Certification follows ISO/IEC 17021-1 in the steps below.
1. Application and proposal
You send us an application with details of your organisation, your sites, your activities and the standard you are seeking. We review the application and send you a proposal.
2. Certification audit
The certification audit is conducted in two stages. Stage 1 assesses your readiness for the audit; stage 2 assesses the implementation and effectiveness of your management system. You address any nonconformities within the deadlines set out in the certification rules.
3. Certification decision
We decide on certification based on the audit results. On a positive decision, we issue a certificate valid for three years.
4. Surveillance
Certification is maintained through surveillance audits at least once per calendar year.
5. Recertification and restoration
Before the certificate expires, we conduct a recertification audit. On a positive decision, certification is renewed for a further three years. If the certificate has expired, certification can be restored within six months, provided the outstanding recertification activities are completed.
6. Extending and reducing the scope
You apply to us to extend the scope; we determine which audit activity is required. The scope is reduced at your request or where parts of it persistently fail to meet the requirements.
7. Refusal, suspension and withdrawal
If your management system does not meet the requirements, we refuse certification and give you the reasons in writing. The conditions for suspension and withdrawal are set out in the certification rules, sections 10 and 11. You can appeal against our decisions.