Service category
Management System Certification
Accredited third-party certification against international ISO standards.
- 15Services in this category
- AccreditedWhere accreditation applies
- Pan-IndiaAssessor coverage
Overview
About management system certification
Independent audit and certification of quality, environmental, safety, security, energy and sector-specific management systems — the core of what a certification body does.
Quality Management System
Certify a quality management system that delivers consistent products and services and satisfies customers.
Learn moreEnvironmental Management System
Certify an environmental management system that controls impacts, meets compliance obligations and reduces waste.
Learn moreOccupational Health & Safety
Certify an OH&S management system that prevents work-related injury and ill health through worker participation.
Learn moreFood Safety Management System
Certify a food safety management system combining HACCP principles, prerequisite programmes and traceability.
Learn moreInformation Security Management System
Certify an ISMS that protects the confidentiality, integrity and availability of information through assessed risk.
Learn moreBusiness Continuity Management System
Certify a business continuity management system built on impact analysis, tested plans and proven recovery times.
Learn moreEnergy Management System
Certify an energy management system that improves energy performance against a measured, verifiable baseline.
Learn moreMedical Devices Quality Management
Certify a medical device QMS meeting regulatory expectations for design, manufacture, sterilisation and vigilance.
Learn moreIT Service Management System
Certify an IT service management system covering service levels, incidents, changes, capacity and continuity.
Learn moreEducational Organizations Management
Certify an educational organisation management system focused on learner needs and demonstrable outcomes.
Learn moreAnti-Bribery Management System
Certify an anti-bribery management system with due diligence, controls, reporting channels and investigation.
Learn moreFacility Management System
Certify a facility management system that connects workplace services to organisational demand and cost control.
Learn morePrivacy Information Management System
Certify a privacy information management system extending ISO 27001 to personal data as controller or processor.
Learn moreSupply Chain Security Management
Certify a security management system addressing threats to cargo, facilities, transport and supply chain partners.
Learn moreAutomotive Quality Management
Certify an automotive QMS built on ISO 9001 with IATF customer-specific requirements and core tools.
Learn moreHow it works
Our management systems process
- 01
Application & Quotation
2–3 working days
You submit an application form covering scope, headcount, sites and shift pattern. We review complexity, confirm audit-day allocation against accreditation rules and issue a fixed quotation.
- 02
Contract & Audit Planning
1 week
On acceptance we appoint a lead auditor with verified technical competence for your sector, agree audit dates and share the audit plan in advance.
- 03
Stage 1 — Readiness Review
1 day (typical)
A documentation and readiness assessment: scope confirmation, review of your management system documents, internal audit and management review evidence, and identification of anything that would block Stage 2.
- 04
Stage 2 — Certification Audit
2–5 days (scope dependent)
On-site assessment of the system in operation. We sample processes, interview staff, examine records and raise findings graded as major, minor or opportunity for improvement.
- 05
Corrective Action & Decision
2–4 weeks
You close out any nonconformities with root-cause analysis and evidence. An independent certification decision-maker — not the audit team — reviews the file and grants certification.
- 06
Certificate Issue
3–5 working days
A three-year certificate is issued and your organisation is listed on our public certified-client directory for verification by your customers.
- 07
Surveillance & Recertification
Annual
Surveillance audits at 12 and 24 months confirm the system remains effective. A full recertification audit is completed before the three-year expiry.
Common questions
Management Systems — common questions
For an organisation with a working quality system, eight to twelve weeks from application to certificate is typical. If the system still has to be built, allow three to six months for implementation before the Stage 1 audit. The audit itself is usually one day for Stage 1 and two to four days for Stage 2, depending on headcount, number of sites and process complexity.
Yes, and it is usually the efficient choice. Both standards share the High Level Structure, so context, leadership, internal audit, management review and improvement can be run as one integrated system. An integrated audit reduces total audit days compared with two separate certifications.
OHSAS 18001 was withdrawn in March 2021 and is no longer a valid certification. Migration requires you to add the elements ISO 45001 introduced — organisational context, interested parties, leadership accountability, worker consultation mechanisms, and OH&S risks and opportunities beyond hazard-level risk. In most cases a transition audit rather than a full initial certification is sufficient.
HACCP is a hazard-control methodology, not a management system. ISO 22000 wraps HACCP inside a full management system with leadership, planning, competence, verification and improvement. FSSC 22000 is ISO 22000 plus the sector-specific ISO/TS 22002 prerequisite programme and additional scheme requirements — and unlike ISO 22000 on its own, it is GFSI-recognised.
Annex A was restructured from 114 controls across fourteen domains into 93 controls across four themes, with eleven genuinely new controls covering threat intelligence, cloud security, ICT readiness for continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring, web filtering and secure coding. Organisations still certified to the 2013 version were required to transition by 31 October 2025.
The standard requires exercising at planned intervals and after significant change, without prescribing a frequency. Common practice is at least annually for each critical plan, with a mix of tabletop and technical exercises. What we assess is whether the programme is justified against your risk profile and whether findings were acted on.
Question not answered here? Ask a certification specialist — we answer technical questions without requiring an enquiry first.
Next step
Ready to get certified?
Talk to our certification specialists. We will scope it honestly, show you the audit-day calculation, and tell you if the timeline you need is not realistic.