Article

From a self assessment to a certificate: how the work runs

The stages between a fifteen-minute readiness checklist and an accredited certificate, what each one produces, and who does the work at each step.

Prem Kumar Dvivedi · 30 August 2026

MSCi — Management System Compliance Incorporation — is asked one question more than any other in a first meeting: what actually happens between here and a certificate. This is the answer, in order.

1. The self assessment

Fifteen minutes, free, and done by you rather than to you. You pick the standard, describe the organisation briefly, and answer the questions an auditor would ask. The result is a score out of 100, the heaviest gaps ranked, and a set of recommendations sent to you as a document.

What it produces: a shared starting point. Everything after this is priced and planned against it rather than against a guess.

2. The gap assessment

This is the self assessment done properly, by somebody who does it for a living, against evidence rather than recollection. A consultant reads what you actually have, watches how work actually happens, and writes down the difference between that and the standard.

It is the step most often skipped and the one that most often decides the cost of everything after it. A self assessment is optimistic by nature — people answer for the organisation they intend to be. The gap assessment establishes the organisation that exists.

What it produces: a written gap list, a scope, and a realistic timeline.

3. Design and documentation

The documented information the standard requires, written to fit how your organisation works rather than lifted from a template. The test we apply is whether the person who has to follow a procedure would recognise their own job in it.

A caution worth stating plainly: length is not compliance. A quality manual nobody reads is a liability at audit, because the auditor will read it and will ask why it does not describe what you do.

What it produces: the policy, the procedures, the records structure, and the risk and objective framework the standard asks for.

4. Training

Two kinds. Awareness training so that people understand what the system is for and can answer an auditor without rehearsing, and internal auditor training so that the organisation can check itself after we have gone.

What it produces: competence records, and — more importantly — a handful of people inside the company who can run this without us.

5. Implementation

The system is used. Records accumulate, non-conformities are raised and closed, corrective actions are taken and evidenced. This is the stage that cannot be compressed: an auditor is entitled to see the system working over a period, and three months of real records cannot be produced in a fortnight.

What it produces: evidence. Which is the only thing a stage 2 audit is really about.

6. Internal audit and management review

Your own audit of your own system, followed by a management review in which leadership actually reviews it and makes decisions. Both are required by the standard, both are commonly treated as paperwork, and both are where an experienced auditor looks first to judge whether a system is real.

What it produces: internal audit reports, corrective actions, and minutes that show decisions rather than attendance.

7. The certification audit

Conducted by a certification body you appoint — never by us, and never by any consultancy that built the system. Stage 1 checks readiness and documentation. Stage 2 tests whether the system is genuinely operating. Findings are raised, corrected and closed, and the certificate follows.

8. Afterwards

Surveillance audits, usually annually, and recertification at three years. The system that stops the day the certificate arrives is the system that fails its first surveillance. This is what our tagline is about: En-route Perfection — the certificate marks a point on the route, not the end of it.

How long, honestly

For a single-site organisation with cooperative leadership and a decent starting score, three to six months is realistic. Multi-site operations, several standards at once, or a system being built from a genuinely low base take longer. Anybody quoting a fixed number before the gap assessment is quoting a hope.

If you have not done step one, it is free, and it is the only step you can complete today. We work across India, Mongolia, Australia, Nigeria, South Africa and the United States, and the sequence above is the same in all six.

About the author

Prem Kumar Dvivedi is an auditor with more than forty years in this industry. He has spent that time on both sides of the table — building management systems and auditing them — across quality, environment, health and safety, food safety and information security.

See how this looks as a working system

Reading about a requirement and seeing the documentation that satisfies it are different things. In a short demo we open the actual manual, procedures and records set for ISO 9001, show you how each clause is answered and where your existing way of working already fits. You will know what implementation involves before you commit to it.

Ask us about this

Tell us what is being asked of you and by whom.

What are you looking for?

We reply within one working day. Your details stay with our consultants.

More reading

All articles