
Certification is not a single audit visit. It is a staged process that normally moves from scope definition and audit planning through readiness checks, audit evidence collection, findings, corrective action, review, certification decision, certificate issue, and ongoing surveillance or recertification.
The exact sequence, terminology, deadlines, and consequences vary by standard, scheme, accreditation rules, and certification body. The practical job for the organisation being audited is to keep scope, ownership, evidence, and corrective actions clear at every stage.
What an audit certification process is
A certification audit is an independent audit against defined criteria. Its scope sets what is covered, such as locations, functions, organisational units, activities, processes, and the relevant period under review, according to ISO audit guidance on audit criteria, evidence, and scope (ISO 19011).
In practical terms, the audit asks: does the organisation meet the applicable certification requirements, and can it show verifiable evidence? Depending on the certification, those requirements may relate to a management system, operational processes, controls, services, products, or other defined criteria.
The audit visit is only one part of the process. Not the whole thing. For many management-system certifications, the audit report, corrective-action review, technical review, certification decision, and certificate issue are separate steps.
The audit certification process at a glance
For management-system certification, ISO’s conformity assessment guidance describes a lifecycle that includes pre-certification activities, audit planning, Stage 1 and Stage 2 initial audits, audit findings and reports, corrective action, certification decision, surveillance, recertification, and special actions such as suspension, withdrawal, or reduction of scope (ISO CASCO, Building trust).
The map below is a common management-system certification lifecycle, not a universal rulebook.
| Step | What happens | Main organisational task |
|---|---|---|
| 1. Application and scope | The organisation defines what it wants certified and provides information for planning. | Confirm locations, business units, services, systems, processes, and boundaries. |
| 2. Quotation and audit planning | The certification body uses application and scope information to plan the audit programme. | Ask what information is needed for planning, quotation, audit days, and logistics. |
| 3. Readiness or optional pre-audit | Some providers offer readiness or pre-assessment activity before the certification audit. | Use it to identify gaps, while confirming its availability, independence safeguards, and effect on the formal audit. |
| 4. Stage 1 audit | The auditor reviews readiness, scope, planning inputs, and relevant documented information. | Make sure required documentation, scope boundaries, and key governance activities are available. |
| 5. Stage 2 audit | The auditor performs the fuller assessment of conformity. | Provide evidence that processes or controls are implemented and operating. |
| 6. Findings and report | Evidence is evaluated against the audit criteria and reported. | Review findings, clarify factual errors, and understand required responses. |
| 7. Corrective action | Nonconformities may require correction, cause analysis, and corrective action evidence. | Assign owners, address root causes, and collect closure evidence. |
| 8. Technical review and certification decision | Many accredited management-system processes separate audit delivery from the certification decision. | Do not assume the audit visit itself grants certification. Track the decision status. |
| 9. Certificate issue | If the decision is positive and requirements are met, the certificate is issued. | Check certificate scope, sites, exclusions, dates, and conditions. |
| 10. Surveillance | Certification is monitored during the certification cycle. | Keep evidence current after the initial certificate is issued. |
| 11. Recertification | The organisation is reassessed before certification is renewed. | Treat readiness as ongoing, not as a last-minute project. |
Exact requirements and timing vary by standard, scheme, accreditation rules, and certification body.
Before the audit: scope, application, planning, and readiness
The most important early decision is scope. Poor scope definition can create mismatched expectations later: the auditor may expect evidence for a site, process, service, or system that the organisation did not prepare, or the certificate may not cover what customers or regulators expect.
A workable scope should answer:
- Which locations or legal entities are included?
- Which products, services, systems, business units, or processes are included?
- Which activities are excluded, and why?
- Which period of operation is relevant?
- Which requirements, controls, or clauses apply to each area?
Certification body selection should stay practical at this stage. Confirm that the body can certify the required standard or scheme, has the right recognition or accreditation where needed, can cover the proposed scope, and can explain what information it needs for its quotation and audit programme. Do not make this more complicated than it needs to be, because the quotation and planning process will not always look the same across schemes.
Some providers offer readiness reviews or pre-assessments before the formal certification audit. These can help identify gaps, but their availability, independence safeguards, and effect on the formal audit vary. They should not be treated as mandatory or as a guarantee of certification.
Internally, preparation should start by assigning owners for each requirement area, collecting current documented information, identifying where operational evidence lives, and resolving obvious gaps before audit dates are fixed.
Stage 1 versus Stage 2 audits
Stage 1 and Stage 2 are often misunderstood because both may involve evidence review, but they usually serve different purposes.
In the ISO 9001 two-stage model, Stage 1 is used to understand the organisation, confirm scope and planning inputs, review readiness and necessary documentation, and identify deficiencies that should be addressed before Stage 2 (ISO 9001 Auditing Practices Group). That model is a useful reference point, but it should not be treated as the exact rule for every certification.
Operationally, Stage 1 asks whether the organisation appears ready for the fuller assessment, the auditor may look at scope, documented information, process maturity, internal audit or review activity where applicable, and whether there are obvious barriers to continuing.
Stage 2 is commonly the fuller assessment of conformity after Stage 1. The exact audit methods and implementation testing depend on the applicable standard, scheme, and certification body, but this is where the organisation should be ready to show that processes or controls are not only documented but operating in practice.
A simple distinction helps:
| Question | Stage 1 | Stage 2 |
|---|---|---|
| Primary concern | Are scope, planning, and readiness sufficient? | Does the organisation conform to the requirements in practice? |
| Typical emphasis | Documentation, scope, context, readiness, audit planning inputs | Implementation evidence, records, interviews, observation, and sampled activity where relevant |
| Main risk | Gaps are found that should be addressed before Stage 2 | Evidence does not support conformity, or practice differs from documented process |
What evidence auditors look for
Auditors do not rely only on verbal assurances. ISO audit guidance describes audit evidence as verifiable information relevant to audit criteria, including records, statements of fact, observations, measurements, or tests. Audit findings result from evaluating that evidence against the criteria (ISO 19011).
The practical goal is to show both design and operation: what the organisation says it does, and evidence that it actually does it.
| Audit stage | What the auditor is trying to confirm | Evidence to prepare | Common delay or failure point | Owner/preparation note |
|---|---|---|---|---|
| Scope and application | The certification boundary is clear and auditable. | Scope statement, organisation chart, site list, service or product descriptions, process map, system inventory where relevant. | Scope excludes something stakeholders expect, or includes areas without evidence. | Assign one scope owner who can resolve boundary questions. |
| Audit planning | The certification body has enough information to plan appropriately. | Application information, contact list, locations, working hours, process owners, remote/on-site access needs. | Missing planning information slows scheduling or creates audit logistics issues. | Confirm what the certification body requires rather than guessing. |
| Readiness or pre-assessment | Obvious gaps are identified before formal audit activity. | Requirement mapping, policy set, procedure list, internal review records where applicable, known gap register. | Readiness review finds issues but no owner is assigned to close them. | Treat readiness outputs as actions, not commentary. |
| Stage 1 | Scope, documentation, context, and readiness are sufficient for Stage 2. | Documented processes, governance records, applicable requirement mapping, internal audit or management review records where relevant to the scheme. | Documentation exists but does not match the actual scope or operating model. | Make sure documents reflect current practice, not an outdated design. |
| Stage 2 | Requirements are implemented and operating. | Operational records, approvals, logs, tickets, change records, training records, risk assessments, incident records, meeting minutes, sampled transactions, interviews, and observations where relevant. | Control owners describe a process differently from the documented procedure, or sampled records are incomplete. | Brief owners on the process and where evidence is stored; do not script answers. |
| Findings and report | Evidence supports conformity or identifies gaps. | Clarifications, additional records requested during audit, factual corrections to draft findings where allowed. | The organisation disputes a finding without providing verifiable evidence. | Respond with records and facts, not opinions. |
| Corrective action | Nonconformities are corrected and recurrence is addressed. | Correction evidence, cause analysis, corrective-action plan, implementation records, effectiveness checks where required. | The response fixes the symptom but does not address cause or show implementation. | Track each action to an owner, due date, evidence item, and closure status. |
| Certification decision | The certification body can complete review and decide. | Final report responses, closure evidence, open-issue status, any requested clarifications. | The audit is finished, but closure evidence or review questions remain unresolved. | Monitor decision status until certificate issue, not just audit completion. |
| Surveillance and recertification | Continued conformity is maintained. | Current records, updated scope, change logs, internal reviews, corrective-action history, evidence from the period since certification. | Evidence is recreated at the last minute or does not cover the surveillance period. | Maintain evidence as work happens, not only before audit week. |
Exact requirements and timing vary by standard, scheme, accreditation rules, and certification body.
Findings, non-conformities, and corrective action
Audit findings show conformity or nonconformity after evidence is evaluated against the audit criteria. A nonconformity means an applicable requirement has not been fulfilled or the organisation cannot show adequate evidence for it (ISO 19011).
Finding categories vary. Some schemes or certification bodies may use terms such as observations, opportunities for improvement, minor nonconformities, or major nonconformities, but the labels, response deadlines, and consequences are not universal. Always confirm the terminology and closure rules for the relevant certification.
A useful corrective-action workflow separates five things:
- Correction: the immediate fix for the specific issue found.
- Cause analysis: why the issue happened.
- Corrective action: what will change to reduce recurrence.
- Implementation evidence: records showing the action was carried out.
- Closure or verification: evidence that the response was accepted or verified where required.
In accredited management-system certification, the process framework includes cause analysis and evaluation of the effectiveness of corrections and corrective actions (ISO CASCO, Building trust). Depending on the scheme and certification body, unresolved issues may require additional review before certification can proceed.
The common operational thing that goes wrong is submitting a plan instead of closure evidence. “We will update the procedure” is not the same as the approved procedure, communication record, training evidence, completed system change, or sampled record showing the new process is in use.
From audit report to certification decision
The audit report is not the certificate. It is part of the evidence package used in the certification process.
A report may include the audit scope, evidence reviewed, findings, nonconformities, auditor conclusions, recommendations, and corrective-action status. Many accredited management-system certification processes separate audit delivery from the certification decision, so the auditor’s recommendation does not automatically grant certification. Confirm the decision process with the relevant certification body or scheme (ISO CASCO, Building trust).
The roles are different:
| Role | Practical responsibility |
|---|---|
| Organisation | Provides evidence, responds to findings, completes corrective actions. |
| Auditor or audit team | Conducts the audit, evaluates evidence, records findings, prepares the report. |
| Technical reviewer or decision function | Reviews whether the certification requirements and process requirements have been met, where applicable. |
| Certification body | Issues, maintains, suspends, withdraws, reduces, or renews certification according to the applicable process. |
This separation matters because an organisation can finish the audit visit and still have open work. More accurately, the visit may be finished while the certification process is still waiting on nonconformity closure, report clarifications, technical review questions, or a pending certification decision.
After certification: surveillance, recertification, and certificate status
Certification creates an ongoing cycle. ISO’s conformity assessment guidance includes surveillance and recertification as part of the management-system certification process, not optional extras after the certificate is issued (ISO CASCO, Building trust).
Surveillance audits check continued conformity during the certification cycle. Recertification reassesses the organisation before the cycle renews. For the management-system programmes covered by IAF MD 5, the initial certification cycle is three years, but this should not be generalised to every certification scheme or used as a universal timing rule (IAF MD 5:2023).
Certificate status can also change. Accredited management-system certification frameworks provide for actions such as suspension, withdrawal, and reduction of scope, but the triggers and restoration process are scheme- and certification-body-specific. Scope expansion may require additional review if the organisation wants the certificate to cover new sites, services, processes, or activities.
The practical lesson is simple: keep the current certificate scope, organisational changes, control evidence, and corrective-action history current between audits.
How to prepare for a smoother certification process
Preparation is less about memorising the audit sequence and more about managing evidence, ownership, and decisions before they become urgent.
Use this operating rhythm:
- Start with scope clarity. Confirm what is included, excluded, and expected by stakeholders.
- Map requirements to owners. Every requirement area should have someone responsible for the process and the evidence.
- Map evidence to audit stages. Separate readiness evidence from implementation evidence and closure evidence.
- Keep records current. Avoid rebuilding months of evidence just before the audit.
- Prepare control owners for interviews. They should understand the process they own, where evidence lives, and how to answer factually.
- Track findings through closure. Each finding needs an owner, response, implementation evidence, and closure status.
- Maintain readiness after certification. Surveillance and recertification are easier to manage when evidence is maintained as part of normal operations.
These practices are intended to make preparation and ownership easier to manage. They do not guarantee audit timing, certification, or a particular certification-body decision.
A certification process runs smoothly when the organisation can answer four questions at any point: what is in scope, who owns each requirement, where is the evidence, and what remains open, more or less.

