Certification process
Undergoing an ISO certification process means that the company prepares, implements, and reviews its management system to meet international standards. Once the review is complete and approved, the company is awarded an ISO certification, proving it has an effective and sustainable management system.
Start-up
We begin by identifying the company’s goals, needs, and prerequisites for certification. Together, we review what the process entails and what is required to achieve certification. In this step, we gather necessary information to provide you with a transparent quote based on the scope of certification. Your company is assigned the auditor best suited for the review. To facilitate communication, this auditor will be your primary contact throughout the process.
Planing the audit
When you are ready to proceed, we plan the audit together with you. The assigned auditor will contact you to discuss the details and create an audit plan tailored to your business’s needs and timeline. We will review expectations for the audit, both before and during the process, and identify the internal resources and key personnel who should be available during the visits.
Stage 1 Audit
A mandatory preliminary review focusing on assessing your organization’s readiness for the formal certification audit. The purpose of the Stage 1 audit is to provide an early insight into how well your management system aligns with the relevant ISO standard and to identify any gaps that may need to be addressed before the next stage.
The Stage 1 Audit includes:
- Document review
- Assessment of management system implementation
- Identification of improvement areas
- Gaining a deeper understanding of your operations
Stage 2 Audit
This is the formal and decisive part of the ISO certification process. At this stage, we assess not only the documentation of the management system but also how it functions in practice and meets the specified standard requirements. This audit is always conducted on-site and includes both interviews and observations.
The result of the audit is a detailed report summarizing the auditor’s observations, including any non-conformities, recommendations for improvements, and whether the company meets the required standards.
Handling Non-Conformities
If minor non-conformities are identified, the certification process can proceed as long as these are addressed within an agreed timeframe.
For major non-conformities, corrective action must be taken before a certificate can be issued, and a follow-up visit by the auditor may be required.
Certification
If all requirements are met, the auditor will recommend that a certificate be issued for the organization. The audit report is then submitted to the certification committee for review and a decision on issuing the certificate.
The certificate is valid for 36 months, provided that the audit program is followed and that ongoing audits demonstrate the effective functioning of the management system.
Surveillance Audits and Recertification
Surveillance audits and recertification are standard requirements for continued certification.
Once the company has obtained its ISO certificate, a three-year audit cycle begins. During this period, surveillance audits are conducted once or twice a year, scheduled in consultation with your auditor.
Every third year, a recertification audit takes place, following a process similar to the initial certification audit. The purpose is to review the entire organization and evaluate improvements made over the three-year period. Recertification is required to maintain the certificate and is planned well in advance to address any non-conformities before the certificate expires.
Recertification includes:
- An analysis of the management system’s effectiveness, based on surveillance audits
- An expanded review to ensure all components of the system continue to operate effectively in practice
Process and appeal
Decision-making process
After the audit, the audit leader makes a recommendation on certification, continued certification, suspension of certification, termination of certification and, where applicable, extension or reduction of scope.
After a Stage 2, certification audit, the audit leader can also recommend that you are not ready for certification.
In most cases of refusal to certify, you have the opportunity to correct deviations within the specified time and then receive a new assessment and recommendation.
The audit leader’s recommendation is assessed by an audit auditor who makes the final decision.
In all cases of refusal of certification, an assessment is made by our audit manager who will forward to the certification committee for final decision.
Appeal of Decision
Scandinavian Business Certification’s auditors always strive to make assessments based on the evidence presented during the audit. The Certification Committee bases its decisions on the audit report and other available facts. If you, as a customer, feel that the decision is incorrect, there is always the opportunity to appeal a certification decision.
Appeals shall be made directly to the Review Board by email at: reviewboard@sbcert.se
For the purpose of an appeal, the following information shall always be provided:
- Name and organization number
- Purpose of appeal
- Any supporting evidence for your appeal
Appeals against certification decisions must be submitted within six weeks of the Certification Committee’s decision.
Procedure for Appeals
When the Review Board receives the case along with any supporting documents, the case will be prepared.
Once the preparation is complete, the decision documentation will be sent to the relevant parties—the appellant and Scandinavian Business Certification—for review and any additional input.
When all necessary additions have been made to the documentation, the Review Board will review it and provide a written assessment with comments, a decision on the matter, and the basis for that decision.
The decision will be communicated to the appellant and Scandinavian Business Certification. If Scandinavian Business Certification is found at fault, corrective actions will be taken. The Review Board’s decision is final and cannot be appealed.
Confidentiality
Our auditors shall exercise caution when handling information communicated during their work. All information handled during the audit is considered confidential. Information relating to auditing shall not be used improperly. The information may not be passed on to third parties unless that party is legally entitled to this information.
This is regulated in our Code of Conduct, as well as in the agreements each auditor must sign to work for Scandinavian Business Certification.
Certificate
On this page you will find up-to-date information about which of our customers have a certification from Scandinavian Business Certification.