What is iso certification coordination?
ISO 9001 and friends via accredited bodies (ANAB / JAS-ANZ) — the gap work organised, the audit coordinated, no certificate-mill shortcuts.
A business usually goes looking for ISO 9001 (or 27001, or 14001, or 45001) for one of two reasons: a customer's procurement team now requires it as a condition of the contract, or the business has grown past the point where quality, information security or safety is still held together by one person's memory and wants a documented system that survives staff turnover. Either way, the certificate that eventually gets framed on the wall is issued by a Certification Body — SGS, BSI, Intertek, DNV, TÜV and others all compete in this market — and that CB is only credible if it is accredited by ANAB, the ANSI National Accreditation Board. A certificate from a CB with no ANAB accreditation, or from an outfit that skips the audit altogether, is worth exactly what a procurement reviewer decides it's worth the moment they check the register and find nothing there.
Between deciding to pursue certification and the CB showing up for an audit, there's real work: reading the standard's clauses against what the business actually does day to day, writing the quality manual and the procedures that don't exist yet, running an internal audit against the new system, holding the management review meeting the standard requires, and closing out whatever the internal audit turned up before the CB's Stage 1 documentation review even starts. That gap-analysis-and-build phase is unregulated — any competent consultant can do it — and it's also the phase most small businesses underestimate, because it's the difference between a management system that exists on paper and one that survives an auditor asking an employee to walk them through a process.
Who does what
| Your CapEasy team | ISO certification coordination, the reconciliations and reporting behind it, and the questions list that keeps it honest. |
| Your CPA or enrolled agent | Everything that carries a licence in United States — rendered exactly as written: issue compilation, review or audit reports — those are restricted to licensed cpa firms. |
| You | One conversation with one named person, and the decisions that are genuinely yours. |
ISO certification coordination in United States
ANAB accredits the Certification Body, not your business — verify the CB, not just the certificate
ANAB doesn't audit individual businesses and it doesn't issue certificates to them; it accredits the Certification Bodies that do, and that accreditation is checked through ANAB's own public accreditation search. A certificate is only as credible as the CB behind it, so before selecting a CB the accreditation should be confirmed directly against ANAB's records for the specific standard being pursued — a CB can be accredited for ISO 9001 and not for ISO 27001, for instance, and the scope matters.
The conflict-of-interest rule: the firm that builds your management system cannot also certify it
ISO and ANAB accreditation rules bar a single firm from both consulting on a management system's design and performing the certification audit of that same system for the same client. That's not a preference — it's a structural rule that keeps the audit independent. We do the gap-analysis, documentation and internal-audit preparation; the Stage 1 and Stage 2 audits are run by a separate ANAB-accredited CB with no role in building what it's auditing.
Certificate mills sell a document, not compliance — and a procurement review will find the gap
Outfits advertising ISO certification 'in days, no audit required' are not issuing an ANAB-accredited certificate — a real Stage 1 and Stage 2 audit takes real weeks, and a certificate that skipped it won't appear on any accredited CB's public register. A customer's procurement or supplier-quality team checking that register during vendor onboarding will find nothing, and a certificate that can't be verified is worse for a bid than having no certificate at all, because it now reads as a business that tried to shortcut the requirement.
Certification is a three-year cycle, not a one-time event — surveillance audits check the system is still in use
A CB-issued ISO certificate is typically valid three years, but it is not self-renewing: a surveillance audit in year one and again in year two checks that the management system is still being followed, not just that it existed for the initial audit, and a full recertification audit runs in year three before the next cycle starts. A system that was built to pass the first audit and then never touched again is a common way certification lapses or fails surveillance.
What your CPA or enrolled agent receives from us
- A clause-by-clause gap analysis mapping the target standard (ISO 9001, 27001, 14001, 45001, etc.) against the business’s actual current processes, with every gap identified before drafting starts.
- A drafted quality manual and the full set of procedures, work instructions and records the standard requires, built from how the business actually operates rather than a generic template.
- A completed internal audit against the new management system, run before the CB’s Stage 1 review, with findings logged and corrective actions tracked to closure.
- Documented management review minutes covering the inputs the standard requires — audit results, corrective actions, process performance — dated ahead of the Stage 1 audit.
- A shortlist of ANAB-accredited Certification Bodies for the specific standard and scope in question, with each CB’s accreditation confirmed against ANAB’s own public register before the client selects one.
- A Stage 1 readiness package handed to the chosen CB — the full documentation set, evidence of the internal audit and management review, and a scope statement matching what will actually be audited.


