Xcellenss — Business excellence and quality | xcellenss.com
From clause mapping to recertification: the ISO 9001 audit cycle in order, with the failure points that actually stop certificates.
ISO 9001:2015 has 10 clauses, but only clauses 4 to 10 carry requirements: context, leadership, planning, support, operation, performance evaluation and improvement. Step one is mapping your processes against those seven areas.
Stage 1 is a documentation review: the auditor reads the system on paper and confirms it is ready for a full audit. Gaps found here are the cheap kind — they cost a rewrite, not a certificate.
Stage 2 is the certification audit, where the system is tested in operation. A major nonconformity — a requirement that is missing or broken — blocks the certificate until it is corrected and re-checked; minor nonconformities are logged with corrective-action deadlines.
On narrow screens, swipe or scroll the plate sideways.
Pass, and the certificate runs for 3 years — but it is not shelfware. Surveillance audits land every 12 months, and findings left unresolved from one visit to the next put the certificate at risk.
At 36 months a recertification audit opens the next 3-year cycle. Organisations that treat each surveillance visit as a rehearsal for recertification rarely fail it; those that shelve the system between visits do.
For the improvement work that keeps the performance evaluation and improvement clauses alive between audits, see Running a DMAIC Improvement Cycle; for how ISO 9001 compares with the other frameworks, see Six Excellence Frameworks Compared.
Further reading