Certification is the start of the obligation, not the end of it

Internal audits, management reviews, surveillance preparation and system maintenance — run for you, on a schedule, so nothing lapses between audits.

Most businesses get certified, breathe out, and then do very little until three weeks before the surveillance audit. By then the internal audit programme has not run, the management review minutes do not exist, three suppliers have changed without approval, and the corrective actions from last year were never closed out.

None of that is a quality problem. It is a maintenance problem — and it is the single most common reason a surveillance audit goes badly.

Your certification body will check that the system is being run, not just that it was built. Internal audits and management review are explicit requirements of every ISO management system standard. Missing them is a non-conformance in its own right, regardless of how well the business is actually performing.

What we run for you

  • 1

    Internal audit programme

    A full annual schedule covering every clause and every process, carried out by an auditor who is independent of the area being audited.

  • 2

    Findings and corrective actions

    Written plainly, tracked to closure, with root cause recorded properly rather than “operator error”.

  • 3

    Management review

    Agenda, inputs, data and minutes prepared to the standard’s requirements, so the review stands up to scrutiny.

  • 4

    Document control

    Procedures kept current as your process, equipment and people change. Obsolete versions withdrawn.

  • 5

    Supplier and change management

    New suppliers assessed, new products brought into scope, changes recorded before they become audit findings.

  • 6

    Pre-surveillance check

    A mock audit ahead of your certification body’s visit, so you find the gaps before they do.

  • 7

    Standard transitions

    When a standard is revised, we map the changes and update your system inside the transition window.

Who this suits

  • Businesses certified to ISO 9001, 45001, 14001, 22000, 27001, 13485 or HACCP that have no dedicated quality manager
  • Sites where the person who built the system has since left
  • Multi-site operations needing a consistent audit programme across locations
  • Businesses holding more than one certification and wanting a single integrated audit schedule
  • Anyone who had a rough surveillance audit last time and does not want a repeat

How it works

We agree an annual programme up front — how many audit days, which months, which processes — and then simply run it. You get a report after each visit, an actions register you can see at any time, and a clear picture going into every surveillance audit.

It is priced as a fixed annual fee, not hourly, so there is no disincentive to pick up the phone.

We are a consultancy, not a certification body. We build and maintain systems and prepare you for audit; your certificate is issued by an independent accredited certification body. Keeping those roles separate is what makes your certificate credible to the customer who asked for it.

Keep your certification in good shape

Tell us which standards you hold, how many sites you run and when your next surveillance audit falls due.

Contact Cert360