Ronnaegel Business Consultancy ENQUIRE
SEND AN ENQUIRY
ISO & QUALITY9 Sep 202614 min read

The ISO Certification Process, Step by Step — And What Auditors Flag

The ten stages from scope to certificate, and the non-conformities that most often derail an SME audit.

Most companies that fail an ISO audit do not fail because the standard is hard. They fail because the sequence was wrong — documentation written before anyone mapped how work is actually done, an internal audit run the week before the certification body arrives, a management review held as a formality with no records to show. The process itself is well defined, and the non-conformities auditors raise are remarkably consistent year after year. Both are worth knowing before you start.

Step 1 — Define the Scope Before Anything Else

Scope is the single decision that shapes every cost and every audit day that follows. It states which sites, which activities and which product or service lines the certificate covers. Companies routinely over-scope in the belief that a broader certificate looks better, then spend the project documenting processes no customer ever asked to see certified. Write the scope statement first, in one or two plain sentences, and have the certification body confirm it is auditable before you commission any documentation work.

Step 2 — Gap Analysis

A structured walk through every clause of the standard against what your business already does. Done properly this is a floor exercise, not a desk exercise: the reviewer follows a job from enquiry to delivery, watches the handovers, and reads the records that already exist. The output is a gap register — clause by clause, what exists, what partly exists, what is missing, and who owns closing it. A gap analysis that produces only a compliance checklist with ticks and crosses has not done the job; you need the ownership and the sequence too.

Step 3 — System Design

Before procedures are written, the architecture is set: the quality policy, measurable quality objectives, the process map showing how your core processes interact, the risk and opportunity register, and the roles carrying authority for each process. This phase needs department heads in the room, not just the project owner, because objectives set without the people accountable for them are the objectives that go unmet at the first audit.

Step 4 — Documentation

The largest phase, and the one most often outsourced badly. Procedures, forms and records should describe how your business actually works, written at the level of detail your staff will genuinely follow. A downloaded template pack renamed with your logo will pass a superficial read and fail the moment an auditor asks an operator to describe the process in their own words. Write less, but write it true — a two-page procedure that matches reality beats a twenty-page one that does not.

Step 5 — Implementation and Evidence Build

This is the step companies try to skip, and the one auditors are quickest to detect. A management system needs to have been running long enough to generate records: completed inspection forms, raised and closed corrective actions, supplier evaluations, training records, calibration certificates. Most certification bodies want to see roughly three months of live operation before Stage 2. Documentation without an evidence trail is the most common reason a Stage 2 audit gets deferred.

Step 6 — Internal Audit

Your own trained staff audit the system against the standard and against your own procedures, covering the full scope before certification. The point is to find your own non-conformities first, raise corrective actions, and demonstrate the system self-corrects. Internal audits that find nothing are a red flag to an external auditor, not a good sign — a clean internal audit report across an entire first-year system usually means the audit was not real.

Step 7 — Management Review

Top management formally reviews the system: audit results, customer feedback and complaints, process performance against objectives, corrective action status, resource needs and changes affecting the business. It must be minuted with decisions and actions, and it must happen before Stage 2. A management review recorded as a fifteen-minute item in an unrelated meeting is one of the easiest non-conformities for an auditor to raise, because the record itself gives it away.

Step 8 — Stage 1 Audit

The certification body's readiness review. The auditor checks that your documented system covers the standard, that scope and site details are correct, that internal audit and management review have taken place, and that you are ready for a full assessment. Findings here are usually described as areas of concern rather than formal non-conformities, and you get time to close them. Treat Stage 1 as free advice from someone who will be back — the gaps flagged here become non-conformities at Stage 2 if left alone.

Step 9 — Stage 2 Audit

The full certification assessment, conducted mostly on the floor. The auditor samples records, interviews staff at every level, follows processes end to end, and tests whether the system described in your documents is the system your people run. Length is set by man-days, which scale with headcount, site count and process complexity. Any non-conformities raised are graded, and the grade decides what happens next.

Major and Minor Non-Conformities

A minor non-conformity is an isolated lapse that does not break the system — one missing signature, one overdue calibration. You submit a corrective action plan, and the certificate normally proceeds. A major non-conformity is the absence or total breakdown of a required part of the system, or a lapse with direct impact on product or service conformity — no internal audit performed at all, no management review, or a repeated failure already raised and not fixed. Majors must be closed and verified, sometimes with a return visit, before the certificate is issued.

Step 10 — Certificate, Surveillance and Recertification

Once non-conformities are closed and verified, the certificate is issued for a three-year cycle. A shorter surveillance audit follows each year to confirm the system is still operating, and a full recertification audit at the three-year mark. The system must keep producing records continuously — the companies that struggle at surveillance are the ones that treated certification as a project with an end date rather than an operating routine.

The Non-Conformities That Come Up Most

Across SME audits the same findings recur, and almost all of them are avoidable with a few weeks' notice:

Internal audit not covering full scope. Some processes audited thoroughly, others never touched across the whole cycle. Management review missing required inputs. Minutes that record attendance but not objectives performance, complaints, audit results or resource decisions. Corrective actions closed without root cause. The symptom fixed, the cause untouched, and the same finding raised again next year. Quality objectives not measurable or not measured. "Improve customer satisfaction" with no metric, no target and no data. Calibration and equipment records lapsed. Measuring equipment in daily use with an expired certificate, or no traceability at all. Document control failures. Uncontrolled or superseded forms in use on the floor while the current version sits in a folder nobody opens. Supplier evaluation not performed. Critical suppliers approved by habit, with no criteria, records or re-evaluation. Training and competence records incomplete. Staff performing work requiring competence, with nothing on file to demonstrate it. Procedures not matching practice. The single most damaging finding — staff describe a workflow entirely different from the documented one.

Why These Happen

Almost every finding on that list traces to one root cause: the system was built as a document set for the auditor rather than as the way the business runs. When procedures are written top-down without the people doing the work, staff quietly keep their own methods and the paper system drifts. When internal audit is treated as a pre-audit formality, it stops finding anything. When corrective action means writing "staff reminded" in a box, the same non-conformity comes back at surveillance — and a repeat finding tends to be graded harder the second time.

How to Avoid Them

Write procedures with the people who do the work, then have them read back the process in their own words before you approve it. Schedule internal audits across the year on a plan that covers the full scope, not in the month before the external audit. Make every quality objective a number with an owner, a target and a place the data actually lives. Run corrective actions with a real root-cause step, and check effectiveness weeks later rather than closing on the day. Keep a single register of controlled documents, calibration due dates, training records and supplier evaluations — one place an auditor can be shown. Hold management review as its own meeting, against the standard's list of required inputs, and minute the decisions.

A Realistic Timeline

For a single-site SME with some documentation in place, a first certification usually runs six to nine months end to end: gap analysis and system design in the first two months, documentation over the following two, then a three-month implementation window generating records, internal audit and management review, and finally Stage 1 and Stage 2 with a few weeks between them. Businesses starting from no documentation, or holding multi-site scope, should plan closer to twelve months. Compressing the implementation window is the compression that always costs you at Stage 2 — there is no way to manufacture three months of records.

Getting It Right the First Time

The difference between a smooth certification and a second attempt is almost never the standard's difficulty. It is whether the system was built into how the business works or bolted on beside it. If you are planning certification, or repairing a system that has already collected findings, a diagnostic conversation is the fastest way to see which of the steps above you are actually ready for.

RELATED PRACTICE ISO & Quality Management →

If this describes a problem you are living with, an enquiry is the fastest way to find out whether it is worth engaging help.

Send an Enquiry

More Insights

All Articles