ISAO — International Standards Accreditation Organization home pageVerify a certificate

Menu

Certification

How ISAO audits and certifies management systems, and issues certificates of registration that anyone can check.

Concept office entrance: the ISAO logo on a frosted band across a glass door with a steel bar handle.

Management system certification is an independent check that the way an organisation is run meets the requirements of a published standard, such as ISO 9001 for quality or ISO/IEC 27001 for information security. Auditors examine the system's documents and records and see how it works in practice. When the requirements are met, a certificate is issued.

ISAO does this work itself. It audits the organisation, makes the certification decision and issues a certificate of registration in its own name. Every certificate ISAO issues is recorded on the public register, where anyone can check it.

Who can apply

Any organisation can apply, whatever its size, sector or legal form. ISAO offers certification to every applicant on the same terms: it does not make certification depend on the size of an organisation, on membership of an association, or on the number of certificates it already holds.

The management system must be in operation before the certification audit, with records of at least one internal audit and one management review.

Standards we certify against

ISAO certifies against the management system standards on the standards pages, among them ISO 9001 (quality), ISO 14001 (environment), ISO 45001 (occupational health and safety) and ISO/IEC 27001 (information security). Each page summarises what the standard covers and which edition is current.

An organisation can be certified against more than one standard, and can ask for the audits to be combined.

How certification works

The same steps apply to every organisation. Each step is recorded, and the organisation receives the outcome in writing.

Step 1: Application and proposal

The organisation tells ISAO which standard it wants to be certified against, the activities to be covered, its sites and the number of people working at each. From this, ISAO works out the audit time needed and sends a written proposal with the audit plan and the fees.

Step 2: Agreement

When the organisation accepts the proposal, both sides sign a certification agreement. It sets out the scope, the audit programme for the three-year cycle, the fees and the rules for using the certificate.

Step 3: Stage 1 audit

The auditor reviews the management system's documents and the organisation's readiness, on site or remotely: whether the scope is right, the main processes are defined, and internal audits and a management review have taken place. Any concerns are reported, so that they can be dealt with before stage 2.

Step 4: Stage 2 audit

The audit team checks that the management system is implemented and effective in practice. They interview people at different levels, observe work and sample records across the activities and sites in the scope.

Step 5: Findings and corrective action

Every finding is reported in writing. A major nonconformity must be corrected, and the correction checked, before certification can be granted. For a minor nonconformity, the organisation sends a corrective action plan, which ISAO reviews and follows up at the next audit.

Step 6: Certification decision

The audit report and the evidence of corrective action are reviewed by people at ISAO who did not take part in the audit, and they decide whether to grant certification. Auditors never decide on the certification of an organisation they audited.

Step 7: Certificate of registration

When certification is granted, ISAO issues a certificate of registration naming the organisation, the standard, the scope and the certified sites, with a unique number and its dates. The certificate is recorded on the public register, and its QR code leads to that record, so anyone can check that it is genuine and see its current status.

Step 8: Surveillance audits

Certification runs for a three-year cycle. During the cycle ISAO audits the organisation at least once a year, to confirm that the management system still meets the standard and keeps improving. The first surveillance audit takes place within twelve months of the certification decision.

Step 9: Recertification

Before the three-year cycle ends, a recertification audit reviews how the system has performed over the whole cycle. When certification is renewed, ISAO issues a new certificate for a further cycle and updates the register.

Organisations with more than one site

An organisation with several sites can hold one certificate for all of them, provided they work under the same management system, controlled and reviewed centrally. ISAO audits the central function and a sample of the other sites, chosen according to their activities, risks and audit results.

The certificate lists every site it covers. Where an organisation needs one, ISAO can also issue a site certificate for an individual site, valid together with the main certificate.

Transferring from another certification body

An organisation certified by another certification body can ask about moving its certification to ISAO. Contact us with the details of the current certificate and the latest audit report, and ISAO will explain in writing whether and how a transfer can be made.

Suspension, withdrawal and reduced scope

ISAO can suspend a certificate when, for example, a surveillance audit cannot take place on time, a major nonconformity is not corrected within the agreed period, or the certificate is misused. While a certificate is suspended, the organisation must not claim certification. If the cause is not put right, ISAO withdraws the certificate.

Where only part of the scope no longer meets the requirements, ISAO reduces the scope instead: it issues a replacement certificate with the reduced scope, and the register shows the earlier certificate as superseded, with a link to the replacement. Every suspension and withdrawal is shown on the register with its date, so the record of each certificate always shows its current position. The suspension and withdrawal policy has the details.

Using your certificate

A certified organisation may refer to its certification in its own documents, website and advertising, provided it does so accurately:

  • refer to the certificate only for the activities and sites it covers, using the scope as worded on the certificate
  • do not suggest that a product or service is certified: management system certification is about how an organisation is run, not what it makes or sells, so the certificate never appears on products, packaging, or test, calibration or inspection reports
  • never use the ISO logo: ISO publishes standards, does not certify anyone, and its logo is its trademark. Say that your management system is certified to ISO 9001, not that you are “ISO certified”
  • show the certificate only in full and unaltered
  • stop referring to the certification while a certificate is suspended or after it is withdrawn, and correct any material that describes a scope that has been reduced

Impartiality and confidentiality

ISAO does not offer consultancy on management systems, and does not certify a system it has helped to design or put in place. Fees do not depend on the outcome of an audit. Auditors and decision-makers declare any interest that could affect their work, and do not work on an organisation where they have a conflict of interest. Our impartiality policy explains how risks to impartiality are managed.

Information obtained during certification is kept confidential. Only the details on the certificate and its current status are published on the register. Our confidentiality policy explains what we disclose and when.

Complaints and appeals

Anyone can complain about ISAO's certification work, or about the way a certified organisation uses its certificate. An organisation can appeal against a certification decision, such as a refusal, suspension, withdrawal or reduction of scope. Complaints and appeals are handled by people who were not involved in the matter.

Use the complaints form. The complaints and appeals policy explains how they are handled.

Fees

The fee depends mainly on the audit time, which follows from the standard, the number of people, the number of sites and the complexity of the activities. ISAO sets out every fee in its written proposal before any work begins. Contact us for a proposal.

How to apply

Apply through the contact form. To help us prepare a proposal, tell us:

  • the organisation's name and address, and a contact name
  • the standard or standards you want to be certified against
  • the scope: the products, services or activities to be covered
  • every site to be included, with its address
  • the number of people working at each site, including part-time and contract staff
  • whether the management system is already certified, and by whom

We reply with any questions, then send a written proposal.