ISO certification cycle
Our certification services are best suited for experienced
companies that have already prepared
most of the documentation required for certification (or
have the internal capabilities to do so).
Certification for an ISO management system standard is a three-year process that covers:
- Year 1: Initial consultation/gap analysis, pre-audit and certification audit
- Year 2: Surveillance audit
- Year 3: Surveillance audit and preparation for re-certification
Your company will be responsible for preparing the mandatory and non-mandatory documentation (policies, procedures and forms) that is specified by the ISO
standard. We recommend that you train one of your employees as a certified Internal Auditor to drive the documentation and
certification process internally.
To pass the Surveillance Audit (in years 2 and 3), your organization will also need to demonstrate that you have implemented the necessary controls and engaged in year-on-year continuous improvements.
3-year audit cycle (with 2 surveillance visits)
Process for ISO certification
A specialized Fiqra Client Manager will contact you to discuss your objectives, requirements and level of preparation.
Is this your first certification? Were you previously certified, and are you looking for re-certification only? Do you need help in developing applicable policies and procedures?
For most of our clients, we follow a structured multi-step approach (although this approach can be tailored depending on your organization’s level of preparation).
In preparation for your gap
analysis, you should:
- Purchase and review the management system standard from the ISO bookstore
- Designate a member of your staff to receive training as an Internal Auditor for the desired standard (see here to request training class)
- Prepare your internal documentation in accordance with the requirements of the management system standard
Step 1: Gap analysis (optional)
During the pre-assessment phase, we review your internal documentation and compare it with the requirements of the desired standard. We prepare a Gap Analysis Report that identifies areas that need more work. This optional step is recommended for less-experienced organizations that are going through their first certification.
In preparation for your pre-audit, you should:
- Take action to remedy areas of non-conformity with the standard
- Start applying the procedures and controls throughout your organization
Step 2: Pre-audit
The Fiqra auditor will assess your organization’s readiness for certification by:
- Verifying that your documentation meets the requirements of the standard
- Ensuring that the procedures and controls have been implemented effectively
In preparation for your certification
audit, you should:
- Take action to remedy any areas of non-conformity with the documentation and control requirements of the standard
Step 3: Certification audit
We will schedule a visit by an accredited Certification Body to review your internal documentation and assess the practical implementation of procedures and controls. We work with Certification Bodies accredited by the United Kingdom Accreditation Service (UKAS). If you pass, your company will be issued an ISO certification that is valid for 3 years.
In preparation for your annual surveillance
audit (in years 2 & 3), you should:
- Update your ISO documentation as needed to reflect changes in your organization
- Collect evidence of areas of continual improvement in applying the controls that are defined in your policies and procedures
What if you do not have the resources or time to prepare your own ISO documentation?
Preparing the mandatory and non-mandatory documentation required for ISO certification can be a time-consuming challenge for many organizations. If you prefer, you can delegate to us the responsibility for preparing the required polices and procedures.
Instead of training your own Internal Auditor, we can provide an experienced auditor to:
- Interpret ISO documentation requirements in light of your business and operational requirements
- Review/edit your existing documents and prepare new ones that are customized to your risk profile
- Train your staff to implement the procedures and controls required to meet the certification requirements and demonstrate continuous improvement in following years
Please go to our menu of turnkey solutions for additional information.