Guide
What Happens During an ISO Audit? A Simple Guide
A plain-English walk through both audit stages, what auditors check, how to prepare, and what non-conformities really mean.
6 min readAn ISO audit is far more structured and predictable than most people expect. An accredited certification body checks your management system in two stages: Stage 1 reviews your paperwork, Stage 2 checks that you actually do what you wrote down. Pass both and you get certified. For many Singapore business owners the audit feels like the scariest part of certification, but once you know what happens at each stage, it becomes straightforward.
Key takeaways
- Audits run in two stages: Stage 1 (documentation) and Stage 2 (implementation). Both must pass.
- Auditors check that you follow your own procedures, not that you have perfect answers.
- The best preparation is a well-run internal audit. Pass your own review and you'll likely pass the real one.
- Non-conformities are findings to fix, not failures. Minor NCs still allow the certificate to be issued.
Stage 1 vs Stage 2 audit
The ISO certification audit is conducted in two stages by an accredited certification body. Both stages must be passed before a certificate is issued. Stage 1 confirms your system is designed correctly. Stage 2 confirms it actually works.
| Stage 1: Documentation review | Stage 2: Implementation audit |
|---|---|
| A desk-based review of your documentation. | The main event, conducted at your premises. |
| Checks that your system meets the requirements of the standard. | Verifies the documented system is followed in practice. |
| Reviews your quality manual (if applicable), procedures, policies, risk assessments and objectives. | Interviews staff, observes processes, reviews records, and checks that Stage 1 actions are addressed. |
| May be remote or on-site. Typically half a day to a full day for SMEs. | Takes 1 to 2 days for a typical Singapore SME. |
| Confirms the system is designed correctly before checking if it works. | Auditor presents findings and recommends whether to grant certification. |
What auditors look for
Auditors aren't trying to catch you out. They're assessing whether your management system meets the standard's requirements. Here are the five main things they focus on:
- Process consistency. Are you actually following the procedures you've documented? If your SOP says incoming materials are inspected, auditors will check inspection records to confirm it's happening.
- Management commitment. Is top management involved? Auditors look for evidence of management reviews, resource allocation, and leadership engagement with the system.
- Risk-based thinking. Have you identified risks and opportunities relevant to your business? The 2015 revisions of ISO standards emphasise proactive risk management over reactive corrective action.
- Competence and training. Can your staff demonstrate they understand their roles within the management system? Auditors may interview operators, supervisors, and managers at random.
- Continual improvement. Are you tracking performance, analysing data, and making improvements? Auditors want to see that the system is evolving, not static.
How to prepare
Preparation doesn't need to be complicated. These five steps will put you in a strong position:
Run a thorough internal audit. This is your dress rehearsal. Treat it seriously and fix any issues found before the certification body arrives.
Complete your management review. Ensure at least one management review meeting has been conducted and properly minuted. This is a mandatory requirement across all ISO standards.
Check your records. Make sure training records, inspection logs, calibration certificates, and corrective action reports are up to date and accessible.
Brief your team. Staff don't need to memorise the standard, but they should understand their role, the company's quality, safety or environmental policy, and where to find relevant documents.
Don't over-prepare. Auditors can tell when responses are rehearsed. Honest, practical answers are better than scripted ones. If something isn't perfect, acknowledge it and show what you're doing to improve.
What if you get non-conformities
Non-conformities aren't failures. They're findings that need to be addressed. There are two types:
- Minor non-conformities are isolated gaps that don't undermine the overall system. For example, a single missing training record or an overdue calibration certificate. You typically have 90 days to submit evidence of correction, and the auditor closes it out remotely. Minor NCs do not prevent certification. The certificate is still issued.
- Major non-conformities indicate a significant breakdown. For example, an entire process operating without any documented procedure, or a complete absence of management reviews. A major NC means certification is withheld until you fix the issue and pass a follow-up audit. This typically adds 4 to 8 weeks to your timeline.
The good news: major non-conformities are rare when you work with an experienced consultant, because the gap analysis and internal audit stages are designed to catch these issues well before the certification audit.
FAQ
Can an audit be done remotely?
Stage 1 can often be conducted remotely, especially for service-based businesses. Stage 2 usually requires an on-site visit, though some certification bodies allow a hybrid approach where part of the audit is done via video conference. This became more common after COVID and is still accepted by most accredited bodies in Singapore.
What if my staff give wrong answers to the auditor?
Auditors understand that not everyone will have perfect answers. What matters is that staff demonstrate a basic understanding of their responsibilities and know where to find the relevant procedures. An honest "I'm not sure, but I'd check this document" is perfectly fine. Auditors are evaluating the system, not testing individual knowledge.
How often are surveillance audits after certification?
Surveillance audits happen once a year during the three-year certification cycle. They're shorter than the initial certification audit, usually half a day to one day for SMEs. The auditor samples different areas each time, so over three years the entire system gets reviewed. After three years, you go through a full recertification audit.
Talk it through with Nachi
Tell us your industry and headcount, and get a quote and a realistic timeline, free, same day.
WhatsApp us: 8901 2255Prefer email? Leave your details and Nachi replies within one working day:
ZES Consulting · 20+ years · 268+ projects · contact page