Why Your Choice of ISO Registrar Matters
Selecting an ISO registrar — also known as a certification body — is one of the most consequential decisions you'll make during your ISO certification journey. The right registrar ensures your certification is internationally recognized, your audit experience is constructive, and your investment delivers long-term value. The wrong choice can lead to wasted money, unrecognized certificates, or an adversarial audit process that demoralises your team.
Whether you're pursuing ISO 9001 for quality management, ISO 14001 for environmental management, ISO 45001 for occupational health and safety, or ISO 27001 for information security, the fundamentals of choosing a registrar remain the same.
What Is an ISO Registrar?
An ISO registrar (or certification body) is an independent, third-party organization that audits your management system against the requirements of an ISO standard and, if you meet those requirements, issues your ISO certificate. They also conduct ongoing surveillance audits (typically annually) and a recertification audit every three years to ensure continued compliance.
For a deeper dive into how registrars work, read our guide: What Is an ISO Registrar?
Step 1: Verify Accreditation — The Non-Negotiable
This is the single most important factor. An accredited registrar has been independently assessed and approved by a national accreditation body that is a signatory to the International Accreditation Forum (IAF) Multilateral Recognition Arrangement (MLA). This means your certificate will be recognized internationally.
What to check
- Is the registrar accredited? Ask them to provide their accreditation certificate and verify it on the accreditation body's website.
- Is the accreditation body an IAF MLA signatory? Check the IAF website to confirm.
- Does the accreditation cover the specific standard you need? A registrar may be accredited for ISO 9001 but not ISO 27001.
- Does the accreditation cover your industry scope (EA/IAF code)? A registrar accredited for construction may not be accredited for healthcare.
Examples of well-known accreditation bodies include UKAS (United Kingdom), ANAB (United States), JAS-ANZ (Australia/New Zealand), and DAkkS (Germany). You can browse accredited registrars in our directory, filtered by accreditation body.
Red flag: Non-IAF accredited registrars
Some organizations offer ISO certificates without legitimate IAF-recognized accreditation. These certificates may not be accepted by customers, regulators, or tender bodies. Always verify accreditation before engaging a registrar.
Step 2: Assess Industry Experience
ISO standards are applied across every industry, but the way they're interpreted and audited varies significantly. A registrar with deep experience in your sector will understand your operational context, regulatory environment, and typical risks — leading to a more relevant and constructive audit.
Questions to ask
- How many organizations in our industry have you certified?
- Can you provide references from clients in our sector?
- Do your auditors hold relevant industry qualifications or experience?
- What EA/IAF codes are you accredited for?
Step 3: Evaluate Auditor Quality and Approach
The auditor assigned to your organization will have a significant impact on your certification experience. A good auditor is thorough but fair, identifies genuine risks, and provides observations that help you improve — not just tick boxes.
What to look for
- Auditor competence: Are auditors qualified (e.g., IRCA-registered) and experienced in your industry?
- Consistency: Will you have the same lead auditor for surveillance and recertification, or will it change each time?
- Approach: Does the registrar take a process-based, risk-based audit approach, or is it purely compliance-focused?
- Feedback from others: What do other certified organizations say about their audit experience?
Step 4: Compare Pricing Carefully
Certification costs vary significantly between registrars, and the cheapest option is rarely the best value. Understanding the pricing structure will help you compare quotes effectively.
Typical cost components
- Application/registration fee: A one-off fee to begin the process.
- Stage 1 audit (document review): A readiness review of your management system documentation.
- Stage 2 audit (certification audit): The full on-site (or remote) audit of your implementation.
- Surveillance audits: Annual audits in years 2 and 3 of the certification cycle.
- Recertification audit: A comprehensive audit every three years.
- Travel and expenses: Some registrars include these; others charge separately.
Use our ISO Certification Cost Calculator to get an indicative estimate of what you should expect to pay, and request free quotes from multiple accredited registrars to compare.
Watch out for
- Unusually low prices — this may indicate insufficient audit days or non-accredited certification.
- Hidden fees for travel, report issuance, or certificate printing.
- Long-term contracts that lock you in with penalty clauses.
Step 5: Consider Geographic Coverage and Logistics
If your organization operates across multiple sites or countries, you'll need a registrar that can manage multi-site audits efficiently. Consider:
- Does the registrar have auditors in your region(s)?
- Can they conduct audits in the language your staff speak?
- Do they offer remote or hybrid audit options?
- How do they handle multi-site sampling?
Our registrar directory lets you filter by geographic coverage to find registrars active in your region.
Step 6: Review the Transfer Process (If Switching Registrars)
If you're already certified and considering switching registrars, the transfer process should be straightforward — but there are rules. The new registrar must review your current certificate, audit reports, and any outstanding nonconformities before accepting the transfer.
Common reasons to switch
- Poor auditor quality or inconsistent auditing approach
- Rising fees without corresponding value
- Registrar losing accreditation for your scope or standard
- Better service, pricing, or industry expertise elsewhere
Step 7: Ask the Right Questions Before Committing
Before signing a contract, have a structured conversation with each registrar you're evaluating. Here's a checklist:
- Confirm their accreditation status and scope (standard + industry EA code).
- Request a detailed, itemised quote covering the full 3-year certification cycle.
- Ask about auditor assignment — will you meet them before the audit?
- Understand their nonconformity grading and close-out process.
- Clarify their policy on remote/hybrid audits.
- Ask about their complaints and appeals process.
- Request client references in your industry.
- Confirm there are no lock-in clauses or penalties for switching.
How to Get Started
Choosing the right registrar takes time, but it's an investment that pays dividends throughout your certification cycle. Here's how to get started today:
- Browse registrars: Use our ISO Registrar Directory to explore accredited certification bodies, filter by standard, accreditation body, and location.
- Estimate your costs: Try our ISO Certification Cost Calculator to understand indicative pricing for your organization.
- Get multiple quotes: Request free quotes from several registrars through our platform to compare pricing and service levels side by side.
- Consider consultancy support: If you're new to ISO, an ISO consultant can help you prepare for certification and navigate registrar selection.
Frequently Asked Questions
Can I use any registrar for ISO certification?
You can, but you should only use a registrar that is accredited by an IAF MLA signatory accreditation body. Using a non-accredited registrar means your certificate may not be recognized by customers, regulators, or procurement bodies.
How much does ISO certification cost?
Costs vary widely depending on your organization's size, number of sites, the standard you're pursuing, and the registrar you choose. Use our cost calculator for an indicative estimate, or get free quotes for accurate pricing.
How long does it take to get ISO certified?
For most organizations, the process takes 3–12 months from the start of implementation to certification. The timeline depends on your existing management system maturity, the standard's complexity, and your available resources.
Can I switch ISO registrars?
Yes. You can transfer your certification to a different accredited registrar at any time, subject to a transfer audit. This is a standard process governed by IAF rules.
What's the difference between a registrar and a consultant?
A registrar audits and certifies your management system. A consultant helps you build and implement the system. They cannot be the same organization — this is a conflict of interest prohibited by accreditation rules.
