What to Expect from a Certification Body Audit
If you’re working towards ISO certification, the certification body audit can feel like a big milestone - and often a daunting one.
The good news? Having gone through 100’s of these, we know the drill – and it’s a structured, predictable process. Once you understand what’s involved, it becomes far more manageable.
In this guide, we’ll walk you through:
What a certification body audit is
The difference between Stage 1 and Stage 2
How to prepare effectively
How a consultant can support you along the way
What is a Certification Body Audit?
A certification body audit is an independent assessment of your management system against the requirements of the relevant ISO standard.
It’s carried out by an accredited third party (your certification body), whose role is to verify that:
Your system meets the requirements of the standard
It is implemented effectively
You are committed to continual improvement
This audit is what ultimately leads to certification.
Stage 1 Audit: Readiness Review
The Stage 1 audit is often described as a documentation review, but it’s really about confirming that you’re ready for the full audit.
At this stage, the auditor will:
Review your policies, procedures, and records
Check your scope and objectives are clearly defined
Assess whether essential elements (e.g. internal audits, management reviews) are in place
Identify any gaps that need addressing before Stage 2
The purpose here is not to catch you out, but to ensure your management system is sufficiently developed.
You won’t “fail” Stage 1, but you will receive findings or recommendations – effectively a checklist of what needs tightening up before the next stage.
Stage 2 Audit: Certification Audit
Stage 2 is the main event - this is where certification is decided.
During this stage, the auditor will assess how your system works in practice. This typically includes:
Interviewing staff across the business
Reviewing live records and evidence
Observing processes in action
Following activities from start to finish
The key focus is simple:
Does what you say and do match what actually happens day-to-day?
The auditor is looking for evidence that your system is:
Documented – you have defined processes
Implemented – your team follows them
Effective – they achieve the intended outcomes
Improving – issues are identified and addressed
If any nonconformities are identified, you’ll be given the opportunity to address them before certification is confirmed.
What Happens After Stage 2? Surveillance Audits
Certification isn’t something you achieve once, it’s something you maintain.
Once you’ve successfully passed Stage 2 and been awarded certification, your business will enter a three-year certification cycle, which includes regular surveillance audits.
Surveillance audits are typically carried out annually and are designed to ensure that your management system continues to meet the requirements of the standard, be effectively implemented, and demonstrate continual improvement.
Unlike the initial certification audit, surveillance audits don’t usually cover everything in one visit. Instead, the auditor will focus on specific areas of your system, often including:
Actions taken since the previous audit
Progress against objectives
Internal audit and management review activities
Any incidents, risks, or nonconformities
At the end of the three-year cycle, you’ll go through a recertification audit, which is similar in scope to Stage 2 and confirms your system is still fit for purpose.
How to Prepare for Your Audit
Preparation is where most organisations either create confidence… or unnecessary stress.
Here are the key areas to focus on:
1. Make sure your system is genuinely in use
Auditors quickly identify systems that exist “on paper” only. Your processes should be part of day-to-day operations.
2. Complete internal audits and management reviews
These are essential prerequisites and a key piece of evidence that your system is monitored and reviewed.
3. Ensure documentation reflects reality
Your procedures should match what your team actually does - not what you think should happen.
4. Prepare your team
Staff don’t need to memorise clauses, but they should:
Understand their role
Be aware of relevant processes
Be able to explain how they follow them
5. Address any known gaps early
Stage 1 findings should be resolved before moving into Stage 2 to avoid delays.
How a Consultant Can Support You
While certification bodies must remain independent, a consultant works on your side to help you prepare.
A good consultant can support you by:
Providing clarity and structure
They translate ISO requirements into practical processes that fit your business – not just templates.
Conducting gap analysis and readiness checks
This helps identify issues early, before the certification audit.
Developing documentation
Ensuring policies, procedures, and records are audit-ready and aligned to the standard.
Training your team
Helping employees understand how the system applies to their role.
Carrying out internal audits
To identify any areas for improvement, check where you’re at, and build confidence ahead of the real audit.
Supporting post-audit actions
Helping you respond to any findings quickly and effectively.
Ultimately, a consultant’s role is to reduce risk, save time, and make the process smoother.
Final Thoughts
A certification body audit isn’t about perfection; it’s about demonstrating that your system works and that you’re committed to improving it. With the right preparation and support, the process becomes far less intimidating and much more valuable.
If you approach it as an opportunity to strengthen your business - rather than just a box to tick - you’ll get far more out of it than a certificate.
Need support with your certification audit?
We help organisations prepare for certification in a way that is practical, proportionate, and built around how your business actually operates.
But our support doesn’t stop at certification. We also work with clients to maintain and improve their management systems year-round, helping them stay compliant, confident, and ready for surveillance audits without the last-minute stress.
We work with all of the main ISO management systems, including ISO 9001, 14001, 45001, 27001 and many more >
If you’d like to chat about your upcoming audit - or how to keep things running smoothly long after certification - get in touch. We’re always happy to help.