ISO Certification Audit Process




Overview
The ISO/IEC 27001:2022, 27701:2019, ISO/IEC 42001:2023, and 9001:2015 certification standards provide a model for establishing, implementing, operating, monitoring, reviewing, maintaining, and improving an Information Security Management System (ISMS), Privacy Information Management System (PIMS), Artificial Intelligence Management System (AIMS), or Quality Management System (QMS), respectively.
The design and implementation of a management system is driven by the organization’s needs and objectives, security requirements, processes employed and its size and structure. Management systems and their supporting processes are expected to change over time, and the implementation will be scaled in accordance with the needs of the organization.
Certification depends on the conformity of an organization’s management system to the applicable ISO standard.
This guide provides an overview of the ISO certification audit process, from initial certification through surveillance and recertification, for organizations pursuing ISO/IEC 27001, ISO/IEC 27701, ISO/IEC 42001, or ISO 9001 certification.
Scope of Certification
The ISO standards do not establish scope requirements; however, a critical component of the certification process is determining the scope of the audit. The scope of certification is determined by the organization itself and may include a specific application, service, or department within the organization, or the organization as a whole.
The requirements of the applicable standard will be audited only within the scope of the management system as defined. When a certificate is issued, it will include the organization’s scope statement for the associated management system.
ISO Certification Process
If the organization is not presently certified to ISO/IEC 27001, 27701, ISO/IEC 42001, or ISO 9001:2015, the audit and certification process has several components:
Initial Certification Audit – Stage 1
The initial certification audit consists of two stages. The first stage is an initial review by the auditor to determine the readiness of the defined management system to undergo a full audit.
Initial Certification Audit – Stage 2
The second stage of the initial certification audit includes interviews, observation, and testing to determine whether the management system has been implemented effectively, and is operating in conformity with the requirements of the applicable ISO standard. At the conclusion of this stage, LBMC’s internal certification review will approve or deny certification based on the audit results and recommendation of the auditor. Audit findings may include nonconformities that must be addressed before the certificate can be issued.
Surveillance Audit
ISO certification is valid for up to a three-year certification cycle following initial certification. Surveillance audits are conducted in years one and two of the cycle. Surveillance audits are conducted to identify significant or relevant changes to the scope of the certified management system and include targeted testing to confirm that the organization is effectively managing and maintaining the certified management system(s). The audit duration is generally one-third of the initial certification audit but may be impacted by changes to the scope of certification.
Re-Certification
At the conclusion of the initial certification cycle, and of each subsequent cycle, re-certification audits are performed to confirm ongoing effective management of the certified management system. As with surveillance audits, the duration of the audit, generally two-thirds of the initial certification audit time, may be impacted by changes to the scope of certification at the time of re-certification.
Special Audits
A special audit may be conducted at any time throughout the certification cycle for reasons including but not limited to the following:
- Expansion of certificate scope, e.g., additional locations, personnel, services, etc.
- Extension of certification to include other standards.
- Audit of corrective actions from previous audits or follow-up audit for suspended certification.
Audit Timing
The required time for any of the audits listed above is strongly dependent on the size of the organization’s scope of certification, i.e., number of personnel, locations, services, etc., and the extent to which the management system conforms to the requirements of the associated standards. Some organizations might be prepared for initial certification within a few months of beginning management system implementation efforts, whereas more complex organizations and management systems may require a longer period to prepare for and achieve certification. LBMC will request an engagement application to determine the organization’s readiness for audit and estimate audit duration and timing.
ISO Certification Conditions
In accordance with ISO/IEC 17021-1:2015, LBMC has established the following processes and conditions for issuing and maintaining certifications to accredited ISO standards:
Granting or refusing certification
All initial and recertification audits, as well as any surveillance, follow-up, or special audits resulting in the issuance of a new or revised certificates, require review and approval by LBMC’s internal Certification Committee. The Certification Committee reviews the audit report prior to making the decision to grant or refuse certification. Prior to deciding whether to grant certification the committee will ensure:
- The information provided is sufficient with respect to the certification requirements and the scope of certification.
- Major nonconformities have been reviewed, and the associated corrections and corrective actions have been verified.
- Correction and corrective action for any minor nonconformities have been reviewed and accepted by the auditor.
Failure to meet any of these criteria will result in refusal of certification by the certification review.
Maintaining and renewing certification, and expansion or reduction of scope
All certificates will be maintained in accordance with the certification process provided above. Clients may request changes to certification for reasons including but not limited to:
- Change in ownership.
- Change in name of the company.
- Change in location.
- Increase or decrease in scope (personnel, locations, services, etc.).
Clients may submit certification change requests to LBMC at any time. LBMC will review requests and determine whether a special audit is necessary or if changes can be audited at the next annual audit. LBMC will also determine if changes are within the accreditation scope of LBMC.
Following a successful audit of the changes, a revised certificate will be issued as appropriate. In most cases this does not change the initial certification date or the certification cycle.
Suspending, withdrawing, and restoring certification
The following are considered sufficient grounds for certificate suspension or withdrawal:
- Major nonconformities or effective correction action plans are not implemented within a specified time.
- Improper use of the certificate, symbol or logo not corrected to the satisfaction of LBMC.
- Client ceases to supply product or service of the certified management system for an extended period.
- Client’s certified management system has persistently failed to meet any of the requirements for certification including requirements for the effectiveness of the management system.
- Client makes a formal request to withdraw certification.
- Infringement by the client of any contractual conditions between the client and LBMC.
- Client is unable or unwilling to ensure conformance to standards revisions.
- Receipt of a serious complaint, or a significant number of second- or third-party complaints, indicating that the management system is ineffective.
- Client does not allow routine surveillance audits to be conducted at the required frequency.
Suspension procedures through withdrawal of certification are as follows:
- Grounds for action are brought to the attention of the client’s Engagement Partner, who reviews the information and decides whether to proceed. The Engagement Partner issues a letter to the client advising them of the details of the grounds for action and the decision on whether to proceed.
- If the Engagement Partner decides to proceed, the client must reply to LBMC within fourteen days of advisory letter issuance.
- If the Engagement Partner determines that the action or position contained in the client’s response is satisfactory, they issue a letter to the client stating this via email or registered mail.
- Due dates will be established for corrective actions, and the Engagement Partner must review the actions at those times to ensure that they are effectively completed to prevent suspension or cancellation.
- If the client does not reply within fourteen days, or if the reply is not satisfactory, or if corrective actions are not effectively completed by the due date, the Engagement Partner determines whether to suspend or withdraw certification.
- If the decision is made to withdraw certification, the Engagement Partner is responsible for suspending the client or canceling the client from the Certificate Registry, and advising the client by email or registered mail.
Project and Personnel Level Impartiality Policy
LBMC evaluates and achieves impartiality in two primary ways: first, we perform a risk assessment, at a minimum annually, to evaluate the risk to overall organization level impartiality and evaluate the safeguards in place to protect against those risks. Second, on a project-by-project basis, we evaluate conflicts of interest related to a specific client and project.
Organization level impartiality evaluation and risk analysis
The organization level risk analysis is completed by the QA Manager with the assistance of the entire LBMC ISO team. The process to identify, analyze, evaluate, treat, monitor, and document the risks related to conflict of interests arising from certification, including any conflicts arising from business and personal relationships, is performed on an ongoing basis. The risk assessment is required to identify all threats to impartiality and to document threats, risks, risk treatment, and residual risk in a matrix format.
LBMC recognizes the following potential threats to impartiality:
- Self-interest threats:threats that arise from person or enterprise acting in their own interest, for example financial self-interest.
- Self-review threats:threats that arise from a person or enterprise reviewing the work done by them.
- Familiarity (or trust) threats:threats that arise from a person or body being too familiar or trusting of another person instead of seeking evaluation evidence to base the audit conclusion on.
- Intimidation threats:threats that arise from a person or enterprise having a perception of being coerced openly or secretively, such as a threat to be replaced or reported to a supervisor.
- Conflicts of Interests:threats that arise because of relationships between LBMC Certification Services and other interested parties or with the parent company, LBMC PC, who might provide ISMS or PIMS management system consultancy services to a client.
- Financial Pressure:threats that arise because a client’s certification decision may result in financial loss to LBMC Certification Services.
- Other threats known or unknown.
The impartiality risk analysis is presented annually to LBMC’s Impartiality Committee to allow input from interested stakeholders.
Project and Personnel Level Impartiality Procedures
All personnel are required to comply with LBMC’s independence, integrity, and objectivity policies. Personnel complete periodic independence representations, disclose any actual or potential conflicts of interest, and review client relationships to help ensure auditor independence throughout the certification process.
The Engagement Partner is responsible for identifying risks to the impartiality for each client. If a risk is identified, the Engagement Partner will document the risk and the measures taken to eliminate or minimize the risk. This includes those risks that arise from LBMC’s activities, relationships, or from the relationships of LBMC personnel.
A relationship that threatens our impartiality can be based on ownership, governance, management, personnel, shared resources, finances, contracts, marketing (including branding), and payment of a sales commission or other inducement for the referral of new clients, etc.
If a member of the audit team, or an immediate family member, has a direct financial interest or a material indirect financial interest in a client, the resulting self-interest threat is considered significant. To eliminate or reduce the threat to an acceptable level, one of the following safeguards must be implemented:
- Dispose of the direct financial interest prior to the individual becoming a member of the audit team;
- Dispose of the indirect financial interest in total or dispose of a sufficient amount of it so that the remaining interest is no longer material prior to the individual becoming a member of the audit team; or
- Remove the member of the audit team from the audit engagement.
If a threat to impartiality is identified before or during an audit, the matter is immediately reported to the Engagement Partner for evaluation. Appropriate safeguards are implemented to eliminate or reduce the threat to an acceptable level. Depending on the circumstances, safeguards may include resolving the conflict of interest, reassigning audit personnel, or discontinuing the audit engagement.
Our Award-Winning Team
We have assembled an exceptional and dedicated team of cybersecurity professionals that clearly differentiates LBMC from other ISO certification service providers. Their backgrounds include time spent with national and regional accounting and consulting firms and direct industry experience.
If you have questions, you can contact Brian Willis, Shareholder at LBMC by using the form below.