Skip to content
itmad
← All articles

Preparing for an ISO Certification Audit: What Auditors Actually Do

How an audit runs hour by hour, how auditors follow an audit trail, and what a major versus minor nonconformity means for your certificate — including what happens if you get one.

Most audit preparation advice is a checklist. Useful, but it misses what actually determines the outcome: how auditors work, and what happens when they find something.

How an auditor actually works

Auditors do not read your manual cover to cover. They follow audit trails — pick a thread and pull it through the organisation to see whether the system holds.

A trail might run: your quality policy commits to on-time delivery → show me the objective → show me how it is measured → show me last quarter’s data → here is a month that missed target → show me the corrective action → show me whether it worked.

At any point in that chain, the answer is either evidence or it isn’t. This is why systems that exist only on paper fail — the documentation survives the first question and collapses at the fourth.

The practical implication for preparation: walk your own trails before the auditor does. Take three commitments in your policy and follow each to evidence. Where the chain breaks is where the finding will be.

What happens on the day

Opening meeting. The audit team confirms scope, plan, timings, and who they need. Short, but this is where you flag site access constraints or staff availability. Do not let the plan be unworkable and hope.

The audit itself. Interviews, document and record sampling, process observation, site walkthroughs. Auditors talk to the people doing the work, not only the management representative. A process owner who cannot describe their own process is a finding regardless of what the procedure says.

Daily feedback, on multi-day audits. You should not learn about a problem for the first time at the closing meeting.

Closing meeting. Findings presented and classified. You can question a finding — dispute the facts if they are wrong, or the interpretation if you believe the requirement is being misapplied. What you cannot do is negotiate it away.

Certification decision. Made separately from the audit team, by someone who was not part of the audit. That independence is a requirement of ISO/IEC 17021 — the auditor recommends, the certification body decides.

Nonconformities: major, minor, and what follows

This is the part organisations most want to understand and least often find explained.

A major nonconformity is a failure that undermines the management system’s ability to achieve intended results — an absent required process, a total breakdown in a required activity, or a pattern of minor issues that together show a systemic failure. Not having done an internal audit at all is a major. So is a documented process that nobody follows anywhere in the organisation.

A major must be corrected, and the correction verified by the certification body, before certification can be granted. Depending on severity, verification may require a follow-up visit rather than a document review — which costs time and money.

A minor nonconformity is an isolated lapse that does not undermine the system — one training record missing, one instance where a procedure was not followed. Certification can generally proceed on the basis of an accepted corrective action plan, with implementation verified at the next surveillance audit.

An observation or opportunity for improvement is not a nonconformity. It requires no corrective action, though ignoring a pattern of them across audits tends not to end well.

What corrective action actually requires. Certification bodies expect three distinct things, and organisations routinely supply only the first:

  1. Correction — fix the immediate problem. The missing record is created.
  2. Root cause analysis — why did it happen? “Human error” is not a root cause; it is where analysis stops too early.
  3. Corrective action — change something so it does not recur, plus evidence that the change is working.

A corrective action response that only corrects will usually be rejected, and rejection costs you time you did not budget.

What to have ready

Evidence over time, not evidence created last week. Records dated in a cluster immediately before the audit are the clearest possible signal of a system built for the auditor rather than the business.

Internal audit results — including findings. An internal audit that found nothing tells an auditor your internal audit does not work. Findings you identified and closed yourself are positive evidence.

Management review minutes covering the required inputs: audit results, performance against objectives, customer feedback, nonconformities, risks and opportunities, resource needs. Its absence is one of the most common majors.

Objectives with actual measurement. Objectives without data are not objectives.

Corrective action records showing closure, with evidence of effectiveness.

Competence records matching the people currently doing the work.

Preparing your people

Staff will be interviewed. They do not need to quote the standard. They need to be able to answer:

  • What do you do, and how do you know you are doing it correctly?
  • What would you do if something went wrong here?
  • Where would you find the procedure for this?
  • What are we trying to improve in your area?

Rehearse those four questions with process owners. Coaching people to give scripted answers is counterproductive — auditors are experienced at detecting it, and it invites a harder look.

Tell staff plainly that “I don’t know, but I know who does” is a perfectly good answer. It is far better than a guess.

Stage 1 and Stage 2

Stage 1 assesses readiness — documentation, scope, context, legal requirements, and whether internal audit and management review are complete. It exists to stop you failing Stage 2.

If Stage 1 identifies significant gaps, fix them before proceeding. Organisations that push ahead regardless usually pay for two Stage 2 audits.

Stage 2 assesses effectiveness — implementation across the organisation, through interviews, records and observation. This determines the recommendation.

Timeline

From decision to certification audit: 1–3 months for a small organisation with focused effort, 3–6 months for medium complexity, 6 months or more where the management system is being built from scratch.

The variable is implementation, not audit scheduling.

Readiness checklist

  • The management system is implemented, not just documented
  • Records span months, not days
  • Internal audits are complete, across all processes, with findings raised and closed
  • Management review is documented and covers the required inputs
  • Objectives are measured and the data exists
  • Corrective actions are closed with evidence of effectiveness
  • Process owners can describe their own processes
  • Competence records match current personnel
  • Legal and other requirements are identified and compliance evaluated

Common questions

What if we get a major nonconformity? Certification is not granted until it is corrected and the correction verified. That may mean a follow-up visit. It is a delay, not a failure — but it is an expensive delay.

Can we challenge a finding? Yes. Dispute the facts if they are wrong, or the interpretation if a requirement is being misapplied. Certification bodies also operate a formal appeals process. Disagreeing with a correctly-raised finding is different from either.

Will they audit every department? Stage 2 covers the certified scope. Sampling applies, but you cannot predict what will be sampled.

How long does the audit take? Duration is set by IAF MD 5 based on your effective personnel count, sites and complexity — not by the certification body’s discretion. See what ISO certification costs.

Can we prepare without a consultant? Yes. Trained internal auditors and a genuine internal audit programme are more valuable than external help immediately before the audit.


Talk to us about certification, or start with how to get ISO certification in the UAE.

This article is provided for information only and does not constitute professional or compliance advice. ITMAD accepts no liability for any action taken in reliance on it.