A certification audit is an assessment after which an independent certification body decides whether to issue a certificate. It takes place in two stages. In the first stage, documentation and readiness are reviewed – the scope of the system, policies, risk methodology, internal audit plan and record of management review; its output is a list of what needs to be completed before the second stage. In the second stage, auditors come to the company, talk to employees, and verify whether the system actually works and whether records exist from routine operation. Findings are divided into opportunities for improvement, minor nonconformities and major nonconformities. Minor nonconformities are addressed with a corrective action plan, while major ones must be eliminated before the certificate is issued. The certificate is issued for a three-year period, during which surveillance audits take place.
See also: Surveillance Audit, Recertification audit, Accredited Certification Body.