| name | iso-certification |
| description | ISO certification preparation knowledge for consulting engagements. Use when working on ISO 9001, 27001, 42001, 14001, 45001 gap analysis, management system design, documentation development, or audit preparation. Covers compliance requirements, process documentation, and certification readiness. |
ISO Certification Preparation Skill
Overview
Provides specialized knowledge for ISO certification engagements including gap analysis methodologies, documentation templates, audit preparation, and certification body coordination across ISO 9001, 27001, 42001, 14001, and 45001.
ISO Standards Quick Reference
ISO 9001:2015 - Quality Management
| Clause | Title | Key Requirements |
|---|
| 4 | Context | Organization context, interested parties, scope |
| 5 | Leadership | Policy, roles, management commitment |
| 6 | Planning | Risks, objectives, change planning |
| 7 | Support | Resources, competence, awareness, communication |
| 8 | Operation | Planning, requirements, design, production |
| 9 | Evaluation | Monitoring, internal audit, management review |
| 10 | Improvement | Nonconformity, corrective action, continual improvement |
ISO 27001:2022 - Information Security
| Clause/Annex | Key Requirements |
|---|
| 4-10 | Management system (same as 9001) |
| A.5 | Organizational controls (37 controls) |
| A.6 | People controls (8 controls) |
| A.7 | Physical controls (14 controls) |
| A.8 | Technological controls (34 controls) |
ISO 42001:2023 - AI Management
| Clause | Key AI-Specific Requirements |
|---|
| 4 | Context including AI context |
| 5 | AI policy and leadership |
| 6 | AI risk assessment, objectives |
| 7 | AI competence, awareness |
| 8 | AI lifecycle, data management, third parties |
| 9 | AI system performance monitoring |
| 10 | AI incident management, improvement |
ISO 14001:2015 - Environmental
| Key Areas | Requirements |
|---|
| Environmental policy | Commitment, objectives |
| Aspects/Impacts | Identification, significance |
| Legal compliance | Requirements register |
| Operational control | Procedures, monitoring |
| Emergency preparedness | Response procedures |
ISO 45001:2018 - OH&S
| Key Areas | Requirements |
|---|
| OH&S policy | Commitment, objectives |
| Hazard identification | Risk assessment |
| Legal compliance | Requirements register |
| Worker participation | Consultation mechanisms |
| Incident investigation | Root cause, corrective action |
Gap Analysis Methodology
Assessment Approach
Phase 1: Document Review
โโโ Existing policies and procedures
โโโ Records and evidence
โโโ Previous audit reports
โโโ Organizational charts
Phase 2: Process Interviews
โโโ Key process owners
โโโ Management representatives
โโโ Technical staff
โโโ Support functions
Phase 3: Control Testing
โโโ Sample evidence review
โโโ Process observation
โโโ Technical verification
โโโ Record examination
Phase 4: Gap Scoring
โโโ Clause-by-clause assessment
โโโ Maturity scoring
โโโ Priority ranking
โโโ Remediation effort estimation
Gap Scoring Matrix
| Score | Level | Description | Action |
|---|
| 0 | Non-existent | No evidence | Implement from scratch |
| 1 | Initial | Ad-hoc, undocumented | Document and formalize |
| 2 | Developing | Partially implemented | Complete implementation |
| 3 | Defined | Documented, consistent | Minor improvements |
| 4 | Managed | Measured, controlled | Optimization only |
| 5 | Optimized | Best practice | Maintain |
Gap Analysis Report Template
1. Executive Summary
- Overall readiness score
- Key gaps identified
- Estimated effort to certification
- Recommended timeline
2. Methodology
- Assessment scope
- Approach taken
- Limitations
3. Findings by Clause
- Current state
- Gap description
- Score
- Remediation action
- Priority
- Effort estimate
4. Remediation Roadmap
- Phased approach
- Resource requirements
- Dependencies
- Timeline
5. Appendices
- Evidence inventory
- Interview log
- Detailed scoring
Documentation Requirements
Document Hierarchy
Level 1: Policy
โโโ Management-approved
โโโ Sets direction
โโโ Reviewed annually
Level 2: Procedures
โโโ How to perform activities
โโโ Process-specific
โโโ Maintained by process owners
Level 3: Work Instructions
โโโ Detailed step-by-step
โโโ Task-specific
โโโ Used at operational level
Level 4: Forms/Records
โโโ Evidence of activities
โโโ Controlled templates
โโโ Retention requirements
Required Documents by Standard
ISO 9001:2015 Minimum:
- Quality policy
- Quality objectives
- Scope of QMS
- Process interactions (optional format)
- Procedures: Document control, Internal audit, Corrective action
- Records: Training, Monitoring, Audit, Management review
ISO 27001:2022 Minimum:
- Information security policy
- ISMS scope
- Risk assessment methodology
- Statement of Applicability (SoA)
- Risk treatment plan
- Procedures per Annex A controls
- Records: Risk assessments, Incidents, Audits
ISO 42001:2023 Minimum:
- AI policy
- AIMS scope
- AI system inventory
- AI risk assessment methodology
- AI impact assessment
- AI lifecycle procedures
- Third-party AI management
Document Control Template
Document Control Information:
โโโ Document ID: [XXX-YYY-NNN]
โโโ Title: [Document Name]
โโโ Version: [X.X]
โโโ Effective Date: [DD-MMM-YYYY]
โโโ Author: [Name]
โโโ Approver: [Name]
โโโ Review Frequency: [Annual]
โโโ Classification: [Internal/Confidential]
โโโ Distribution: [Controlled/Uncontrolled]
Revision History:
| Version | Date | Author | Changes |
|---------|------|--------|---------|
| 1.0 | Date | Name | Initial release |
Internal Audit Program
Audit Planning
Annual Audit Plan:
โโโ Scope (all clauses over cycle)
โโโ Frequency (at least annual)
โโโ Audit team (qualified, independent)
โโโ Schedule (aligned with operations)
โโโ Risk-based focus areas
Audit Cycle:
Year 1: All clauses + high-risk processes
Year 2: All clauses + different risk areas
Year 3: Full certification preparation
Audit Checklist Example (ISO 9001 Clause 8)
| Requirement | Evidence to Check | Finding |
|---|
| 8.1 Planning | Process plans, work instructions | |
| 8.2 Requirements | Customer specs, contract review | |
| 8.3 Design | Design plans, verification records | |
| 8.4 External provision | Supplier evaluations, inspections | |
| 8.5 Production | Control plans, monitoring records | |
| 8.6 Release | Inspection records, authorizations | |
| 8.7 Nonconforming | NCR records, disposition evidence | |
Finding Classification
| Category | Definition | Response Time |
|---|
| Major NC | System failure, missing requirement | Before certification |
| Minor NC | Isolated instance, partial compliance | 90 days typical |
| Observation | Improvement opportunity | Discretionary |
| Good Practice | Exceeds requirements | Document for sharing |
Certification Process
Certification Timeline
Pre-Certification (3-12 months):
โโโ Gap analysis
โโโ System development
โโโ Implementation
โโโ Internal audits
โโโ Management review
Stage 1 Audit (1-2 days):
โโโ Documentation review
โโโ Readiness assessment
โโโ Scope confirmation
โโโ Stage 2 planning
Gap Closure (4-8 weeks):
โโโ Address Stage 1 findings
โโโ Additional implementation
โโโ Evidence collection
Stage 2 Audit (2-5 days):
โโโ Implementation verification
โโโ Process observation
โโโ Interview staff
โโโ Evidence sampling
Certification:
โโโ NC closure (if any)
โโโ Certificate issuance
โโโ 3-year cycle begins
Surveillance (Annual):
โโโ Subset of clauses
โโโ NC follow-up
โโโ Continuous compliance
Certification Body Selection
| Criterion | Considerations |
|---|
| Accreditation | UKAS, ANAB, JAS-ANZ, etc. |
| Industry experience | Relevant sector expertise |
| Geographic coverage | Local auditors available |
| Cost | Audit fees, travel, extras |
| Reputation | Client references |
| Timeline | Availability, speed |
Management Review Template
Inputs (Required by Standards)
- Status of previous actions
- Changes to internal/external issues
- Performance and effectiveness:
- Customer satisfaction
- Objectives achievement
- Process performance
- Nonconformities and corrective actions
- Audit results
- Supplier performance
- Resource adequacy
- Improvement opportunities
Outputs (Required by Standards)
- Improvement decisions
- Resource needs
- System change needs
- Updated objectives
- Action items with owners
Meeting Agenda Template
Management Review Meeting
Date: [Date]
Attendees: [Top management required]
1. Opening / Previous Actions (15 min)
2. Context Changes (10 min)
3. Performance Dashboard (20 min)
4. Audit and NC Summary (15 min)
5. Risk and Opportunity Update (15 min)
6. Resource Review (10 min)
7. Improvement Initiatives (15 min)
8. Decisions and Actions (20 min)
9. Close
Output: Management Review Minutes (mandatory record)
Integrated Management Systems
Common Structure (Annex SL)
All ISO management system standards share:
- Clauses 4-10 structure
- Common terms and definitions
- Risk-based thinking requirement
- Process approach
- Leadership and commitment
- Continual improvement cycle
Integration Benefits
| Benefit | Description |
|---|
| Reduced duplication | Single policy, procedures |
| Efficiency | One audit, one review |
| Consistency | Aligned approaches |
| Resource savings | Shared team, tools |
| Stakeholder confidence | Comprehensive system |
Common Integration Combinations
| Combination | Industries |
|---|
| 9001 + 14001 | Manufacturing, construction |
| 9001 + 27001 | Technology, services |
| 27001 + 42001 | AI/ML companies |
| 9001 + 45001 | Manufacturing, oil & gas |
| 9001 + 14001 + 45001 | Heavy industry |
References
See references/ folder for:
- Detailed clause requirements
- Document templates
- Audit checklists
- Certification body comparison