01Application & reviewConfirm the standard, scope, sites, activities, organisation size and competence needed for the audit team.
↓02Audit programme & planningDetermine audit time, objectives, criteria, team, locations and the initial three-year certification cycle.
↓INITIAL CERTIFICATION · STAGE 103Stage 1 audit — readiness reviewReview documented information, scope, site conditions, key processes, internal audits and management review to assess readiness for Stage 2.
↓READINESS GATEReady for Stage 2?Stage 1 areas of concern must be addressed before the Stage 2 audit proceeds.
↓INITIAL CERTIFICATION · STAGE 204Stage 2 certification auditEvaluate implementation and effectiveness of the management system, including operational control and conformity with the audit criteria.
↓05Findings & corrective actionRecord audit findings. The organisation analyses causes and provides corrections and corrective actions for nonconformities as required.
↓06Independent certification decisionPersonnel independent of the audit review the evidence and decide whether certification can be granted.
↓07Certificate issuedThe certification document states the client, standard, scope, locations and effective and expiry dates.
↓YEAR 1Surveillance audit 1Sample the system and confirm continuing conformity.
YEAR 2Surveillance audit 2Review performance, changes and selected processes.
BEFORE EXPIRYRecertification auditEvaluate continued fulfilment and effectiveness for a new certification cycle.
↓08Recertification decisionReview the recertification evidence and decide whether certification continues into the next cycle.
Certification is maintained, not simply awarded. Surveillance audits take place during the cycle, while special audits, suspension, withdrawal or scope reduction may apply when circumstances require them.
Official ISO/IEC 17021-1 overview →