Audit & Assurance
ISO Management System Audits
Independent ISO 9001, ISO 27001, ISO 22301, ISO 14001 and ISO 45001 management system audits — gap assessments, certification readiness reviews and integrated management system assessments for regulated and non-regulated organisations.
Executive Overview
ISO management system standards establish internationally recognised frameworks for quality, information security, business continuity, environmental and occupational health and safety management. For many organisations, ISO certification is a contractual, regulatory or market access requirement. For others, the management system itself is the primary objective — a structured approach to operational risk management that improves resilience, reduces non-conformances and demonstrates governance to customers, regulators and boards.
Independent ISO management system audits provide organisations with an objective assessment of their system against standard requirements, current certification body expectations and emerging audit focus areas. Where organisations hold multiple certifications, integrated management system audits identify inconsistencies in how common framework elements are addressed across different standards, providing insight that single-standard audits cannot deliver.
Sthira Assure ISO management system audits are conducted by assessors experienced in ISO standards and their application across regulated and non-regulated industries. We assess systems as they are implemented in practice, not as they are described in documentation. Our findings are risk-rated, referenced to specific standard requirements and structured to support targeted remediation before certification body review.
Standards Covered
- ISO 9001:2015 (Quality)
- ISO 27001:2022 (Information Security)
- ISO 22301:2019 (Business Continuity)
- ISO 14001:2015 (Environmental)
- ISO 45001:2018 (OH&S)
- ISO 19011 (Audit Guidelines)
Request a Management System Audit
Discuss your ISO audit requirements and certification scope.
Get in TouchCommon Compliance Risks
Certified Without Operationalised
ISO certification requires that the management system is implemented and maintained in practice, not just documented. Many organisations achieve initial certification but allow systems to drift — internal audits become procedural rather than substantive, management reviews lose connection to real performance data and corrective actions address surface symptoms without root cause analysis. Surveillance audits and recertification assessments test whether the system is alive, not just archived.
Integrated System Inconsistencies
Organisations managing multiple ISO standards — quality, security, business continuity, environmental and occupational safety simultaneously — frequently maintain siloed management systems that share documentation labels but not coherent risk management. Integrated management system audits identify where common framework elements (context, objectives, internal audit, management review) are being addressed inconsistently across standards, creating both compliance gaps and operational inefficiency.
Context and Risk Assessment Depth
ISO management system standards from the 2015 generation onwards require organisations to determine their context — internal and external issues, interested parties and their requirements — and use this as the foundation for risk-based thinking and strategic direction. Inspectors and certification bodies consistently find that context of the organisation documentation is generic, not organisation-specific, and that the connection between context, risk assessment and system objectives is superficial.
Surveillance Audit Non-Conformances
Certification body surveillance audits, typically conducted annually between three-year recertification cycles, assess whether the management system continues to meet standard requirements. Non-conformances raised during surveillance audits can jeopardise certification and require evidence of corrective action within defined timelines. Independent pre-surveillance assessment identifies potential non-conformances before the certification body does, allowing targeted remediation.
Scope of Services
Common Audit Findings
These findings are consistently observed across ISO management system audits regardless of standard or industry. They reflect the gap between documented systems and operationalised systems that independent audit routinely identifies.
Frequently Asked Questions
What is an ISO management system audit and why commission one independently?
An ISO management system audit assesses whether the organisation's management system is implemented and maintained in conformance with the requirements of the applicable ISO standard. Independent audit — separate from the certification body surveillance process — provides objective assessment of system effectiveness, identifies non-conformances before the certification body does, and gives management an honest view of system performance that internal self-assessment cannot reliably deliver. For organisations where ISO certification supports customer, regulatory or contractual requirements, maintaining audit readiness is a business continuity issue.
Can you audit multiple ISO standards in a single engagement?
Yes. Integrated management system audits assess multiple ISO standards simultaneously, examining how the organisation addresses common framework elements — context, leadership, planning, support, operation, performance evaluation and improvement — across quality, security, environmental and safety management systems. Integrated audit is more efficient than separate audits for each standard and provides insight into system coherence that single-standard assessment cannot offer. We scope integrated audits based on the standards held and the degree of integration in the organisation's management system.
How do ISO management system audits relate to GxP compliance for pharmaceutical organisations?
ISO 9001 provides the general quality management system framework on which pharmaceutical QMS requirements, including ICH Q10 and EU GMP, are built. ISO 27001 is increasingly relevant to pharmaceutical organisations managing GxP-regulated data in cloud environments, as it provides the security control framework that underpins vendor qualification. ISO 22301 business continuity management is relevant to organisations with supply chain resilience obligations. For pharmaceutical clients, management system audits are often scoped alongside GxP audit activities to provide a complete picture of quality system compliance.
What is the difference between a first-party, second-party and third-party audit?
First-party audits are internal audits conducted by or on behalf of the organisation against its own management system. Second-party audits are conducted by a customer or interested party on their supplier — supplier qualification audits are a common form. Third-party audits are conducted by independent certification bodies or independent consultants with no commercial relationship with the auditee. Sthira Assure conducts independent second-party and advisory third-party assessments — not certification audits, which are the exclusive domain of accredited certification bodies.
Request a Management System Audit
Contact our team to discuss your ISO management system requirements, certification scope and audit programme design.