The ISO certification audit process generally follows several sequential stages, each with a distinct purpose and output. Understanding the flow helps your internal team prepare documentation and implementation evidence earlier, making the certification process smoother.
1. Application and initial review
The organization submits a certification application to the certification body, including scope, number of sites, and the target standard. The certification body reviews the completeness of the management system documentation before scheduling an audit.
2. Stage 1 audit (readiness)
Auditors assess the readiness of the management system documentation and the organization’s understanding of the standard’s requirements. Findings at this stage are usually areas to address before the Stage 2 audit is scheduled.
3. Stage 2 audit (implementation)
Auditors verify that the management system is genuinely implemented and consistently followed on the ground, not just on paper — including staff interviews, record reviews, and observation of work processes.
4. Certification decision
The Stage 2 audit results are reviewed by an independent technical committee at the certification body to decide whether the certificate can be issued, including following up on any nonconformities.
5. Annual surveillance
Once the certificate is issued, surveillance audits are conducted periodically (typically annually) to confirm the management system continues to operate to the standard.
6. Recertification
Near the end of the certificate’s validity (typically three years), a recertification audit is conducted to renew the certificate for the next cycle.
For a full visual walkthrough of these stages, see our Certification Process page.