- Home
- Certification
- Nine steps, and three people who must not be the same person.
Nine steps, and three people who must not be the same person.
ISO/IEC 17021-1:2015 separates the audit, the technical review and the certification decision. That separation is what a certificate is worth, and it is the reason the cycle looks the way it does.
From application to renewal.
Application and review
Scope, sites, headcount, shifts, processes and any outsourcing are established in writing. This determines audit time; an inaccurate application produces an audit programme that will not survive Stage 1.
Client and bodyContract and audit programme
The certification body confirms competence for the scope, determines audit time and appoints an audit team with no conflict of interest.
Certification bodyStage 1 — readiness
Documentation, internal audit, management review, site conditions and the scope as stated. The output is a written statement of what must be in place before Stage 2, and when.
Audit teamStage 2 — implementation
Evidence that the system is implemented and effective, gathered on site through interview, observation, record sampling and process walkthrough.
Audit teamFindings and correction
Nonconformities are stated with the requirement and the evidence. The organisation submits correction, root-cause analysis and corrective action; the body verifies effectiveness, not intention.
Client, then bodyIndependent technical review
A competent reviewer who took no part in the audit examines the file for completeness, consistency and whether the evidence supports the recommendation.
Independent reviewerCertification decision
Taken by authorised personnel who neither audited nor reviewed. The certificate is issued with a scope, sites and validity that match exactly what was assessed.
Authorised decisionSurveillance
Periodic audits confirm continued conformity and address changes to scope, sites, personnel, complaints and use of the mark.
During the cycleRecertification
A full review of performance across the whole cycle before renewal — not a repeat of Stage 2, and not a formality.
End of cycle
What certification is not.
A certification audit
What it does- Tests whether a management system meets a standard and is effective.
- Samples evidence against the audit programme.
- Reports nonconformities against stated requirements.
- Leads to a decision by someone independent of the audit.
Consultancy
What the same body must not do- Design or write the management system it will certify.
- Provide specific solutions to the nonconformities it raised.
- Train the organisation on implementing its own system in a way that amounts to consultancy.
- Certify a system it built — under any group or brand arrangement.
The rest of the certification route
Describe the claim — not the service.
Tell us what must be relied on, who will rely on it and by what date. We will confirm the correct programme, evidence requirement and responsible entity — or tell you it is outside our scope.
