How to prepare for an ISO certification audit
Whether it is ISO 9001, 14001 or 45001, certification audits follow the same shape and look for the same thing: objective evidence that your management system is real and effective. Here is how the process works and exactly what to have ready.
How the audit works
Initial certification is normally two stages. Stage 1 is a readiness review of your documentation and whether you are ready for assessment. Stage 2 is the main on-site audit that checks the system is implemented and working against the standard. Once certified, surveillance audits follow at regular intervals (often yearly), with a fuller recertification on a multi-year cycle. Use a certification body accredited (in the UK, by UKAS) for your standard and scope.
The evidence auditors want to see
The specifics vary by standard, but the core evidence pack is consistent:
- ✓Scope, context and interested parties, and the management-system policy and objectives
- ✓Controlled documents and the current versions in use, with version history
- ✓Risk assessments / environmental aspects / hazard identification, as relevant to the standard
- ✓Your legal and other requirements register, and evidence you evaluate compliance
- ✓Competence and training records for the people the system relies on
- ✓Internal audit programme, reports and the resulting findings
- ✓Non-conformances and corrective actions, with root cause and evidence of closure
- ✓Management review inputs, minutes and decisions
- ✓Records that the system has actually run — not just that it was written
How to prepare without a last-minute scramble
The organisations that sail through are the ones whose evidence is already current — because the system is lived, not revived for audit week. Run your internal audits on schedule, close out non-conformances, keep documents and competence records up to date, and hold it all where you can produce the evidence pack on demand — which is what an ISO compliance system does.
Be audit-ready every day, not just audit week
Complys keeps the documents, audits, actions, competence and review records an assessor asks for — current and ready to show.
ISO compliance software →FAQs
What are Stage 1 and Stage 2?
Certification is normally a two-stage initial audit. Stage 1 is a readiness review — the certification body checks your documentation and whether you are ready for full assessment. Stage 2 is the main audit, on site, checking the system is implemented and effective against the standard. After certification, surveillance audits follow (typically annually) with recertification on a multi-year cycle.
What is the single most common reason to struggle?
Evidence that the system is written but not lived — procedures no one follows, internal audits not done, corrective actions left open. Auditors look for objective evidence that the system runs day to day, so the fix is to keep the records current, not to assemble a binder the week before.
How do we choose a certification body?
Use a body accredited by a recognised accreditation body (in the UK, UKAS) for the standard and scope you need. Accredited certification is what most customers and tenders expect; an unaccredited certificate carries far less weight.
Related: ISO internal audit checklist, corrective actions & non-conformances, and ISO 45001 requirements.