What Documents Are Needed for ISO Certification?

What Documents Are Needed for ISO Certification?

As businesses prepare for ISO certification, the question of necessary documentation often looms large. This guide clarifies that it's not about the quantity of paperwork but the quality and relevance of documents in relation to actual operations. Find out what auditors really want to see and how to ensure your management system stands up to scrutiny.

Adarsh
Adarsh
11 min read

One of the most common questions businesses ask before starting ISO certification is:

“What documents do we need for ISO certification?”

There is no single document pack that works for every company.

The documents and records needed depend on the ISO standard, the organization’s activities, its size, risks, processes and certification scope.

More importantly, ISO certification is not about creating a large folder of paperwork. Auditors want to see that the management system is actually being used in day-to-day operations.

Here is a simple overview of the documents and evidence businesses should normally think about before an ISO certification audit.

Do You Need an ISO Manual?

Not every ISO management system standard requires a traditional “ISO manual.”

Some organizations still choose to create one because it provides a useful overview of their management system, but the focus should be on maintaining the documented information that is actually required and useful.

A management system should clearly explain:

  • what the organization does;
  • which processes are included;
  • who is responsible for important activities;
  • how key processes are controlled; and
  • how performance is monitored.

The documentation should reflect the real business rather than being copied from another company.

What Is the ISO Certification Scope?

One of the first things an organization should define is its management system and certification scope.

The scope explains which activities, products, services and locations are intended to be covered.

For example:

Provision of software development and technical support services.

or

Manufacture and supply of industrial electrical components.

A clear scope helps both the organization and certification body understand what will be assessed.

If a company operates from several locations, it should also be clear which sites are included.

Do You Need an ISO Policy?

Management system standards commonly require policies relevant to the subject of the standard.

For example, an organization applying for ISO 9001 certification will normally establish a quality policy.

Depending on the standard, policies may address areas such as:

  • quality;
  • environmental management;
  • occupational health and safety;
  • information security; or
  • other management system commitments.

A policy should not exist only because an auditor may ask for it.

Employees should understand the parts relevant to their work, and management should use the policy to guide the management system.

What Procedures Are Needed for ISO Certification?

Businesses often assume they need dozens of procedures before certification.

That is not necessarily true.

The organization should document processes where documentation is required or where written controls are useful for ensuring consistent operation.

Examples may include procedures or controls for:

  • document management;
  • corrective action;
  • internal audits;
  • operational activities;
  • purchasing;
  • competence and training;
  • customer complaints;
  • risk management; and
  • monitoring and measurement.

The exact requirements depend on the ISO standard and the organization.

A small business should not create unnecessary procedures simply to make its management system look larger.

What Records Will an ISO Auditor Check?

Documents explain how something is supposed to happen.

Records show that it actually happened.

This distinction is important during certification audits.

An auditor may examine records such as:

  • completed internal audit reports;
  • management review records;
  • employee training records;
  • inspection results;
  • maintenance records;
  • customer complaints;
  • corrective action records;
  • supplier evaluations;
  • monitoring results; and
  • performance data.

The exact evidence will depend on the standard and processes being assessed.

Are Internal Audit Records Required?

Internal auditing is an important part of a management system.

Before the certification audit, the organization should normally have completed internal audit activities appropriate to its system.

Internal audits help businesses identify weaknesses before an external auditor does.

A useful internal audit should show:

What was audited?
Which process or area was reviewed?

Who performed the audit?

What evidence was examined?

Were any problems found?

What action was taken?

Internal auditing should be treated as a management tool rather than a form completed only for certification.

What Is Management Review?

Management review demonstrates that senior management is actively evaluating the management system.

During management review, leadership may consider information such as:

  • audit results;
  • performance against objectives;
  • customer feedback;
  • nonconformities;
  • corrective actions;
  • organizational changes;
  • resource needs; and
  • opportunities for improvement.

The organization should maintain appropriate evidence that management review has taken place.

This can include meeting records, minutes, reports or another suitable form of documented information.

Do You Need Employee Training Records?

Organizations need to ensure that people performing relevant work are competent.

An auditor may therefore review evidence relating to employee competence.

This could include:

  • training records;
  • qualifications;
  • experience;
  • competency assessments;
  • licences where applicable; and
  • job-specific authorization.

Having an attendance sheet alone does not necessarily prove competence.

The organization should be able to explain how it determines whether employees are capable of performing their assigned responsibilities.

What About Risk Assessment Documents?

Risk-based thinking is an important element of modern management system standards.

The exact approach varies depending on the standard.

Organizations should be able to demonstrate how they identify and address relevant risks and opportunities.

This does not always require a complicated risk register.

What matters is that risks relevant to the management system are understood and appropriately managed.

For some standards, more specific risk assessment requirements may apply.

Do You Need Corrective Action Records?

Problems happen in every organization.

A strong management system does not pretend that problems never occur. Instead, it provides a structured way to identify and address them.

Corrective action records may show:

  1. What went wrong?
  2. Why did it happen?
  3. What action was taken?
  4. Was the action effective?

Auditors may review corrective actions resulting from complaints, internal audits, process failures or previous external assessments.

Should You Prepare Documents Just for the ISO Audit?

No.

One of the biggest mistakes businesses make is creating documents immediately before the certification audit simply because they think an auditor expects to see them.

This can create a management system that looks good on paper but does not reflect actual operations.

Instead, documents and records should support normal business processes.

If employees follow one process while the written procedure describes something completely different, the documentation may create problems rather than solve them.

How Much Documentation Is Enough?

The right amount depends on the organization.

A small service company may need a simpler documentation structure than a large manufacturing business operating several sites.

The goal should be:

Enough documentation to control the management system effectively, but not unnecessary paperwork that nobody uses.

Good documentation should be easy to understand, current and relevant to the people who use it.

What Should You Have Ready Before an ISO Audit?

Before the certification audit, businesses should check that they can provide evidence of a functioning management system.

A useful readiness check includes:

  • defined certification scope;
  • applicable policies;
  • documented processes where needed;
  • management system records;
  • internal audit evidence;
  • management review evidence;
  • objectives and performance information;
  • employee competence records;
  • corrective action records; and
  • evidence that day-to-day activities follow the management system.

The exact documentation required will depend on the ISO standard being assessed.

Choosing an ISO Certification Body

Preparing documents is only one part of the certification process.

Organizations should also choose an independent certification body and check factors such as accreditation, applicable accreditation scope, impartiality and auditor competence.

Guardian Assessment Private Limited operates as Guardian Certification and provides management system certification and other conformity assessment services.

Businesses researching the organization can review the public Guardian Assessment Private Limited business profile for additional company information.

For any specific ISO standard, organizations should also verify the current applicable accreditation scope before proceeding with certification.

Final Thoughts

ISO certification does not require businesses to create paperwork for the sake of paperwork.

The purpose of documented information is to support a management system that works.

Instead of asking:

“How many documents do we need?”

a better question is:

“Can we clearly demonstrate that our management system is implemented and working?”

When policies, procedures, records, internal audits, management reviews and operational evidence reflect what actually happens in the business, the organization is in a much stronger position for an independent certification audit.

More from Adarsh

View all →

Similar Reads

Browse topics →

More in Business

Browse all in Business →

Discussion (0 comments)

0 comments

No comments yet. Be the first!