Glossary
ISO and management system terms in plain English.
-
Accreditation vs certification
Two different things that get used interchangeably and should not be. Management systems are certified. Laboratories are accredited. Getting this wrong signals inexperience.
-
Audit days
The auditor time a certification body allocates to your audit, derived from a published table rather than negotiated. Knowing the table lets you check any quote you are given.
-
Calibration
Establishing the relationship between an instrument's readings and a traceable reference. It tells you what the error is — it does not by itself correct or certify the instrument.
-
CAPA— Corrective and Preventive Action
Corrective and Preventive Action — the combined process for investigating problems, fixing their causes and preventing recurrence. Standard terminology in medical devices under ISO 13485 and FDA regulation.
-
Certification body
The independent organisation that audits your management system and issues your certificate. Sometimes still called a registrar in the US. Accreditation is what makes its certificates meaningful.
-
Context of the organization
Clause 4 of every modern ISO management system standard — the internal and external issues that affect your ability to achieve intended results. The foundation the rest of the system is built on.
-
Corrective action
Action taken to eliminate the cause of a nonconformity so it does not recur. Distinct from correction, which only fixes the immediate problem in front of you.
-
Design controls
The structured requirements governing medical device design and development under ISO 13485 and FDA regulation. They apply from the moment commercial design begins, not at submission.
-
Documented information
The ISO term covering both documents and records. Introduced in the 2015 revisions to replace the older split, and deliberately flexible about format.
-
Effective number of personnel— the figure behind your audit fee
All people involved within the scope of certification, including part-time, temporary and shift workers. The figure that determines your certification body's audit days, and not the same as headcount.
-
Environmental aspect
An element of your activities, products or services that interacts with the environment. Identifying aspects and determining which are significant is the foundation of ISO 14001.
-
Exclusion
A requirement of the standard that does not apply to your organisation and is formally left out of scope. Permitted, but only with justification and only where conformity is unaffected.
-
Gap analysis
A structured comparison of your current state against the requirements of a standard. Normally the first paid step in a certification project, and the point at which the real cost becomes knowable.
-
Global ACI— Global Accreditation Cooperation Incorporated
Global Accreditation Cooperation Incorporated — the body that replaced both IAF and ILAC on 1 January 2026. It sets transition periods when a standard is revised.
-
Harmonized Structure
The common clause structure shared by modern ISO management system standards, set out in Annex SL. Formerly called the High Level Structure, renamed in 2021.
-
Hierarchy of controls
The ranked order in which occupational health and safety risks must be addressed — elimination first, personal protective equipment last. ISO 45001 requires it to be applied, not merely considered.
-
IAF MD 5
The mandatory document that sets how certification bodies calculate audit time for quality, environmental and health and safety management systems. Publicly available and worth reading.
-
Interested parties
Persons or organisations that can affect, be affected by, or perceive themselves affected by your decisions. Clause 4.2 asks you to determine who they are and what they require.
-
Internal audit
A first-party audit of your own management system, conducted by you. Required by every ISO management system standard, and the mechanism that finds problems before a certification body does.
-
ISMS— Information Security Management System
Information Security Management System — the set of policies, processes and controls that manage information security risk. The thing ISO 27001 certifies.
-
Legal and other requirements
The compliance obligations an organisation must identify, access and evaluate under ISO 14001 and ISO 45001. Broader than law — it includes anything you have voluntarily committed to.
-
Management review
A structured review of the management system by top management, at planned intervals. Required by the standard, frequently reduced to a formality, and one of the first things an auditor checks.
-
Measurement uncertainty
A quantified expression of the doubt attached to a measurement result. Central to ISO/IEC 17025 accreditation, and the thing that separates a calibrated instrument from a defensible result.
-
Metrological traceability
An unbroken chain of calibrations linking a measurement result to a national or international standard, each with stated uncertainty. What makes a measurement defensible rather than merely recorded.
-
Nonconformity
Non-fulfilment of a requirement. In an ISO audit it is the formal finding that something required by the standard, your own system, or a regulation is not being met.
-
Notified body
An organisation designated by an EU member state to assess whether medical devices meet EU regulatory requirements before CE marking. Not the same as a certification body, and not interchangeable.
-
Objective evidence
Data supporting the existence or truth of something — records, statements of fact, measurements. What an auditor must have before raising a finding, and what you need to defend one.
-
Outsourced process
A process that is part of your management system but performed by an external provider. It stays inside your system and under your control, however it is contracted.
-
QMSR— Quality Management System Regulation
FDA's Quality Management System Regulation, in force since 2 February 2026. It amends 21 CFR Part 820 and incorporates ISO 13485:2016 by reference, aligning US device regulation with the international standard.
-
Quality manual
A document describing the scope and structure of a quality management system. No longer required by ISO 9001 since the 2015 revision, though many organisations still keep one.
-
Quality objectives
Measurable objectives for the quality management system, set at relevant functions and levels. Clause 6.2 requires them to be monitored, communicated and supported by a plan.
-
Quality policy
A short statement of top management's intentions and direction for quality. Required, must include commitments to satisfy requirements and to continual improvement, and must be communicated.
-
Risk treatment plan
The document recording how each identified information security risk will be handled — modified, retained, avoided or shared — with owners and timescales. Required by ISO 27001.
-
Risk-based thinking
The principle running through ISO 9001:2015 that risks and opportunities should be considered when planning the system. Not the same as formal risk management, and deliberately not prescriptive.
-
Root cause analysis
Structured investigation to find why a problem actually happened, rather than stopping at the first plausible explanation. The step that makes corrective action worth doing.
-
Scope of certification
The boundary of what your certificate covers — which sites, processes, products and people. The single decision that most affects both what you must build and what you will pay.
-
Special process
A process whose output cannot be verified by subsequent inspection or measurement. It must be validated in advance and its operators qualified, because you cannot check the result afterwards.
-
Stage 1 audit
The first half of initial certification — a readiness and documentation review that checks whether you are prepared for the real assessment. Failing it is common and recoverable.
-
Stage 2 audit
The full certification assessment — an auditor examines whether your management system is genuinely implemented and effective, not just documented. The audit that determines whether you get the certificate.
-
Statement of Applicability
The document listing which ISO 27001 Annex A controls apply to your ISMS, which do not, and why. Mandatory, unique to ISO 27001, and the first thing an auditor asks for.
-
Supplier evaluation
Determining and applying criteria for selecting, monitoring and re-evaluating external providers. Clause 8.4.1 requires records, and missing re-evaluation is one of the most common findings in the standard.
-
Surveillance audit
The shorter annual audits in years two and three of a certification cycle. They sample the system rather than covering all of it, but they can suspend a certificate.
-
Transition audit
The audit that moves a certificate from a superseded edition of a standard to the current one. Usually conducted alongside a scheduled surveillance or recertification audit, with extra time added.
-
Verification vs validation
Two requirements that are constantly conflated. Verification asks whether you built it to specification. Validation asks whether it works for its intended use.