Getting ISO certified follows the same six stages whatever the standard: gap analysis, develop the system, implement it, internal audit, management review, then a two-stage external audit by an accredited certification body. Stage 1 of that external audit checks your system and documentation against the standard. Stage 2 checks that you have actually implemented it, using objective evidence from the way you really operate.
That sequence is identical for ISO 9001 quality, ISO 45001 safety, ISO 14001 environment, ISO/IEC 27001 information security and ISO/IEC 42001 AI management. What changes between them is the subject matter, not the path.
ISO 9001:2026 update, 17 September 2026. ISO published the new edition on 16 September 2026. The Australian adoption is still pending, so a certification audit here is currently conducted against AS/NZS ISO 9001:2016. The six stages below do not change. Our guide to the ISO 9001:2026 changes and transition covers what is changing and how the transition works.

In the United States? This guide covers the Australian route, including JAS-ANZ accreditation. If your ISO 9001 requirement came from a FAR clause or a prime contractor’s flow-down, read ISO 9001 for US federal contractors instead.
The ISO certification process at a glance
| Stage | What happens | Who does it |
|---|---|---|
| 1. Gap analysis | Compare what you already do against the standard, and find what is genuinely missing | You, or an independent consultant |
| 2. Develop | Build the documented information the standard requires, around how you actually work | You, mentored or built for you |
| 3. Implement | Run the system long enough to generate real records | Your team |
| 4. Internal audit | Audit the whole system against the standard, clause 9.2 | A competent, independent auditor |
| 5. Management review | Top management formally reviews performance, clause 9.3 | Your leadership team |
| 6. External audit | Stage 1 documentation review, then Stage 2 implementation audit | An accredited certification body |
Stage 1: Gap analysis
A gap analysis compares your current operations against the requirements of the standard and tells you what is actually missing. It is the cheapest stage and the one most often skipped, which is why so many projects run over.
The useful output is not a list of missing documents. It is an honest picture of which requirements you already meet without knowing it. Most established businesses are further along than they expect: you already control your processes, keep records, train people and deal with problems. A good gap analysis finds that existing practice and tells you what genuinely has to change.
Stage 2: Develop the system
This is where the documented information gets built: scope, policy, objectives, the processes the standard requires, and the records that will demonstrate them. The trap here is building a system that describes an idealised business rather than yours. A system that contradicts how work is really done creates a permanent gap between the documents and reality, and that gap is exactly what an auditor finds.
Our guide to what a Streamline management system is sets out the design principle we work to: minimum administrative overhead, every element earning its place, built around your real operations. The ISO clause guides explain what each clause actually asks for, and our guide to SMARTER objectives under clause 6.2 covers the part most systems get wrong.
Stage 3: Implement it
This is the stage you cannot compress, and the reason certification has a minimum realistic timeframe. A certification body cannot audit implementation that has not happened yet. You need the system running long enough to have produced genuine records: completed inspections, closed corrective actions, training records, supplier reviews, whatever your processes generate.
Three to six months is the realistic window for most businesses. Shorter than that and the system tends to be rushed, with internal people unable to do their day jobs. Much longer and projects lose momentum and fall off the radar. Our article on whether certification in 10 days is possible explains what actually determines the timeframe, and why a project schedule agreed at the start, including with the certification body, is worth more than good intentions.
Stage 4: Internal audit (clause 9.2)
Before anyone external audits you, the standard requires you to audit yourself. Clause 9.2 asks for an internal audit programme covering the whole system, conducted by auditors who are competent and, critically, objective and impartial with respect to the area being audited. People cannot audit their own work.
This is where a lot of small businesses get stuck, because they do not have someone in-house who is both competent to audit and independent of the work. An independent internal audit solves both problems at once, and it is the last realistic chance to find a nonconformity before the certification body does. See also what an ISO internal audit costs in Australia, and our complete guide to the ISO 9001 audit for what auditors actually look for.
Stage 5: Management review (clause 9.3)
Top management must formally review the system at planned intervals, and the standard specifies the inputs: audit results, customer feedback, performance against objectives, nonconformities and corrective actions, status of actions from previous reviews, changes affecting the system, and opportunities for improvement.
It does not need to be a separate ceremony. If you already hold a monthly leadership meeting, the right standing agenda items turn it into your management review, and the minutes become the record. What an auditor looks for is evidence that leadership actually engaged with the data and made decisions, not that a meeting was held.
Stage 6: The external certification audit
Certification is carried out by an independent certification body, in two distinct stages.
Choose your certification body before you finish building.
The body you pick decides whether your certificate is accepted by the customers asking for it. They must be accredited by JAS-ANZ for your standard and scheme, and their audit calendar will set your dates, so approach them early rather than at the end. This is the most expensive decision to get wrong in the whole process, because an unaccredited certificate usually means doing the work twice.
Compare accredited certification bodies in Australia →Stage 1: your system and documentation against the standard
The auditor reviews your documented information to confirm the system you have designed actually meets the requirements of the standard. They will look at your scope and its justification, your policy and objectives, your risk work, your internal audit programme and management review, and whether the system covers everything it claims to.
Stage 1 also establishes readiness for Stage 2. If your documentation is incomplete, or your internal audit and management review have not happened, this is where it stops. A weak or ambiguous scope statement is a common cause of trouble here, which is why clause 4.3 and how you determine scope is worth getting right early.
Stage 2: implementation, evidenced
Stage 2 is about objective evidence. The auditor is no longer asking whether your system is designed correctly. They are asking whether you are doing what it says, and they will test that by sampling records, interviewing the people who do the work, and walking your operations.
The difference shows immediately. In a system built around real operations, you ask how a process is controlled and the person who runs it answers from experience, then produces the record from where it already lives. In a system assembled for the audit, the manager answers on everyone’s behalf and the records all carry dates from the same fortnight.
Any nonconformities raised are classified, and you will be given a period to respond with corrections, root cause analysis and corrective action before the certificate is recommended.
After certification: surveillance and recertification
A certificate normally runs for three years, with surveillance audits roughly annually and a full recertification audit at the end of the cycle. Your own internal audit and management review obligations continue throughout, every year, not just before an external visit. Ongoing maintenance and support is what keeps that from becoming an annual scramble.
Accreditation and certification are not the same thing
People commonly say “ISO accreditation” when they mean certification, and it is worth being precise because the distinction matters when a client asks for evidence.
| Term | Who it applies to |
|---|---|
| Certification | Your organisation. You get certified to a standard by a certification body. |
| Accreditation | The certification body. They are accredited by a national accreditation body, JAS-ANZ in Australia and New Zealand. |
So when a tender asks for “ISO accreditation”, what it almost always wants is certification from an accredited certification body. Choosing an unaccredited body is the single most common way businesses end up with a certificate a customer will not accept. Our guide to certification bodies in Australia covers how to choose one, and how to check whether a certificate is genuine shows how to verify one you have been given.
Does the process change by standard?
No. All of these share the same Annex SL high-level structure, so the six stages are identical. What differs is what you are managing and what the auditor will sample.
| Standard | What it manages | Cost and timeline |
|---|---|---|
| ISO 9001 | Quality, product and service conformity, customer satisfaction | ISO 9001 cost |
| ISO 45001 | Work health and safety, hazards, worker consultation | ISO 45001 cost |
| ISO 14001 | Environmental aspects, impacts and compliance obligations | ISO 14001 cost |
| ISO/IEC 27001 | Information security, risk and Annex A controls | ISO 27001 cost |
| ISO/IEC 42001 | AI governance and responsible AI use | ISO 42001 cost |
If you need more than one standard, build them as a single integrated management system rather than parallel systems. Context, leadership, objectives, competence, internal audit and management review are shared, so you carry one system and face one combined audit instead of three.
Three ways to get there
- Do it yourself. Viable if you have someone with the time and the competence, though it is worth reading what an ISO consultant actually does before deciding. The clause guides and FAQs are free and will take you a long way. You will still need an independent internal audit.
- Mentored. Your team builds the system, we guide it, review what you produce and keep you on track. Cheaper than a full build, and the knowledge stays in your business rather than leaving with a consultant.
- Built for you. We design and implement the system with you, then hand over something your team can actually run.
Whichever route you take, the clause 9.2 internal audit has to be independent, and a gap analysis at the start will save you money at every stage after it. If you are weighing up quotes, our note on whether cheap certification is worth it is worth five minutes first.
How to get ISO certified: FAQs
What are the requirements for ISO certification?
A management system that meets every applicable requirement of the standard, implemented in practice rather than only documented, evidenced by real records, and verified by a completed internal audit and management review before an accredited certification body audits you in two stages.
How do I get ISO certified in Australia?
Run a gap analysis, develop the system around how you actually operate, implement it for long enough to generate records, complete an independent internal audit and a management review, then engage a JAS-ANZ accredited certification body for the Stage 1 and Stage 2 audits.
What is the difference between a Stage 1 and Stage 2 audit?
Stage 1 reviews your system and documentation against the standard and confirms you are ready. Stage 2 tests whether you have implemented it, using objective evidence: sampled records, interviews with the people doing the work, and observation of your operations.
How long does ISO certification take?
Three to six months is realistic for most businesses. The limit is not paperwork, it is that you must run the system long enough to produce genuine records for the Stage 2 auditor to sample. Faster is possible where an organisation already has strong records and simply needs the system articulated around them.
Is ISO accreditation the same as ISO certification?
No. Your organisation is certified. The certification body is accredited, by JAS-ANZ in Australia and New Zealand. A tender asking for “ISO accreditation” is almost always asking for certification issued by an accredited certification body.
Can we do it ourselves without a consultant?
Yes, if someone in the business has the time and competence. The requirement you cannot self-serve is the clause 9.2 internal audit, which must be objective and impartial with respect to the area audited. Many businesses build the system themselves with mentoring and bring in an independent auditor for that step.
Does ISO issue the certificate?
No. ISO writes the standards but does not perform certification or issue certificates. Certification is carried out by independent certification bodies, which is why a certificate claiming to be issued by ISO is not genuine.
How Streamline can help
Streamline designs, implements, audits and mentors practical ISO management systems for Australian businesses. We can run the gap analysis, build the system with you, mentor your team while they build it themselves, provide the independent internal audit, and stay on afterwards through your surveillance audits. You deal directly with a qualified, experienced ISO consultant who knows what accredited certification bodies actually look for.
Speak with an experienced ISO consultant
Not sure which standard you need, or where to start? Contact us for a free initial consultation. Email hello@streamline.business or call Brisbane 07 3667 8280, Sydney 02 8315 7780 or Melbourne 03 9034 3990.
Stay in the Loop
Get an email when we post an article. Your email address will not be used for marketing, and you can unsubscribe at any time.
We handle your details in line with our privacy policy.











