How we work

How we get you certification-ready.

Rigorous, transparent and practical — from the first scoping call to the certification audit and beyond. Here is exactly what to expect at each stage.

ABS certification process planning and audit preparation

Working with ABS

ABS is a consulting and advisory firm. We take your organisation from the first conversation to certification readiness, then coordinate and support you through the independent audit — helping you close any findings and guiding you through to successful certification.

Our job is to make sure the audit holds no surprises. Every engagement begins with a fixed-price scoping call and a proposal within 24 hours, so you know the scope and cost before you commit. From there, the work follows the same five steps, whatever the standard.

The five steps

The effort in each step depends on your standard, the size of your organisation and how much of your system is already in place — but the path is the same.

01 — Discovery & Scope Definition

We understand your business, customer requirements, applicable standards, certification goals and timelines to define the right compliance roadmap.

It starts with a scoping conversation: what your organisation does, which customers or tenders are driving the need, which standard or framework fits, how many sites are involved and how complex your operations are. Where more than one standard applies, we look at whether an integrated approach will save effort. From that, we send a fixed-price proposal within 24 hours setting out the scope and approach. Nothing else begins until you are comfortable with the scope and cost. You'll provide: a basic picture of your business, sites, customer requirements and any existing certifications.

02 — Gap Assessment & Roadmap

We assess your current systems, controls and documentation against the selected standard and identify priorities, gaps and required actions.

We work through the standard requirement by requirement and build a clear picture of what already works, what needs strengthening and what is missing. You get a prioritised roadmap of actions rather than a list of complaints. This step is deliberately thorough, so significant weaknesses surface early rather than during the formal audit, and it can usually be carried out remotely. You'll provide: access to existing policies, procedures and records, and to the people who run the processes.

03 — Implementation & Control Strengthening

Our consultants help develop and implement practical policies, processes, controls and evidence aligned with your actual business operations.

We work alongside your team to close the gaps — building or reshaping the management system, drafting the policies and procedures that are genuinely missing, strengthening controls, and making sure the evidence the standard expects is actually produced. Everything is shaped around how your business already runs, so the system is practical to operate rather than a set of documents on a shelf. We also train the people who operate it day to day. You'll provide: the people who own the processes, and the time for them to embed the changes.

04 — Audit Readiness & Pre-Assessment

We review implementation, verify evidence, conduct readiness checks and help your team prepare confidently for the independent certification or attestation audit.

Before the formal audit, we check that the system is working as intended. We review implementation, verify that the evidence is complete, and help you run internal audits and a management review where the standard requires them, so the system has a track record of operating. A readiness check approached the way an auditor would approach it highlights anything still to close, and we brief your team on the questions and evidence requests to expect. You'll provide: records that show the system operating, and the people who will speak to the auditor.

05 — Independent Audit & Certification Support

We coordinate and support you through the independent assessment process, help address audit findings and guide you through to successful completion.

Your certification body — or, for attestations such as SOC 2, a licensed CPA firm — carries out the independent assessment. For ISO management systems this normally happens in two stages: Stage 1 reviews whether the system is documented and ready, and Stage 2 assesses whether it is genuinely implemented and effective, through interviews, records and observation. We coordinate with you through the process and stay available throughout; if findings are raised, we help you plan and evidence the corrective action through to successful completion. You'll provide: records and people who can show the system working day to day.

Maintaining your certification

A certificate is a living thing. For most ISO standards, certification runs on a three-year cycle, with surveillance audits — typically annual — carried out by your certification body in between. These are lighter than the original assessment, but they confirm that your system is still operating and improving rather than drifting after the certificate is on the wall.

At the end of the cycle, a recertification audit renews the certificate for the next period. We can stay involved across that cycle — keeping the system current, helping run internal audits, training new staff, and preparing you for each surveillance visit. If your organisation changes materially — new sites, new activities, a wider scope — we help you work out what that means for your certification and when to raise it. The principle throughout is continuity: certification should reflect how your organisation actually runs, today and over time.

Common questions about how we work

Can you support us remotely?

Most of it, yes. Gap analysis, documentation review, training and audit preparation are routinely delivered fully remotely. Some standards — for example ISO 45001, where site safety must be observed — involve an on-site element, and your certification body may require an on-site audit. We confirm the approach for your scope upfront, so there are no surprises.

What documentation do we need to prepare?

It depends on the standard, but typically your policies, key procedures, records that show the system operating (for example management review and internal audit results), and evidence relevant to the standard's requirements. We tell you exactly what is in scope at the gap-analysis stage and help you build whatever is missing, so nothing is discovered for the first time during the audit.

What happens if we have a non-conformity?

A non-conformity is not a failure — it is a finding to be addressed. You implement corrective action within an agreed timeframe and your certification body verifies it. Certification proceeds once findings are closed. We help you plan and evidence the corrective action, and our approach is to surface gaps during our own gap analysis so material issues rarely appear for the first time at the audit.

How quickly can we get the certificate after Stage 2?

Once any Stage 2 findings are closed, your certification body makes its certification decision and issues the certificate. There is no fixed timeline for the journey as a whole: it depends on the standard, your scope, organisation size, sites and shifts. We give you a firm timeline with your initial quote.

Looking for a specific standard? See, for example, ISO 27001 or ISO 9001 — or contact us to talk through your scope.

Get started

Ready to get certified?

Get a free, fixed-price quote within one business day. No obligation, no sales pressure, no follow-up spam — just a clear path to certification.

Book a 30-min consultation
24-hour response time Fixed price, multi-currency Consulting & audit readiness Remote & on-site delivery
Call us