Processes and compliance

ISO standards in industry: what they really ask for and how to stay on top of them

An ISO certificate is not earned on audit day. It is earned with what the company records every week. Management system standards ask for less paperwork than people think, and more consistency. Here is what they ask for, what they share and how to organize it.

In this article
  1. What an ISO standard is, and what it is not
  2. The four standards you hear about most in industry
  3. What they have in common
  4. What really takes effort
  5. How to organize it so you are not rushing before the audit
  6. What the auditor looks at
  7. The certificate is not the finish line
  8. Common mistakes

What an ISO standard is, and what it is not

ISO, the International Organization for Standardization, publishes standards that capture good practice agreed between countries. Management system standards say what an organization must achieve, not which tool to use.

ISO does not certify anyone. The certificate comes from an independent certification body, accredited by each country’s accreditation body. In the United States, ANAB is one of them.

They are not laws either. In general, a company gets certified because its customers, a tender or its own management ask for it.

The four standards you hear about most in industry

StandardWhat it coversWhat it aims for
ISO 9001Quality managementThat the product or service meets what the customer asks for, every time, and that the company improves
ISO 14001Environmental managementThat the environmental impact of the activity is known and controlled
ISO 45001Occupational health and safetyThat risks to people are identified and controlled
ISO/IEC 27001Information securityThat information stays confidential, intact and available when needed

There are many more, some specific to one industry. This article focuses on these four.

What they have in common

Current management system standards share the same chapter structure. So if you already have one, the second costs less.

In practice, they all ask for five things:

  1. Defined processes: who does what, in what order and by what criteria.
  2. Documented information: the documents to keep current and the records that prove what was done.
  3. Objectives and KPIs that are measured and reviewed.
  4. Internal audits and management review, on schedule.
  5. Nonconformities and corrective actions: when something fails, you find the cause, fix it and check that the fix worked.

The standard does not ask for a thick manual. It asks you to prove that you work the way you say you do.

What really takes effort

Procedures are written once. The hard part is day-to-day consistency:

  • Records filled in late, or rebuilt the week before the audit.
  • Two versions of the same document: the current one on the intranet and the old one, printed in the shop.
  • Nonconformities that are opened and never closed, or closed without checking whether the action worked.
  • Periodic controls that depend on memory: calibrations, equipment checks or supplier evaluations.
  • Actions from the last audit that nobody followed up.

How to organize it so you are not rushing before the audit

Documents

Each procedure with an owner, a current version and a review date. The people who apply it must know it, and for the important ones it is worth having them sign.

Records

The record is created when the work is done, not afterward. An inspection done with a checklist on a phone is already the record, with its date, author and photos.

Internal audits

An annual program with dates, scope and auditor. Each audit with its checklist, and each finding turned into an action with an owner and a deadline.

Nonconformities

A fixed path: detect, analyze the cause, correct and verify. It is not closed until someone checks that the action worked. To set up the path, see how to run an approval workflow without email.

KPIs

Few of them, calculated from real work data, not from a spreadsheet someone fills in at the end of the month.

What the auditor looks at

More than documents, the auditor looks for consistency between what the procedure says and what people do. They usually ask for:

  • A sample of records from a period they choose.
  • The year’s nonconformities, with their analysis and closure.
  • Follow-up on the actions from the last audit.
  • Proof that people know the procedures that affect them.

If you find it in minutes, the audit is a conversation. If it takes days, it is an exam. What makes proof useful is covered in how to prove a control was done.

The certificate is not the finish line

Certification is granted after an initial audit, kept through surveillance audits and renewed every few years.

That is why ISO is ongoing work, not a project with an end date.

Common mistakes

  • Treating ISO as a project that ends with the certificate. The next year, everything gets rebuilt.
  • Procedures that describe how things should be, not how people work. The auditor finds the gap.
  • A tool used only for the audit, separate from daily work. It gets filled in after the fact.
  • Confusing the tool with compliance. No software certifies anything: the certification body does, by looking at how you work.

To see how each step gets recorded, request a demo and we will walk through one of your processes.

Last updated:

Frequently asked questions

Frequently asked questions

Who issues an ISO certificate?

An independent certification body, accredited in each country. ISO publishes the standards, but it does not certify any company.

What do ISO 9001, 14001 and 45001 have in common?

They share the same structure: processes, documented information, objectives, internal audit, management review and nonconformities. Running them as one system saves work.

Can software get you certified?

It helps keep records, documents and nonconformities in order and find them fast. Compliance is judged by the certification body, not by the tool.

Keep reading

More on processes and compliance

Periodic controls: how to prove they were done

Doing a control and being able to prove it are two different jobs. The second one usually surfaces on audit day, when someone spends a week hunting for emails, screenshots and signatures.

4 min read

Field service

How to design a checklist technicians actually fill in

A checklist ticked without looking is worse than no checklist at all. It takes time, creates paperwork and gives confidence nobody has earned. And the culprit is almost never the technician: it is the design.

4 min read

All blog articles

Request a demo

Shall we look at it with your operation?

Tell us how you work today and we will show you attendo with your own data. If it is not a fit, we will say so.

  • With your operation, not a generic demo
  • A real person from our team replies
  • No cold calls afterwards

Would you rather talk first?

Which area do you want to see in the demo?

With your work email we prepare the demo around your case.

In one or two sentences.

If you chose Maintenance (CMMS)

If you chose Field work (Field Service)

If you chose Facility Management

If you chose any other area

Only if you would rather we call you.

Data protection. Controller: AxisOne Group SL. Purpose: preparing the demo you request and replying to you. Legal basis: your consent and the request you make. Recipients: we do not disclose your data; Cloudflare (website) and Brevo (email notices and confirmation) process it on our behalf. Rights: access, rectification, erasure, objection, restriction and portability, at privacy@attendo.me. More information in the privacy policy.

What happens when you send it. Someone from our team reads what you tell us and writes to you to agree on a time for the demo. Our hours: Monday to Thursday 9:30 AM to 6:30 PM and Friday 9:30 AM to 2:30 PM, Spain time.