Frequently Asked Questions about ISO Certification
Answers to the most common questions about choosing an ISO standard, preparation, certification and maintaining a management system.
About ISO
ISO certification shows that a business operates an organised management system that meets the requirements of a specific international standard. Depending on the standard, the system may cover quality, occupational health and safety, the environment, information security, energy, food safety or other areas of how a business operates.
It depends on your activity, your clients, contractual requirements, the tenders you take part in and your business goals. For example: • ISO 9001 — Quality Management • ISO 14001 — Environmental Management • ISO 45001 — Occupational Health & Safety • ISO/IEC 27001 — Information Security • ISO 22000 — Food Safety • ISO 50001 — Energy Management If you don't know which standard applies to you, we can look at your business's activity and requirements and point you to the right standards.
Not in every case. Certification can, however, be: • a condition for taking part in a tender, • a client's or partner's requirement, • a condition of a specific contract, • a supply-chain requirement, • a significant commercial advantage. Some sectors may also have specific legal or regulatory requirements that need to be looked at separately.
It can be an important mark of commercial credibility, especially when a client or a supply chain requires a proven management system. Depending on the sector, ISO can help a business to: • meet the requirements of large clients, • take part in specific tenders, • demonstrate its organisational capability, • gain access to new partnerships or markets. On its own it does not guarantee commercial success, but it can remove significant barriers to entry.
Cost & time
There is no single timeframe that applies to every business. The time needed depends mainly on: • the size of the business, • the number of sites, • the activity, • the standard chosen, • the existing organisation, • the level of documentation, • how ready the staff are, • how complex the processes are. After an initial assessment we can estimate the steps and the timeline much more accurately.
The cost is not the same for every business. It depends on factors such as: • the standard or standards, • the size and activity of the company, • the number of employees, • the sites, • how complex the processes are, • the current state of the system, • the extent of the consulting support needed. The cost of preparation and consulting should usually also be distinguished from the cost of the independent certification body, where these are provided by different organisations.
Certification process
The process can be organised in four main stages: 1. Assessment We look at how the business works today and identify what is already in place and what needs to be added. 2. Design We organise the management system, the procedures and the necessary documentation. 3. Implementation The system is put into real operation, staff are briefed or trained and the necessary checks are carried out. 4. Certification The business is prepared for the final assessment against the relevant standard.
Yes. Our support can cover the whole process, depending on what the business needs: • initial assessment, • gap analysis, • system design, • writing procedures and documentation, • defining responsibilities, • staff training, • implementation support, • internal audit, • corrective actions, • preparation for the final audit. The aim is for the system to fit the way the business actually works, not to burden the business with unnecessary procedures.
Not necessarily. There are usually many practices already in place that cover part of a standard's requirements but are not sufficiently organised or documented. The initial assessment identifies: • what already works well, • what needs to be documented, • what needs to improve, • which new procedures are really necessary. The aim is not to create paperwork, but a working system that serves the business.
Not when the system is designed properly. A modern management system should be proportionate to: • the size, • the activity, • the risks, • the complexity of the business in question. A small business does not need to work with the same procedures and the same level of documentation as a large industrial organisation.
In most cases there is no need to hire a dedicated person just for ISO. Specific responsibilities can be given to existing staff, and the system can be organised so that running it day to day stays practical. The right solution depends on the size and complexity of the business.
Yes, to the extent that each employee is affected by the system. Training does not mean that everyone has to know the whole ISO standard. Each employee mainly needs to know: • their responsibilities, • the procedures that concern them, • what they need to record, • how deviations or problems are handled.
Yes. Many ISO standards share a common structure and can be combined into one Integrated Management System. For example, you can combine: ISO 9001 + ISO 14001 + ISO 45001 so that shared activities, such as: • document control, • internal audits, • management review, • corrective actions, • risk management are organised once, for all of them. This can significantly reduce the complexity of implementation.
A nonconformity does not necessarily mean the whole process has failed. What is needed is to: 1. identify the cause, 2. decide on the right corrective action, 3. carry out the correction, 4. provide the relevant evidence, where required. Proper preparation before the audit significantly reduces the risk of major deviations.
Much of the consulting, documentation, meetings and training can, depending on the case, be done remotely. Where it matters to assess premises, production processes or physical working conditions, being on site may also be needed. The right way of working together is decided after the initial assessment.
The first step is a short initial assessment of your business's needs. We look at: • your activity, • the size of the business, • the standards you are interested in, • why you need certification, • where things stand today, • any specific deadlines. The right scope of work and the support needed can then be defined.
Public tenders
It depends on the terms of the specific tender notice. Some tenders require specific standards or other evidence relating to: • quality, • environmental management, • health and safety, • information security, • technical or professional capability. Each tender notice has to be looked at separately. If you have a specific tender in mind, we can review its requirements and identify which standards apply to you.
Support after certification
Yes, provided that this service is included in the agreed scope of work. Support for an existing system can include: • updating procedures, • internal audits, • system review, • following up corrective actions, • preparation for surveillance audits, • adapting to changes in the business or in the requirements.
Certification does not mean the system stops running. The business has to keep applying and improving the system and meet the scheduled audits. What is usually needed: • monitoring objectives, • keeping the required records, • internal audits, • corrective actions, • management review, • surveillance audits.
An internal audit checks whether the system: • is applied as designed, • meets the requirements of the standard, • works effectively, • shows deviations that need to be corrected. It is a key tool for finding problems before the external audit.