The Certification Process
Nine steps, from first enquiry to recertification.
- 1
Enquiry & application
Send us the application and questionnaire. We reply with the audit duration and a fee proposal.
Your organisation - 2
Certification agreement
If you accept the proposal, sign the certification agreement and return it by email or fax.
Your organisation - 3
Audit plan issued
The audit team leader sends you the audit plan before the visit.
ITS Certification Body - 4
Pre-audit (optional)
If you wish, a pre-audit can be carried out before Stage 1 and Stage 2. This is not mandatory.
Optionaloptional - 5
Audit (Stage 1 & Stage 2)
Stage 1 reviews documentation; Stage 2 is the on-site audit. Any nonconformity must be corrected.
ITS Certification Body - 6
Certification decision
Once corrective action is complete, the certification committee decides on registration.
ITS Certification Body - 7
Certificate issued
Following a positive decision, the certificate is issued.
ITS Certification Body - 8
Surveillance audit
At least once a year, a surveillance audit confirms the system is still in place.
ITS Certification Bodyevery year - 9
Recertification audit
Every three years the certificate is renewed. The recertification audit must be completed before the expiry date, and any nonconformities must be closed before that date as well.
ITS Certification Bodyevery 3 years
Ready to start at step 1?
Tell us your organisation’s size and the standards you need, and we will send the audit duration and fee proposal.
When certification is refused
An application for certification may be rejected at the application review. We publish in advance what is checked, in accordance with the ITS procedures.
7.1 (1)·(2)Application review — the application is accepted or rejected
Before proceeding with the audit, ITS reviews the application documents and the information attached, received from the organization, in accordance with P511 Application and Contract of Certification, so as to ensure the following.
- (a) That the information on the applicant organization and its management system is sufficient to develop the audit programme
- (b) That any known difference in understanding between the certification body and the applicant has been resolved
- (c) That the certification body has the competence and the ability to perform the certification activity
- (d) That account is taken of the scope of certification applied for, the location(s) of the applicant, the time needed to complete the audit and any other matters affecting the certification activity, such as language, conditions relating to safety and threats to impartiality
- (2) Following the application review, ITS shall accept or reject the application. Where it is rejected, the reason shall be documented and clearly communicated to the applicant.
After certification — maintaining and renewing
The following is in accordance with the ITS procedure “P811 Certification procedure guide”.
7.6.1 (1)Surveillance activities
Surveillance activities may include the following, and the certification organization shall cooperate with the ITS upon request.
- ① The ITS querying the certification organization on aspects related to the certification
- ② Auditing the organization's declarations about its operations (e.g., publications, website)
- ③ Requesting the certification organization to provide documents and records (written or electronic)
- ④ Other means of monitoring the performance of the certified organization
7.6.1 (2)Surveillance audit
A surveillance audit is an on-site audit but does not need to be an audit of the entire system, and the ITS shall plan these surveillance audits in conjunction with other surveillance activities to maintain confidence that the certified organization's certified management system continues to meet the requirements during the period between recertification audits. Each surveillance audit of the relevant management system shall include the following.
- ① Internal audit and management review
- ② An audit of actions taken to address nonconformities identified in the previous audit
- ③ Handling of complaints
- ④ The effectiveness of the management system(s) with respect to achieving the certified organization's objectives and the intended results of each management system(s)
- ⑤ Progress of activities planned for the purpose of continual improvement
- ⑥ Ongoing operational control
- ⑦ Audit of changes
- ⑧ Use of the mark and/or reference to other certifications
7.6.2.1 (1)Purpose of the recertification audit
The purpose of the recertification audit is to verify the continued conformity and effectiveness of the management system as a whole and to confirm the continued relevance and applicability of the management system to the scope of certification. The recertification audit shall be planned and conducted to assess the continued fulfilment of all requirements of the applicable management system standard or other reference document, and shall be planned and conducted in a reasonable amount of time to ensure that recertification occurs in a timely manner prior to the certification expiration date.
7.6.2.1 (2)Consideration of management system performance in the most recent certification cycle
The recertification activity shall include an audit of the previous surveillance audit reports and shall consider the management system performance for the most recent certification cycle.
7.6.2.1 (3)Changes may require a stage 1 audit
If there are significant changes to the management system, the certified organization, or the context in which the management system operates (e.g., changes in legislation), a stage 1 audit may be required at the time of the recertification audit.
7.6.2.2 (1)What the recertification audit includes
The recertification audit shall include an on-site audit that addresses the following points.
- ① The effectiveness of the management system as a whole in the light of internal and external changes, and its continued relevance and applicability to the scope of certification
- ② Demonstrated commitment to maintaining the effectiveness and improvement of the management system in order to enhance overall performance
- ③ The effectiveness of the management system(s) in relation to the achievement of the certified organization's objectives and the intended outcomes of each management system(s)
7.6.2.2 (2)Deadlines for correction and corrective action for major nonconformities
The ITS shall establish deadlines for corrections and corrective actions for all major nonconformities, and these actions shall be implemented and verified prior to the expiration of the certification.
7.6.2.2 (3)Recertification completed before the expiry date
If the recertification activity is successfully completed before the expiration date of the currently held certification, the expiration date of the new certification may be based on the expiration date of the existing certification. The issue date of the new certificate shall be on or after the recertification decision date.
7.6.2.2 (4)Limitations on the certification recommendation
If the ITS has not completed the recertification audit, or is unable to verify the implementation of corrections and corrective actions for major nonconformities before the certification expiration date, recertification shall not be recommended and the validity of the certification shall not be extended. The organization shall be notified and the consequences explained.
7.6.2.2 (5)Reinstatement of certification
Following the expiration of a certification, the ITS may reinstate the certification within six months, provided that the outstanding recertification activities are completed; otherwise, at a minimum, a stage 2 audit shall be conducted. The certification validity date shown on the certificate shall be on or after the recertification decision date, and the expiration date shall be based on the previous certification cycle.
7.6.3 (1)Special audits — when the organization changes
The special audit shall be conducted when changes affecting the system of the certified organization occur; the application shall be audited in accordance with the certification audit operating procedure, and the applicant or registered organization shall be informed of the special audit for the changes.
7.6.3 (2)Special audits — short-notice audits
ITS may conduct an audit of a certified organization at short notice, or without notice, to investigate a complaint, respond to a change, or follow up with a certified organization whose certification has been suspended. In this case the ITS shall perform its duties as follows.
However, for occupational health and safety management systems, where the ITS becomes aware that a significant safety-related event has occurred, such as a major accident or a major breach of law, and a special audit is required — apart from the involvement of the competent authority — to investigate whether the management system has been compromised or is operating effectively, the ITS shall document the results of the investigation.
The ITS shall describe the conditions under which such short-notice visits are conducted and inform the certified organization in advance.
The ITS shall pay particular attention to the assignment of the audit team, as the organization has insufficient opportunity to object to the appointment of the audit team members.
What a certified organisation must do
Keeping certification takes longer than getting it. Failing to meet these obligations can lead to suspension.
11 obligations after certification — open
- 1.Maintain the management system in conformity with the certification standard and ITS audit requirements, and comply with the laws and regulations related to the certification scheme.
- 2.Notify ITS within one month of any of the changes listed below.
- 3.Cooperate so that all audits, regular or special, can be carried out in accordance with ITS requirements.
- 4.Permit witness and special audits conducted directly by the accreditation body. Refusal may invalidate the certification contract.
- 5.Follow the rules on the use of the certification mark and on publicity.
- 6.Pay the audit fee by the stated deadline.
- 7.Correct any nonconformities raised within the required time and submit the results to ITS.
- 8.Keep all certification-related documents exchanged with ITS during application and maintenance.
- 9.Record complaints received from interested parties, customers and employees and the corrective actions taken, and submit those records on request.
- 10.Submit a list of revisions whenever the manual is revised.
- 11.Do not use the certification in a way that could damage the reputation of ITS, and do not make statements that mislead others about what is certified.
Changes you must notify within one month (6)
- 1.Legal, commercial or ownership status
- 2.Organisation and management (key managerial, decision-making or technical staff)
- 3.Contact address and sites
- 4.Scope of operations under the certified management system
- 5.Major changes to the management system and processes
- 6.A serious incident or breach of regulation that requires the involvement of the regulatory authority
When certification is suspended or withdrawn
We publish in advance when certification stops and when it is withdrawn — as required of certification bodies by ISO/IEC 17021-1.
15 grounds for suspending the whole certification — open
- 1.Failure to undergo the surveillance audit within the required time, and still not within one month of the notice of suspension
- 2.The audit shows the organisation lacks the resources or structure to meet the standard, or the system is largely not operating
- 3.Credibility of the system is lost through claims by interested parties or public controversy
- 4.No action taken in response to changes in the system or in certification requirements
- 5.A major nonconformity found at the on-site verification audit recurs at the re-verification audit
- 6.No corrective action within one month of a notice about misuse of the certification mark
- 7.Non-payment of the audit fee
- 8.Failure to meet the obligations set out in the certification agreement
- 9.Use beyond the scope stated on the certificate
- 10.Information or documents provided at application or audit are found to be false
- 11.Reorganisation or major system changes not disclosed
- 12.Breach of the contract or agreement with ITS
- 13.The organisation itself requests suspension
- 14.Corrective action for a major nonconformity not taken within 90 days
- 15.An administrative penalty or corrective order from the authorities (serious accident or breach of law) is not effectively addressed within the required time
Grounds for suspending part of the scope
- 1.No record of the system operating for one year for part of the standard, scope or site
- 2.No production for one year for some products within the scope
Grounds for withdrawing certification
- 1.No corrective action three months after suspension (may be deferred, documented, with the accreditation body's agreement where there is good reason)
- 2.The organisation formally returns the certificate
- 3.Production, activities or services within the scope are discontinued (limited to that scope)
- 4.The organisation ceases to exist or cannot be contacted
- 5.Certification has been suspended three or more times within the validity period
- 6.Failure to return the certificate for more than one month after a request
Restoring a suspended certification
ITS restores the suspended certification once the issue that caused the suspension is resolved.
Responsibility for certification
- Responsibility for conformity
- Responsibility for consistently achieving the intended results of the management system and for conformity with certification requirements lies with the certified organisation, not with the certification body.
- Auditing is based on sampling
- The audit is based on sampling within the organisation's management system, so 100% compliance with requirements is not guaranteed.
- Who decides
- ITS has the responsibility and authority for decisions on granting, refusing, maintaining, expanding or reducing the scope, renewing, suspending, restoring and withdrawing certification. Those decisions are made by competent persons who did not carry out the audit.
Appeals and complaints
You may appeal in these cases
- 1.The application was rejected without good reason
- 2.You cannot agree with how the audit was conducted or with its result
- 3.Tangible or intangible damage has occurred or is expected because ITS or an auditor did not follow the applicable rules
- 4.Any other outcome of ITS's handling that is unsatisfactory
How it is handled
- By when
- In writing, before 45 days have passed.
- Who handles it
- Where the matter is serious a handling team may be formed, made up of people with no direct interest in it.
- When you get an answer
- ITS notifies the outcome in writing within one month, in accordance with its complaints and appeals procedure.
- If you disagree with the outcome
- The matter follows the arbitration or authoritative interpretation of the accreditation body.
Complaints and appeals must be recorded and answered (ISO/IEC 17021-1). Anything you send is kept on record.
See also
This is taken from the ITS procedure “P811 Certification procedure guide” (2026-08-10, E4, R0). Please contact the certification administration office for the full text.
