Last Updated on August 20, 2026 by Hafsa J.
ISO/IEC 17065 Internal Audit and Assessment Prep: The Clause 8.6 Audit and Surviving the Witnessed Assessment
If you run a product, process, or service certification body, “audit preparation” means two completely different jobs, and almost every guide online blurs them into one. The first is your own internal audit under Clause 8.6 of ISO/IEC 17065:2012: the audit you run on yourself to confirm your management system still does what the standard requires. The second is the accreditation body’s on-site assessment, including the witnessed audits where an assessor travels with your evaluator and watches you certify a real client in real time.
They are not the same exercise, they are not run by the same people, and they do not score the same things. Treat them as one and you will walk into your accreditation assessment having rehearsed the wrong performance.
Here is the clean split before anything else. Your Clause 8.6 internal audit is something you own, schedule, and staff. Its criteria are the clauses of ISO/IEC 17065 plus the requirements of every scheme you operate, and the cardinal rule is that nobody audits their own work (8.6.3). The accreditation body’s assessment is something done to you by ANAB, UKAS, or another signatory to the IAF MLA (now the Global Accreditation Cooperation, which replaced IAF on 2026-01-01). It decides whether you get or keep your accreditation. The witnessed audit sits inside that external assessment and is the part most new certification bodies underestimate, because it is the only part where the assessor judges you on a live client rather than on paper.
This article keeps those two lenses apart on purpose. We will walk through the Clause 8.6 internal audit first, because a clean internal audit is the single best preparation for the external one, then through the on-site assessment and the witnessed audit at the center of it, with the opening meeting, closing meeting, and non-conformity mechanics that decide the outcome.
Three exercises people keep confusing
Before the detail, fix the three things apart in your head. The table below is the whole article in miniature.
| Dimension | Internal audit (Clause 8.6) | External accreditation assessment | Witnessed audit |
|---|---|---|---|
| Who runs it | Your own CB, using a competent internal auditor | The accreditation body (ANAB, UKAS, and similar) | The accreditation body’s assessor, on site with your client |
| What it checks | Your management system meets ISO/IEC 17065 plus every scheme you operate, and is effectively implemented (8.6.1) | Whether you qualify for, or keep, accreditation across your scopes | Whether your evaluator actually applies your procedures on a real certification job |
| Criteria | ISO/IEC 17065 clauses plus scheme requirements (8.6.2) | The same standard and scheme rules, judged by an outside party | Your documented process against live performance |
| Who may run it | Anyone, except they cannot audit their own work (8.6.3) | Assigned assessors with competence in your scopes | A technical assessor qualified for the relevant scheme |
| Output | Findings and non-conformities feeding corrective action (8.6.4), records kept (8.6.5) | A formal assessment report, non-conformities, an accreditation decision | A scored observation feeding the overall assessment decision |
| When | On your own programmed cycle, at planned intervals | Initial assessment, then surveillance and reassessment | During an assessment, when the accreditation body witnesses you certify a live client |
| Frequency anchor | Set by importance and prior results (8.6.2) | Cycle defined by the accreditor | UKAS’s initial assessment fee includes two witnessed assessments (UKAS is the only accreditor publishing a full fee schedule) |
The pattern to hold onto: the left column is work you do to yourself and control entirely. The middle and right columns are work done to you, by people you do not manage, who decide whether your certificates carry an accreditation mark at all.
Lens 1: your Clause 8.6 internal audit
Clause 8.6 of ISO/IEC 17065 is the part of the management system requirements that obliges you to audit yourself. If you have built your management system under Option A, 8.6 applies directly. If you run Option B on an ISO 9001 system, you still have to internally audit against 17065, because a 9001 internal audit on its own does not verify the impartiality, competence, and process clauses that make you a certification body. Either way, the internal audit is your dress rehearsal for everything the accreditation body will later do to you.
Build the programme first (8.6.1 and 8.6.2)
Clause 8.6.1 wants a planned audit programme that verifies two things: that your management system conforms to the requirements of ISO/IEC 17065, and that it is effectively implemented and maintained. Conformance and effectiveness are separate tests. A procedure can exist, be approved, and sit in your document library while nobody actually follows it. The programme has to confirm the procedure is real in practice, not just on the shelf.
Clause 8.6.2 then tells you how to shape that programme: define the audit criteria, scope, frequency, and methods, taking into account the importance of the activities concerned and the results of previous audits. In practice that means two things. First, your audit criteria are not generic; they are the clauses of ISO/IEC 17065 plus the requirements of every certification scheme you operate. If you certify under three schemes, each scheme’s own rules are part of what you audit against. Second, you weight the programme by risk. The impartiality arrangements (Clause 4.2), the certification decision independence (Clause 7.6), and the evaluation process (Clause 7.4) carry more consequence than, say, your document control, so they get audited more thoroughly and more often, especially if a previous audit raised anything there.
The rule that trips small bodies: you cannot audit your own work (8.6.3)
Clause 8.6.3 requires that auditors do not audit their own work, and that the audit is conducted objectively and impartially. This is the same separation principle that runs through the whole standard, applied inward. The person who wrote your impartiality procedure cannot be the person who audits whether it works. The evaluator who certified a client last quarter cannot audit the evaluation process this quarter and pass judgement on files that include their own.
For a large body this is trivial. For a five-person certification body it is the hardest sentence in Clause 8. With limited staff, you have three workable routes: rotate auditors so each audits an area they did not build or operate, bring in a competent external internal-auditor on contract, or split the programme so that any one person only ever audits the parts they are independent of. Whatever you choose, the records have to show the independence, because this is one of the first things an assessor checks when they review your internal audit file.
Findings, non-conformities, and corrective action (8.6.4 and 8.7)
Clause 8.6.4 requires you to ensure the audit results are reported to the personnel responsible for the audited area, and that any needed corrective actions are taken without undue delay. The internal audit does not end at a list of findings; it ends when the corrective action is done and verified. That is where Clause 8.7 takes over: for each non-conformity you identify, review it, determine its cause, decide what action is needed to stop it recurring, implement that action, record the results, and review whether the action was effective.
The most common internal-audit weakness an assessor finds is not a missing audit; it is an audit that lists non-conformities and then stops. The cause analysis is thin, the corrective action treats the symptom, and there is no record that anyone checked the fix actually worked. An assessor reads your closed non-conformities precisely to see whether you can run the corrective-action loop they are about to put you through on their own findings.
Keep the records (8.6.5)
Clause 8.6.5 requires you to retain records of the audit programme and its results. For an assessor, those records are the evidence that 8.6 happens at all. Expect them to ask for the programme, the criteria you audited against, the auditor independence for each audit, the findings, and the corrective-action closure. A useful way to organise this is a Clause 8.6 internal-audit checklist that lists every clause of ISO/IEC 17065 plus your scheme requirements, with a column for the evidence sampled, the result, and any non-conformity raised. Built once, that checklist becomes both your audit working paper and the record you hand the assessor. You can structure your own from the clause list, or start from the downloadable 8.6 checklist that accompanies our ISO/IEC 17065 documentation kit and tailor it to the schemes you operate.
Lens 2: the accreditation body’s on-site assessment
Now the lens flips. Where the Clause 8.6 audit is yours to run, the on-site assessment is run by your accreditation body, and the only thing you control is how prepared you are when they arrive. In the United States the accreditor most product certification bodies deal with is ANAB, the ANSI National Accreditation Board. Internationally you might work with UKAS in the UK, JAS-ANZ in Australia and New Zealand, or SCC in Canada. All four are signatories to the IAF MLA for the 17065 product scope, which is what makes a certificate issued under one of them recognised in the others. That mutual recognition arrangement is now administered by the Global Accreditation Cooperation, which replaced IAF on 2026-01-01.
What the assessment actually covers
An initial accreditation assessment has two halves. The office assessment looks at your management system and records: your impartiality arrangements, your competence framework, your procedures, your certification files, and the internal audit and management review records you have just been reading about. The witnessed assessment, covered in the next section, takes the assessor out to watch you certify a live client. Most of what fails an assessment is found in the office half, because that is where the gap between what your documents say and what your records show becomes visible.
Cost is the part accreditors are least transparent about. ANAB, JAS-ANZ, and SCC are quote-only, so you find out the price after scoping. UKAS is the only accreditor that publishes a full fee schedule, which makes it the best public window into what accreditation costs anywhere. For a small-scope certification body, UKAS lists an application fee of GBP 1,796 and an initial assessment fee of GBP 11,437.50, and that initial assessment fee already includes two witnessed assessments. A larger scope with overseas sites pushes the initial assessment to around GBP 34,614, roughly three times as much. Annual fees and surveillance assessments then recur for the life of the accreditation. US bodies will not get these exact numbers from ANAB, but the structure (an application fee, an initial assessment with witnessed audits built in, then recurring surveillance) is the same shape. You can read the published UKAS fee schedule on the UKAS website.
The opening meeting
The assessment opens with a meeting. The assessor confirms the scope being assessed, the plan and timetable, which files and which witnessed jobs they intend to sample, and the logistics. This is not a formality to rush. It is where you learn what they will sample, and it is your chance to make sure the right people and the right records are available on the right days. Treat the opening meeting as the moment the assessment plan becomes real, and have your management representative, your relevant evaluators, and your records ready to match it.
Non-conformities and the closing meeting
An accreditation assessment ends with a closing meeting where the assessor presents their findings. Findings are normally graded. A major non-conformity is a failure that breaks a requirement of the standard or your ability to deliver valid certification, and it usually blocks the accreditation decision until it is resolved. A minor non-conformity is a lapse that does not by itself undermine the system but still has to be corrected. Assessors also raise observations or opportunities for improvement, which are not non-conformities but signal where a future finding could appear.
For each non-conformity the assessor records, you will be asked for a corrective action that follows the same Clause 8.7 logic as your internal audit: cause, action, evidence, and a check that it worked. The accreditation decision is then made by the accreditation body, not by the assessor in the room, once your corrective actions are accepted. This is the moment your internal-audit discipline pays off. A body that already runs the 8.7 loop cleanly on its own findings closes external non-conformities quickly. A body that has only ever listed findings struggles here, in full view of the people deciding its accreditation.
The witnessed audit: the part you cannot rehearse on paper
The witnessed audit is the centerpiece of an accreditation assessment and the part new certification bodies consistently underprepare for. Everything else can be staged from documents. This cannot. The assessor goes out with your evaluator and watches you certify a real client, in real conditions, while it happens. They are not checking whether your procedure reads well. They are checking whether your evaluator actually does what the procedure says, under the pressure of a live job with a paying client in the room.
Why it carries so much weight
An accreditation body cannot put its mark on your certificates on the strength of your paperwork alone. The witnessed audit is how it confirms that the competence framework, the evaluation method, and the impartiality you describe on paper survive contact with a real product, process, or service. This is also why it is not optional or cheap to skip: UKAS builds two witnessed assessments into its initial assessment fee for a small-scope body, which tells you the accreditor treats two live observations as the minimum needed to trust a new certification body.
Picking the client to be witnessed
You usually get some say in which job the assessor witnesses, and the choice matters more than people expect. The instinct is to pick your easiest, friendliest client. Resist the extremes. Pick a job that is genuinely representative of the scope you are seeking, because a witnessed audit on a trivial job proves little and an assessor knows it. Avoid the most complex or most contested client you have, because a witnessed audit is a bad place to discover a problem live. Confirm the client is willing to host an extra observer, schedule it where the full evaluation steps will actually be exercised, and make sure the job falls squarely inside the scope on your application rather than at its edge.
Preparing your auditor
Your evaluator is the one being watched, so prepare the person, not just the file. They should know the scheme requirements cold, carry the evaluation plan and checklist, and run the job exactly as your procedures specify, not a polished special version invented for the day. Assessors are experienced at spotting a performance. The failure mode here is an evaluator who normally cuts a corner and tries to do it by the book only while watched; the inconsistency shows, and it reads worse than the original shortcut. Brief them that the assessor will be observing silently, that they should not perform for the assessor or defer evaluation judgements to them, and that the client interaction stays theirs to lead.
What the assessor scores
The assessor is judging whether your live practice matches your documented system and the standard. Concretely they watch whether your evaluator follows the evaluation plan, applies the scheme’s criteria correctly, gathers sufficient and traceable evidence for each requirement, records non-conformities against the client honestly, communicates those to the client and gives the chance to correct before any decision, and keeps the evaluation independent of the later review and certification decision. They are also watching competence in the field: does the evaluator actually understand the product or process well enough to certify it. A witnessed audit that exposes a gap between your written method and your evaluator’s real behaviour produces a non-conformity that goes straight into the closing meeting.
The connection to accreditation suspension
It helps to remember why the accreditation body is this thorough. Accreditation can be suspended, and a suspended accreditation is a different thing from an invalid certificate. When UKAS suspended all of the British Board of Agrรฉment’s scopes effective 2026-02-26 after a corporate restructuring problem, the existing BBA certificates remained valid even while the accreditation was suspended. The witnessed audit is part of how an accreditor satisfies itself, on live evidence, that it can keep standing behind your work, so that this kind of intervention stays rare. We cover the certifier-versus-certificate distinction in detail in our analysis of the BBA suspension.
A Clause 8.6 readiness check before you book the assessor
Before you invite an accreditation body to assess you, run your own Clause 8.6 internal audit to completion and confirm the items below are not just done but evidenced. This is the spine of the downloadable 8.6 checklist concept: one line per requirement, mapped to the clause, with the evidence you would hand an assessor. Use it as a final readiness pass.
Disclaimer: This readiness list is a preparation aid, not a substitute for your formal Clause 8.6 internal audit or the accreditation body’s assessment. Results depend on the accuracy of your inputs and do not constitute professional advice.
Where this leaves you
The certification bodies that pass their first accreditation assessment cleanly are rarely the ones with the thickest manuals. They are the ones that ran a real Clause 8.6 internal audit, found their own problems before the assessor did, and closed them through the full corrective-action loop, so that the external assessment is a confirmation rather than a discovery. Keep the two lenses apart, give the witnessed audit the preparation it deserves rather than treating it as a formality at the end, and the on-site assessment stops being something that happens to you and becomes something you are ready for.
If you are still building the management system and procedures behind all of this, our step-by-step implementation guide and our breakdown of the impartiality and consultancy firewall go deeper on the structures an assessor will test, and the ISO/IEC 17065 documentation kit gives you the audit checklist, procedures, and records framework to start from.