What Are the Steps of the ISO 9001 Registration Process?

What Are the Steps of the ISO 9001 Registration Process?

You have made the plans, built the quality system, and conducted internal audits. The next test is independent: can an accredited certification body verify that your Quality Management System meets ISO 9001 requirements and works in practice?

The ISO 9001 Registration Process, more commonly called the certification process, follows eight practical steps. Knowing the proper steps helps you choose the right certification body, prepare for the assessment audit, and get more value from your investment.

What Is the ISO 9001 Certification Process?

ISO 9001 certification is an independent confirmation that your organization’s quality management system conforms to the applicable standard. ISO develops and publishes standards, but ISO does not certify organizations or issue certificates. An external certification body performs the audit and makes the certification decision.

Eight-stage ISO 9001 certification roadmap on an office monitor

Many organizations still call the certification body a registrar and describe the work as ISO registration. Both terms are understood, but certification body and certification are the current terms used by ISO and accreditation organizations. The process begins after your company has built and tested its quality system, completed internal audits, and addressed important readiness gaps.

ISO 9001:2015 remains the published edition while a new edition proceeds through ISO’s publication process. Confirm the applicable edition and transition timing with the certification body before signing a contract, especially if your audit falls near a standards transition.

1. Find an ISO 9001 Certification Body

Begin searching for an ISO 9001 certification body while your company is still building and validating its QMS. Starting early gives you time to compare accredited scope, availability, audit timing, and the experience needed for your industrial sector.

Accreditation bodies evaluate certification bodies for competence, consistency, and impartiality. Accreditation bodies maintain directories of the registrar organizations that they accredit. In the United States, use the ANSI National Accreditation Board directory of management systems certification bodies. ANAB was formerly known as the ANSI-ASQ National Accreditation Board, which is why older material may use that name.

In Canada, consult the Standards Council of Canada directory of accredited organizations. Organizations in other countries can start with the relevant national accreditation body or use the current list of ISO member bodies to locate national standards contacts.

2. Select an ISO 9001 Certification Body

Select a certification body with accredited scope and experience relevant to your industry. Some certification bodies cover many sectors, while others specialize. Ask the organization to confirm that its accredited scope covers your operations, products, services, and locations.

ISO 9001 certification body comparison workspace on a laptop

Accreditation and technical qualifications come first, but the overall experience a client gets with a registrar also matters. Keep in mind accreditation, scheduling issues, fees, travel expenses, surveillance costs, and comfort level. Compare the interpersonal skills of the auditors, office support, the ability to get questions answered, whether audits are a value-added experience, and flexibility in adjusting dates with reasonable notice. Ask how the audit team will be selected and whether it has experience in your industrial sector.

Certification-body independence is another key consideration. The body must protect impartiality and avoid conflicts that would make it audit its own consulting work. You can ask how the organization manages consultancy relationships, auditor assignments, appeals, and complaints before you commit.

3. Complete an ISO 9001 Application

Your company and the certification body will complete an application and agree on an application contract. This important step defines the rights and obligations of both parties, including liability issues, confidentiality, access rights, the proposed certification scope, covered sites, audit time, fees, and rules for using the certification mark.

ISO 9001 application and certification contract checklist on a monitor

Give the certification body accurate information about employee count, shifts, outsourced processes, remote activities, products, services, locations, and any exclusions you believe apply. Incomplete scope information can change the audit plan, cost, and schedule later.

4. Complete the Stage 1 Document and Readiness Review

Initial certification normally includes Stage 1 and Stage 2. During Stage 1, the certification body reviews your readiness, scope, site conditions, internal audits, management review, and the documented information needed to understand the quality management system. ISO 9001:2015 does not specifically require every organization to maintain a quality manual, but a clear quality manual can still help when it accurately describes the system.

Allow enough time for the audit team to review the system and for your organization to resolve readiness concerns before Stage 2. Timing varies with scope, complexity, site count, available evidence, and certification-body scheduling, so treat any two-to-four-week estimate as a planning range rather than a universal rule.

5. Determine Whether You Need a Pre-Assessment

A pre-assessment is an optional review that can identify significant omissions or weaknesses before the formal certification assessment. It may save time by exposing gaps in implementation, records, logistics, or employee readiness while your organization can still correct them.

Do not confuse an optional pre-assessment with the required Stage 1 audit. Ask the certification body what it offers, what limits apply, and how it protects impartiality. The body may evaluate whether the quality system and documentation meet requirements, but it cannot design the system and then independently certify its own work.

6. Conduct the Registration Assessment Audit

Stage 2 is the main registration assessment audit. This may include a physical onsite inspection of procedures in action, remote audit activity where accepted, personnel interviews, record review, and objective evidence showing whether the QMS is implemented and effective. The length and delivery method depend on the audit scope, site count, risk, complexity, and size of your organization.

Lead auditor reviewing an ISO 9001 assessment agenda and evidence checklist

ISO 9001 Audit Activities

In general, the flow of activities during an ISO audit process includes:

  1. Opening meeting. The audit team and key personnel confirm the scope, schedule, communication methods, and general approach. This is the time to clarify anything unclear and communicate last-minute operational changes.
  2. Brief facility tour. Auditors get a practical view of the layout, processes, interfaces, and areas included in the certification scope.
  3. Additional document review. Audit team members review documented information and records for the areas they will audit.
  4. Examination. Personnel are interviewed and objective evidence is collected to determine whether the system has been effectively implemented.
  5. Daily review. At the end of each day or the beginning of the next, the audit team reviews issues identified during the assessment. Potential findings or nonconformities can be clarified while evidence is still available.
  6. Closing meeting. The team states its conclusions regarding the audit and presents findings, nonconformities, and observations, along with the next steps in the certification process.
  7. Audit report. The certification body issues a report documenting the audit scope, evidence, conclusions, and any required responses.

ISO 9001 Audit Findings

If auditors find that the system does not meet the standard or your own procedures, they document findings and classify nonconformities according to the certification body’s rules. Your organization must respond with corrections, root-cause analysis, and appropriate corrective action for nonconformities.

ISO 9001 audit findings and corrective action register on a monitor
  • A minor nonconformity is a limited failure that does not indicate a broad breakdown of the Quality Management System.
  • A major nonconformity indicates a significant failure, absence of an effective required process, or a condition that creates serious doubt about the system’s ability to achieve intended results.

Certification generally cannot proceed while major nonconformities remain unresolved and unverified. Minor findings also require an accepted corrective action plan, but the exact evidence, timing, and follow-up depend on the certification body’s procedures. A focused re-audit of the involved areas may be required, with associated costs, when the body needs additional objective evidence.

ISO 9001 Auditors

ISO auditors work for or contract with certification bodies to perform registration assessments and surveillance audits. They are the front line of the process. The certification body is responsible for ensuring that auditors meet training, audit, and industrial-sector competence requirements.

ISO 9001 auditor reviewing competency records and objective evidence

Verify credentials when a person claims a professional auditor certification. Ask for current proof and confirm the credential with the issuing organization when possible. For ASQ credentials, the ASQ Certification Verification Registry is the current verification resource.

Auditors collect objective evidence and make recommendations. The certification body reviews the audit report, responses, and supporting evidence and makes the ultimate certification decision.

7. Complete the ISO 9001 Registration

After the audit report is complete and required nonconformities are addressed, the certification body conducts an independent review and decides whether to issue the certificate. Once approved, your company can register as ISO 9001 certified and may be listed in a register. Follow the body’s rules when you publicize the registration or use the certification in advertising.

Review the certificate carefully. Confirm the organization’s legal name, covered sites, certification scope, standard edition, issue and expiry dates, certificate number, and the certification body’s accreditation information. Keep the certificate and related audit records controlled and available for customers or other stakeholders who need to verify the claim.

8. Complete Surveillance Audits and Recertification

Certification is not a one-time event. During the three-year certification cycle, the certification body performs surveillance audits to confirm that the system is maintained, changes are controlled, and previous findings remain effectively addressed. Before the certificate expires, a recertification audit supports the next certification decision.

Three-year ISO 9001 surveillance and recertification calendar on a wall display

Audit frequency and coverage can vary with the certification program, organizational changes, prior performance, and risk. Treat each surveillance audit as a source of valuable feedback. Close corrective actions, monitor process results, and use continual improvement in ISO 9001 to strengthen the system between visits.

What Should You Consider Before ISO 9001 Registration?

Document review, readiness work, and pre-assessment timing depend on the size and complexity of your organization. The number of audit days also depends on scope, employee count, sites, shifts, risk, and the certification body’s program. Set realistic target dates so both your team and the audit team can prepare without rushing evidence or corrective action.

The registration and audit process should provide more than a certificate. It should give you valuable feedback about whether the quality system works and where it can improve. Consider the reasons for ISO 9001 certification, the full cost of the certification cycle, and the return on investment you expect.

Strong preparation combines controlled documented information, competent people, completed internal audits, management review, and verified corrective actions. A well-maintained ISO 9001 procedures framework can support that work when it is adapted to the organization’s actual processes and applicable standard.

Frequently Asked Questions

What Is the ISO 9001 Certification Process?

The ISO 9001 certification process is an independent assessment of an organization’s Quality Management System by a certification body. It includes application and scope review, Stage 1 and Stage 2 audits, corrective action where needed, a certification decision, surveillance, and recertification.

How Do You Choose an Accredited ISO 9001 Certification Body?

Confirm that the certification body’s accredited scope covers your industry and operations. Compare competence, scheduling, total fees, surveillance costs, support, impartiality, auditor experience, and the overall client experience.

What Happens During Stage 1 and Stage 2 Audits?

Stage 1 reviews scope, readiness, documented information, internal audits, and management review. Stage 2 evaluates implementation through interviews, records, observation, and objective evidence before the certification body makes its decision.

Can a Certification Body Help Implement Your Quality Management System?

A certification body can explain its audit process and identify nonconformities, but it must protect impartiality. It cannot design the system and then independently certify its own consulting work.

What Happens After ISO 9001 Certification?

The organization maintains the QMS, closes findings, monitors results, and completes surveillance audits during the certification cycle. A recertification audit is completed before certificate expiry to support the next certification decision.

Discover Dash

Best Manual Deals