What an ISO standard is, and what it is not
ISO, the International Organization for Standardization, publishes standards that capture good practice agreed between countries. Management system standards say what an organization must achieve, not which tool to use.
ISO does not certify anyone. The certificate comes from an independent certification body, accredited by each country’s accreditation body. In the United States, ANAB is one of them.
They are not laws either. In general, a company gets certified because its customers, a tender or its own management ask for it.
The four standards you hear about most in industry
| Standard | What it covers | What it aims for |
|---|---|---|
| ISO 9001 | Quality management | That the product or service meets what the customer asks for, every time, and that the company improves |
| ISO 14001 | Environmental management | That the environmental impact of the activity is known and controlled |
| ISO 45001 | Occupational health and safety | That risks to people are identified and controlled |
| ISO/IEC 27001 | Information security | That information stays confidential, intact and available when needed |
There are many more, some specific to one industry. This article focuses on these four.
What they have in common
Current management system standards share the same chapter structure. So if you already have one, the second costs less.
In practice, they all ask for five things:
- Defined processes: who does what, in what order and by what criteria.
- Documented information: the documents to keep current and the records that prove what was done.
- Objectives and KPIs that are measured and reviewed.
- Internal audits and management review, on schedule.
- Nonconformities and corrective actions: when something fails, you find the cause, fix it and check that the fix worked.
The standard does not ask for a thick manual. It asks you to prove that you work the way you say you do.
What really takes effort
Procedures are written once. The hard part is day-to-day consistency:
- Records filled in late, or rebuilt the week before the audit.
- Two versions of the same document: the current one on the intranet and the old one, printed in the shop.
- Nonconformities that are opened and never closed, or closed without checking whether the action worked.
- Periodic controls that depend on memory: calibrations, equipment checks or supplier evaluations.
- Actions from the last audit that nobody followed up.
How to organize it so you are not rushing before the audit
Documents
Each procedure with an owner, a current version and a review date. The people who apply it must know it, and for the important ones it is worth having them sign.
Records
The record is created when the work is done, not afterward. An inspection done with a checklist on a phone is already the record, with its date, author and photos.
Internal audits
An annual program with dates, scope and auditor. Each audit with its checklist, and each finding turned into an action with an owner and a deadline.
Nonconformities
A fixed path: detect, analyze the cause, correct and verify. It is not closed until someone checks that the action worked. To set up the path, see how to run an approval workflow without email.
KPIs
Few of them, calculated from real work data, not from a spreadsheet someone fills in at the end of the month.
What the auditor looks at
More than documents, the auditor looks for consistency between what the procedure says and what people do. They usually ask for:
- A sample of records from a period they choose.
- The year’s nonconformities, with their analysis and closure.
- Follow-up on the actions from the last audit.
- Proof that people know the procedures that affect them.
If you find it in minutes, the audit is a conversation. If it takes days, it is an exam. What makes proof useful is covered in how to prove a control was done.
The certificate is not the finish line
Certification is granted after an initial audit, kept through surveillance audits and renewed every few years.
That is why ISO is ongoing work, not a project with an end date.
Common mistakes
- Treating ISO as a project that ends with the certificate. The next year, everything gets rebuilt.
- Procedures that describe how things should be, not how people work. The auditor finds the gap.
- A tool used only for the audit, separate from daily work. It gets filled in after the fact.
- Confusing the tool with compliance. No software certifies anything: the certification body does, by looking at how you work.
To see how each step gets recorded, request a demo and we will walk through one of your processes.
Last updated: