FROM APPLICATION TO ONGOING REVIEW
The certification process, clearly explained.
Management system certification is a sequence of application review, assessment and decision activities. The organization remains responsible for its management system. The certification body evaluates evidence against the applicable requirements and decides whether certification can be granted within the proposed scope.
The overview below describes a typical management system certification journey. Your agreed programme and applicable scheme determine the exact arrangements.
START WITH
Your scope
PLAN FOR
Evidence & review
YOUR CERTIFICATION JOURNEY
From a clear scope to continuing review.
01
Describe your organization and intended scope
Identify the standard, the activities you want included and the locations at which they are carried out. Explain the number of personnel, shifts, outsourced activities and any existing certification. Clear scope information helps avoid a quotation based on assumptions that later need to change.
02
Application review and proposed arrangements
An application review establishes whether the requested work can be undertaken and what information is needed to plan it. Availability, competence, sector scope, sites and audit arrangements must be considered. A target date should be discussed as a planning requirement, not treated as a promise of certification.
Review the proposal and applicable terms carefully. Distinguish initial assessment from later surveillance, recertification, travel and any follow-up work.
03
Plan the assessment
Agree the people, records, sites and activities that need to be available. Tell the certification body about significant changes before the audit. Access to outsourced services, temporary sites or protected information may require arrangements that cannot be improvised on the day.
04
Stage 1
Stage 1 helps establish understanding of the management system and readiness for the next assessment stage. Its results may identify matters to resolve before Stage 2. It should not be interpreted as a certificate or a promise that the organization will pass the later assessment.
05
Stage 2
Stage 2 examines implementation and effectiveness within the agreed scope. Auditors gather evidence through suitable activities such as interviews, observation and review of records. An organized document collection is useful, but it must correspond to how the organization actually works.
The distinction between the two stages is described in the ISO 9001 Auditing Practices Group guidance. That guidance is educational; it does not replace the applicable requirements.
06
Address findings
Review each finding, establish what needs correction and determine how to address its cause. The evidence needed and the timing for review depend on the nature of the finding and the programme. A quick document edit may not be enough where the issue concerns implementation.
07
Certification decision and certificate information
The audit outcome feeds into the certification decision. Where certification is granted, check the organization name, standard and edition, certified activities, locations and dates. Use the certificate only for the scope and status it represents.
08
Maintain the system
Certification is followed by the ongoing activities required by the programme, including surveillance and recertification where applicable. Changes in activities, sites or the organization may affect the scope or assessment arrangements. Keep the certification body informed and confirm any implications before making public claims.
FREQUENTLY ASKED QUESTIONS
Questions about the certification process
What is the difference between Stage 1 and Stage 2?
Does an audit guarantee a certificate?
What happens when an audit identifies a nonconformity?
Can the whole assessment take place remotely?
What happens after a certificate is issued?
START WITH YOUR ORGANIZATION