Skip to content
VISCOUNTQuality Certifications

How certification works

How certification works

You will know the scope, the audit dates and the fee before you commit to anything.

What the sequence looks like
  1. 01Client's information
  2. 02Proposal preparation
  3. 03Payment
  4. 04On-site audit
  5. 05Certificate

The three-year certification cycle

A certificate is valid for three years, and the cycle is what keeps it valid: certification, a surveillance audit in each of the two following years, then recertification before it expires.

  1. 01

    Stage 1 and Stage 2

    Certification

    Two stages. Stage 1 is a document review and information gathering exercise; Stage 2 is the audit that determines certification.

    • Stage 1 — document review and information gathering
    • Stage 2 — the certification audit itself
    • Nonconformities raised in writing, with a response window
    • An independent certification decision, made by someone who did not conduct the audit
  2. 02

    First follow-up audit

    1st Annual Surveillance

    A follow-up audit in the first year of the cycle, confirming the system is still operating and that corrective actions were effective.

    • Verification that previous nonconformities were closed at root cause
    • Review of internal audit and management review records since certification
    • Sampling of the areas most likely to have drifted
  3. 03

    Second follow-up audit

    2nd Annual Surveillance

    The second follow-up audit, in the final year before recertification, covering the parts of the system not sampled in year one.

    • Coverage of clauses and sites not sampled at the first surveillance
    • Review of any scope, site or organizational changes
    • Confirmation that certification marks are being used correctly
  4. 04

    Renewal audit for the next cycle

    Recertification

    A renewal audit before the certificate expires, assessing the whole management system and its performance across the full three years.

    • Assessment of the complete management system, not a sample
    • Review of performance and improvement across the cycle
    • A new certificate issued for the next three-year cycle

The audit process, step by step

Four phases, eight steps, in the order you will experience them. Nothing is scheduled and nothing is invoiced before you have agreed a written scope.

Customer information

Phase 1

  1. Informative questionnaire

    You tell us the standard, your headcount, your sites and the processes to be covered. This is what audit duration is derived from, so it decides the fee.

Pre-audit

Phase 2

  1. Audit proposal

    A written scope, the audit day count and the fee. No audit is scheduled until you have agreed it.

  2. Audit plan

    Dates, the audit team, and which sites, shifts and processes will be visited. You receive the plan in advance of the audit.

On-site audit

Phase 3

  1. On-site audit

    Stage 1 document review and Stage 2 audit, conducted against the standard and what is actually happening in your operation.

  2. Audit report

    Findings in writing, graded, with the evidence they rest on and a window to respond.

Certification

Phase 4

  1. Certification decision

    Taken independently of the audit team. An auditor recommends; a separate reviewer decides.

  2. Certificate finalisation

    Scope wording, accreditation marks and validity dates confirmed against the decision.

  3. Certificate awarded

    The certificate is issued and published in our public register, valid for three years subject to surveillance.

Findings and how they are graded
Major nonconformity
A failure that means part of the standard is not implemented, or a breakdown likely to result in a product or service failing to meet requirements. Certification cannot proceed until it is corrected and the correction verified.
Minor nonconformity
An isolated lapse against a requirement that is otherwise implemented. You submit a corrective action plan with root cause, and we verify it at the next audit.
Observation
Not a breach of the standard. Something we noticed that could become one, offered so you can act before it does. No response required.
What we cannot do

ISO/IEC 17021-1 requires us to manage threats to our impartiality, and consulting on a management system we then certify is the clearest threat there is. So we will not write your procedures, run your internal audits, or act as your management representative.

What we will do is tell you plainly what the standard requires, explain why a finding was raised and what would close it, and deliver training on the standard itself.

Impartiality statement

Request a quote

Find out what certification would involve.

Tell us the standard, your headcount and your sites. We will come back with a scope and a fixed fee within one working day.

Request a quote