Companies approaching their first ISO management-system certification tend to picture a single event: the audit. In fact certification is a three-year cycle of audits with different purposes, and the certificate is only as good as the organisation's performance across all of them. Knowing the cycle in advance changes how you prepare, and stops the second-year surprise that catches so many first-time certificate holders.
This applies to any management-system standard: ISO 27001, ISO 42001, ISO 9001, ISO 22301, ISO 27701 as an extension, and others. The cycle is defined by ISO/IEC 17021-1, the standard that accredited certification bodies must themselves meet.
Who audits you
An ISO certificate is issued by a certification body, sometimes called a registrar. The body should be accredited for the relevant standard by a national accreditation body: UKAS in the UK, DAkkS in Germany, ANAB in the United States, RvA in the Netherlands, and so on, most of which are members of the International Accreditation Forum. Accreditation is what makes the certificate recognised; an unaccredited certificate is a private opinion.
Certification bodies employ or contract auditors. The auditor who visits you must be competent in the standard and in your sector, and must be independent of you: they cannot have consulted on the system they are auditing. This is why readiness consultants and certification auditors are different people, and often different companies.
Stage 1: readiness
Stage 1 is a review of whether you are ready for the real audit. The auditor reads the documentation: scope, policy, risk methodology and results, statement of applicability, objectives, internal audit and management review records, and the main procedures. They check that the scope makes sense, that the mandatory elements exist, and that the system has been operating long enough to have generated records.
Stage 1 is often done remotely and typically takes a day or two. Its output is a report listing areas of concern that could become nonconformities at Stage 2. It is not a pass or fail in the certification sense, but a Stage 1 that identifies serious gaps will usually lead to Stage 2 being postponed. Treat the Stage 1 report as a free gap assessment from the person who will do Stage 2.
Stage 2: the certification audit
Stage 2 tests whether the system works. The auditor samples across the scope: interviewing control owners, examining records, watching processes run. For ISO 27001 that means walking through risk treatment, access control, change management, incident handling, supplier management, backup and the rest, asking for the evidence behind each. The duration is set by the certification body from tables based on the number of people in scope and the complexity, and can run from two or three days for a small company to weeks for a large one.
Findings are graded:
- Major nonconformity: a requirement is not met at all, or a failure that raises significant doubt about the system's ability to achieve its objectives. A major blocks certification until it is closed and the closure verified, sometimes with a follow-up visit.
- Minor nonconformity: a lapse in a requirement that does not undermine the system. Minors do not block certification, but each needs a corrective action plan accepted by the body, and closure will be checked at the next audit.
- Observation or opportunity for improvement: not a nonconformity; a note that something could become one or could be done better.
With no majors open, the auditor recommends certification, the body's independent reviewer confirms, and the certificate is issued with a three-year validity.
Years one and two: surveillance
A certificate carries a condition: annual surveillance audits, usually at roughly twelve-month intervals, with the first no later than twelve months after the certification decision. Surveillance audits are shorter than Stage 2, commonly a third of the duration, and sample rather than cover everything. Over the two surveillance visits the body aims to have looked at the whole system once more.
Surveillance always checks certain things: the internal audit and management review have happened, the previous findings have been closed, complaints and incidents have been handled, the scope is still accurate, and the certificate and mark are being used correctly. Beyond that, the auditor picks areas, weighted towards changes and towards where issues were found before.
This is where first-time certificate holders stumble. The energy that went into Stage 2 dissipates, the quarterly access review slips to annual, the internal audit is forgotten, and the surveillance auditor finds a system that ran for the certification and then stopped. Minors here are common; a major at surveillance can lead to suspension of the certificate.
Year three: recertification
Before the certificate expires, a recertification audit reviews the whole system again, in the light of the previous cycle. It is shorter than the original Stage 2, because the body already knows the organisation, but it covers the full scope and asks the larger question: has the system been effective over three years, and is it still appropriate. A successful recertification issues a new three-year certificate and the cycle starts again.
Changing scope or body
Scope can be extended during the cycle, with an extension audit sized to the change. It can also be reduced, which bodies will ask questions about. Moving to a different certification body is possible; the new body will review the current certificate and audit reports and may certify on a transfer audit rather than a full Stage 1 and 2, provided the certificate is in good standing.
Keeping a certificate
The organisations that find the cycle easy share three habits. The management system has an owner whose job continues after Stage 2. The periodic controls are on a calendar with artefacts, so surveillance evidence accumulates on its own. And the internal audit is done properly and on time, so the certification auditor's findings are rarely news.
The certificate is the visible output. The cycle is the actual product, and buyers who know the difference will ask for your surveillance reports, not just the certificate on the wall.
