What certification auditors actually ask for
27 March 2026 · 4 min read · Certification
Documentation is not the hard part. Demonstrating that your management system is operating is.
Stage 1 tests design, Stage 2 tests operation
Stage 1 is largely a documentation review: is there a defined scope, a risk methodology, a Statement of Applicability, and evidence that leadership is involved. Most organisations that fail here failed on scope clarity, not on missing paperwork.
Stage 2 is where systems come apart. The auditor samples records and looks for a system that has been running, not one assembled the week before.
The records that matter most
Internal audit reports with genuine findings. Management review minutes with decisions attached. Corrective actions that were closed with evidence. Access reviews performed on the cadence your policy claims. Supplier assessments that predate the audit.
A control with a beautiful policy and no operating records is a nonconformity.
Build the evidence habit early
The organisations that pass smoothly are those that started generating records at the beginning of the programme rather than documenting first and operating later. Three months of real records beats a perfect manual every time.
Working through this yourself?
We run ISO 27001 and ISO 42001 readiness programmes and quantum training for teams facing exactly these decisions.
Book a discovery call