THE QUESTION FILE · FAQ

Frequently asked questions

Questions answered across the QSI service spec sheets and resource guides, consolidated here and grouped by theme. Each block links back to the page it was drawn from.

FAQ-01 · 06 QUESTIONS

Choosing a certification body

What to check before signing with any certification body: accreditation, scope coverage, sector approvals, auditor competence and how audit duration is calculated.

FROM THE GUIDE · 06 QUESTIONS

Choosing a Certification Body in Saudi Arabia: 10 Questions to Ask

The foundational question. Legitimate CBs operate under ISO/IEC 17021-1 and are accredited by a recognised accreditation body. In Saudi Arabia, the national accreditation body is the Saudi Accreditation Center (SAAC) (saac.gov.sa), an IAF MLA signatory; international accreditors such as IAS are also recognised through the IAF framework (iaf.nu). Don't accept a logo on a brochure. Ask for the accreditation certificate number and verify it in the accreditor's public directory. If the "accreditor" is not an IAF member, walk away: you would be buying an unaccredited certificate with extra steps.

Accreditation is granted per scheme. A CB accredited for ISO 9001 is not automatically accredited for ISO 22000 or ISO 45001. Check that the standard you need appears in the CB's accreditation scope, and if your certificate must serve a specific purpose (a tender, a regulator file), confirm with the end user which accreditations they accept, before you sign.

In regulated sectors, accreditation alone may not be enough. The clearest Saudi case is food: if your HACCP or ISO 22000 certificate needs to support SFDA facility licensing or product registration, the CB should hold the relevant SFDA approval for food-sector certification (sfda.gov.sa). Ask directly, and ask for the approval reference. A food factory certified by a body SFDA does not recognise has bought a certificate its own regulator won't read.

Under ISO/IEC 17021-1, CBs must assign auditors competent in your technical area: certification schemes classify industries into technical clusters, and auditors are qualified per cluster. Ask: does the CB have auditors qualified for your sector? Have they audited companies like yours: same processes, similar scale? An auditor who understands your industry finds the issues that matter; one who doesn't audits the paperwork and misses the plant. For Saudi operations, also ask about language.

Accredited CBs calculate audit days from your headcount, sites, shifts and complexity using IAF mandatory rules: the duration is derived, not invented. A CB quoting a complex, multi-shift site at a fraction of the expected days is either planning a superficial audit or not planning to follow the rules; both end badly at accreditation review. You are entitled to ask how the days were determined.

Certification pricing has recurring parts: initial audit (stage 1 + stage 2), annual surveillance audits, and recertification in year three, plus possible fees for certificate issue, follow-up visits or scope changes. Insist on a quote covering the whole cycle with every fee named. The classic trap is a low headline price for initial certification with surveillance priced after you are committed. Compare cycle-total against cycle-total, never initial-audit against initial-audit.

FAQ-02 · 37 QUESTIONS

Standards and schemes

Questions asked about the individual standards QSI certifies, drawn from each service spec sheet and the standard-specific guides.

FROM THE SPEC SHEET · 04 QUESTIONS

ISO 9001 Certification

No. It applies to any organisation that needs controlled processes and evidence-based improvement.

Timing depends on readiness, scope and closure of findings. QSI will not promise a certificate before audit evidence exists.

No. You need documents and records that reflect how work is actually controlled.

QSI can explain findings and certification rules, but cannot provide consultancy for its own certification clients.

FROM THE SPEC SHEET · 04 QUESTIONS

ISO 14001 Certification

No. It certifies the management system. The audit checks how legal obligations are identified, evaluated and controlled.

Yes. Operational controls, emergency preparedness and monitoring records are reviewed against actual site conditions.

Yes, if the environmental management system is appropriate to the site and scope.

Aspect evaluation, compliance controls, objectives, monitoring, training and management review are usually central.

FROM THE SPEC SHEET · 04 QUESTIONS

ISO 45001 Certification

No. The audit must test whether hazard controls operate in the workplace.

Worker participation and awareness are part of the standard, so interviews are expected.

Yes, if scope, sampling and audit planning rules support it.

Weak hazard assessment, poor incident learning, incomplete controls and unclear responsibilities are common.

FROM THE SPEC SHEET · 04 QUESTIONS

ISO 22000 Certification

HACCP focuses on hazards and controls. ISO 22000 embeds those controls inside a managed system with objectives, review and improvement.

Yes. Records, prerequisite programmes, CCP monitoring and corrective action evidence are central to the audit.

Yes, when storage or distribution activities affect food safety and customers require certified controls.

QSI is SFDA-approved (CB-2024-FO-0011), and food-sector audits in Saudi Arabia are planned with that regulatory context in view. The certificate itself attests the named standard and scope.

FROM THE SPEC SHEET · 04 QUESTIONS

HACCP Certification

It is a direct way to show hazards are identified, controlled, monitored and corrected with records.

Yes. A HACCP file that does not match the floor is a certification risk.

Often, yes. HACCP can become the food-safety core of a wider ISO 22000 management system.

The certificate scope must be specific. It should not imply product certification unless that is explicitly covered.

FROM THE SPEC SHEET · 04 QUESTIONS

FSSC 22000, Through Partner Certification Bodies

No such claim is made here. FSSC 22000 is delivered through partner certification bodies, and the issuing body is named before any engagement begins.

FSSC builds on ISO 22000, adds the sector prerequisite programmes and FSSC additional requirements, and is benchmarked under GFSI, which is what global buyers are checking for.

The certificate is issued by the licensed partner body, so recognition follows that body’s license and accreditation. That is stated openly, which is exactly what a serious buyer verifies.

Where scopes and sites overlap, planning can align FSSC activity with ISO 22000 or HACCP work to reduce disruption. The scheme rules stay controlling.

FROM THE SPEC SHEET · 04 QUESTIONS

Additional Standards and Product Compliance

Do not assume that. Scope and accreditation status must be verified before claims are published.

Integrated audits may be possible when scopes, sites and system controls overlap. Planning confirms this.

It is route-to-market support around defined product evidence and documentation, not a blanket approval.

They are important long-tail services, but each needs careful scope confirmation before stronger claims are made.

FROM THE GUIDE · 03 QUESTIONS

HACCP Certification in Saudi Arabia: The Complete Guide

HACCP (Hazard Analysis and Critical Control Points) is a preventive food safety methodology built on the Codex Alimentarius General Principles of Food Hygiene. Instead of relying on end-product testing, you identify the biological, chemical and physical hazards in your process, decide where they must be controlled, and monitor those points continuously. The Codex framework rests on 12 steps, which include the 7 HACCP principles: Conduct a hazard analysis. Determine the critical control points (CCPs). Establish critical limits. Establish monitoring procedures. Establish corrective actions.

There is no single law that says "every food business must hold a HACCP certificate", but in practice several drivers make it close to unavoidable: SFDA-licensed food factories. The Saudi Food and Drug Authority (sfda.gov.sa) requires locally manufactured food products to be produced in a licensed establishment, and the registration file for products such as food supplements must include a HACCP, GMP or ISO 22000 certificate for the manufacturing facility. If you want your products registered and cleared, certified food safety controls are part of the file. Municipality and inspection regimes.

For a factory with reasonable hygiene infrastructure already in place, a realistic end-to-end timeline is 3 to 6 months: implementation and record-building are the long poles, not the audit itself. Sites starting from scratch on PRPs (facility modifications, new monitoring equipment, staff training) should plan for longer.

FROM THE GUIDE · 02 QUESTIONS

ISO 22000 vs HACCP: Which Does Your Food Business Need?

Management system structure. ISO 22000 follows the same high-level structure as ISO 9001 and ISO 14001: context of the organisation, leadership, planning, support, operation, performance evaluation, improvement. That makes it straightforward to integrate with existing ISO certifications. PRPs formalised. ISO 22000 requires you to select and document prerequisite programmes systematically; most manufacturers use ISO/TS 22002-1 as the reference for food manufacturing PRPs. OPRPs.

Costs follow effort: ISO 22000 audits take more auditor days and the system takes longer to build, so expect a higher total investment. (Actual fees depend on site size, processes and headcount; get quotes rather than relying on generic figures.)

FROM THE GUIDE · 01 QUESTIONS

ISO 22000:2018 Requirements Summarised for Food Manufacturers

Certification follows the accredited two-stage model under ISO/IEC 17021 rules (with food-scheme-specific requirements applied by the certification body): stage 1 readiness review, stage 2 on-site audit during production, then annual surveillance and recertification in year three. Auditors will want to see the plant running, records at the line, a live traceability test, and evidence the two PDCA loops are both turning: management review that actually discusses verification data, and a hazard control plan that reflects this year's process, not the consultant's template.

FROM THE GUIDE · 03 QUESTIONS

ISO 45001 for Construction and Contractors in Saudi Arabia

1. Prequalification. There is no Saudi law that says every contractor must hold ISO 45001. In practice, it barely matters: large clients impose it contractually. Saudi Aramco and other major industrial clients embed OHS management system expectations in contractor prequalification and safety requirements, and the Vision 2030 giga-projects and major government tenders routinely list ISO 9001, ISO 14001 and ISO 45001 in prequalification criteria. Without them, contractors are filtered out before the technical bid is even read, or scored down against certified competitors. 2.

ISO 45001:2018 follows the same high-level structure as ISO 9001 and ISO 14001, which makes integration straightforward. The requirements that bite hardest on contractors: Hazard identification and risk assessment (6.1.2). Not one generic register, but a living process covering routine and non-routine activities: work at height, excavation, lifting operations, confined spaces, hot works, temporary electrics, plant-pedestrian interfaces, and Saudi-specific realities such as heat stress in summer months.

The value of ISO 45001 certification depends on who issued it. Clients' prequalification teams increasingly verify that the certificate comes from a certification body accredited under ISO/IEC 17021-1 by a recognised accreditation body. In the Kingdom, the Saudi Accreditation Center (saac.gov.sa) is the national accreditation body and an IAF MLA signatory. An unaccredited certificate can cost you the very prequalification you bought it for. --- QSI Cert is a SAAC-accredited, SFDA-approved certification body based in Riyadh, with an Al Khobar office opening in 2026.

FAQ-03 · 07 QUESTIONS

The audit

How a certification audit actually runs: the two-stage model, the evidence trail, what gets checked, how findings are graded and closed.

FROM THE GUIDE · 05 QUESTIONS

What Auditors Actually Check: Inside a Stage 2 Certification Audit

Under ISO/IEC 17021-1 (the standard that governs certification bodies themselves), initial certification requires two stages. Stage 1 established that your documented system is ready. Stage 2 answers a different question: is the system implemented and effective? Documents told us what you say you do; stage 2 checks what you actually do.

Auditors do not read your manual and tick boxes. They pick a thread and pull it. A typical trail in a manufacturing company: Pick a recent customer order. Check how the order was reviewed: did you confirm you could meet the requirements? Follow it into planning: work order, specifications, drawing revision. Onto the floor: is the operator working to the current revision? How were they trained for this task? Show me the competence record. The instrument used to check the part: calibration status, and what happens when an instrument is found out of calibration.

Top management. Not a courtesy meeting. Expect questions on strategic context, risks, why the objectives are what they are, resource decisions, and what management review changed this year. Leadership (clause 5) can only be audited by talking to leaders. Sales / customer service. Order review evidence, handling of changes, customer complaints and what they triggered, customer satisfaction data and what was done with it. Planning / operations.

Records too clean: identical handwriting, same pen, no corrections, filled in batches, a signal of retrospective completion. Dates that don't line up: training completed after the work was done; management review minutes created after stage 1. The "shadow system": the documented procedure on the server and the real method taped to the machine. One heroic person who knows everything: a system that lives in one head fails clause 7 and fails the business. Objectives with no data trail, and internal audits that never find anything.

The audit team recommends; it does not certify. An independent technical reviewer at the certification body (someone not involved in your audit) reviews the audit report, findings and corrective actions, and makes the certification decision. ISO/IEC 17021-1 requires this separation to protect impartiality. Once granted, the certificate is valid for three years, maintained through surveillance audits.

FROM THE GUIDE · 01 QUESTIONS

Major vs Minor Non-Conformities: What They Mean and How to Close Them

A non-conformity (NC) is the non-fulfilment of a requirement: a requirement of the standard, of your own documented system, or of applicable legal/customer requirements within your scope. Three elements make a finding legitimate, and a competent auditor will give you all three in writing: The requirement (with clause reference); The objective evidence observed; The statement of non-conformity connecting the two. If any of the three is missing or wrong, you are entitled to challenge the finding, professionally, at the audit, before it is finalised.

FROM THE GUIDE · 01 QUESTIONS

How to Prepare for Your First ISO 9001 Audit: A Practical Checklist

Minor nonconformities: isolated lapses. You submit corrective action plans (and usually evidence) within the certification body's deadline; certification proceeds. Major nonconformities: a system element missing or collapsed. You must implement correction and corrective action, and the certification body must verify closure (sometimes by a follow-up visit) before the certificate can be issued. Either way, the auditor recommends; an independent reviewer at the certification body makes the certification decision.

FAQ-04 · 02 QUESTIONS

Certificates and the register

Why accreditation decides what a certificate is worth, and how to verify any certificate against the issuing body and its register.

FROM THE GUIDE · 02 QUESTIONS

Understanding Accreditation: SAAC, IAS, and Why Your Certifier's Certifier Matters

Nothing physically stops a company from printing "ISO 9001 certificate" on nice paper. Unaccredited "certification" is cheaper and faster precisely because nobody audits the issuer: no witnessed audits, no competence requirements, no impartiality rules, no oversight of audit duration. The consequences surface later: Tender rejection. Prequalification teams increasingly verify accreditation marks and check registries. Regulator rejection. A certificate from a non-approved, non-accredited issuer will not carry an SFDA file. Customer audits anyway.

Read the certificate. Identify the CB and the accreditation mark(s). Check the scope wording and the sites listed: a certificate covering a head office does not cover a factory that is not named. Check the accreditor is real. Is it SAAC, IAS or another IAF MLA signatory? (iaf.nu lists signatories.). Check the CB's accreditation scope. On the AB's registry (e.g. SAAC's accredited-bodies directory), confirm the CB is accredited for that standard. Accredited for ISO 9001 does not mean accredited for ISO 22000. Verify the certificate itself.

FAQ-05 · 02 QUESTIONS

Training

Auditor training and what course certificates qualify the holder to do.

FROM THE GUIDE · 02 QUESTIONS

Lead Auditor Training: IRCA-Style Paths and What They Qualify You For

IRCA (the International Register of Certificated Auditors, operated by the Chartered Quality Institute (CQI) in the UK, quality.org) is the best-known international scheme for certifying management system auditors. Two distinct things carry the name, and mixing them up causes most of the confusion: CQI-IRCA certified training courses: courses (like the 5-day Lead Auditor course) whose content, tutors and exams are approved by CQI-IRCA and delivered through Approved Training Partners.

Immediately after passing: Lead and manage audits within organisations: internal audit programmes, and second-party (supplier) audits on behalf of your employer. For quality, HSE and food safety professionals, this is the primary, immediate payoff. Strengthen your role in certification audits from the auditee side: you understand how external auditors think, plan and grade, which transforms how you prepare your organisation.

ASK DIRECTLY

Not answered here?

Send the question through the contact form, or request a quote with the scope details and a lead auditor will answer it in context.

Contact QSIRequest a quote
WHATSAPPMessage an auditor