Approach (Audit Process)
The certification process consists of the following phases:
- Certification Audit (first year only)
- Stage 1: Initial assessment of the design of the management system
- Stage 2: Full review of the implementation of the management system
- Certification Decision: The certification committee reviews audit files and audit team recommendation and makes the decision whether to grant certification. A certification is valid for 3 years from the date of issuance.
- Surveillance Audit: Audits are held in each of the next two years following the initial certification, prior to the anniversary of the certification date.
- Re-Certification: A full audit of the management system, fully completed prior to the certificate expiration date, which will extend the certification an additional 3 years. To ensure audits are completed prior to the certificate expiration date, this audit will start earlier than the surveillance audits.
- Other audits: Appropriate audit procedures are performed when factors affecting the current certification are identified, e.g.:
- Expansion of scope
- Short-notice audits, i.e. to investigate complaints, respond to changes, or follow up on suspended certification
Processes for granting, refusing, maintaining, renewing, suspending, restoring or withdrawing certification or expanding or reducing the scope of certification
All decisions to grant, refuse, maintain (i.e., continue), renew, suspend, restore, or withdraw certification as well as expand or reduce the scope of existing certification are reviewed by an impartial and qualified member of our team. Prior to the decision, the decision-maker will review and verify that sufficient information has been obtained to support a certification decision, any nonconformities have been addressed appropriately, and appropriate actions have been taken (major nonconformities) or will be taken (minor nonconformities).
For any change affecting the ISO certification, including change in name, location, or scope, the certification committee will assess the extent and timing of required audit procedures.
If a positive certification decision is made, a certificate will be prepared and published to risk3sixty ISO Certifications certificate directory and at IAF CertSearch.
If certification is unable to be granted, you will be notified and informed of the outstanding requirements to complete certification.