Choose a standard because it fits the business
An ISO standard should support a real customer, process, safety, environmental or information-security requirement. Certification should not be treated as a decorative certificate detached from daily operations.
Complete a gap assessment
Compare current processes with the selected standard. Identify missing policies, records, responsibilities, controls, training and review mechanisms. The action plan should be proportionate to the organisation's size and risk.
Implement and record the system
Create only the documents and records that are useful and required. Train the team, operate the controls, review evidence and correct problems before the certification audit.
Check the certification body
Ask who accredits the certification body, what scope will appear on the certificate, how surveillance works and which fees recur. No consultant should promise a valid certificate without the required independent audit process.
Frequently asked questions
ISO develops international standards but does not directly certify organisations. Certification is performed by certification bodies.
Yes, where the selected standard is applicable and the management system is implemented. Documentation can be proportionate to size and complexity.
