others engage a consultant for an independent assessment.
Step 3: Design and Document Your Management System
Develop the policies, procedures, and records required by the standard. This includes defining your scope, establishing objectives, documenting processes, and creating the records that demonstrate conformity. The documentation should reflect what you actually do - not an idealized version of your operations.
Step 4: Implement the System
Put the documented system into practice. Train staff on new procedures. Begin collecting records. Ensure that processes are followed consistently. Implementation typically takes 3 to 12 months depending on the organization's size, complexity, and starting maturity.
Step 5: Internal Audit
Conduct a full internal audit of your management system against the standard's requirements. Internal auditors should be trained (ISO 19011 provides guidance) and should be independent of the areas they audit. The internal audit identifies nonconformities and opportunities for improvement before the external auditor arrives.
Step 6: Management Review
Top management must formally review the management system's performance, including internal audit results, customer feedback, process performance data, and the status of corrective actions. This demonstrates leadership commitment - a core requirement of all modern ISO management system standards.
Step 7: Select a Certification Body
Choose an independent certification body to conduct your certification audit. Factors to consider include the CB's experience in your industry sector, their auditor competence, pricing, and whether they hold accreditation. ISO.org notes that accreditation is not compulsory and that non-accreditation does not necessarily mean the certification body is not reputable.
Step 8: Stage 1 Audit (Documentation Review)
The certification body conducts a Stage 1 audit - primarily a review of your management system documentation and readiness for the full audit. The auditor verifies that your documentation addresses all clauses of the standard, that your scope is clearly defined, and that you have completed at least one internal audit cycle and management review. Stage 1 identifies any areas that need attention before Stage 2.
Step 9: Stage 2 Audit (Certification Audit)
The Stage 2 audit evaluates the implementation and effectiveness of your management system. Auditors interview staff, observe processes, review records, and gather objective evidence that your system is operating as documented and achieving its intended outcomes. Nonconformities (major or minor) may be raised. Major nonconformities must be resolved before certification can be granted.
Step 10: Certification Decision
Based on the audit findings, the certification body makes a certification decision. If the system conforms to the standard's requirements and any nonconformities have been addressed, a certificate is issued. The certificate is valid for three years, subject to ongoing surveillance.
After Certification: The Ongoing Cycle
Surveillance Audits
Certification bodies conduct surveillance audits - typically annually - to verify that the management system continues to operate effectively. Surveillance audits are shorter than the initial certification audit and focus on specific areas of the system on a rotating basis.
Recertification
Before the three-year certificate expires, a full recertification audit is conducted. This is similar in scope to the initial Stage 2 audit and evaluates the system's overall effectiveness over the certification cycle.
Common Misconceptions
"ISO certification means perfection." It does not. Certification means your system meets the standard's requirements and you have processes for continual improvement. Nonconformities can exist - what matters is that you identify and correct them.
"The auditor will tell you how to fix problems." Certification auditors identify nonconformities but cannot provide consulting advice. Their role is to assess conformity, not to design your system.
"Certification is permanent." It is not. Certificates expire after three years and can be suspended or withdrawn if surveillance audits reveal significant nonconformities.
Timeline and Cost Factors
The total time from decision to certification typically ranges from 6 to 18 months, depending on organizational size, complexity, and starting maturity. Costs include internal implementation effort, potential consultant fees, and certification body fees for the audits themselves. Certification body fees vary significantly based on organization size (measured in employee count), number of sites, and the complexity of operations.
0 Comments
Sign in or create an account to join the discussion.
No comments yet. Be the first to share your thoughts.