iso-9001-external-audit

By July 25th, 2026ISO Audit And Certificate9 min read

ISO 9001 External Audit: What Happens During Certification

If your organisation is pursuing ISO 9001 certification, the external audit is the final hurdle. Also called a certification audit or third-party audit, this assessment is carried out by an accredited certification body to verify that your Quality Management System (QMS) conforms to the ISO 9001:2015 standard. Understanding what happens during an ISO 9001 external audit removes the uncertainty and helps your team prepare effectively. This article explains the entire process from Stage 1 through to the certification decision, including what auditors look for and how nonconformities are handled.

What Is an ISO 9001 External Audit?

An ISO 9001 external audit is an independent, systematic examination of your QMS by a certification body that is not part of your organisation. The purpose is to determine whether your system meets the requirements of ISO 9001:2015, is effectively implemented, and is capable of achieving your quality objectives. Unlike internal audits, which are conducted by your own staff, external audits provide an impartial assessment that carries weight with customers, regulators, and other stakeholders.

The external audit is conducted in two stages. Stage 1 is a readiness review, and Stage 2 is the full certification audit. After initial certification, surveillance audits are carried out periodically to maintain your certificate.

Stage 1 Audit: Readiness Review

The Stage 1 audit is a preliminary assessment of your QMS documentation and preparedness. It usually takes place on-site, although remote audits are becoming increasingly common. The auditor reviews your documented information to confirm that the QMS is designed in accordance with ISO 9001:2015. Typical activities during Stage 1 include:

  • Reviewing your quality policy and quality objectives
  • Checking the scope of your QMS
  • Verifying that your documented information meets clause 7.5 requirements
  • Assessing your understanding of applicable statutory and regulatory requirements
  • Evaluating the resources allocated for the QMS
  • Confirming that internal audits and management reviews have been conducted
  • Identifying potential nonconformities or areas requiring improvement

Stage 1 is not a pass-or-fail exercise. Instead, it identifies gaps that must be addressed before Stage 2. If significant issues are found, the auditor may recommend postponing Stage 2 until corrective actions are completed.

Stage 2 Audit: Full Certification Audit

Stage 2 is the main certification audit. It takes place on-site and evaluates the actual implementation and effectiveness of your QMS. While Stage 1 focused on documentation, Stage 2 examines how your processes operate in practice. The auditor will spend time interviewing staff, observing activities, and reviewing records to gather objective evidence of conformity.

The External Audit Process Step by Step

The external audit follows a structured process that ensures consistency and thoroughness. Understanding each step helps your team know what to expect and how to contribute.

StepActivityWho Is Involved
1Opening meeting: auditor explains scope, criteria, schedule, and methodsAuditor, top management, QMS team
2Documentation review: audit plan, quality manual, procedures, recordsAuditor, QMS manager
3Site inspection: walk-through of operational areasAuditor, process owners
4Employee interviews: discussions with staff at all levelsAuditor, employees
5Evidence gathering: sampling records, observing processes, verifying controlsAuditor
6Auditor review: findings analysis and nonconformity identificationAuditor (internal)
7Closing meeting: presentation of findings, nonconformities, and recommendationsAuditor, top management, QMS team

What Auditors Look For During the Audit

ISO 9001 external auditors are trained to gather objective evidence. They do not rely on what you tell them; they verify claims by examining records, observing activities, and interviewing staff. The key areas auditors focus on include:

  • Leadership and commitment – Does top management demonstrate involvement in the QMS? Are quality policy and objectives communicated?
  • Risk-based thinking – Has the organisation identified risks and opportunities that affect product conformity and customer satisfaction?
  • Operational planning and control – Are processes defined, controlled, and monitored? Are criteria for acceptance established?
  • Resource management – Are personnel competent? Is infrastructure and environment suitable for operations?
  • Measurement and analysis – Are monitoring, measurement, analysis, and evaluation activities defined and implemented?
  • Continual improvement – Does the organisation take corrective actions and pursue improvement opportunities?

Documentation Review

A significant portion of the external audit involves reviewing documented information. ISO 9001:2015 requires certain documents and records, although the standard is less prescriptive than its predecessor. The auditor will expect to see:

Document TypeExamplesClause Reference
Scope of QMSQuality manual or scope statement4.3
Quality policySigned policy document5.2
Quality objectivesObjectives register with targets6.2
ProceduresDocumented process maps7.5
Records of monitoringInspection reports, calibration certificates9.1
Internal audit recordsAudit reports, checklists9.2
Management review minutesMeeting minutes with agenda items9.3
Corrective action recordsCorrective action reports10.1

Site Inspection and Process Observation

The auditor will conduct a physical walk-through of your facility. This is not a casual tour; the auditor observes how processes operate in real time. During the site inspection, the auditor will look for evidence that documented procedures are being followed. They may note housekeeping, equipment condition, labelling of materials, and safety practices. If a process deviates from what is documented, the auditor will investigate the reason and may raise a nonconformity.

Employee Interviews

Interviews are a critical part of the external audit. The auditor will speak with employees at various levels to gauge their awareness of the QMS. Questions typically cover:

  • What is the quality policy and how does it relate to your work?
  • What are your quality objectives and how do you measure them?
  • How do you know if your process is working correctly?
  • What would you do if you identified a problem?
  • How do you handle nonconforming outputs?
  • When was the last internal audit and what was the outcome?

Employees should answer honestly. Auditors can tell when someone has been coached to give rehearsed answers. A simple, truthful response is far more effective than a scripted one.

Nonconformities: Minor, Major, and Observations

If the auditor finds that your QMS does not meet a requirement, they will raise a nonconformity. Nonconformities are classified into categories:

CategoryDefinitionImpact on Certification
Minor nonconformityAn isolated lapse that does not affect the QMS’s ability to achieve intended resultsCorrect within 30–90 days; certificate can be issued once resolved
Major nonconformityA significant failure that compromises the QMS effectiveness or a total absence of a required processCertification cannot proceed until corrective action is verified
ObservationA finding that is not a nonconformity but indicates a potential future riskNo immediate impact; may be reviewed at next audit

When a nonconformity is raised, you must perform root cause analysis and implement corrective actions within an agreed timeframe. The auditor may verify the corrective action on-site or through evidence submission.

The Audit Report

After the closing meeting, the auditor prepares a formal audit report. This document summarises the audit activities, presents findings including nonconformities and observations, and provides a recommendation regarding certification. The report is reviewed by the certification body’s independent decision-maker, who makes the final certification decision.

The audit report typically includes:

  • Audit dates, scope, and criteria
  • Names of auditor(s) and auditee representatives
  • Summary of processes audited
  • Positive findings and strengths
  • Nonconformities and observations
  • Recommendation for certification

Certification Decision and Beyond

If the audit concludes with no major nonconformities, the certification body issues an ISO 9001 certificate valid for three years. The certificate is subject to annual surveillance audits to ensure continued compliance. In the third year, a recertification audit is conducted, which repeats the full Stage 2 process.

Surveillance audits are typically less intensive than the initial certification audit, but they are still thorough. The auditor will focus on changes to the QMS, corrective actions from previous audits, and areas of particular risk.

How to Prepare for an ISO 9001 External Audit

Preparation is the key to a successful external audit. Start by conducting thorough internal audits and management reviews well before the external auditor arrives. Address any nonconformities identified during internal audits and verify that corrective actions are effective. Ensure that all documented information is current, accessible, and properly controlled. Brief your team on what to expect and remind them that honest answers are always the best approach.

Frequently Asked Questions

How long does an ISO 9001 external audit take?

The duration depends on the size and complexity of your organisation. A typical Stage 1 audit lasts one day. Stage 2 can range from two to five days. Surveillance audits are usually one to two days.

Can an external audit be conducted remotely?

Some certification bodies offer remote auditing for Stage 1 and certain surveillance activities. Stage 2 generally requires on-site presence because the auditor needs to observe processes and interview staff in person.

What happens if we fail the external audit?

You cannot ‘fail’ as such. If major nonconformities are identified, certification is withheld until you implement corrective actions and the auditor verifies them. The certification body will provide a clear timeline for resolution.

Do we need to hire a consultant for the external audit?

You are not required to hire a consultant. However, many organisations benefit from external support during the preparation phase. The presence of a consultant should be disclosed to the certification body.

How much does ISO 9001 certification cost?

Costs vary significantly based on organisation size, scope, certification body, and geographic location. Typical costs include the application fee, audit fees (Stage 1, Stage 2, surveillance), and certificate maintenance fees. Contact a certification body for a tailored quotation.

What is the difference between certification and accreditation?

Certification is the process by which a certification body issues a certificate confirming that your QMS meets ISO 9001 requirements. Accreditation is the independent evaluation of the certification body itself by an accreditation body such as UKAS or ANSI.

Start Your ISO 9001 Certification Journey

An ISO 9001 external audit does not need to be intimidating. With proper preparation, a well-documented QMS, and a committed team, you can achieve certification and unlock the benefits of a world-class quality management system. Bitrixme helps organisations across the Gulf region prepare for ISO 9001 certification with expert guidance, documentation templates, and audit support.

Prefer instant communication? Reach us on WhatsApp.