QUICK ANSWER
ISO certification in Australia follows a standard path: gap analysis, system build, a period of operating the system for real evidence, then a two-stage external audit with an accredited certification body. For a well-prepared small-to-mid business, kick-off to certification audit typically takes 4–8 weeks, followed by annual surveillance audits and recertification every three years.
The process, start to finish
Whether you’re certifying to ISO 9001, ISO 45001, or building an integrated system covering both, the path to certification follows the same broad shape. Understanding each stage up front makes the process far less abstract — and makes it easier to spot where delays typically happen.
1. Gap analysis
Before any documentation gets written, a proper engagement starts by assessing what you already have against what the standard actually requires. Most businesses are already doing a meaningful share of what ISO 9001 or ISO 45001 asks for informally — the gap analysis identifies what’s missing, what needs tightening, and what can be formalised from existing practice rather than built from scratch.
2. System build
This is where the management system itself gets documented: policies, procedures, risk registers, document control, and the records your team will actually use day to day. The aim is a system that’s usable, not shelf-ware built purely to satisfy an auditor — documentation your team can genuinely follow is documentation that survives an audit.
3. Implementation and evidence generation
A system on paper isn’t enough — certification bodies need to see it operating in practice. This stage is about running the system for real: internal audits, toolbox talks or quality checks (depending on the standard), corrective actions, and management review, generating the evidence trail an external auditor will look for.
4. Stage 1 audit (documentation review)
Your certification body’s auditor reviews your documented system against the standard’s requirements, checking it’s complete and fit for purpose before assessing it in practice. Gaps identified here get addressed before Stage 2, rather than surfacing as a surprise on the day.
5. Stage 2 audit (implementation review)
The auditor now checks that your system operates the way your documentation says it does — interviewing staff, sampling records, and observing processes in action. This is the audit that determines whether certification is granted.
“Stage 1 checks your system is documented properly. Stage 2 checks it’s actually being used — that’s the audit that earns certification.”
6. Ongoing surveillance and recertification
Certification isn’t a one-off event. Accredited certification bodies run annual surveillance audits to confirm the system is still operating, with full recertification required every three years. A system built properly at the outset makes these check-ins straightforward rather than a scramble.
Realistic timeline
4–8 weeks
Typical kick-off to certification audit, for a well-prepared small-to-mid Australian business
That range assumes a motivated internal team and prompt turnaround on document review and sign-off. Larger, multi-site, or more complex organisations should expect a longer build phase — not because the process changes, but because there’s genuinely more to document and evidence across more locations and more people.
What actually drives cost
Certification cost is driven mainly by three factors: the size of your organisation (headcount and number of sites), how much of the documentation and system-build work is done for you versus alongside you, and which standard (or combination) you’re certifying to. PSMG scopes pricing individually rather than quoting a flat number, because a 15-person single-site business and a 200-person multi-site operation are genuinely different projects with different audit-day requirements.
How PSMG runs this process
PSMG manages each stage end-to-end — gap analysis, system build, implementation support, and audit preparation — and works exclusively with JAS-ANZ accredited certification bodies, so the certificate you end up with is recognised wherever a tender, panel, or client requires it. The goal at every stage is a system built to pass audit the first time, and one your team will actually keep using once the certificate is issued.
info@pspmg.com.au | 1300 810 127 | psmg.com.au