What you are actually being asked to build
ISO 9001 is often described as a documentation standard, which is how organisations end up with sixty procedures nobody reads and a nonconformity at their first audit anyway. The standard asks for something narrower and harder: evidence that you understand your processes, that you control them, and that you act when they do not perform.
Strip it back and there are four things a certification body needs to see working. You know what your organisation is for and who it serves. You have identified the processes that deliver that, and their sequence and interactions. You measure whether they are working. And when they are not, something happens as a result.
Everything else — the policy, the objectives, the documented information, the management review — exists to serve those four. If a document you are writing does not serve one of them, you are writing it for the folder, not the system.
The reframe
Ask of every procedure you are about to write: if this document vanished tomorrow, would anyone do the work differently? If not, do not write it. An auditor cannot fault you for a procedure you were never required to have.
Scope: the decision that shapes everything
Scope is the first thing on the certificate and the first thing an auditor reads, and it determines how much work the whole project is. It names what your management system covers: which activities, which products and services, which sites.
The temptation is to scope broadly, because a broad certificate looks better in a tender. The cost is that everything inside that boundary must genuinely be controlled, audited and evidenced. A narrow, honest scope certified well is worth more than a broad one that collapses under sampling.
- Name the products and services, not the departments. Certification follows what you deliver, not your org chart.
- Be explicit about sites. A second branch inside the scope needs its own evidence, and auditors will visit.
- If you exclude a requirement, you must justify why it does not apply and be able to defend that. Exclusions are allowed; unexplained gaps are not.
- Write the scope statement early and test it against a tender document. If it would not satisfy the customer asking for the certificate, widen it now rather than after certification.
Document what you do, not what you wish you did
The single most expensive mistake in a self-run implementation is writing aspirational procedures. Someone sits down, describes how the process ought to work, and the organisation is then audited against that description. Every gap between the ideal and the reality becomes a finding — findings you created yourself, in a document nobody asked you to write.
The alternative takes less time and produces a better system. Go and watch the process. Write down what actually happens, including the workaround everyone uses and the step that gets skipped when it is busy. Then decide, deliberately, which parts of that reality need to change — and change them before you document the new version.
- 1.Map the process as it runs today, with the people who run it in the room.
- 2.Mark the steps that are genuinely necessary for control, and the ones that are habit.
- 3.Fix what needs fixing in the process itself — not in the description of it.
- 4.Document the result at the lowest level of detail that keeps it controlled. A one-page flow beats an eight-page procedure that goes unread.
- 5.Have the people who do the work confirm it is accurate before it is approved.
This also makes internal audit dramatically easier later. When the documented process is the real process, an audit is a short conversation and a look at some records, rather than an exercise in explaining why nobody follows the manual.
Nine months, honestly
For an organisation of twenty to two hundred people with no existing system, nine months from decision to certification audit is realistic if someone owns it for a meaningful part of their week. Six is possible with focus. Eighteen usually means it stalled, not that it was thorough.
- Month 1–2Scope and context. Define the boundary, identify interested parties, list your processes and their sequence. Write the quality policy last, once you know what it is describing.
- Month 3–4Process work. Map and correct the processes that matter. This is the bulk of the effort and the part that produces real improvement.
- Month 5Documented information. Write only what is required or genuinely useful. Set up version control and make the current version the easiest one to find.
- Month 6Run it. The system needs a history before it can be audited. Start recording, measuring and acting now, not in month eight.
- Month 7Internal audit. Audit the whole scope at least once. Expect findings — an internal audit that finds nothing is evidence the audit was weak, not the system strong.
- Month 8Management review and corrective action. Close the findings properly, with evidence. Hold a real review with real decisions recorded.
- Month 9Stage 1 and Stage 2. The certification body checks readiness first, then samples the system in operation. Three months of genuine records is the practical minimum.
Where small organisations get stuck
The failure modes are consistent, and all five are avoidable if you know they are coming.
- 1.The template trap. A purchased document set describes someone else’s organisation. Auditors recognise them instantly, and every unedited clause is a gap between your paperwork and your practice.
- 2.No records at audit time. The system is designed beautifully and switched on three weeks before Stage 2. There is nothing to sample, and readiness fails.
- 3.Objectives that cannot be measured. "Improve customer satisfaction" is not an objective. A number, a method, a date and an owner is.
- 4.Management review as a formality. A meeting with no decisions recorded is a finding. The review is where the standard expects the system to actually change.
- 5.One person holds it all. If the implementation lives in one head, the surveillance audit a year later finds a system that stopped when that person got busy.
None of these require a consultant to avoid. They require someone with allocated time, a habit of writing things down as they happen, and the discipline to start recording early.
Questions we get asked
Can we really get ISO 9001 certified without a consultant?
Yes, and many organisations do. A consultant buys speed and reduces the risk of misreading a requirement, but nothing in the standard requires external help. What it does require is someone internal with genuine time allocated — the implementations that fail without a consultant are almost always the ones where nobody owned it, not the ones where nobody was hired.
How long does ISO 9001 certification take?
Nine months from a standing start is a realistic plan for a small to mid-sized organisation. The binding constraint is usually not the documentation but the records: a certification body needs to see the system operating, which in practice means at least three months of real use, one full internal audit and one management review before the Stage 2 audit.
How much documentation does ISO 9001 actually require?
Far less than most implementations produce. The 2015 revision removed the mandatory procedure list and asks instead for documented information necessary for the effectiveness of the system, plus specific retained records. In practice that is a scope statement, a policy, objectives, and the records that show your processes ran and were reviewed.
What does certification cost?
The certification body charges for Stage 1, Stage 2 and annual surveillance audits, usually priced on headcount, sites and scope complexity. That fee is often the smaller number: internal time is the real cost, and it is worth estimating honestly at the outset so the project is resourced rather than squeezed around other work.
Do we need software to be certified?
No. Certification requires documented information under control and evidence that processes run as described, which spreadsheets and a well-organised drive can satisfy. Software becomes worth its cost when finding evidence, chasing overdue actions and rebuilding the trail before each audit starts consuming more time than the licence would.
General guidance based on ISO 9001:2015 as published. Requirements, clause numbering and your certification body’s expectations should be verified against your current copy of the standard. This is not legal or certification advice.

