Understanding ISO 9001:2015 Clause by Clause
A practical walk through clauses 4 to 10 — what each one actually asks for, what auditors look for as evidence, and the misreadings that cause most nonconformities.
Read articleAccredited Management Systems Certification Body
GMSCPL is India’s trusted partner for ISO management system certification, third-party auditing and lead auditor training.
We certify
Slide 1 of 4: Certifying Excellence. Building Trust.. Evidence sampled, findings raised, the mark earned.
Trusted by organisations across manufacturing, IT, healthcare, food and construction.
Client marks are displayed only with written permission. Sector labels shown while permissions are confirmed.
Our certification services
Accredited certification against the international management system standards that customers, regulators and tenders actually ask for.
Certify a quality management system that delivers consistent products and services and satisfies customers.
Learn moreCertify an environmental management system that controls impacts, meets compliance obligations and reduces waste.
Learn moreCertify an OH&S management system that prevents work-related injury and ill health through worker participation.
Learn moreCertify a food safety management system combining HACCP principles, prerequisite programmes and traceability.
Learn moreCertify an ISMS that protects the confidentiality, integrity and availability of information through assessed risk.
Learn moreCertify a medical device QMS meeting regulatory expectations for design, manufacture, sterilisation and vigilance.
Learn moreIntensive five-day lead auditor courses aligned to IRCA/CQI criteria, with continuous assessment and examination.
Learn moreTwo-day practical internal auditor training covering planning, evidence gathering, findings and reporting.
Learn moreWe certify 25+ standards in total, including IATF 16949, ISO 50001, ISO 22301, ISO 37001 and ISO 27701. See the full list →
Inside the work
Drag, scroll or use the arrows. Each frame opens the part of the practice it belongs to.
By the numbers
Figures are maintained from internal certification records and reviewed at management review. We publish what we can evidence.
Why choose GMSCPL
A certificate is worth exactly what the audit behind it was worth. These six things are how we make sure ours is worth something.
Audits are conducted to ISO/IEC 17021-1 requirements with documented impartiality controls. The person who decides your certification is not the person who audited you — a separation many buyers assume exists everywhere and should verify.
Our assessors come from the industries they audit. Competence is matched to your scope, technical area and process risk before assignment, and every auditor is witnessed periodically in the field.
Audit duration is calculated to IAF MD 5 from effective headcount and risk category, and we publish the calculation with your quotation. You can see exactly why the number is what it is.
Application review in 2–3 working days, audit dates agreed at contract, certification decision within a committed window after nonconformity closure. Delays get explained, not absorbed.
Assessors across Indian states and an international network for multi-site and overseas scopes, so travel cost and lead time do not become the deciding factor in your audit plan.
A named client relationship manager, automatic surveillance and expiry reminders, mark usage guidance, and a public certificate directory your customers can check without contacting you.
Certification process
A transparent, time-bound journey. Every stage has a defined purpose, a stated output, and a reason it exists at all.
01Chapter one
We size the audit from your sites, headcount, shift pattern and processes using the IAF MD 5 calculation, and we show you that calculation. A quotation you cannot check is a quotation you cannot compare.
02Chapter two
A readiness review of your documented system, internal audits and management review — deliberately early enough that gaps are still cheap to close. You get findings in writing, not a verdict.
03Chapter three
Effectiveness is assessed on the floor, in the interviews and against the records — not from the meeting room. Nonconformities are raised against a clause, with the evidence attached, so they can be argued with.
04Chapter four
An independent reviewer who has never met your team decides whether the certificate is issued. That separation is the whole reason a third-party certificate is worth more than a self-declaration — and it is the first thing an accreditation body checks.
Durations, fees and the surveillance cycle are set out in full on the process pages. See the full process →
Industries we serve
A food safety audit conducted by someone who has worked a processing floor finds different things from one conducted by a generalist. We staff accordingly.
Client feedback
Sample placeholder content shown while consented, attributable quotations are collected — see the note below.
The audit team was thorough and professional, and genuinely helped us improve our QMS rather than just tick boxes. The nonconformities they raised were ones we should have found ourselves — which is exactly what we were paying for.
What stood out was the transparency on audit days. We were shown the IAF MD 5 calculation with the quotation, so there was no negotiation about scope creep later. Every quote we had received before was a single number with no explanation.
Our ISO 27001 auditor had actually run infrastructure. He asked to see access review evidence and change records instead of reading our policy documents back to us. The findings were uncomfortable and completely fair.
These are placeholder testimonials written to demonstrate layout. A certification body must not publish fabricated client quotations — real, consented, attributable testimonials replace these before launch. More client feedback →
From the blog
Practical technical writing on the standards we certify — transition deadlines, clause interpretation and what auditors actually look for.
A practical walk through clauses 4 to 10 — what each one actually asks for, what auditors look for as evidence, and the misreadings that cause most nonconformities.
Read articleAnnex A went from 114 controls to 93, and eleven controls are genuinely new. Here is what changed structurally, what changed substantively, and how to rebuild your Statement of Applicability.
Read articleMost IT companies pursue ISO 27001 to unblock a sales conversation. That is a good reason. Here are the four other returns that tend to surprise them.
Read articleCommon questions
The questions we are asked most, answered directly — including the ones with awkward answers.
For most organisations, ISO 9001. It establishes the management system structure — context, leadership, planning, competence, internal audit, management review — that every other standard reuses, so a later ISO 14001 or ISO 45001 becomes an addition rather than a fresh build. The exceptions are sector-driven: an IT services company whose customers are asking security questions should start with ISO 27001, a food business with ISO 22000 or HACCP, and a medical device manufacturer with ISO 13485.
Cost is driven by audit days, which are calculated under IAF MD 5 from your effective headcount and the risk category of your activity — not set commercially. That means we cannot quote meaningfully without your headcount, scope and number of sites, and any body that quotes a flat price without asking for those is not calculating audit days properly. Our quotations show the calculation, cover the full three-year cycle including both surveillance audits, and state travel separately at cost.
For an organisation with a working system, typically eight to twelve weeks from application to certificate: two to three days for the quotation, about a week to contract and plan, Stage 1, a gap of two to four weeks, Stage 2, then nonconformity closure and the certification decision. If the system still has to be built, add three to six months of implementation before any of that starts.
Three years from the certification decision date, conditional on successful surveillance audits at approximately twelve and twenty-four months. It is not a three-year certificate you can put in a drawer; missing a surveillance audit puts it at risk of suspension.
It means the certification body itself has been assessed by a national accreditation body against ISO/IEC 17021-1, and that the accreditation body is a signatory to the IAF Multilateral Recognition Arrangement. That MLA signature is the mechanism by which a certificate issued in India is recognised elsewhere. A certificate without accreditation from an MLA signatory is a private document — it may look identical and many customers will not accept it.
Not to the same client. ISO/IEC 17021-1 prohibits a certification body from providing management system consultancy to an organisation it certifies, and we apply that rule strictly. We do offer advisory services — gap analysis, documentation and implementation support — but an organisation that receives them from us must be certified by a different body for the cooling-off period the accreditation rules define. We tell clients this in writing before any engagement begins.
Question not answered here? Ask a certification specialist — we answer technical questions without requiring an enquiry first.
Next step
Talk to our certification specialists. We will scope it honestly, show you the audit-day calculation, and tell you if the timeline you need is not realistic.