ISO Certification Services: What's Actually Included in a Package
You've received a quote for ISO certification services. The figure is somewhere between "more than you expected" and "fine, if this is what it takes." The proposal mentions a gap analysis, documentation support, something about an internal audit, and certification audit liaison. What does any of that actually mean, and what happens if one of those stages gets cut from the scope?
Most of the confusion around ISO certification services comes from inconsistent packaging. Two providers quoting for the same standard can include very different things under the same label — and the gaps usually only become obvious when you're three months in and discover the certification body's fees weren't included, or that "documentation support" meant templates rather than actual written procedures.
This guide breaks down what a well-structured ISO certification services package covers at each stage, what's commonly left out, and how scope changes depending on the standard and the size of the business.
The Four Core Stages of ISO Certification Services
A properly structured package covers the full preparation journey — from where you are now to the point where an independent certification body comes in to run the formal audit. That journey has four distinct stages, and all four need to be in scope for the process to work.
Stage 1: Gap Analysis
This is the starting point. A gap analysis compares your current processes, documentation, and management practices against the specific requirements of the standard you're pursuing. The output tells you what's already in place (usually more than you expect), what needs to be created, and what needs to change.
A proper gap analysis isn't a generic checklist. It should be specific to your business — your processes, your sector, your current documentation baseline. The more detailed the gap analysis, the more accurate the implementation plan and the timeline that follows.
If a provider doesn't include a formal gap analysis in their package, or skips it in favour of going straight to documentation, that's worth questioning. You can't build an accurate implementation plan without knowing where you're starting from.
Stage 2: Documentation and Management System Build
This is the largest part of the work, and the one where scope varies most between providers.
Every ISO standard requires a set of documented information — a policy statement, written procedures for key processes, a risk register, records of objectives and management review. According to ISO's own guidance on ISO 9001, the standard doesn't prescribe a specific number of documents, but it does require documented evidence sufficient to demonstrate that your system is planned, implemented, and controlled.
What "documentation support" actually means in practice ranges considerably:
- Templates only — the provider gives you a folder of blank documents and expects your team to fill them in
- Guided drafting — the provider works through the documents with you, reviewing drafts and flagging gaps
- Full co-authoring — the provider writes the procedures with input from your team, refines them, and ensures they're audit-ready before anything is submitted
The difference matters. A template handed to a business with no prior management system experience will produce a document that looks right and fails the audit, because the content won't reflect how the business actually works. Auditors interview staff. If the procedure doesn't match what people do, that's a finding.
Stage 3: Internal Audit
Before the external certification body arrives, a practice audit should be run against your own management system. This is the internal audit, and it serves one function: finding problems before the formal auditor does.
A good internal audit isn't a box-tick. It tests whether the documented procedures are actually being followed, whether records are current and complete, and whether any nonconformances from earlier stages have been properly closed out. The findings feed directly into the corrective actions your team takes in the weeks before the external audit.
Some packages exclude the internal audit or treat it as an add-on. This is a false economy. The cost of finding a major nonconformance at Stage 2 of the external audit — in terms of rescheduling, corrective action time, and certification body fees for a follow-up visit — typically exceeds the cost of having done a proper internal audit in the first place.
Stage 4: Certification Audit Liaison
The formal certification audit is conducted by an independent, accredited certification body — not by the consultant or service provider who prepared your business. Your service provider's role at this stage is to support the process: coordinating the audit schedule, preparing your team for what auditors will ask, reviewing audit plans, and helping with corrective action responses if nonconformances are raised.
This is one of the most variable parts of a package. Some providers offer active liaison throughout; others consider their work done once the internal audit is complete and the business submits itself for external assessment. Clarifying this at the proposal stage saves a difficult conversation later.
For more on what the audit stages themselves involve and what auditors are looking for, the guide on ISO certification audit stages covers that in detail.
What's Usually Not Included — and Often Assumed to Be
These are the gaps that consistently catch businesses off guard when reviewing a final invoice.
| Item | Typically Included | Typically Excluded | Notes |
|---|---|---|---|
| Gap analysis | ✓ Usually | Depth varies — confirm whether it's a full written report or a verbal review | |
| Documentation support | ✓ Usually | Check whether this means templates, guided drafting, or full co-authoring | |
| Internal audit | ✓ Usually | Confirm it's a structured audit, not just a document review checklist | |
| Certification audit liaison | ✓ Often | Scope varies — clarify how actively the provider supports during the audit | |
| Certification body fees | ✗ Separate | Always a separate cost — paid directly to the accredited certification body | |
| Staff awareness training | ✗ Often excluded | May be available as an add-on; confirm scope upfront if team training is needed | |
| Post-certification surveillance support | ✗ Separate | Annual surveillance audits require ongoing system maintenance; often a separate retainer | |
| Multi-site or multi-standard scope | ✗ Usually priced separately | Additional sites or standards expand scope significantly — confirm pricing for each |
How Scope Changes by Standard and Business Size
The four stages apply regardless of which ISO standard you're pursuing — but what each stage involves changes considerably depending on the standard and the size of the business.
By Standard
ISO 9001 (quality management) tends to have the broadest application and the most established documentation templates, which can make the documentation stage faster for businesses with some existing process documentation. ISO 14001 (environmental management) requires specific environmental aspects and impacts registers that most businesses won't have at all, making the gap analysis and documentation stage more intensive. ISO 45001 (health and safety) often overlaps with existing legal compliance work — risk assessments, incident records — which can reduce the documentation workload if those are already in place.
Pursuing two or three standards simultaneously is possible and often done to reduce overall cost and disruption. A good provider will integrate the documentation stages where standards overlap rather than treating each one as a completely separate project.
By Business Size
A ten-person business has fewer processes to document, a shorter internal audit, and a shorter Stage 2 external audit. The scope is proportionately smaller and the timeline is typically at the faster end of the range. A 200-person business with multiple departments and operational sites has more complexity at every stage — more processes to document, more staff to interview in the internal audit, and a more involved certification audit.
"The documentation requirements are proportionate to the size and complexity of the organisation." — ISO 9001:2015 (general principle)
⚠️ Flag for sign-off: confirm this paraphrase accurately reflects the standard's proportionality principle before publishing.
For a full picture of what ISO certification services cover at each stage — and how AceQu structures the process for businesses of different sizes — the team can walk you through the scope based on your specific standard and current situation.
Questions to Ask Any Provider Before You Sign
These are the questions that tend to surface the gaps between what's in the proposal and what's actually in scope:
- Does the gap analysis produce a written report, or is it a verbal review? A written report gives you a clear baseline and a reference point if scope disputes arise later
- What does "documentation support" actually mean — templates, guided drafting, or full co-authoring? The answer tells you how much of the writing your team will be doing
- Is the internal audit a structured audit with a written findings report, or an informal walkthrough? Auditors look for documented internal audit records, not just evidence that a conversation happened
- Are certification body fees included or separate? They should always be separate — if a provider claims to include them, ask which accredited body the fee covers
- What support do you provide during the Stage 2 audit itself? Some providers attend; others consider their involvement complete before the external auditor arrives
- What happens after the certificate is issued? Annual surveillance audits are mandatory. Knowing whether post-certification support is available and what it costs matters before you commit to the initial package
Not sure what's actually in scope for your business?
AceQu provides ISO certification services across ISO 9001, 14001, and 45001 — with a clear scope of work confirmed before you commit to anything. Gap analysis through to audit liaison, with no hidden assumptions about what's included.
Frequently Asked Questions
What is typically included in ISO certification services?
A standard ISO certification service package covers four stages: gap analysis (comparing your current processes against the standard), documentation support (helping you build the required policies and procedures), internal audit preparation (a practice run before the formal external audit), and certification audit liaison (coordinating with the independent certification body that issues the certificate). Scope varies by provider and by the standard being pursued.
Does an ISO certification service include the actual certificate?
Usually not directly. Most ISO certification service providers prepare your business for the audit but are separate from the certification body that issues the certificate. The certification body is an independent, accredited organisation that conducts the formal audit and issues the certificate if your business passes. Your service provider helps you get ready for that audit — they don't issue the certificate themselves.
What is not included in a typical ISO certification service?
Certification body fees (the cost of the formal audit and the certificate itself) are almost always separate from the consultant or service provider's fee. Staff training beyond the immediate management system team, post-certification surveillance audit support, and ongoing system maintenance are also commonly excluded from initial packages — though some providers offer these as add-ons.
How long does ISO certification services take from start to finish?
For most small to medium businesses, the full process — from gap analysis through to the certificate being issued — takes three to nine months. The timeline depends on how much of a management system already exists, how quickly the business can produce documentation, and how long the certification body's audit queue is. Businesses with existing documented processes consistently move faster.
How does scope vary by ISO standard?
The four core stages (gap analysis, documentation, internal audit, certification audit) apply across ISO 9001, 14001, and 45001. What changes is the content — the specific processes, risks, and evidence each standard requires. A business pursuing multiple standards simultaneously will have overlapping scope in some areas, which a good provider will consolidate rather than duplicate.