Available

Generic Third-Party Audit Preparation Kit


A working pack for a third-party certification audit of an organisation’s management system. Built on the Harmonized Structure shared across ISO standards, it gives a self-assessment, a document and evidence register, a briefing plan, an interview guide, a corrective action log, and a readiness summary: common-core orientation, not a substitute for mapping the organisation’s certified standard.

All products

  • Status Available
  • Regulatory baseline ISO 9001:2026, Quality management systems: Requirements (sixth edition, published 16 September 2026, superseding ISO 9001:2015); ISO/IEC Harmonized Structure for management system standards (successor to Annex SL), as described on ISO’s own management system standards page; ISO 19011:2026, Guidelines for auditing management systems; ISO/IEC 17021-1:2015, Conformity assessment, requirements for bodies providing audit and certification of management systems, Part 1, Requirements
  • Baseline checked 2026-09-17

Problem

An organisation with a management system on paper often has no real sense of whether it would survive a certification audit. The audit is not primarily a paperwork check; it tests whether the organisation can show that its stated policy, its planning and its own monitoring actually operate day to day, and most organisations discover the gap between the two only when an auditor finds it. A generic pack can orient the organisation to what any certification auditor checks first; it cannot, on its own, tell the organisation whether it meets its own certified standard’s specific requirements.

Outcome

Before an audit happens, the organisation completes a common-core self-assessment against the Harmonized Structure shared across ISO management system standards, assembles its evidence, and briefs staff on what a certification audit actually looks like from the inside, with open items tracked through a corrective action log to an explicit readiness decision. This is a structured starting orientation across the seven shared areas, not a certification-readiness verdict against any one standard: the organisation’s own certified standard, its specific clauses, and its certification body’s actual criteria still have to be checked and mapped directly.

What’s included

Four editable documents and five worksheets, supplied as DOCX, XLSX, PDF and ZIP

  • A short written guide in PDF explaining what a third-party certification audit actually covers, structured against the Harmonized Structure shared across ISO management system standards, and stating plainly where a specific certified standard’s own requirements take over from that shared structure
  • An audit readiness self-assessment in XLSX, opening with an audit context and criteria sheet (certification body, standard, edition, audit stage, scope and criteria), then working through context, leadership, planning, support, operation, performance evaluation and improvement with a gap, priority, owner and corrective-action-log reference on every check, and a formula-driven summary
  • A document and evidence register in XLSX, listing the records an audit most often asks to see, where each one is held, and its currency and traceability, plus a sample and evidence request log
  • A pre-audit briefing plan in DOCX, built as fixed tables covering the audit team, agenda, access and confidentiality, administrative and operational preparation, daily debrief and escalation, and the closing meeting, with contingency guidance for a remote audit or unavailable personnel and records
  • An interview preparation guide in DOCX, on how staff are typically questioned at audit and how to answer from the actual record rather than from memory
  • A finding and corrective action log in XLSX, for tracking what an audit raises from root cause through verified, evidenced closure
  • An audit readiness summary in XLSX, aggregating every open item into a single readiness gate with a named accountable manager’s go, go-with-conditions, no-go or deferred decision

Who it’s for

  • Organisations preparing for a first or renewal certification audit who want a common-core starting orientation before mapping their own certified standard’s specific requirements
  • Quality, compliance and management-system staff who hold a system on paper and want to know whether it would survive examination
  • Organisations that have never been through a third-party certification audit and do not know what to expect

Price

The entry price is EUR 99 / NOK 1 070, excluding value added tax.

LicenceOne-off, excluding MVAOptional annual updates, excluding MVAOne-off in Norway, including 25% MVA
Personal, one named userEUR 99 / NOK 1 070EUR 35 / NOK 375NOK 1 337.50
Organisation, one legal entityEUR 249 / NOK 2 680EUR 79 / NOK 850NOK 3 350
List prices exclude merverdiavgift (MVA). EUR and NOK are both shown; your billing country sets which list applies by default and you may pay in the other. What you are actually charged depends on where you are and whether you are buying as a business, which is set out under the table.

Personal to Organisation upgrade, for the difference between the two current list prices: EUR 150 / NOK 1 610, excluding value added tax.

The purchase is perpetual and the update subscription is optional. If you subscribe, you receive revised files when the regulatory baseline changes; if you let it lapse, you keep everything you already have. A lapsed subscription costs you updates, never access.

Licence and VAT

Personal, one named user and Organisation, one legal entity. Both are one-off and perpetual: you keep the files.

How merverdiavgift is charged

The seller is RMX DRIFT AS, organisation number 931 140 574, registered for merverdiavgift in Norway. Every product here is an electronic service for MVA purposes, so the rate is decided by where you are established and whether you are buying as a business or as a private individual.

If you are in Norway, you are charged 25 per cent MVA on top of the kroner list price. The final column above is that total, and it is the amount a private buyer in Norway pays. A Norwegian business or public body is charged the same 25 per cent and can normally reclaim it as input MVA through its own return, so the ex-MVA column is the real cost to you.

If you are a business or public body established outside Norway, the sale is zero-rated as a remotely deliverable service under merverdiavgiftsloven section 6-22. You are charged the list price with no Norwegian MVA added, and you account for any VAT due in your own country under the reverse charge. Enter your organisation or VAT number at checkout: without it we cannot treat the sale as a business supply and MVA is added.

We do not currently sell to private individuals outside Norway. A sale to a consumer in another country would make us liable to register and account for that country’s VAT from the first sale, and we have chosen not to take that on until the volume justifies it. If you are buying for professional use, purchase through your employer or company and enter its number, or get in touch.

Prices are reviewed twice a year and the two currency lists are held close to parity, so switching currency saves you almost nothing. Nothing on this page is tax advice; if your situation is unusual, ask your own adviser.

What this is not

  • This is not an audit and does not perform one. It does not assess or approve any organisation’s management system, and it does not issue or recommend certification.
  • It does not replace the organisation’s own management system, and it is not a template for building one from nothing.
  • It is not specific to any one certification body’s method or to any one management system standard’s full requirements, and it does not by itself establish certification readiness against a specific standard. The Harmonized Structure it uses is a shared common core, not a substitute for the buyer’s own certified standard’s subject-specific clauses; where a specific certification body’s own requirements, or the buyer’s chosen standard’s own clauses, differ from or go beyond the general structure here, those specific requirements govern and still need their own mapping.
  • It carries no aviation content and does not cover UAS, safety management system, or other aviation-specific audits. The NorthSky Aviation Third-Party Audit Preparation Kit covers that instead.

FAQ

Will this ensure I pass my certification audit?

No. This is a common-core starting orientation across the Harmonized Structure shared by ISO management system standards, not a certification-readiness verdict. Your own certified standard’s specific clauses and your certification body’s actual criteria still need to be checked and mapped directly.

Does this kit perform the audit or certify my organisation?

No. It is not an audit and doesn’t assess, approve, or issue any certification — it prepares you for an audit someone else conducts.

Does this replace our existing management system?

No. It doesn’t replace your management system and isn’t a template for building one from nothing.

Does this cover aviation-specific audits?

No. It carries no aviation content — the NorthSky Aviation Third-Party Audit Preparation Kit covers UAS and safety management system audits instead.

What do I need to open the files?

Microsoft Word 2016 or later (or any DOCX-compatible editor), Microsoft Excel 2016 or later (or any XLSX-compatible editor), and any PDF reader.

Can I share this with other organisations?

No. The licence is single-organisation with no redistribution.

NorthSky provides operational risk decision support and advisory guidance. Outputs do not constitute regulatory certification, aerodrome licensing, compliance verification, or formal authority determinations.