ISO Certification Audit Stages: A Step-by-Step Overview
The audit is the part of the ISO certification process that makes most people nervous. It shouldn’t, but the nerves are understandable when nobody has explained what actually happens during each visit.
The process is structured, not unpredictable. Knowing what auditors look for at each stage and what they do when they find something wrong removes most of the anxiety before the first auditor walks through the door.
Stage 1: The Document Review
The Stage 1 audit is sometimes called a readiness review, and that’s a fair description. The auditor isn’t assessing whether your management system is working yet, they’re checking whether you’re ready for Stage 2.
What Stage 1 involves:
- The auditor reviews your key documents,your policy statement, procedures, risk register, objectives, and management review records
- They check that the documented scope of your management system is clear and appropriate
- They confirm you’ve completed an internal audit and that the results have been reviewed
- They identify any significant gaps that would prevent Stage 2 from going ahead
Stage 1 is usually shorter than Stage 2, for a small business, it might be half a day on-site or a remote review of submitted documents. The output is a report noting what’s in place, what needs attention before Stage 2, and confirmation of whether Stage 2 can be scheduled.
What causes Stage 1 to be delayed:
- Key documents missing entirely (no quality policy, no internal audit records)
- The scope of the management system not clearly defined
- No evidence that management has reviewed the system
- Significant misalignment between the documented procedures and what the business actually does
None of these are failures, they’re findings that need to be addressed. A Stage 1 finding is considerably less painful than a major nonconformance at Stage 2.
Stage 2: The Implementation Audit
This is the main event. Stage 2 is where the auditor verifies that your management system isn’t just documented, it’s actually being used.
What happens during Stage 2:
- The auditor interviews staff at various levels, from senior management to operational teams
- They observe processes in action where relevant, how a complaint is handled, how a supplier is approved, how a safety incident is recorded
- They review records as evidence, completed forms, training logs, corrective action records, supplier evaluations
- They check that what your procedures say should happen is what actually happens
The interviews are the part that catches people out. An auditor won’t just ask “do you follow this procedure?”, they’ll ask specific questions: “can you walk me through the last time you dealt with a customer complaint?” or “what would you do if a supplier failed to deliver on quality?” If the answer matches the procedure and the records back it up, that’s good. If the team member describes a completely different process from what’s documented, that’s a finding.
What makes Stage 2 go smoothly:
- Staff who’ve been trained and know what the management system involves
- Records that are current, complete, and accessible on the day
- A management system that reflects real processes, not theoretical ones
- Clear ownership, people who know which procedures are theirs and why
AceQu’s ISO certification services include internal audit preparation specifically designed to simulate what Stage 2 looks like, so the team isn’t encountering the questions for the first time when the external auditor asks them.
What Is a Nonconformance and What Happens Next?
A nonconformance (sometimes written NC) is a finding where something required by the standard hasn’t been met.
They come in two categories:
Major Nonconformance
A major NC means a requirement of the standard hasn’t been implemented at all, or has failed so significantly that the management system can’t be relied upon in that area. Examples: no internal audits have been conducted; a key process has no documented procedure and no evidence of control; a critical safety risk has been identified but no action taken.
A major NC prevents certification from being issued until it’s been addressed and verified by the auditor.
Minor Nonconformance
A minor NC means a requirement is partially met but has a gap or weakness. Examples: a procedure exists but records show it hasn’t been followed consistently; an objective is set but progress hasn’t been measured.
A minor NC doesn’t prevent certification, but it does require a corrective action plan. The business documents what it’s going to do, and the certification body typically reviews evidence of correction at the first surveillance audit.
Most Stage 2 audits for businesses that have prepared properly result in a handful of minor NCs at most. A well-prepared business finding zero NCs is not unusual.
Surveillance Audits: What Comes After Certification
Certification isn’t a one-time event. Once the certificate is issued, it’s valid for three years, but with annual surveillance audits to confirm the management system is still working.
What surveillance audits involve:
- A shorter on-site visit (typically one day or less for a small business)
- Review of records generated since the last audit
- Verification that previous nonconformances have been addressed
- Checking that objectives are being measured and reviewed
- Confirming that any changes to the business (new processes, new sites, new risks) have been reflected in the management system
Surveillance audits aren’t designed to catch businesses out, they’re designed to confirm that the system is alive and being maintained, not sitting in a folder gathering dust since the certificate was issued.
At the end of the three-year cycle, a full recertification audit is conducted, which is essentially a repeat of Stage 2. For more on how ISO systems are maintained after certification, the AceQu guide covers the practical day-to-day side in detail.
How to Get Ready Before the Auditor Arrives
The single most effective preparation is running a structured internal audit before Stage 2 , going through your own management system the way an external auditor would, identifying gaps, and fixing them before anyone external sees them.
Beyond that:
- Brief your team on what auditors will ask, and practise the answers against your actual procedures
- Make sure all records from the past six to twelve months are organised and accessible
- Confirm that any previous internal audit findings have been formally closed out
AceQu works with businesses through internal audit support as part of the full ISO certification services package, including identifying what’s likely to come up at Stage 2 and making sure it’s not a surprise.
Pingback: ISO Certification Services: What's Actually Included in a Package