ISO audit
- Hours of preparation in total
- 48
- Requirements in scope
- 30
- Evidence items to find and file
- 90
Every figure here comes from the figures you enter and the method stated beside it: your scope, your evidence per requirement, your minutes per item, your people and your weeks. Where a guide names a published figure it names the source and the date it was read. This site publishes no opinion on whether you will pass: what an auditor will accept is the auditor's decision on the day, and the standards and rules cited on each guide are where the preparation starts, not the verdict.
An ISO audit is the visit at which a certification body, or your own internal auditor, tests whether the management system you wrote down is the one you run. For a business with a certificate that is a stage one and stage two audit to get it, a surveillance audit each year to keep it and a recertification audit at the end of the cycle, and an internal audit of the whole system somewhere in between. Most of the findings raised at any of them are not about the work being done badly; they are about the record that shows it was done being somewhere nobody can find on the day. This page sets out what an ISO audit tests, how the audited business prepares for it, and what it costs to keep the findings as a record rather than a closing-meeting memory.
Open the Audit preparation checklist Free to use. No account, no card, no trial clock.
Size the audit from the scope letter
The certification body's plan names the clauses and the sites in scope and the days it will take; an internal audit plan names the processes. The free preparation checklist on this site turns either into the evidence items to gather and the hours per owner per week before anyone starts pulling records.
File the evidence against each requirement
For each clause or control the auditor wants the procedure, a record of it being followed and a record of it being checked. Filing the three against the requirement, with a location and an owner, is the preparation; a well-run business that skips this step still collects findings for records it has but cannot produce.
Close every finding with an owner, a date and the evidence of closure
A minor nonconformity from the surveillance audit that is still open at the next one becomes a major, and a major left open suspends the certificate. Recording each finding against its requirement with a corrective action, an owner and a due date, and dating the closure with the evidence, is what the next auditor opens the visit by asking for.
Will it hold your audit programme, beyond the ISO audit?
Tell us which audit is coming, what you have to show for it today, and what went wrong last time.
What the person preparing for the audit asks before running the ISO audit
Is an ISO internal audit the same as the certification audit?
No. The internal audit is one the business runs on itself, and every management system standard requires it. The certification audit is run by an accredited certification body and is what the certificate rests on. The internal audit is the rehearsal, and its findings closed before the visit are the ones that never become the certification body's.
How far ahead should an ISO audit be prepared for?
From the day the plan or scope letter arrives, because the load per evidence owner per week is what decides whether the date holds. The free checklist gives that figure in five minutes, and a high one is the signal to add owners, narrow the scope or talk to the certification body early.
Does Capanix tell me whether I will pass?
No. It sizes the preparation and keeps the record of the audits, findings and corrective actions. Whether a particular auditor accepts a particular piece of evidence is their decision on the day, and the standards cited on this page are where the preparation starts.