Getting ready for ISO certification can feel daunting, especially when an organization is unsure what the certification auditor will actually look for.
An ISO certification audit is an independent assessment to determine whether an organization’s management system meets the requirements of the relevant ISO standard and is effectively implemented. The certification audit normally takes place in two stages: Stage 1 and Stage 2.
Stage 1 is primarily a readiness review. The auditor looks at the organization’s documented management system, scope of certification, key processes, applicable requirements and overall preparedness for Stage 2.
Stage 2 is the more in-depth audit, where the auditor evaluates whether the management system is actually implemented and working in practice. This means having procedures and documents alone is not enough—the organization needs to demonstrate evidence that people are following the system and that it is achieving its intended results.
Stage 2 is where the auditor moves beyond “show me your procedure” to “show me how this actually works.”
For example, if your organization has a procedure requiring suppliers to be evaluated before approval, the auditor may select several suppliers and ask to see their evaluation records. The auditor may then interview the person responsible for purchasing and ask how suppliers are selected, what happens when a supplier performs poorly and whether the process is consistently followed.
Similarly, for ISO 45001, an auditor may not simply review your risk assessments. They could walk around the workplace, interview workers and supervisors, check whether identified controls are actually implemented and compare what they see on site against the documented risk assessment.
For ISO 9001, the auditor could trace an actual customer order from enquiry through quotation, contract review, production or service delivery and finally customer feedback. For ISO 14001, the auditor may examine environmental aspects, operational controls, legal requirements and actual environmental performance.
The key principle is simple:
The auditor is looking for consistency between what you say, what you do and what you can prove.
How Should an Organization Prepare for Stage 2?
The best preparation is not to create more documents just before the audit. Instead, organizations should test whether their management system is genuinely being used.
1. Trace real transactions
Select several recent customer orders, projects, purchases or service activities and follow them from beginning to end. Check whether the required records and controls are actually in place.
2. Check your records, not just your procedures
If your procedure says something must be recorded, make sure the records exist, are complete and are properly maintained.
3. Interview your own employees
Ask employees simple questions such as: “What do you do when there is a customer complaint?” or “What do you do if you identify a safety hazard?” Employees should understand the parts of the management system relevant to their work.
4. Verify corrective actions
Do not simply close nonconformities by saying that a procedure has been updated. Check whether the root cause was addressed and whether the corrective action actually worked.
5. Check legal and regulatory requirements
Where applicable, make sure relevant legislation, licenses, permits and other compliance obligations have been identified and periodically evaluated.
6. Conduct an internal audit before certification
A good internal audit should test the effectiveness of the system—not merely confirm that documents exist.
7. Review management meeting outputs
Management should be able to demonstrate that it has reviewed performance, risks, objectives, audit results, complaints, incidents and opportunities for improvement, as applicable.
8. Look at the workplace, not only the office files
For standards such as ISO 45001 and ISO 14001, physical implementation can be particularly important. What the auditor sees on site should be consistent with the documented system.
An auditor may ask different questions depending on the ISO standard and organization. However, the following questions illustrate the depth of questioning organizations should prepare for
An organization can have a beautifully documented management system and still struggle during Stage 2 if employees do not understand it, records are incomplete, controls are not consistently implemented or management cannot demonstrate effectiveness.
Being certificate-ready means you may have the required documents. Being audit-ready means your people, processes, records and actual workplace practices can withstand independent scrutiny.
For organizations in Singapore preparing for ISO 9001, ISO 14001, ISO 45001, ISO 27001 or other ISO certification, a structured gap assessment, internal audit or mock certification audit can help identify these weaknesses before the certification body arrives.
QuESH can help organizations assess their readiness, identify implementation gaps and prepare for the realities of Stage 1 and Stage 2 certification audits.
Book your a free 30-minute, no-obligation consultation today!
At QuESH, our articles aim to create value for organizations and individuals by sharing insights and practical tips on achieving business excellence. Drawing from our experience as ISO auditors and consultants, we cover key topics such as quality management, workplace safety, environmental compliance, and health systems. Our content provides actionable solutions to help businesses of all sizes overcome challenges, drive growth, and unlock their full potential.
Subscribe With Us!ISO 45001:2018 emphasizes the critical role of "worker participation" in occupa…
Since the publication of ISO 45001: 2018 Standard in March 2018, there have bee…
What will the revised DPTM offer?