An independent, third-party certification body · operating to ISO/IEC 17021-1:2015
Verify a Certificate ↗·Global · Remote & on-site·EN
Certification

What ISO 9001 actually asks of you

Most organisations meet ISO 9001 for the first time in a tender document. A buyer asks for it, the deadline is three weeks away, and someone is sent to find out what it involves.

By that point the answer is usually the wrong one: certification takes months, not weeks, and it cannot be produced retrospectively. The organisations that win those tenders started eighteen months earlier, often for reasons that had nothing to do with tendering.

This is what the standard actually asks for.

The idea underneath it

ISO 9001 is a quality management standard, which is an unhelpful phrase because most people hear quality and think inspection. It is not about checking work at the end.

The standard asks a narrower and more useful question: can your organisation produce the same result every time, and can you show how?

That is the whole idea. Not paperwork for its own sake. A documented way of working that means the job you did well last year is the job you will do well next year, whoever happens to be on site, and whether or not the person who originally set it up still works for you.

The certificate is not the point. The certificate is evidence that the system exists and is being used.

What the standard requires

In outline, ISO 9001 asks you to:

  • Understand what your organisation does and who depends on it
  • Identify the risks that would stop you delivering, and decide what to do about them
  • Define how work is actually carried out, in enough detail that it can be repeated
  • Keep records that show it was carried out that way
  • Check the system yourself, at intervals, and act on what you find
  • Have leadership accountable for it, not delegated to a filing cabinet

Almost every organisation already does most of this. What certification adds is that it is written down, applied consistently, and verified by someone who does not work for you.

An inspector recording measurements on a clipboard in a workshop
Records are the difference between doing the work and being able to show it.

What changes in practice

Tenders. Many buyers will not accept a bid from an uncertified supplier. Government procurement, mining, and anyone trading internationally increasingly treat it as a threshold requirement rather than a differentiator. No certificate, no seat at the table.

Rework. Most quality failures are process failures rather than people failures. When the same mistake happens three times with three different people, the process is the cause. A documented system makes that visible, and work done twice is money already spent.

Two workers examining a manufactured component together
When the same fault appears three times with three different people, the process is the cause.

Continuity. Organisations that depend on a handful of experienced people carry a risk they rarely price. When one of them leaves, the knowledge leaves too. A management system is, among other things, an insurance policy against that.

Confidence. Your customer cannot audit you themselves. An accredited certificate is how they know without having to check.

It is a cycle, not an event

This is the part most often misunderstood, and it matters for budgeting.

Certification runs on a three-year cycle. An initial assessment in two stages, then a surveillance audit each year to confirm the system is still operating, then a full reassessment before the cycle renews.

When each audit falls across the three-year cycle
Stage 1 — documentation review 1 month in
Stage 2 — on-site assessment 3 months in
First surveillance audit 12 months in
Second surveillance audit 24 months in
Recertification 36 months in

Source: ISO/IEC 17021-1:2015 — the three-year certification cycle

The audits are not a formality. A certificate can be suspended or withdrawn if the system has stopped being used, and a certification body that never withdrew one would not be worth much. Certification is a state you maintain, not a document you own.

What it does not do

An honest account has to include this.

ISO 9001 does not certify your product. It certifies the management system around it. A certified organisation can still ship a defective unit; what the standard asks is that the organisation notices, records it, finds the cause, and changes something.

It also does not make you better than an uncertified competitor. It demonstrates that you have a system and that an independent party has examined it. Whether you use that system well is up to you.

Anyone who tells you otherwise is selling something.

Where it starts

It starts with scope. Before an audit, before documentation, before anything else, you decide what is being certified: which activities, which sites, which parts of the business. That scope is what appears on the certificate, and it is what a customer reads when they check it.

Get the scope wrong and the certificate says something you did not intend.

If a tender has ever asked you for ISO 9001, you already know what it costs not to have it. The question is whether the next one finds you ready.