Morgan Compliance Group
What Happens During an ISO Certification Audit? Stage 1, Stage 2 and Beyond
An ISO certification audit is an independent assessment carried out by an accredited certification body to check whether a management system meets the requirements of the relevant standard and is genuinely being followed in practice, not just documented. First certification normally involves two stages, followed by periodic surveillance audits and eventual recertification.
Book a Free ConsultationReviewed by Daniel Morgan, TechIOSH - Last reviewed 2026-09-24
Stage 1 is a readiness review. The certification body checks that management system documentation exists, covers the intended scope, and that the business is genuinely prepared for a full assessment. Significant gaps identified here are usually raised before Stage 2 proceeds, giving the business a chance to address them.
Stage 2 is the main assessment. The auditor examines evidence that the system is implemented and operating in practice - typically through site visits, staff interviews, and sampling records - rather than reviewing documents in isolation. This is where the difference between a system that exists on paper and one that is genuinely followed becomes apparent.
Following certification, surveillance audits are carried out periodically, usually annually, to confirm the system continues to operate effectively between full assessments. These are generally narrower in scope than the original Stage 2 audit but still involve site visits and evidence sampling.
A full recertification audit takes place at the end of the three-year certification cycle, reassessing the whole system against current requirements, including any changes to the standard itself since the original certification.
Throughout this process, findings are categorised by severity. Understanding this distinction matters, since it determines what response is expected and how quickly.
Frequently asked questions
What happens if the auditor finds a problem?
Findings are usually categorised by severity. Minor findings normally require a corrective action within an agreed timeframe, while major findings can delay or prevent certification until resolved.
How long does a certification audit take?
This depends on business size, number of sites and scope, but a single-site business audit is often completed within one to two days for each stage.
Can a business fail a surveillance audit and lose certification?
Yes, if significant non-conformities are found and not adequately corrected within the certification body’s required timescale, certification can be suspended or withdrawn.
What is the difference between Stage 1 and Stage 2?
Stage 1 checks readiness and documentation; Stage 2 is the full assessment of whether the system is genuinely implemented and operating as documented.
How often does recertification happen?
Typically every three years, with annual surveillance audits in between, though this can vary by certification body and standard.
Can a business choose which certification body carries out the audit?
Yes, provided the chosen body holds suitable UKAS accreditation (or equivalent recognised accreditation) for the relevant standard and technical scope.
Related
How we can help
Explore ISO Management Systems for practical support.
Need ongoing advice? See Monthly Safety Support.
Not Sure Where to Start?
Book a free consultation and explain what your business is trying to achieve. Morgan Compliance Group will help identify the most practical next step.
Book a Free Consultation
