ISO Certification FAQ

    Answers to the most common questions about ISO certification, standards, audits, and more.

    Generic ISO Questions

    What is ISO?
    ISO stands for the International Organization for Standardization. It is an independent body that develops international standards to ensure the quality, safety, and efficiency of products, services, and systems.
    What does it mean to be ISO certified?
    Being certified means that an independent auditor has verified that your business processes meet the specific requirements of a particular ISO standard.
    Why should my company get ISO certified?
    Certification can improve internal efficiency, reduce waste, and increase customer trust. It is also often a requirement to bid on large contracts or government tenders.
    How long does the certification process take?
    The timeline varies based on the size of the organization and the complexity of the standard. Generally, it takes between six and twelve months.
    Who issues ISO certificates?
    ISO itself does not issue certificates. Certification is performed by external, third party organizations known as registrars or certification bodies.
    What is a certification body?
    A certification body is an organization that audits your company and issues your certificate if you meet the standard requirements.
    What is the difference between ISO and accreditation?
    ISO creates the standards. Accreditation is the formal recognition by an authoritative body that a certification body is competent to perform audits.
    How much does ISO certification cost?
    Costs depend on the number of employees, the number of locations, and the specific standard. Fees typically include consultant costs and registrar audit fees. Use our free ISO Certification Cost Calculator to get an instant estimate tailored to your business.
    Is ISO certification mandatory?
    For most industries, ISO certification is voluntary. However, some sectors or specific clients may require it as a condition of doing business.
    What is a Gap Analysis?
    A Gap Analysis is an initial assessment to identify where your current processes fall short of the ISO requirements.
    How long is an ISO certificate valid?
    Most ISO certificates are valid for three years, provided the company passes regular surveillance audits.
    What is a surveillance audit?
    This is a partial audit conducted annually by your registrar to ensure your management system still meets the standard between full recertification cycles.
    Can a small business get ISO certified?
    Yes. ISO standards are designed to be scalable and can be applied to a company of any size, from a solo consultant to a global corporation.
    What is an Internal Audit?
    An internal audit is a self check performed by your own staff or a consultant to ensure your processes are working as intended before the official audit.
    Do I need a consultant to get certified?
    While not mandatory, many companies hire consultants to speed up the process and ensure their documentation is correct.
    What is a Non-Conformity?
    A non-conformity is a finding during an audit where a process does not meet a specific requirement of the ISO standard. When found, a corrective action must be taken.
    What is a Major non-conformity?
    A major non-conformity is a significant failure that indicates the management system is not meeting its core objectives. It requires an immediate corrective action plan.
    What is a Minor non-conformity?
    A minor non-conformity is a small slip in a process that does not compromise the overall effectiveness of the management system. It still requires a corrective action to prevent recurrence.
    Can I lose my ISO certification?
    Yes. If a company fails a surveillance audit or fails to correct major non-conformities, the certification body can suspend or withdraw the certificate.
    What is Annex SL?
    Annex SL is a high level structure used by all modern ISO standards. It ensures that different standards use the same basic layout and terminology.
    Does ISO certification guarantee product quality?
    It does not guarantee the quality of every single product. Instead, it proves that you have a consistent system in place to manage and improve quality.
    What is a Quality Manual?
    A Quality Manual is a document that describes how an organization will achieve the quality goals defined by the ISO standard.
    What is Root Cause Analysis?
    This is a method of problem solving used to identify the underlying cause of a failure or non-conformity so it can be prevented in the future.
    What are Corrective Actions?
    Corrective actions are the steps taken to eliminate the cause of an existing problem and prevent it from happening again.
    What are Preventive Actions?
    Preventive actions are proactive steps taken to identify potential problems and ensure they do not occur in the first place.
    What is a Management Review?
    This is a formal meeting where top management evaluates the performance and effectiveness of the management system.
    What is the scope of certification?
    The scope defines the specific products, services, and locations that are covered by the ISO certificate.
    What is an "Interested Party"?
    An interested party is any person or organization that can affect or be affected by your business, such as customers, employees, or suppliers.
    What is a registrar?
    A registrar is another name for a certification body. They are the ones who conduct the official audit and issue your certificate.
    How do I choose a certification body?
    You should look for a registrar that is accredited, has experience in your industry, and offers a transparent pricing structure.
    What happens during a Stage 1 audit?
    The auditor reviews your documentation to ensure you have all the necessary pieces in place before the full on site audit.
    What happens during a Stage 2 audit?
    The auditor visits your site to interview staff and observe processes to verify that you are actually doing what your documentation says.
    Can I transfer my ISO certificate to a different registrar?
    Yes. You can transfer your certification to another accredited registrar at any point in the three year cycle.
    What is the IAF?
    The IAF is the International Accreditation Forum. They manage the global network of accreditation bodies to ensure certificates are recognized worldwide.
    What is Continuous Improvement?
    Continuous improvement is the ongoing effort to enhance products, services, or processes over time.
    What is an Auditor?
    An auditor is a trained professional who evaluates whether a company meets the requirements of a specific standard.
    Does ISO certification apply to individuals?
    No. ISO certification applies to organizations. However, individuals can get certified as auditors or lead implementers.
    How is ISO 9001 different from 9002 or 9003?
    ISO 9002 and 9003 were retired years ago. Today, ISO 9001 is the single standard for quality management systems.
    What is the ISO logo policy?
    Certified companies can use a specific logo provided by their registrar, but they cannot use the official ISO logo itself.
    What is "Risk-Based Thinking"?
    This involves identifying potential risks and opportunities so that the organization can plan its actions accordingly.
    What are the benefits of an Integrated Management System?
    Integrating systems like 9001 and 14001 reduces duplication of work and simplifies the audit process.
    How do I update my certification to a new version?
    When a standard is updated, there is usually a three year transition period to upgrade your systems and pass a transition audit.
    What is the PDCA cycle?
    It stands for Plan, Do, Check, Act. It is a four step process for continuous improvement in any management system.
    Who is responsible for ISO in a company?
    While one person may lead the implementation, top management is ultimately responsible for the success of the system.
    What is an Aspect?
    In environmental standards, an aspect is an element of an organization's activities that can interact with the environment.
    What is an Impact?
    An impact is the change to the environment that results from an organization's aspects.
    What is a SWOT analysis?
    SWOT stands for Strengths, Weaknesses, Opportunities, and Threats. It is often used to determine the context of an organization.
    What is a Lead Auditor?
    A Lead Auditor is a person who has the training and experience to lead an audit team during a certification audit.
    How does ISO help with customer satisfaction?
    ISO standards require you to monitor customer feedback and take action to improve based on what you learn.
    Is ASCB equivalent to UKAS?
    No, ASCB is not equivalent to UKAS, and this is an important distinction for SMEs to understand. UKAS is the sole national accreditation body in the UK, recognised by the UK government under the Accreditation Regulations 2009, and operates within the International Accreditation Forum (IAF), meaning UKAS-accredited certifications carry mutual recognition across international markets. ASCB, by contrast, is an independent organisation that is not approved or affiliated with government, nor appointed as the UK's national accreditation body. Think of it like the difference between a driving licence issued by the DVLA and one issued by a private motoring school: both may involve a genuine test of competence, but only one carries the weight of official state recognition. Certifications awarded by bodies accredited through ASCB are not recognised as equivalent to those accredited by UKAS or other IAF members, and are not considered conformant with UK Accreditation Regulations 2009. That said, ASCB remains a valid option for smaller businesses that operate in domestic or niche markets and do not require international recognition, but SMEs pursuing government contracts, export markets, or supply chain requirements that specify UKAS-accredited certification should be aware that an ASCB-accredited certificate may not be accepted.

    ISO 9001: Quality Management

    What is the main goal of ISO 9001?
    The primary goal is to provide a framework that ensures consistent quality and increases customer satisfaction.
    What is a "Process Approach"?
    This means managing activities as a system of linked processes rather than separate departments. Process mapping is the primary tool used to visualise and manage these linked processes.
    Do I need to document every single process for ISO 9001?
    No. You only need to document processes that are necessary for the effectiveness of your quality system.
    What are Quality Objectives?
    These are measurable goals related to quality that an organization sets for itself. Read our full guide to Quality Objectives to learn more.
    What is "Customer Focus" in ISO 9001?
    It means putting the needs and expectations of the customer at the center of your business decisions.
    Does ISO 9001 apply to service companies?
    Yes. ISO 9001 is applicable to any organization, whether they provide physical products or intangible services.
    What is Evidence-Based Decision Making?
    This principle states that decisions should be based on the analysis of data and information rather than guesswork.

    ISO 14001: Environmental Management

    What is the main focus of ISO 14001?
    It helps organizations manage their environmental responsibilities and reduce their impact on the planet.
    What is an Environmental Policy?
    This is a formal statement from top management outlining the company's commitment to environmental performance.
    Does ISO 14001 require me to reduce carbon emissions?
    It requires you to set your own goals for improvement, which could include reducing emissions, waste, or water use.
    What is "Life Cycle Thinking"?
    This involves considering the environmental impact of a product from its creation to its final disposal.
    Is ISO 14001 only for manufacturing?
    No. Offices, schools, and hospitals also use ISO 14001 to manage energy, waste, and procurement.

    ISO 45001: Occupational Health & Safety

    What is the purpose of ISO 45001?
    It provides a framework to prevent work related injuries and ill health while providing safe and healthy workplaces.
    What is the role of workers in ISO 45001?
    The standard emphasizes worker participation and consultation in identifying hazards and improving safety.
    What is a Hazard?
    A hazard is a potential source of harm or a situation with a potential to cause injury or ill health.
    What is the "Hierarchy of Controls"?
    This is a system used to minimize or eliminate exposure to hazards, starting with elimination and ending with personal protective equipment.

    ISO 27001: Information Security

    What does ISO 27001 protect?
    It protects the confidentiality, integrity, and availability of information.
    What is an ISMS?
    It stands for Information Security Management System, which is the total set of policies and controls used to manage data security.
    What is the Statement of Applicability (SoA)?
    This document lists which security controls from the standard you have implemented and why.
    Is ISO 27001 only for IT companies?
    No. Any organization that handles sensitive data, such as law firms or HR agencies, can use ISO 27001.
    What is the relationship between ISO 27001 and GDPR?
    While they are different, ISO 27001 provides an excellent framework for meeting many of the security requirements of GDPR.

    ISO 13485: Medical Devices

    Who needs ISO 13485?
    Any organization involved in the design, production, installation, or servicing of medical devices.
    How is ISO 13485 different from ISO 9001?
    ISO 13485 includes stricter requirements for risk management, sterile production, and regulatory reporting.
    What is a Medical Device File?
    This is a collection of records that demonstrate a device's compliance with the standard and regulatory requirements.
    Does ISO 13485 cover software?
    Yes. If software is used as part of a medical device or as a medical device itself, it must meet the standard's requirements.
    What is "Post Market Surveillance"?
    This is the process of monitoring a medical device's performance after it has been released to the public.

    ISO 42001: Artificial Intelligence

    What is ISO 42001?
    It is the international standard for Artificial Intelligence Management Systems (AIMS).
    Why was ISO 42001 created?
    It was developed to help organizations manage the unique risks and ethical concerns associated with AI technology.
    Does ISO 42001 focus on the technology or the management?
    It focuses on the management system, ensuring that AI is developed and used responsibly and transparently.
    What are the key concerns addressed by ISO 42001?
    It addresses issues such as algorithmic bias, lack of transparency, data privacy, and accountability.
    Can a small startup get ISO 42001 certified?
    Yes. The standard is designed to be scalable for companies of all sizes that work with AI.
    How does ISO 42001 relate to the EU AI Act?
    It provides a practical framework that can help organizations demonstrate compliance with emerging AI regulations.

    ISO 50001: Energy Management

    What is an EnMS?
    It stands for Energy Management System, which is the framework used to improve energy performance.
    What is an Energy Baseline?
    This is a snapshot of energy use over a specific period used as a starting point to measure future improvements.
    What are Energy Performance Indicators (EnPIs)?
    These are quantitative values or measures of energy performance as defined by the organization.
    Does ISO 50001 help save money?
    Yes. By identifying energy waste and improving efficiency, organizations can significantly reduce their utility costs.
    What is the difference between ISO 14001 and ISO 50001?
    ISO 14001 looks at the broad environmental impact, while ISO 50001 focuses specifically on energy efficiency and consumption.

    Advanced and Integrated Questions

    What is ISO 31000?
    This is the international standard for Risk Management. It provides guidelines rather than requirements for certification.
    What is ISO 22301?
    This is the standard for Business Continuity Management, helping companies prepare for and recover from disasters.
    What is a "Gap Audit"?
    This is an informal audit conducted to see how close a company is to being ready for the official certification audit.
    What is an Opportunity for Improvement (OFI)?
    This is a suggestion made by an auditor to help a company enhance its processes, even if there is no non-conformity.
    Can ISO certification help with insurance premiums?
    Some insurance companies offer lower rates to businesses that can prove they have managed their risks through ISO certification.
    What is "Operational Control"?
    This refers to the processes and methods used to ensure that business operations stay within the required limits.
    What is a Document Control process?
    This is the system used to ensure that only the most current and approved versions of documents are used.
    What is the "Auditee"?
    The auditee is the person or department being audited during the ISO assessment.
    What is a Certification Cycle?
    This refers to the three year period between the initial certification and the recertification audit.
    Can ISO standards be used in the public sector?
    Yes. Many government agencies use ISO standards to improve their service delivery and transparency.
    What is "Top Management" in the context of ISO?
    This refers to the people who direct and control an organization at the highest level, such as CEOs or Directors.
    How do I know if a certificate is authentic?
    You can verify a certificate by checking the online database of the accreditation body or the registrar that issued it.
    Where can I find a directory of ISO registrars?
    Websites like isocentral.org provide directories and resources to help you find the right certification partner for your needs.