Self-assessment · 7 questions · about two minutes
Facts checked on 28 September 2026 · how this fits with an audit
Seven questions that turn a request for ISO into the specific standard, the specific evidence, and the next step.
Who this is for: a Singapore business whose customer, tender or parent company has asked for ISO, usually in one sentence, and that wants to know which standard that sentence means and what it will take.
| What was asked for | What it covers | The practical first step |
|---|---|---|
| ISO 9001 | How you run quality: process control, customer requirements, corrective action. | Write down your main process and how you check it. Most firms already do this; it is simply not documented. |
| ISO 14001 | How you manage environmental impact: waste, emissions, legal obligations. | List your legal obligations and main impacts, then the controls you already use. |
| ISO 45001 | Safety management for your people: hazards, controls, consultation, incident response. | Start from your risk assessments. In many cases this is the same work as bizSAFE Level 3 or Star. |
| bizSAFE Level 3 or equivalent | A Singapore workplace-safety certification, not an ISO certificate. Many tenders accept either. | Compare the two routes on cost and timeline before choosing: Level 3 and ISO 45001 overlap heavily in evidence. |
Certification is voluntary unless a customer, a contract or a regulator makes it necessary. ISO itself does not certify or issue certificates. An independent certification body does, and accredited certificates can be checked on the International Accreditation Forum CertSearch database.
1. What did the customer or the requirement actually name?
Use their words. This one decides which standard the rest of the answers are aimed at.
2. Is the requirement in writing?
A tender document, a contract clause, a supplier questionnaire, an email.
3. Do you already hold a management system certificate, or has one lapsed?
4. Is there someone inside the company who owns the system and has time set aside for it?
A management system with no owner is a folder that goes out of date.
5. For your main activity, can you already show a written process, a record of it being followed, and a review of it?
The three things an auditor asks for first, in any of the three standards.
6. Who will carry out the certification audit?
ISO states plainly that it does not perform certification or issue certificates. An independent certification body does, and accreditation comes from a national accreditation body.
7. Do you know the auditor fee is separate from the consultancy fee, and paid to them directly?
Every fee we quote is for preparation. The certification body invoices you for the audit.
Most SMEs asked for ISO are asked for one specific standard, in one sentence, in a document they already hold. The expensive mistakes come from guessing: buying 14001 when the tender said 9001, or paying a consultant to do the audit when the certification body has to be independent.
Three rules keep it cheap. Match the standard to the exact wording. Keep preparation and the certification audit in separate sets of hands. And start from the evidence you already have, such as safety assessments done for bizSAFE or process documents written for a customer, because most of it transfers.
Who actually certifies us, you or someone else?
Someone else. ISO states plainly that it does not perform certification or issue certificates. Certification is written assurance from an independent body, and accreditation is the recognition of that body by a national accreditation body. We prepare the system, the documents and the internal audit. The certification body audits you, decides, and issues the certificate in your name.
How do I check a certificate is real?
Ask for the certificate and check it on the International Accreditation Forum CertSearch database, which consolidates data from accreditation bodies and certification bodies. You can also confirm the certification body accreditation with the Singapore Accreditation Council.
Is ISO mandatory for Singapore companies?
No. ISO certification is voluntary unless a customer, a contract clause or a regulator requires it. The obligations that are legal, such as risk assessments under the WSH (Risk Management) Regulations or appointing a DPO under the PDPA, are separate from certification and apply whether or not you hold a certificate.
Can one consultant prepare us and also audit us?
Not if you want a certificate worth anything. Certification requires an independent audit by a certification body that did not advise you. For bizSAFE the same principle is written into WSHC rules, which reject applications where the consultancy and the audit come from the same company. We advise; we never audit.