top of page

How to Prepare for an ISO Audit: A Step-by-Step Guide for Australian Businesses

Jun 10
4 min read

ISO audits make many business owners and managers nervous — but they don't have to. An ISO audit is simply a systematic, structured review of your management system. If you've implemented your system correctly, the audit is a confirmation of that work, not a surprise exam.

This guide walks you through exactly how to prepare, what auditors look for, and the most common gaps businesses encounter before certification.

Understanding the ISO Audit Process

ISO certification involves two main audit stages:

Stage 1 Audit (Document Review)

The Stage 1 audit is a desktop review. Your auditor will:

·       Confirm your documented management system is complete and covers all relevant clauses

·       Review your scope statement, policies and key procedures

·       Identify any major gaps before the Stage 2 audit

·       Confirm your organisation is ready to proceed to Stage 2

Stage 1 is generally conducted remotely or on-site over half a day to a full day.

Stage 2 Audit (Implementation Audit)

The Stage 2 audit is where your auditor assesses whether your system is actually implemented and working. They will:

·       Interview staff at various levels to verify awareness and implementation

·       Review records, registers and completed forms

·       Inspect your workplace and operations

·       Assess whether your system is achieving its intended outcomes

Non-conformances raised at Stage 2 must be closed before certification is issued.

Step-by-Step: How to Prepare for Your ISO Audit

Step 1: Confirm Your Documentation Is Complete

Before anything else, check that your management system documentation covers every clause requirement of your relevant standard(s). The most common documentation gaps auditors find are:

·       Missing context of the organisation analysis (clause 4.1 and 4.2)

·       Incomplete risk and opportunity register

·       Objectives without measurable targets or action plans

·       Legal compliance obligations not fully documented

·       Management review not yet conducted

Use an internal audit checklist aligned to your standard's clauses to verify completeness.

Step 2: Conduct an Internal Audit

Your management system must have at least one complete internal audit cycle before certification. The internal audit should:

·       Cover all relevant clauses of the standard

·       Be conducted by someone other than those responsible for the area being audited

·       Result in documented findings and a corrective action plan

·       Show evidence of closure for any non-conformances raised

If you've never done an internal audit before, use a structured checklist and record your findings on a non-conformance or corrective action form.

Step 3: Conduct Your Management Review

ISO standards require a management review — a formal meeting where senior leadership reviews the performance of the management system. This must be documented and include review of:

·       Previous audit findings and corrective actions

·       Customer/stakeholder feedback

·       Performance against objectives

·       System changes that may affect the management system

·       Resource adequacy

·       Opportunities for improvement

A completed and signed management review record is one of the first things auditors look for.

Step 4: Verify Records Are in Place

Auditors will sample your records to verify the system is operating. Before your audit, confirm you have current records for:

·       Staff inductions and competency assessments

·       Completed operational checklists or monitoring records

·       Calibration records (if applicable)

·       Supplier/contractor evaluations

·       Incident and corrective action registers (even if empty, they should be established)

·       Communication records (toolbox talks, safety meetings, etc.)

Step 5: Brief Your Team

Auditors will speak to staff at all levels — not just management. Brief your team on:

·       What the audit is (and isn't) — it's not a test of individuals

·       Where to find procedures and policies if asked

·       How to describe their role in the management system in plain language

·       The importance of saying "I don't know, but I can find out" rather than guessing

Staff who understand the system will perform well in interviews. Staff who are unprepared can raise red flags even when your documents are solid.

Step 6: Review Common Non-Conformances

Certain non-conformances come up repeatedly in ISO audits. Checking these areas before your audit can prevent them:

·       Objectives not measurable or without clear targets

·       Legal register not reviewed or updated

·       Corrective actions not closed within agreed timeframes

·       Competency records incomplete for key roles

·       Internal audit scope doesn't cover all clauses

·       Management review not attended by top management

What Happens If You Get a Non-Conformance?

Non-conformances are not the end of the world — they're a normal part of the audit process. There are two types:

·       Major non-conformance: A systemic failure to meet a requirement. Must be closed before certification can be issued.

·       Minor non-conformance: An isolated gap or weakness. Must be addressed by agreed timeframe, often before the next surveillance audit.

If you receive a non-conformance, work with your auditor to understand the root cause and develop a corrective action that addresses it systematically, not just the specific instance.

How Long Does It Take to Get ISO Certified?

From starting your documentation to receiving your certificate, most small to medium businesses take:

·       4–8 weeks: Using a complete, audit-ready template

·       3–6 months: Building a system from scratch internally

·       6–12 months: With multiple rounds of consultant drafting and revision

The fastest path to certification is a quality template combined with experienced audit support to close any gaps before Stage 2.


Certify Edge provides audit-ready IMS templates and certification support services — Start your certification journey at certifyedge.com.au


 
 
 

Comments


bottom of page