Short, plain English answers to the questions we are asked most often about ISO certification in Australia. Each answer is deliberately brief and links to the full guide on that topic, so use this page to find your starting point rather than as the whole explanation. Figures are Australian dollars and apply to Australian organisations.
Getting started
An independent audit confirming your management system meets a published standard. You build and run the system, an accredited certification body audits it and issues the certificate. See the ISO standards we work with.
Usually whichever your customers or tenders ask for. Quality is ISO 9001, safety ISO 45001, environment ISO 14001, information security ISO 27001. If a tender prompted the question, send us the wording and we will tell you what it requires.
No. It is voluntary. It becomes a commercial requirement when a client, principal contractor or tender makes it a condition of supply, which is how most organisations end up needing it. See ISO 9001 for tenders.
Both are legitimate. If nobody is asking for the certificate, building to the standard without certifying gives you the operational benefit at lower cost. If a tender needs the certificate, the system alone will not satisfy it.
No. A small organisation usually has fewer processes and fewer significant risks, so there is less to control. Size changes the effort, not the eligibility.
You are certified. Certification bodies are accredited. An accreditation body such as JAS-ANZ audits the certification body, which is what makes the certificate mean something. See ISO certification bodies in Australia.
Cost and funding
For ISO 9001, 45001 or 14001, most small to medium organisations land between $7,000 and $25,000 in the first year, covering both consulting support and the certification body audit fees. See the ISO 9001 certification cost guide.
More than the others, typically $15,000 to $30,000 in the first year, because the risk assessment, Statement of Applicability and Annex A controls carry more work. See the ISO 27001 certification cost guide.
Because they are pricing different things. Some cover only the certification audit, some only consulting, some both. Scope, number of sites, headcount and how much work you do yourself all move the number. Ask what is included before comparing.
Yes, substantially. The management clauses are shared, so a standard built as part of an integrated system generally runs 50% to 75% of its standalone cost, and the more you build at once the further toward the lower end it goes.
Sometimes. Funding usually arrives through broader business capability or industry programs where certification counts as eligible expenditure, rather than as an ISO specific grant. See government funding and grants.
A surveillance audit in years two and three, then a recertification audit. Surveillance audits are shorter and cheaper than the initial certification audit. Budget for internal audit and management review time as well.
Timelines and validity
Three to six months for most small and medium organisations. Shorter is usually rushed, because the system has to run long enough to produce records worth auditing. Longer and projects lose momentum. Larger, multi-site and multinational organisations run longer.
Rarely, and not well. The constraint is not how fast a consultant works, it is that a certification body needs evidence the system has been operating. See ISO 9001 certification in 10 days.
Three years, with a surveillance audit each year and a recertification audit before it expires.
The certification body can suspend and eventually withdraw the certificate. Suspension is usually recoverable, withdrawal means starting again. Tell them early if a date is a problem rather than letting it pass.
The standards
The international standard for a quality management system: a documented, working way of running the business so it consistently meets customer and regulatory requirements. See ISO 9001 quality management systems.
The standard for an occupational health and safety management system, built around hazard identification, worker consultation and controlling risk to health and safety. See ISO 45001 safety consulting.
The standard for an environmental management system: identifying where your operation affects the environment, controlling what matters, and meeting your compliance obligations. See ISO 14001 consulting.
The standard for an information security management system, built on a risk assessment, a Statement of Applicability and the Annex A controls. See ISO 27001 information security.
The standard for an artificial intelligence management system, covering governance of AI you build or use. See ISO 42001 AI management.
The standard for testing and calibration laboratories, covering technical competence and valid results rather than management system conformity alone. See ISO 17025 for laboratories.
A food safety approach based on identifying hazards and controlling them at critical points in the process. See HACCP food safety systems.
ISO 14001:2026 was published on 15 April 2026 and replaces both the 2015 edition and the 2024 climate change amendment. The clause structure is retained, so existing systems transition without a rebuild. See the ISO 14001:2026 transition guide and the ISO 9001 equivalent.
Yes, as a context issue. Clause 4.1 requires you to determine whether climate change is a relevant issue for your organisation, and clause 4.2 notes interested parties may have climate related requirements. It is not a requirement to measure emissions or set targets. See climate risk assessment.
Integrated management systems
One management system meeting several standards at once, with a single set of processes, internal audits and management reviews rather than running them in parallel.
Yes, and we usually recommend it. They share the same high level structure, so context, leadership, competence, document control, internal audit, management review and improvement are run once rather than three times.
Yes. Expect a standard built as part of an integrated system to run 50% to 75% of its standalone cost, and the certification body audits them together, which costs less than separate audits.
Certification bodies and certificates
An accredited certification body, independent of any consultant. In Australia most are accredited by JAS-ANZ. See ISO certification bodies in Australia.
Check the accreditation covers the standard and the scope you need, confirm they have auditors competent in your industry, and compare the full three year cost rather than the first year alone. See how to choose a certification body.
Yes. Forgeries are now visually convincing, so the document itself proves nothing. See how to tell if an ISO certificate is real or fake.
Look the certification body up on the accreditation body register for the region where it was accredited, then confirm the certificate and its scope with that body directly. Do not rely on a logo or a PDF.
Yes. A transfer is a defined process and does not mean starting again, provided your current certificate is valid and in good standing. Timing it with a surveillance or recertification audit is usually cleanest.
Audits
Stage 1 reviews the documented system and readiness. Stage 2 tests whether you do what the system says, by sampling records and interviewing people. Both are carried out by the certification body.
By being able to show objective evidence against each clause. The auditor is not looking for perfection, they are looking for a system that operates and that finds its own problems. See the ISO 9001 audit process.
A failure to meet a requirement of the standard or of your own system. Major nonconformities must be closed before certification, minor ones with an agreed corrective action. Finding your own is a sign the system works.
Your own check that the system is working and being followed, required by clause 9.2 of every management system standard, done before the certification body arrives. See internal auditing.
Anyone competent and independent of the area being audited. In a small organisation nobody is independent enough, which is when an external internal auditor is used. See independent internal audits.
A review of what you already have against the requirements of the standard, so you know what is missing before committing to a project. See gap analysis audits.
Consultants and how we work
Helps you design, build and implement the management system, and prepares you for the certification audit. See how an ISO consultant can help.
No. ISO 19011 requires audits to be independent, so the person who built the system cannot certify it. That independence is what makes the certificate credible.
Yes, and if you have a capable operations or HSE person it is often better value. See ISO mentoring, where your team builds it with an experienced auditor alongside.
Ongoing support where we run the management system routines with you, for organisations that need the system maintained without hiring for it. See outsourced ISO manager.
Yes. A gap analysis or a certification readiness review tells you where it would fail before a certification body finds it.
Yes, across Australia, on site and remotely. See ISO consultants Australia.
Still have a question?
Streamline designs, audits and mentors management systems across ISO 9001, 45001, 14001, 27001, 42001, 17025 and HACCP, standalone or integrated. You work directly with a qualified ISO Lead Auditor from the first conversation through to your certification audit. If a tender or a customer has asked you for certification, send us the wording and we will tell you what it actually requires.
Email hello@streamline.business, or call Brisbane 07 3667 8280, Sydney 02 8315 7780 or Melbourne 03 9034 3990.
Book a free consultation →










