What is iso certification coordination?
ISO 9001 and friends via accredited bodies (ANAB / JAS-ANZ) — the gap work organised, the audit coordinated, no certificate-mill shortcuts.
An Australian business usually starts chasing ISO 9001 (or 27001, 14001, 45001) for one of two reasons: a tender or a large customer's procurement panel now lists it as a condition of doing business, or the business has outgrown running quality, information security or WHS on one person's memory and wants a documented system that survives someone leaving. Either way, the certificate that ends up on the wall is issued by a Certification Body — SAI Global, Intertek, BSI, SGS, TÜV SÜD, DNV, Lloyd's Register and others all compete for the work — and that CB is only worth what its accreditation says it's worth. In Australia, the accrediting body is JAS-ANZ, the Joint Accreditation System of Australia and New Zealand, structurally the same role India's NABCB plays: JAS-ANZ doesn't certify businesses itself, it accredits the CBs who do, and it maintains a public register at register.jasanz.org/accredited-bodies where anyone — including a procurement panel checking a tender submission — can verify a CB actually holds current JAS-ANZ accreditation for the standard being claimed.
Between deciding to pursue certification and a CB auditor showing up, there's real work: reading the target standard's clauses against what the business actually does, drafting the quality manual and procedures that don't exist yet, running an internal audit against the new system, holding the management review the standard requires, and closing out whatever the internal audit found before the CB's Stage 1 documentation review starts. That gap-analysis-and-build phase is unregulated in Australia — any competent consultant can do it — and it's also the phase most businesses under-budget for, because a management system that only exists on paper collapses the moment a Stage 2 auditor asks an employee to walk through the actual process.
Who does what
| Your CapEasy team | ISO certification coordination, the reconciliations and reporting behind it, and the questions list that keeps it honest. |
| Your registered BAS or tax agent | Everything that carries a licence in Australia — rendered exactly as written: work out what goes on your bas, or advise you on it — under tasa 2009 that requires registration we do not hold. |
| You | One conversation with one named person, and the decisions that are genuinely yours. |
ISO certification coordination in Australia
JAS-ANZ accredits the Certification Body, not your business — check the CB, not the certificate on the wall
JAS-ANZ doesn't audit individual businesses and issues nothing to them directly; it accredits the Certification Bodies that do, and that accreditation is checked against JAS-ANZ's own public register at register.jasanz.org/accredited-bodies. A CB can hold JAS-ANZ accreditation for ISO 9001 and not for ISO 27001 — scope is specific to the standard, so the accreditation check needs to name the exact standard being pursued, not just the CB.
The conflict-of-interest rule: the firm that builds your management system cannot also certify it
JAS-ANZ's accreditation rules bar a single entity from both consulting on a management system's design and performing the certification audit of that same system for the same client. That's a structural rule, not a preference — it's what keeps the audit independent of the work being audited. We do the gap analysis, documentation and internal-audit preparation; the Stage 1 and Stage 2 audits are run by a separate JAS-ANZ-accredited CB with no role in building what it's auditing.
A "certificate" from an unaccredited certifier won't survive a tender panel or a customer audit
Outfits offering ISO certification with no real Stage 1/Stage 2 audit are not issuing a JAS-ANZ-accredited certificate — a genuine audit takes real weeks, and a certificate that skipped it won't appear against register.jasanz.org's accredited-bodies list. A procurement panel or a customer's supplier-quality team checking a tender submission against that register will find nothing, which reads worse on a bid than never having claimed certification.
Certification is a three-year cycle — surveillance audits check the system is still in use, not just that it once existed
A JAS-ANZ-accredited ISO certificate is typically valid three years, and it is not self-renewing: a surveillance audit in year one and again in year two checks the management system is still being followed day to day, and a full recertification audit runs in year three before the next cycle starts. A system built only to survive the initial audit and then left alone is the most common way certification lapses or fails surveillance.
What your registered BAS or tax agent receives from us
- A clause-by-clause gap analysis mapping the target standard (ISO 9001, 27001, 14001, 45001, etc.) against the business's actual current processes, with every gap identified before drafting starts.
- A drafted quality manual and the full set of procedures, work instructions and records the standard requires, built from how the business actually operates rather than a generic template.
- A completed internal audit against the new management system, run before the CB's Stage 1 review, with findings logged and corrective actions tracked to closure.
- Documented management review minutes covering the inputs the standard requires — audit results, corrective actions, process performance — dated ahead of the Stage 1 audit.
- A shortlist of JAS-ANZ-accredited Certification Bodies for the specific standard and scope in question, with each CB's accreditation confirmed against register.jasanz.org before the client selects one.
- A Stage 1 readiness package handed to the chosen CB — the full documentation set, evidence of the internal audit and management review, and a scope statement matching what will actually be audited.


