Insights · 5 min read

Application review: what a certification body asks for, and why

Most organizations experience application review as a form. It is a gate.

Published by CAS — Conformity Assessment Services · 4 September 2026

Most organizations experience application review as a form. It is a gate.

Before anything is scheduled, before a quotation is meaningful, the certification body has to establish that it can lawfully and competently do the work you are asking for. ISO/IEC 17021-1 sets out what must be asked and what must be decided, and the decision to proceed has to be recorded with its justification.

Understanding what each question is for makes the process shorter, and occasionally saves an organization from a certificate it should not have been given.

What is asked

The scope of certification sought. Which activities, products and services, at which sites. This is checked against the certification body's own accredited scope — and accreditation is granted scheme by scheme and sector by sector, so this is a real filter rather than a formality.

The general features of the organization. Name, addresses, sites, processes and operations. This determines whether multi-site sampling applies and how the audit is structured.

Human resources. Not the payroll headcount — the effective number of personnel, including part-time, temporary, seasonal, contracted and shift workers. Audit duration is calculated from this figure under IAF MD 5, which is why an incomplete answer produces a plan that does not fit.

Outsourced processes. All of them. A process performed by somebody else on your behalf is still within the scope of your management system, and it is still audited. Organizations often omit these because they think of them as somebody else's operation.

The standards sought. Named individually, with editions.

Whether management system consultancy has been provided, and by whom. The question people are most tempted to answer loosely, and the one where a loose answer causes the most damage.

What the certification body decides with it

Six determinations, and each can end the process.

Do we have the competence? For your sector, your processes, your standard. If the answer is no, the honest response is to say so rather than to send whoever is available.

Is the scope inside our accreditation? If the scheme or the technical sector is outside it, the certificate either would not be accredited or should not be issued at all.

Is the information sufficient? Incomplete information at this stage produces an audit plan built on assumptions, which surface on site.

Is anything unresolved between us? Differences in understanding about scope, requirements or process are settled here, not discovered during Stage 2.

Can we actually perform it? Working language, access to sites, availability of competent auditors in the locations involved.

Is there an impartiality bar? This is where the consultancy question lands.

The consultancy question, and why loose answers are expensive

ISO/IEC 17021-1 clause 5.2.7: where an organization received management system consultancy from a body that has a relationship with the certification body, that is a significant threat to impartiality — and the recognised mitigation is that the certification body shall not certify the system for at least two years after the consultancy ends.

Clause 5.2.10 applies the same two-year period to individuals who consulted for you: they do not take part in your audit or other certification activities.

Clause 5.2.6 does it again for internal audits performed by the certification body.

Three clauses, one shared feature: a two-year memory.

So the question is not administrative curiosity. A certification granted in breach of these clauses is a certification at risk — and the risk sits with the certified organization as much as with the body that issued it, because the certificate is the thing that becomes unreliable.

The awkward version of this conversation happens when the answer surfaces after a contract, sometimes after a Stage 1. At application review it costs nothing but a few minutes.

What a good application review feels like

It should feel like being asked precise questions by someone who knows why they are asking, and it should end with a clear statement of what will happen, over what period, and on what basis the days were calculated.

If a certification body can tell you the day-count before it knows your shift pattern and your outsourced processes, it has not done an application review. It has quoted.

When the answer is no

Sometimes the review concludes that the work should not be done. Outside accredited scope. No competence for the sector. An impartiality bar. Inability to perform at the sites or in the working language.

Hearing that is better than the alternative, and a body that says it is telling you something useful about how it operates. The alternative is a certificate that does not survive scrutiny, issued to an organization that will rely on it in front of a customer.

What to bring

Four things make the review fast and the quotation accurate: the effective headcount including shifts and seasonal peaks, the site list with what happens at each, the list of outsourced processes, and an honest account of any consultancy support and when it ended.

None of it is difficult to assemble. All of it is difficult to correct later.

Apply for certification →Verify a certificate

Read next

A programme shaped by its inputs leaves a trailTwo of Stage 1's seven objectives are not about youThe accreditation number checked out. That is not the same as the certificate being real.
Application review: what a certification body asks for, and why — CAS · CAS