Article
From a self assessment to a certificate: how the work runs
The stages between a fifteen-minute readiness checklist and an accredited certificate, what each one produces, and who does the work at each step.
Prem Kumar Dvivedi · 30 August 2026
MSCi — Management System Compliance Incorporation — is asked one question more than any other in a first meeting: what actually happens between here and a certificate. This is the answer, in order.
1. The self assessment
Fifteen minutes, free, and done by you rather than to you. You pick the standard, describe the organisation briefly, and answer the questions an auditor would ask. The result is a score out of 100, the heaviest gaps ranked, and a set of recommendations sent to you as a document.
What it produces: a shared starting point. Everything after this is priced and planned against it rather than against a guess.
2. The gap assessment
This is the self assessment done properly, by somebody who does it for a living, against evidence rather than recollection. A consultant reads what you actually have, watches how work actually happens, and writes down the difference between that and the standard.
It is the step most often skipped and the one that most often decides the cost of everything after it. A self assessment is optimistic by nature — people answer for the organisation they intend to be. The gap assessment establishes the organisation that exists.
What it produces: a written gap list, a scope, and a realistic timeline.
3. Design and documentation
The documented information the standard requires, written to fit how your organisation works rather than lifted from a template. The test we apply is whether the person who has to follow a procedure would recognise their own job in it.
A caution worth stating plainly: length is not compliance. A quality manual nobody reads is a liability at audit, because the auditor will read it and will ask why it does not describe what you do.
What it produces: the policy, the procedures, the records structure, and the risk and objective framework the standard asks for.
4. Training
Two kinds. Awareness training so that people understand what the system is for and can answer an auditor without rehearsing, and internal auditor training so that the organisation can check itself after we have gone.
What it produces: competence records, and — more importantly — a handful of people inside the company who can run this without us.
5. Implementation
The system is used. Records accumulate, non-conformities are raised and closed, corrective actions are taken and evidenced. This is the stage that cannot be compressed: an auditor is entitled to see the system working over a period, and three months of real records cannot be produced in a fortnight.
What it produces: evidence. Which is the only thing a stage 2 audit is really about.
6. Internal audit and management review
Your own audit of your own system, followed by a management review in which leadership actually reviews it and makes decisions. Both are required by the standard, both are commonly treated as paperwork, and both are where an experienced auditor looks first to judge whether a system is real.
What it produces: internal audit reports, corrective actions, and minutes that show decisions rather than attendance.
7. The certification audit
Conducted by a certification body you appoint — never by us, and never by any consultancy that built the system. Stage 1 checks readiness and documentation. Stage 2 tests whether the system is genuinely operating. Findings are raised, corrected and closed, and the certificate follows.
8. Afterwards
Surveillance audits, usually annually, and recertification at three years. The system that stops the day the certificate arrives is the system that fails its first surveillance. This is what our tagline is about: En-route Perfection — the certificate marks a point on the route, not the end of it.
How long, honestly
For a single-site organisation with cooperative leadership and a decent starting score, three to six months is realistic. Multi-site operations, several standards at once, or a system being built from a genuinely low base take longer. Anybody quoting a fixed number before the gap assessment is quoting a hope.
If you have not done step one, it is free, and it is the only step you can complete today. We work across India, Mongolia, Australia, Nigeria, South Africa and the United States, and the sequence above is the same in all six.
About the author
Prem Kumar Dvivedi is an auditor with more than forty years in this industry. He has spent that time on both sides of the table — building management systems and auditing them — across quality, environment, health and safety, food safety and information security.
See how this looks as a working system
Reading about a requirement and seeing the documentation that satisfies it are different things. In a short demo we open the actual manual, procedures and records set for ISO 9001, show you how each clause is answered and where your existing way of working already fits. You will know what implementation involves before you commit to it.
More reading
- ISO 14001:2015: documentation and compliance requirements
Everything ISO 14001:2015 requires you to document, clause by clause, with what an auditor asks to see for each. Written as requirements rather than as a checklist.
12 September 2026
- ISO 14001:2026: documentation and compliance requirements
Everything ISO 14001:2026 requires you to document, clause by clause, with what an auditor asks to see for each. Written as requirements rather than as a checklist.
12 September 2026
- ISO 22000:2018: documentation and compliance requirements
Everything ISO 22000:2018 requires you to document, clause by clause, with what an auditor asks to see for each. Written as requirements rather than as a checklist.
12 September 2026
