An ISO audit is a systematic, independent and documented review of whether a management system (for example ISO 27001 for information security or ISO 9001 for quality) meets the requirements of the respective standard. There are three audit types: internal audit, certification audit and surveillance audit.
An ISO audit checks whether a management system meets the requirements of the underlying standard and is operated effectively in practice. The audit methodology itself is standardized in ISO 19011. What gets audited: documented process design, actual implementation in day-to-day operations, the effectiveness of the measures, and lessons learned from previous incidents and audits.
1. Internal audit (first-party audit). The organization audits itself, led by independent internal auditors or external appointees. Results feed into the management report. Mandatory for ISO 27001 and ISO 9001, at least once a year.
2. Certification audit (third-party audit). An accredited certification body reviews the management system for the initial certification. It runs in two stages: Stage 1 (document review), Stage 2 (on-site audit over several days). On success, the certificate is issued for three years. For the full process of an ISO 27001 certification, see ISO 27001 certification explained simply.
3. Surveillance audit. Held annually after the initial certification. The certification body checks ongoing effectiveness on a sampling basis. In the third year the recertification audit follows, which reviews the full scope again.
| Severity | Meaning | Impact |
|---|---|---|
| Major non-conformity | Significant deviation from the standard | Certificate is withdrawn or not granted; correction within 90 days plus re-audit |
| Minor non-conformity | Smaller deviation | Correction within 90 days, no re-audit but evidence required |
| Observation | Note without obligation to act | Recommendation for improvement, no formal defect |
Three factors decide the audit outcome and the audit duration:
You can estimate in advance how many audit days are realistic for your certification audit, and roughly what it costs, with our audit cost calculator based on IAF MD 5.
In Kopexa, audit preparation runs continuously instead of in a last-minute sprint. Evidence is collected automatically, the audit trail is tamper-proof, and the auditor can get read-only access to the platform, which typically shortens the on-site days by 30 to 50 percent.