ISO Certification – A Critical Quality Assurance

23 Jan    Blogs

ISO is the International Organization for Standardization in India. It is the independent organization that provides standards in various terms such as quality, safety, and efficiency of products and services provided by the businesses.

The quality of the product/service has to be of assured and high-grade quality to stay ahead of the competition. The ISO certification provides the guarantee to the customers opting to buy and use the product/service.


The ISO certification thereby increases the overall credibility and efficiency of the organization.

The process of acquiring ISO certification can be explained into two major steps.

1.Pre-requisite to acquiring ISO Certification in India

The organization has to decide which type ISO they intend to acquire.

ISO 9001

By far the most popular family is that of ISO 9000. A family of quality management standards, there are fourteen in total. Of these, ISO 9001:2015 is the only one that can be certified to. It was first published in 1987, and has since been updated about every 7 years. The standard details how to put a Quality Management System (QMS) in place to better prepare your organization to produce quality products and services. It is customer focused, and places an emphasis on continuous improvement and top management processes that extended throughout the organization.

The standard was updated in 2015, and now places a greater emphasis on risk management. The standard is generic, and can be used in any organization in any sector. Over 1,000,000 ISO certifications have been given out in over 170 countries according to the ISO Survey of Management System Standard Certifications.

ISO 14001

ISO 14000 is a family of standards relating to the environment. It includes multiple standards, similar to ISO 9000. ISO 14001:2015 is the most popular in the family, and is the only one in which an organization can be certified.

It establishes requirements for an Environmental Management System (EMS) and is based on the continuous improvement model PDCA (Plan-Do-Check-Act). It is a voluntary standard, put in place by companies who want to improve their processes, and is very popular, with over 300,000 certifications in 171 countries worldwide.

ISO 27000

This family of standards concerns information technology, with the goal of improving security and protecting company assets. Started in 2005, the two most popular standards are ISO 27001:2013 and 27002:2013. 27001 is management-based system, whereas 27002 is a technical document, focused on the individual and putting a code of conduct in place.

Organizations can choose either standard; ISO 27001 has over 22,000 certifications worldwide. It is a broad standard, and for this reason the certification can be customized to fit the needs of the organization, and is not mandatory.

ISO 22000

This standard is focused on the development and implementation of a food safety management system, and can help any organization that works in the food chain. With multiple standards including 22001 for food and drink, 22002 for food manufacturing, and more, this family is used in a variety of organizations directly or indirectly involved with food. These include obvious choices such as restaurants of any kind, and also companies such as food manufacturers or even food transportation services such as caterers.

With over 26,000 certifications, ISO 22000:2005 is one of the more common standards. It can be applied on its own or integrated with ISO 9001. 22000 is currently under revision with the updated version expected to be released early 2017.

ISO 50001

One of the newest standards, the energy standard ISO 50001:2011 is nevertheless becoming increasingly important. Released in 2011, the standard is meant for companies to put in place an Energy Management System (EMS) dedicated to improving energy usage and efficiency. This includes reducing an organization’s energy footprint by reducing greenhouse gas emissions as well as energy cost.

It is not required, but with over 5,000 certifications and a 234% certification increase in the past calendar year according to the Office of Energy Efficiency & Renewable Energy, it is clear that companies are finding benefits and think the standard improves their business processes.

ISO/TS 16949

One of the older standards, ISO/TS 16949 refers to the automotive industry. TS stands for Technical Specification. Prior to the standard, suppliers were asked by car manufacturers to standardize to the regulations of each individual country, which often led to suppliers needing multiple certifications for the same vehicle.

According to the British Standards Institution (BSI), in 1999 the ISO/TS 16949 standard was created by the International Automotive Task Force (IATF) to help streamline this process. It focuses on avoidance of errors, and defines the requirements for the development, production, and installation of automotive-related products. Today certification is required by almost all tier 1 companies, and in turn many of them require their tier 2 and 3 suppliers to certify. The standard has over 50,000 certifications.

ISO 13485

The medical equipment standard ISO 13485 is a single document and does not belong to a family like many of the ISO standards. Published in 2003, with one revision published in 2016. It puts a QMS in place for the production of medical devices and equipment, and is very specific to the health industry.

It is a regulated standard, and has over 25,000 certifications. It is often implemented with ISO 9000 to show that an organization is qualified to do business with, and the document can be catered to the needs of a specific organization.

ISO 31000

It is very important for an organization in any field to be able to manage risk effectively. ISO 31000:2009 puts in place a risk-management system to do just that. It was created in 2009 as an attempt to create a universally recognized program to reduce risk, eliminating the need for the many standards in other industries that include risk. The standard allows a company to better identify threats before they occur, and effectively allocate and use resources for risk treatment.

ISO 26000

A relatively new standard, ISO 26000 focuses on social responsibility and was released in 2010. It cannot be certified to, but rather provides guidance on how businesses can operate in a socially responsible way. It helps clarify what social responsibility is, and helps organizations put in place the methodology to take effective actions relating to global social responsibility. The certification is used in over 60 countries.

ISO 20121

The newest standard on this list, ISO 20121 was started in 2012. It came about due to overwhelming support of BS 8901, an event sustainability standard put in place with support from the Head of Sustainability at the London 2012 Olympics. It is a voluntary event sustainability management system.

ISO 20121 is relevant to all members of an event’s supply chain, from organizers to caterers, and assists these organizations in reducing their environmental footprint while still being a financial success. These can be of any size, from music festivals to a school function, even something on a scale as large as the Olympics.

Choosing the right ISO Body

The ISO certificate is provided by external bodies and the organization has to research well about the external body and carry on the process of the ISO registration.

2.The Process

  • Application:The applicant and the registrar need to agree on a contract. This contract defines the obligations of both parties and their rights.
  • Documents Review:The documents and quality manuals will be inspected by the ISO auditor to carry out the process effectively.
  • Plan of Action:The plan of action has to be discussed with the ISO auditor and the gaps of acquiring ISO certification need to be fixed in the organization.
  • Initial Certification Audit:There are two stages in the Initial Certification Audit. The first stage involves the organization to identify the gaps and fulfil the requisites to acquire the ISO certification. The second stage involves the auditor to investigate whether all the requisites are fulfiled by the organization.
  • Gaining Certification:If all the requisites are affirmed, then the registrar will grant the ISO certification.
  • Surveillance audit:The surveillance audit is kept to confirm that the organization abide by the rules of the ISO and is maintaining the firm well.

The time involved in acquiring the ISO certification varies from organization to organization. The average time taken for ISO certification for small organizations is six to eight months.

The average time taken for ISO certification for medium organizations is eight to twelve months. The average time taken for ISO certification for large organizations is twelve to fifteen months.

TS Associates a leading conglomerate in providing the service of ISO certification service provider in India. TS Associates caters remarkable commitment in ISO certification.

About TS Associates :

TS Associates is a leading national law firm in India comprising over numerous professionals, with offices in Mumbai (Headquarter) and Pune. TS Associates was set up in 2017 and has since established an excellent reputation for its integrity and value based proactive, pragmatic and innovative legal advice and its ability to help clients effectively traverse the complicated legal and regulatory regime in India. The mission of the Firm is to provide outstanding legal solutions in the chosen practice areas with a strong emphasis on ethics. Clients benefit from the expertise and experience as a large firm while still enjoying the privilege of personal attention and responsiveness of a small firm. Our Practice areas are – IPR, Secretarial, Legal, Company Registration, Annual Filings, Returns and Tax.

Get in touch for free consultation on info@tsassociates.co.in or call 9692924221/ 9124477784

ByShashi Mishra

Shashi Mishra is Founder of TS Associates and Certified Lead Auditor from (International Register of Certificated Auditors-IRCA). He has a Good Expertise Over Legal, Intellectual Property, Income TAX, GST and Corporate Compliances.

Leave a Reply

Your email address will not be published. Required fields are marked *