Streamline ISO Consultants

  • Home
  • Security & AI
    • ISO 27001 Information Security
    • ISO 42001 AI Management
    • Cyber & Information Security Advisory
    • Essential Eight
    • SOC 2
    • TISAX
  • ISO Consulting Services
    • ISO Consultants Australia
    • ISO 9001 for US Companies
    • ISO Mentoring
    • Independent ISO Internal Audit Services Australia (Clause 9.2)
    • ISO Gap Analysis Audits: Know Where You Stand Before Stage 1
    • ISO Certification Auditors
    • ISO System Development
    • ISO Management System Maintenance & Ongoing Support
  • ISO Standards
    • ISO 9001 Quality Management
    • ISO 45001 Occupational Health and Safety
    • ISO 14001 Environmental Management
    • ISO 17025 Testing and Calibration
    • HACCP Food Safety
    • ISO 19443 Nuclear Supply Chain
  • Resources
    • All Articles
    • ISO Clause Guides
    • Quality Quotes
  • About
    • ISO FAQs
    • Quality Policy
    • Client Testimonials
    • ISO 9001 Certificate
  • Contact
    • Business Info
    • Privacy Policy

By Streamline ISO Consultants

How to Get ISO Certified in Australia: The Full Certification Process

Getting ISO certified follows the same six stages whatever the standard: gap analysis, develop the system, implement it, internal audit, management review, then a two-stage external audit by an accredited certification body. Stage 1 of that external audit checks your system and documentation against the standard. Stage 2 checks that you have actually implemented it, using objective evidence from the way you really operate.

That sequence is identical for ISO 9001 quality, ISO 45001 safety, ISO 14001 environment, ISO/IEC 27001 information security and ISO/IEC 42001 AI management. What changes between them is the subject matter, not the path.

ISO 9001:2026 update, 17 September 2026. ISO published the new edition on 16 September 2026. The Australian adoption is still pending, so a certification audit here is currently conducted against AS/NZS ISO 9001:2016. The six stages below do not change. Our guide to the ISO 9001:2026 changes and transition covers what is changing and how the transition works.

Auditor examining an ISO certificate during a certification audit
Certification is a two-stage audit: Stage 1 checks that your documentation meets the standard, and Stage 2 checks you have implemented the system as documented.

In the United States? This guide covers the Australian route, including JAS-ANZ accreditation. If your ISO 9001 requirement came from a FAR clause or a prime contractor’s flow-down, read ISO 9001 for US federal contractors instead.

The ISO certification process at a glance

StageWhat happensWho does it
1. Gap analysisCompare what you already do against the standard, and find what is genuinely missingYou, or an independent consultant
2. DevelopBuild the documented information the standard requires, around how you actually workYou, mentored or built for you
3. ImplementRun the system long enough to generate real recordsYour team
4. Internal auditAudit the whole system against the standard, clause 9.2A competent, independent auditor
5. Management reviewTop management formally reviews performance, clause 9.3Your leadership team
6. External auditStage 1 documentation review, then Stage 2 implementation auditAn accredited certification body
The path is the same for every management system standard. Only the subject matter changes.

Stage 1: Gap analysis

A gap analysis compares your current operations against the requirements of the standard and tells you what is actually missing. It is the cheapest stage and the one most often skipped, which is why so many projects run over.

The useful output is not a list of missing documents. It is an honest picture of which requirements you already meet without knowing it. Most established businesses are further along than they expect: you already control your processes, keep records, train people and deal with problems. A good gap analysis finds that existing practice and tells you what genuinely has to change.

Stage 2: Develop the system

This is where the documented information gets built: scope, policy, objectives, the processes the standard requires, and the records that will demonstrate them. The trap here is building a system that describes an idealised business rather than yours. A system that contradicts how work is really done creates a permanent gap between the documents and reality, and that gap is exactly what an auditor finds.

Our guide to what a Streamline management system is sets out the design principle we work to: minimum administrative overhead, every element earning its place, built around your real operations. The ISO clause guides explain what each clause actually asks for, and our guide to SMARTER objectives under clause 6.2 covers the part most systems get wrong.

Stage 3: Implement it

This is the stage you cannot compress, and the reason certification has a minimum realistic timeframe. A certification body cannot audit implementation that has not happened yet. You need the system running long enough to have produced genuine records: completed inspections, closed corrective actions, training records, supplier reviews, whatever your processes generate.

Three to six months is the realistic window for most businesses. Shorter than that and the system tends to be rushed, with internal people unable to do their day jobs. Much longer and projects lose momentum and fall off the radar. Our article on whether certification in 10 days is possible explains what actually determines the timeframe, and why a project schedule agreed at the start, including with the certification body, is worth more than good intentions.

Stage 4: Internal audit (clause 9.2)

Before anyone external audits you, the standard requires you to audit yourself. Clause 9.2 asks for an internal audit programme covering the whole system, conducted by auditors who are competent and, critically, objective and impartial with respect to the area being audited. People cannot audit their own work.

This is where a lot of small businesses get stuck, because they do not have someone in-house who is both competent to audit and independent of the work. An independent internal audit solves both problems at once, and it is the last realistic chance to find a nonconformity before the certification body does. See also what an ISO internal audit costs in Australia, and our complete guide to the ISO 9001 audit for what auditors actually look for.

Stage 5: Management review (clause 9.3)

Top management must formally review the system at planned intervals, and the standard specifies the inputs: audit results, customer feedback, performance against objectives, nonconformities and corrective actions, status of actions from previous reviews, changes affecting the system, and opportunities for improvement.

It does not need to be a separate ceremony. If you already hold a monthly leadership meeting, the right standing agenda items turn it into your management review, and the minutes become the record. What an auditor looks for is evidence that leadership actually engaged with the data and made decisions, not that a meeting was held.

Stage 6: The external certification audit

Certification is carried out by an independent certification body, in two distinct stages.

Choose your certification body before you finish building.

The body you pick decides whether your certificate is accepted by the customers asking for it. They must be accredited by JAS-ANZ for your standard and scheme, and their audit calendar will set your dates, so approach them early rather than at the end. This is the most expensive decision to get wrong in the whole process, because an unaccredited certificate usually means doing the work twice.

Compare accredited certification bodies in Australia →

Stage 1: your system and documentation against the standard

The auditor reviews your documented information to confirm the system you have designed actually meets the requirements of the standard. They will look at your scope and its justification, your policy and objectives, your risk work, your internal audit programme and management review, and whether the system covers everything it claims to.

Stage 1 also establishes readiness for Stage 2. If your documentation is incomplete, or your internal audit and management review have not happened, this is where it stops. A weak or ambiguous scope statement is a common cause of trouble here, which is why clause 4.3 and how you determine scope is worth getting right early.

Stage 2: implementation, evidenced

Stage 2 is about objective evidence. The auditor is no longer asking whether your system is designed correctly. They are asking whether you are doing what it says, and they will test that by sampling records, interviewing the people who do the work, and walking your operations.

The difference shows immediately. In a system built around real operations, you ask how a process is controlled and the person who runs it answers from experience, then produces the record from where it already lives. In a system assembled for the audit, the manager answers on everyone’s behalf and the records all carry dates from the same fortnight.

Any nonconformities raised are classified, and you will be given a period to respond with corrections, root cause analysis and corrective action before the certificate is recommended.

After certification: surveillance and recertification

A certificate normally runs for three years, with surveillance audits roughly annually and a full recertification audit at the end of the cycle. Your own internal audit and management review obligations continue throughout, every year, not just before an external visit. Ongoing maintenance and support is what keeps that from becoming an annual scramble.

Accreditation and certification are not the same thing

People commonly say “ISO accreditation” when they mean certification, and it is worth being precise because the distinction matters when a client asks for evidence.

TermWho it applies to
CertificationYour organisation. You get certified to a standard by a certification body.
AccreditationThe certification body. They are accredited by a national accreditation body, JAS-ANZ in Australia and New Zealand.
You are certified. Your certification body is accredited. Asking for “accredited certification” is asking for both.

So when a tender asks for “ISO accreditation”, what it almost always wants is certification from an accredited certification body. Choosing an unaccredited body is the single most common way businesses end up with a certificate a customer will not accept. Our guide to certification bodies in Australia covers how to choose one, and how to check whether a certificate is genuine shows how to verify one you have been given.

Does the process change by standard?

No. All of these share the same Annex SL high-level structure, so the six stages are identical. What differs is what you are managing and what the auditor will sample.

StandardWhat it managesCost and timeline
ISO 9001Quality, product and service conformity, customer satisfactionISO 9001 cost
ISO 45001Work health and safety, hazards, worker consultationISO 45001 cost
ISO 14001Environmental aspects, impacts and compliance obligationsISO 14001 cost
ISO/IEC 27001Information security, risk and Annex A controlsISO 27001 cost
ISO/IEC 42001AI governance and responsible AI useISO 42001 cost
Running more than one? An integrated management system shares the common clauses once instead of three times.

If you need more than one standard, build them as a single integrated management system rather than parallel systems. Context, leadership, objectives, competence, internal audit and management review are shared, so you carry one system and face one combined audit instead of three.

Three ways to get there

  • Do it yourself. Viable if you have someone with the time and the competence, though it is worth reading what an ISO consultant actually does before deciding. The clause guides and FAQs are free and will take you a long way. You will still need an independent internal audit.
  • Mentored. Your team builds the system, we guide it, review what you produce and keep you on track. Cheaper than a full build, and the knowledge stays in your business rather than leaving with a consultant.
  • Built for you. We design and implement the system with you, then hand over something your team can actually run.

Whichever route you take, the clause 9.2 internal audit has to be independent, and a gap analysis at the start will save you money at every stage after it. If you are weighing up quotes, our note on whether cheap certification is worth it is worth five minutes first.

How to get ISO certified: FAQs

What are the requirements for ISO certification?

A management system that meets every applicable requirement of the standard, implemented in practice rather than only documented, evidenced by real records, and verified by a completed internal audit and management review before an accredited certification body audits you in two stages.

How do I get ISO certified in Australia?

Run a gap analysis, develop the system around how you actually operate, implement it for long enough to generate records, complete an independent internal audit and a management review, then engage a JAS-ANZ accredited certification body for the Stage 1 and Stage 2 audits.

What is the difference between a Stage 1 and Stage 2 audit?

Stage 1 reviews your system and documentation against the standard and confirms you are ready. Stage 2 tests whether you have implemented it, using objective evidence: sampled records, interviews with the people doing the work, and observation of your operations.

How long does ISO certification take?

Three to six months is realistic for most businesses. The limit is not paperwork, it is that you must run the system long enough to produce genuine records for the Stage 2 auditor to sample. Faster is possible where an organisation already has strong records and simply needs the system articulated around them.

Is ISO accreditation the same as ISO certification?

No. Your organisation is certified. The certification body is accredited, by JAS-ANZ in Australia and New Zealand. A tender asking for “ISO accreditation” is almost always asking for certification issued by an accredited certification body.

Can we do it ourselves without a consultant?

Yes, if someone in the business has the time and competence. The requirement you cannot self-serve is the clause 9.2 internal audit, which must be objective and impartial with respect to the area audited. Many businesses build the system themselves with mentoring and bring in an independent auditor for that step.

Does ISO issue the certificate?

No. ISO writes the standards but does not perform certification or issue certificates. Certification is carried out by independent certification bodies, which is why a certificate claiming to be issued by ISO is not genuine.

How Streamline can help

Streamline designs, implements, audits and mentors practical ISO management systems for Australian businesses. We can run the gap analysis, build the system with you, mentor your team while they build it themselves, provide the independent internal audit, and stay on afterwards through your surveillance audits. You deal directly with a qualified, experienced ISO consultant who knows what accredited certification bodies actually look for.

Speak with an experienced ISO consultant

Not sure which standard you need, or where to start? Contact us for a free initial consultation. Email hello@streamline.business or call Brisbane 07 3667 8280, Sydney 02 8315 7780 or Melbourne 03 9034 3990.

General guidance only. This article is general information, not legal, financial, safety or compliance advice, and it does not take account of your specific circumstances. Streamline ISO Consultants are ISO management-system consultants, not lawyers or licensed advisers. Standards, laws and regulator guidance change, and details were correct only at the time of writing. Always seek professional advice before acting. See our full Disclaimer.

Stay in the Loop

Get an email when we post an article. Your email address will not be used for marketing, and you can unsubscribe at any time.

We handle your details in line with our privacy policy.

More ISO Certification Information

  • ISO Frequently Asked Questions
    Frequently Asked Questions: ISO FAQs
  • ISO certification bodies in Australia
    How to Choose an ISO Certification Body in Australia
  • Quality inspector in an Australian machining workshop checking a machined aluminium component against a tablet record, with CNC machines and Australian flags behind
    How Much Does ISO 9001 Certification Cost in…
  • ISO 45001 workplace safety inspection
    ISO 45001 Consulting, Safety Audits and Mentoring
  • ISO 14001 environmental management
    ISO 14001 Consulting, Environmental Audits and Mentoring
  • Consultant guiding a business owner through their ISO management system at a laptop
    ISO Mentoring: Expert Guidance for DIY ISO Systems
  • AI startup team reviewing AI tools
    What Is ISO 42001? Australian Certification Guide
  • ISO 9001 quality management inspection
    ISO 9001 Quality Management Consulting, Audits & Mentoring
  • ISO 27001 information security risk analysis
    ISO 27001 Consulting, Internal Audits & Mentoring

Filed Under: Articles Tagged With: #certification, #iso9001

Quick Information Request

Brisbane ISO Consultants

Level 14, 167 Eagle St
Brisbane Queensland 4000
Phone: 07 3667 8280
Email: hello@streamline.business

Sydney ISO Consultants

Level 5, 20 Bond Street,
Sydney NSW 2000
Phone: 02 8315 7780
Email: hello@streamline.business

Melbourne ISO Consultants

Level 8, 350 Collins Street
Melbourne, Victoria 3000
Phone: 03 9034 3990
Email: hello@streamline.business

Client and partner logos

KEY ISO ARTICLES

Articles, Deep Dives & More
Frequently Asked Questions
Quality Quotes
Funding Grants for ISO Certification
ISO Consultants
Strategic Planning - Mystical Art?
ISO Certification Auditors
How to get ISO 9001 Certification
ISO Certification Cost
How to tell if your ISO Cert is fake
4-year-olds and Root Cause Analysis
Fast ISO 9001 Certification
The Ultimate Guide to ISO 9001 Audit
ISO 45001 Certification Cost
Who's Interested in a Party?
How to use Smartsheet for ISO
Smarter Quality Objectives
Local Government QMS
Quality Assurance, Quality Control or QMS
ISO Certification in Sydney
ISO Certification in Melbourne
ISO Certification in Brisbane
SAI Global Consultant Affiliate Program

QUICKLINKS TO ISO INFO

ISO Consultants Australia
ISO Mentoring
ISO 27001 Certification Cost
ISO 9001 Quality Management
ISO 45001 Health & Safety
ISO 14001 Environment
ISO 17025 Testing & Calibration
ISO 27001 Information Security
ISO 42001 AI Management
ISO 22000 HACCP Food Safety

Search

FOLLOW OR GET IN TOUCH

linkedinmail
Smartsheet Platinum Partner

Copyright © 2026 Streamline · Log in

Privacy Policy · Terms of Use · Disclaimer

Call us Enquire