What to Expect from a Certification Body Audit

If you’re working towards ISO certification, the certification body audit can feel like a big milestone - and often a daunting one. 

The good news? Having gone through 100’s of these, we know the drill – and it’s a structured, predictable process. Once you understand what’s involved, it becomes far more manageable. 

In this guide, we’ll walk you through: 

  • What a certification body audit is 

  • The difference between Stage 1 and Stage 2 

  • How to prepare effectively 

  • How a consultant can support you along the way 

What is a Certification Body Audit?

A certification body audit is an independent assessment of your management system against the requirements of the relevant ISO standard.   

It’s carried out by an accredited third party (your certification body), whose role is to verify that: 

  • Your system meets the requirements of the standard 

  • It is implemented effectively 

  • You are committed to continual improvement 

This audit is what ultimately leads to certification. 

Stage 1 Audit: Readiness Review

The Stage 1 audit is often described as a  documentation review, but it’s really about confirming that you’re ready for the full audit. 

At this stage, the auditor will: 

  • Review your policies, procedures, and records 

  • Check your scope and objectives are clearly defined 

  • Assess whether essential elements (e.g. internal audits, management reviews) are in place 

  • Identify any gaps that need addressing before Stage 2 

The purpose here is  not to catch you out, but to ensure your management system is sufficiently developed. 

You won’t “fail” Stage 1, but you will receive findings or recommendations – effectively a checklist of what needs tightening up before the next stage.  

Stage 2 Audit: Certification Audit

Stage 2 is the  main event  - this is where certification is decided. 

During this stage, the auditor will assess how your system works in practice. This typically includes: 

  • Interviewing staff across the business 

  • Reviewing live records and evidence 

  • Observing processes in action 

  • Following activities from start to finish  

The key focus is simple: 

Does what you  say  and do match what actually happens day-to-day? 

The auditor is looking for evidence that your system is: 

  • Documented  – you have defined processes 

  • Implemented  – your team follows them 

  • Effective  – they achieve the intended outcomes 

  • Improving  – issues are identified and addressed  

If any nonconformities are identified, you’ll be given the opportunity to address them before certification is confirmed. 

What Happens After Stage 2? Surveillance Audits

Certification isn’t something you achieve once, it’s something you maintain. 

Once you’ve successfully passed Stage 2 and been awarded certification, your business will enter a  three-year certification cycle, which includes regular surveillance audits.  

Surveillance audits are typically carried out annually and are designed to ensure that your management system continues to meet the requirements of the standard, be effectively implemented, and demonstrate continual improvement. 

Unlike the initial certification audit, surveillance audits don’t usually cover everything in one visit. Instead, the auditor will focus on specific areas of your system, often including: 

  • Actions taken since the previous audit 

  • Progress against objectives 

  • Internal audit and management review activities 

  • Any incidents, risks, or nonconformities 

At the end of the three-year cycle, you’ll go through a  recertification audit, which is similar in scope to Stage 2 and confirms your system is still fit for purpose. 

How to Prepare for Your Audit

Preparation is where most organisations either create confidence… or unnecessary stress. 

Here are the key areas to focus on: 

1. Make sure your system is genuinely in use

Auditors quickly identify systems that exist “on paper” only. Your processes should be part of day-to-day operations. 

2. Complete internal audits and management reviews

These are essential prerequisites and a key piece of evidence that your system is monitored and reviewed.  

3. Ensure documentation reflects reality

Your procedures should match what your team actually does - not what you think should happen. 

4. Prepare your team

Staff don’t need to memorise clauses, but they should: 

  • Understand their role 

  • Be aware of relevant processes 

  • Be able to explain how they follow them 

5. Address any known gaps early

Stage 1 findings should be resolved before moving into Stage 2 to avoid delays. 

How a Consultant Can Support You

While certification bodies must remain independent, a consultant works  on your side  to help you prepare. 

A good consultant can support you by: 

Providing clarity and structure

They translate ISO requirements into practical processes that fit your business – not just templates.  

Conducting gap analysis and readiness checks

This helps identify issues early, before the certification audit.   

Developing documentation

Ensuring policies, procedures, and records are audit-ready and aligned to the standard. 

Training your team

Helping employees understand how the system applies to their role. 

Carrying out internal audits

To identify any areas for improvement, check where you’re at, and build confidence ahead of the real audit. 

Supporting post-audit actions

Helping you respond to any findings quickly and effectively. 

Ultimately, a consultant’s role is to  reduce risk, save time, and make the process smoother

Final Thoughts

A certification body audit isn’t about perfection; it’s about demonstrating that your system works and that you’re committed to improving it. With the right preparation and support, the process becomes far less intimidating and much more valuable. 

If you approach it as an opportunity to strengthen your business - rather than just a box to tick - you’ll get far more out of it than a certificate. 

Need support with your certification audit?

We help organisations prepare for certification in a way that is practical, proportionate, and built around how your business actually operates. 

But our support doesn’t stop at certification. We also work with clients to  maintain and improve their management systems year-round, helping them stay compliant, confident, and ready for surveillance audits without the last-minute stress. 

We work with all of the main ISO management systems, including ISO 9001, 14001, 45001, 27001 and many more >

If you’d like to chat about your upcoming audit - or how to keep things running smoothly long after certification - get in touch. We’re always happy to help. 

Next
Next

ISO 14001:2026 has been published – what organisations need to know