
Introduction
The ISO accreditation process is often searched by organizations preparing for ISO certification, although accreditation and certification have different meanings. Organizations are generally certified to an ISO management system standard, while certification bodies may be accredited to demonstrate their competence to perform certification activities.
A key part of obtaining ISO certification is the certification audit. During this process, an accredited certification body evaluates whether the organization’s management system meets the requirements of the applicable ISO standard and whether those requirements are effectively implemented in practice.
The certification journey typically includes a Stage 1 audit followed by a Stage 2 audit. Stage 1 focuses largely on management system documentation and readiness, while Stage 2 evaluates implementation and effectiveness through records, interviews, observations, and other objective evidence.
Certification does not end after the initial audit. Organizations normally undergo periodic surveillance audits and later a recertification audit to confirm that the management system continues to meet applicable requirements and is maintained over time.
Understanding these stages makes the audit process easier to prepare for and helps organizations know what evidence auditors are likely to review. This guide explains the ISO audit and certification process from Stage 1 and Stage 2 through surveillance and recertification, while also clarifying where accreditation fits into the overall process.
Stage 1: Documentation Review and Readiness Assessment
The ISO stage 1 audit is the first of several audits that will map out the ISO certification process. That's why it is important to carry out sufficient review of your organization's documented documentation to ensure that your processes and systems are in place and conform to the requirements of the ISO standard.
The stage 1 audit is important to ensure the organization is ready for the stage 2 audit, which will assess whether the processes are being implemented in practice. To this end, the auditor will complete a stage 1 audit which will involve the following:
Review of Documentation: The auditor at stage 1 will review the documented policies, procedures, and records relevant to the organization's management system documentation; the organization's risk management processes; other relevant processes.
Evaluate Compliance: The auditor will review whether the organization has fulfilled the obligations for all the key requirements in the ISO standard, e.g., set defined business objectives, identified processes, assigned roles and responsibilities to employees.
Preliminary Assessment: The auditor will use stage 1 audit as an opportunity to observe if there are any possible areas of concern within the organization that need to be addressed before the stage 2 audit. The auditor may share feedback, and/or areas for concern and wherever appropriate ask the organization to action corrective actions to ensure readiness of the next stage 2 audit.
Stage 2: Full Certification Audit (Implementation Review)
The Stage 2 audit is the most important stage of the ISO certification process. At Stage 2, the auditor will assess the actual implementation of the processes and systems you documented during Stage 1. Stage 2 is designed to evaluate whether your organization is appropriately following the processes, meeting the requirements and continuously improving.
The key activities of the Stage 2 audit are:
On-site Audit: The auditor conducts an on-site audit during which they will check your documented procedures against daily activity to see if they are being followed. This could consist of observing the processes in action, interviewing employees or reviewing records to ensure your organization is meeting the standard.
Interviews and Observations: the auditor will interview personnel, related to each of the processes defined in your documentation, to assess each personnel's understanding of the related processes and their role in meeting compliance with the standard.
Any corrective actions: If at any time during the Stage 2 audit the auditor finds any non-conformities, or areas for improvement, the auditor will record these non-conformities and request corrective actions. Your organization must complete corrective actions for any non-conformities before the audit can proceed to finalization of the audit and certification.
Surveillance Audits: Maintaining Your ISO Certification
After getting ISO certification doesn't mean your organization is done with ISO. Your company will undergo surveillance audits periodically (usually annually) to verify your organization is still meeting the ISO standard and maintaining the processes required to show continual improvement.
Surveillance audits are meant to make sure your organization continues to comply with the ISO standard and is continuing improvements where required. Surveillance audits will usually not cover the full details of your initial Stage 2 audit. Surveillance audits focus on the verification of continuing compliance with ISO standards, review of corrective actions, and the effectiveness of the management system being operated by the organization. The auditors will review corrective actions taken from previous audits and verify the corrective actions were successful.
Recertification: Renewing Your ISO Certification
ISO certifications are usually issued for a three-year period requiring recertification thereafter. An ISO recertification audit is a complete audit of the management system and management practices of your organization, similar to a Stage 2 Audit.
Recertification audits are used to review the effectiveness and sustainability of the management system over the three-year period of the previous certifications. Recertification audits check that processes are still being followed, and the management system is still achieving the intended outcomes. The auditor will need to deal with any non-conformity during and audit if the reason provided to deal with the non-conformity does not align with the recorded issues before reissuing a new certification.
Conclusion
An ISO audit process should be carefully structured and rigorous process that can help ensure organizations are compliant with the requirements of international standards. The audit process is useful for everyone when it comes to applying for an ISO certification from Stage 1 to stage 2 where Stage 1 is focused on determining how ready organizations are for certification, stage 2 where you evaluating the implementation of systems, and continues through the recertification process. It is an ongoing process enabling conformity and continuous improvement.
Although the audit process could seem overwhelming, breaking it down into the individual stages, and expecting what comes at each stage can help you and your organization successfully transition through the certification processes and enjoy the many benefits of ISO certification including operational efficiency, customer satisfaction, and market credibility.
Contact Us
Pacific Certifications can assist your organization in understanding and navigating the ISO certification process. Our team of experts is here to guide you through each stage of the audit process and ensure your continued compliance with ISO standards.
For assistance, contact us at support@pacificcert.com.
Visit our website at www.pacificcert.com.
Author: Alina
Also read: Maintaining ISO Certification: Surveillance Audits, NCRs & Continuous Compliance
