If your organization is considering ISO 9001 or AS9100 certification, or is facing its first third-party audit, the “stages” of the audit program may confuse you. It’s all actually fairly simple, but let’s decipher them.

Now, keep in mind this article is about your external, third-party audit conducted by your certification body (CB), not internal audits. These stages are defined in the rules governing CB audits, such as ISO 17021-1 (for both ISO 9001 and AS9100 audits) and various bolt-on standards for AS9100 audits, in particular. Don’t worry about any of those, however.

The good news is the stages are the same for both ISO 9001 and AS9100, so we can cover both in this explanation.

Also, the terms “audit” and “assessment” are often used interchangeably in this context, and I will stick with “audit” because it’s easier.

Stage 0: The Gap Analysis (Optional)

All CBs offer optional “gap analysis” audits or “gap assessments.” These are not required and do not comprise a part of the official audit. They are a way for the CBs to make a bit more money by selling another service.

If you have used a consultant like Oxebridge, or feel confident in your system and internal audit program, there is no need to buy a CB’s gap analysis option. It’s a waste of money.

Worse, some CBs engage in a bit of trickery — if not outright fraud — by implying the gap analysis is mandatory. If you ask, they will admit it isn’t, but it’s like a car salesman adding the “undercoat option” without telling you you don’t need it. Always check your CB quote and contract, and be sure to remove the gap analysis if you didn’t specifically ask for it.

If your company has a complex QMS or you simply have doubts about its conformity, then by all means buy the gap analysis. Just remember it’s optional.

Initial Audit – Stage 1

When you are a company wanting to get certified for the first time, you must undergo what is called an “Initial” Audit. The Initial Audit is a one-time step, and you only go through it when you are audited for the first time. If you let your certification lapse or lose it, you might have to start over and face another Initial Audit, since the scheme treats you as if you had nothing prior. But that’s rare.

The Initial Audit is, by design, the longest you will ever go through. It is comprised of two stages: Stage 1 and Stage 2. The Initial Audit is the only audit type that has these two stages, so, again, once you are certified, you won’t have to worry about this again.

Stage 1 is essentially the CB’s effort to verify a few very basic things before they commit to performing the more detailed Stage 2. Stage 1 includes a rough document review, typically of your Quality Manual (if you have one) and top-level QMS procedures. It’s not a comprehensive document review, however; that used to be the case decades ago but isn’t anymore.

Instead, Stage 1 is a quick check of a few things:

  1. Verification that your company actually exists. This flushes out scam organizations that claim to have a facility but are actually just some guy working out of a cubicle in his local library.
  2. Verification that you have implemented the QMS. This is a very rough verification, by checking to see if you have the necessary QMS documentation in place and, at least on paper, the controls required by the particular standard (ISO 9001 / AS9100).
  3. Identification of huge gaps. Here, the CB auditor is looking for obvious huge problems that would make pursuing Stage 2 wasteful for all the parties involved. For example: you have no QMS documentation at all; you have not performed any internal audits and have no schedule to do so; you are missing crucial staff to run the QMS.
  4. Verification of the scope for Stage 2. The CB will ensure they fully understand what you do, what your products or services are, etc., so they can properly plan the Stage 2 audit. Usually this has already been done during quoting, but the Stage 1 audit is a final check so the CB can update the plan if need be.

Stage 1 is often a half-day or a full day, depending on the size of your company. Since all audit events and stages are based on employee count, very large organizations with many facilities might face a multi-day Stage 1.

The rules for both ISO 9001 and AS9100 allow Stage 1 to be done remotely, but each CB may have additional rules that require it to be performed on-site. Obviously, it’s preferable to have Stage 1 done remotely since it reduces your costs (no expenses) and makes it easier for the CB to schedule the audit, but it’s not a bad idea to have the auditor come on-site and see your plant firsthand before Stage 2.

During Stage 1, the CB does not write “nonconformities,” but instead writes up “areas of concern” (AOCs). These are things the CB will expect you to address before Stage 2 and, if you don’t, may end up becoming NCs at that later stage. So paying careful attention to AOCs is crucial.

In a worst-case scenario, the CB may report that you are nowhere near ready for Stage 2 and pause your certification journey. They may just push out the date for your Stage 2 or, in extreme cases, may tell you you are so far away from being ready that they won’t schedule Stage 2 at all and you are not ready for certification.

Finally, some wonky rules say that if a Stage 2 isn’t conducted within a year of Stage 1, you start over with a new Stage 1. So delaying your Stage 2 scheduling can force you to start from scratch.

Initial Audit – Stage 2

If the CB has opted to proceed to Stage 2, this is where the real action begins. An Initial Audit’s Stage 2 is the longest audit you will ever go through. Most of the time, it must be performed on-site, too. (For AS9100, rules require at least 2/3 of the planned audit time to be done on-site; ISO 9001 has more flexibility and, in cases where the company is not manufacturing anything, they may do 100% of Stage 2 off-site.)

You will receive an Audit Schedule about a month before Stage 2; if you don’t get it, you need to ask for it (CBs often forget to send this). The schedule will lay out each of the planned days for Stage 2, breaking it down by what part of the standard they intend to audit hour-by-hour. You have the right to negotiate this, but only by moving the slots around, not by cutting audit time. For instance, if the CB has scheduled two hours of the audit of purchasing for a Monday, but your purchasing department only operates on Tuesday, you can request that they adjust the schedule.

The calculation for Stage 2 audit duration is (again) based on employee count, along with other factors like the nature of your products or services, whether design is included, distance between facilities, and other risk-related considerations. But it will almost always be a multi-day event unless you are a very tiny organization with only 10 employees or fewer. The CB only has a little bit of wiggle room in adjusting the Stage 2 duration, based on things like risk and number of facilities, etc. There are certain minimums they cannot drop below, however.

(In reality, the audit duration tables are a bit unfair. Small organizations tend to get over-audited at Stage 2, and huge organizations get under-audited. It’s an imperfect system.)

At the end of Stage 2, you will receive three types of findings from the CB:

  • Major Nonconformities: these are very serious lapses or gaps that must be addressed before the CB can release your certificate. A failure to close the Majors in the time frame dictated by the CB will mean you don’t get certified and may have to start from scratch (all the way back to an Initial Audit). In many cases, a Major will require the CB auditor to come back on-site to perform a “corrective action verification” audit. This is typically a half-day, but could be more if you have many Major NCs. In some cases, this can be done remotely.
  • Minor Nonconformities: these are smaller issues that don’t necessarily put your certification at risk. For ISO 9001, you can be certified with open minor NCs, provided you have proven to the CB that you have filed a corrective action plan on your end, and provided they agree with that plan. For AS9100, however, the Minors must also be closed before the CB releases your certificate, but they are usually pretty easy to resolve. Minors don’t trigger the need for a special, on-site verification by the CB.
  • Opportunities for Improvement (OFI): these are controversial findings in that they hand the CB auditor a chance to provide “consulting” while circumventing the rules that prohibit CBs from performing consulting. By calling them “OFIs,” the CBs essentially get away with it. See this article on how CBs are supposed to write OFIs, but never do. OFIs represent a perceived gap the CB auditor sees but cannot justify writing an NC, typically because the problem is not a violation of any direct requirement in the ISO 9001 or AS9100 standard. I say “perceived” because OFIs are the auditor’s opinions, even if they stamp their foot and insist they are 100% correct. OFIs are a toxic practice and should be banned, but they make the client feel warm and fuzzy, so no one stops it. You do not have to take action on CB’s OFIs and can ignore them entirely. I recommend you write them up in your corrective action system so they are logged, at least, but then close the CA in your system by saying, “the recommendation was not taken.”

Assuming all goes well with Stage 1 and Stage 2, and all your NCs are bought off by the CB, you will then receive your certificate.

Surveillance Audits

Now you enter the surveillance period of your certification, which, unless you lose or abandon it, will remain a permanent state. You won’t see those Stage 1 and Stage 2 audits ever again.

Surveillance Audits are annual by default, but some companies opt to undergo them every six months to have a more routine check by the CB. That’s up to you.

A Surveillance Audit is not a full audit of ISO 9001 or AS9100, but 50% of the standard and 50% of your QMS. So after two Surveillance audits, your entire QMS has been checked against the standard. As a result, Surveillance Audits are much shorter than that Stage 2.

During Surveillance, they write up NCs and OFIs just as they did during the other audit events. You must close all Majors and (for AS9100) the Minors, too, in order to maintain your certification. If you exceed the CB’s required response date, you will lose your certification and have to start over from scratch.

Three-Year Recertification

Every three years, you then undergo a Recertification Audit. This is a bit longer than a typical Surveillance, but less than the Stage 2. In fact, it’s typically calculated at 2/3 the duration of Stage 2.

The Recertification is a full check of your entire QMS against the entire ISO 9001/AS9100 standard. Again, this will result in NCs and OFIs if the CB finds any issues. And, again, you have to close those or face losing your certification.

Once you pass your Three-Year Recertification, you resume with annual Surveillance Audits for the next two years. And from then on, it’s rinse-and-repeat.

Special Audit

Sometimes, a CB may announce they are performing a Special Audit on your company. This is an audit outside of the normal annual cycle and typically prompted by some big customer complaint, scandal, or other problem your company may be involved in. Special Audits are usually pre-scheduled, but can be unannounced.

A Special Audit will have its own plan and schedule, since it’s prompted by some unusual thing that happened. If you ensure your company operates properly, ethically, and doesn’t ship defective product, you probably will never face a Special Audit.

AB Witness Audit

Your certification body must be accredited, or your certificate is fake. To achieve this, the CB itself undergoes annual audits, but not to ISO 9001. Instead, it is to ISO 17021-1 and whatever other scheme rules apply. These are performed by an Accreditation Body (AB), which then writes NCs against the CB. You can identify which AB has accredited your CB because both logos (the CB and the AB) typically appear on your certificate.

Major ABs include ANAB (USA),  IAS (USA), UKAS (UK), JASANZ (Australia), DAkkS (Germany), etc.

The annual audit of the CB by the AB occurs in two steps: an office audit held at the CB’s headquarters and then a “witness audit” where the AB shadows along with the CB during an audit of their client. This may be you. You may be notified by the CB that — through a random roll of the dice — your audit will be the one selected by the AB to witness the CB.

You cannot refuse. Some pretty draconian rules behind the scenes say that any client who refuses to allow the AB to witness the CB is banned for life from certification. So you don’t just lose your certification; you can’t even re-apply. I am pretty sure this wouldn’t hold up in court, but it’s never been tested.

In such cases, don’t panic. The AB just sits silently during the audit and isn’t really even allowed to talk much to you. They are witnessing your CB, not you.

Hardgrading and Softgrading

For all audits, CBs may engage in what is called “hardgrading” or “softgrading” of their findings. Both practices are prohibited, but CBs do them anyway. These are as follows:

  • Hardgrading: This is when the CB writes what should be a Minor nonconformity, but grades it as a Major. This might be because the auditor is unskilled or just not competent. More often, however, this happens during AB Witness Audits. While during your normal annual audit, the CB might write Minor NCs, when they have the AB looking over their shoulder, they almost always write them as Majors, no matter how significant. This is so that the AB can go home feeling they did something. It’s wholly unfair, but you have no recourse outside of the courts.
  • Softgrading: This is when the CB auditor writes what should have been a Major NC, but classifies it as a Minor. This is typically done by “friendly” auditors who don’t like upsetting clients or by a (secret) policy by the CB, who is afraid that writing Majors will cause the client to fire them. It’s also a bad practice, but it happens in the majority of audits. CBs are in a competitive industry and don’t want to lose clients to competing CBs.

Moldy Bread

Finally, there is one very, very bad practice that many auditors engage in, and which doesn’t have any official name. I call it the “Moldy Bread Scenario,” where a CB auditor writes an OFI but says, “If I come back next year and you haven’t addressed this, I will escalate this to a nonconformity.” Or, alternatively, they threaten to elevate a Minor to a Major at the next audit.

Let’s call this what it is: spite. The auditor’s ego has gotten in the way of his objectivity, and now they want to ensure you obey them or face punishment. It’s bullshit.

Nonconformities must be based on two main factors: requirements and evidence. The NC either exists, or it doesn’t. An OFI doesn’t “go bad” over time just because you chose not to take the auditor’s (cloaked) consulting advice. If the auditor does elevate it later, they are only doing so out of spite.

A Minor NC can become a Major if the evidence proves the situation has worsened. But the CB auditor cannot read the future, so they have no idea what state your QMS will be in next year.

Instead, tell the CB auditor to write the OFI as an NC now, but be sure to base it on documented requirements and evidence. They typically cannot, so they will drop the matter entirely. If the auditor threatens, “This will become a Major next year,” tell them you will address it next year, and he will (again) have to write his Major NC based on requirements and evidence.

Heck, you might not even get the same auditor next year!

In closing, I hope this guide helps you understand the overall process. As always, if you need help getting ready for any audit, whether an Initial one or an upcoming Surveillance, feel free to reach out.

 

Advertisements

Aerospace Exports Inc