The ten stages from scope to certificate, and the non-conformities that most often derail an SME audit.
Most companies that fail an ISO audit do not fail because the standard is hard. They fail because the sequence was wrong — documentation written before anyone mapped how work is actually done, an internal audit run the week before the certification body arrives, a management review held as a formality with no records to show. The process itself is well defined, and the non-conformities auditors raise are remarkably consistent year after year. Both are worth knowing before you start.
Scope is the single decision that shapes every cost and every audit day that follows. It states which sites, which activities and which product or service lines the certificate covers. Companies routinely over-scope in the belief that a broader certificate looks better, then spend the project documenting processes no customer ever asked to see certified. Write the scope statement first, in one or two plain sentences, and have the certification body confirm it is auditable before you commission any documentation work.
A structured walk through every clause of the standard against what your business already does. Done properly this is a floor exercise, not a desk exercise: the reviewer follows a job from enquiry to delivery, watches the handovers, and reads the records that already exist. The output is a gap register — clause by clause, what exists, what partly exists, what is missing, and who owns closing it. A gap analysis that produces only a compliance checklist with ticks and crosses has not done the job; you need the ownership and the sequence too.
Before procedures are written, the architecture is set: the quality policy, measurable quality objectives, the process map showing how your core processes interact, the risk and opportunity register, and the roles carrying authority for each process. This phase needs department heads in the room, not just the project owner, because objectives set without the people accountable for them are the objectives that go unmet at the first audit.
The largest phase, and the one most often outsourced badly. Procedures, forms and records should describe how your business actually works, written at the level of detail your staff will genuinely follow. A downloaded template pack renamed with your logo will pass a superficial read and fail the moment an auditor asks an operator to describe the process in their own words. Write less, but write it true — a two-page procedure that matches reality beats a twenty-page one that does not.
This is the step companies try to skip, and the one auditors are quickest to detect. A management system needs to have been running long enough to generate records: completed inspection forms, raised and closed corrective actions, supplier evaluations, training records, calibration certificates. Most certification bodies want to see roughly three months of live operation before Stage 2. Documentation without an evidence trail is the most common reason a Stage 2 audit gets deferred.
Your own trained staff audit the system against the standard and against your own procedures, covering the full scope before certification. The point is to find your own non-conformities first, raise corrective actions, and demonstrate the system self-corrects. Internal audits that find nothing are a red flag to an external auditor, not a good sign — a clean internal audit report across an entire first-year system usually means the audit was not real.
Top management formally reviews the system: audit results, customer feedback and complaints, process performance against objectives, corrective action status, resource needs and changes affecting the business. It must be minuted with decisions and actions, and it must happen before Stage 2. A management review recorded as a fifteen-minute item in an unrelated meeting is one of the easiest non-conformities for an auditor to raise, because the record itself gives it away.
The certification body's readiness review. The auditor checks that your documented system covers the standard, that scope and site details are correct, that internal audit and management review have taken place, and that you are ready for a full assessment. Findings here are usually described as areas of concern rather than formal non-conformities, and you get time to close them. Treat Stage 1 as free advice from someone who will be back — the gaps flagged here become non-conformities at Stage 2 if left alone.
The full certification assessment, conducted mostly on the floor. The auditor samples records, interviews staff at every level, follows processes end to end, and tests whether the system described in your documents is the system your people run. Length is set by man-days, which scale with headcount, site count and process complexity. Any non-conformities raised are graded, and the grade decides what happens next.
A minor non-conformity is an isolated lapse that does not break the system — one missing signature, one overdue calibration. You submit a corrective action plan, and the certificate normally proceeds. A major non-conformity is the absence or total breakdown of a required part of the system, or a lapse with direct impact on product or service conformity — no internal audit performed at all, no management review, or a repeated failure already raised and not fixed. Majors must be closed and verified, sometimes with a return visit, before the certificate is issued.
Once non-conformities are closed and verified, the certificate is issued for a three-year cycle. A shorter surveillance audit follows each year to confirm the system is still operating, and a full recertification audit at the three-year mark. The system must keep producing records continuously — the companies that struggle at surveillance are the ones that treated certification as a project with an end date rather than an operating routine.
Across SME audits the same findings recur, and almost all of them are avoidable with a few weeks' notice:
Almost every finding on that list traces to one root cause: the system was built as a document set for the auditor rather than as the way the business runs. When procedures are written top-down without the people doing the work, staff quietly keep their own methods and the paper system drifts. When internal audit is treated as a pre-audit formality, it stops finding anything. When corrective action means writing "staff reminded" in a box, the same non-conformity comes back at surveillance — and a repeat finding tends to be graded harder the second time.
For a single-site SME with some documentation in place, a first certification usually runs six to nine months end to end: gap analysis and system design in the first two months, documentation over the following two, then a three-month implementation window generating records, internal audit and management review, and finally Stage 1 and Stage 2 with a few weeks between them. Businesses starting from no documentation, or holding multi-site scope, should plan closer to twelve months. Compressing the implementation window is the compression that always costs you at Stage 2 — there is no way to manufacture three months of records.
The difference between a smooth certification and a second attempt is almost never the standard's difficulty. It is whether the system was built into how the business works or bolted on beside it. If you are planning certification, or repairing a system that has already collected findings, a diagnostic conversation is the fastest way to see which of the steps above you are actually ready for.
If this describes a problem you are living with, an enquiry is the fastest way to find out whether it is worth engaging help.
Send an Enquiry