ISO Audit

An ISO audit is a systematic, independent and documented review of whether a management system (for example ISO 27001 for information security or ISO 9001 for quality) meets the requirements of the respective standard. There are three audit types: internal audit, certification audit and surveillance audit.

An ISO audit checks whether a management system meets the requirements of the underlying standard and is operated effectively in practice. The audit methodology itself is standardized in ISO 19011. What gets audited: documented process design, actual implementation in day-to-day operations, the effectiveness of the measures, and lessons learned from previous incidents and audits.

Three audit types to distinguish

1. Internal audit (first-party audit). The organization audits itself, led by independent internal auditors or external appointees. Results feed into the management report. Mandatory for ISO 27001 and ISO 9001, at least once a year.

2. Certification audit (third-party audit). An accredited certification body reviews the management system for the initial certification. It runs in two stages: Stage 1 (document review), Stage 2 (on-site audit over several days). On success, the certificate is issued for three years. For the full process of an ISO 27001 certification, see ISO 27001 certification explained simply.

3. Surveillance audit. Held annually after the initial certification. The certification body checks ongoing effectiveness on a sampling basis. In the third year the recertification audit follows, which reviews the full scope again.

Typical findings and their severity

SeverityMeaningImpact
Major non-conformitySignificant deviation from the standardCertificate is withdrawn or not granted; correction within 90 days plus re-audit
Minor non-conformitySmaller deviationCorrection within 90 days, no re-audit but evidence required
ObservationNote without obligation to actRecommendation for improvement, no formal defect

Audit preparation: what makes the difference

Three factors decide the audit outcome and the audit duration:

  • A current audit trail: complete documentation of all decisions, changes and incidents. Excel lists regularly fail here.
  • A clean internal audit plan: whoever documents the internal audits has already done two thirds of the preparation.
  • Demonstrated effectiveness: auditors want to see that policies do not just exist but are lived (samples with employees, tickets, logs).

You can estimate in advance how many audit days are realistic for your certification audit, and roughly what it costs, with our audit cost calculator based on IAF MD 5.

In Kopexa, audit preparation runs continuously instead of in a last-minute sprint. Evidence is collected automatically, the audit trail is tamper-proof, and the auditor can get read-only access to the platform, which typically shortens the on-site days by 30 to 50 percent.