An ISO audit does not begin with a request for every file your organization has ever created. It begins with a question: can the language service provider demonstrate, through objective evidence, that its stated processes meet the applicable standard? For organizations asking what documents do auditors need, the practical answer is a controlled set of documents and records that shows how requirements are defined, applied, monitored, and improved.
For ISO 17100 certification, documentation must demonstrate more than a written quality policy. Auditors need evidence that personnel competence, project workflows, supplier controls, client requirements, review activities, and corrective actions operate consistently in practice. The same principle applies to audits against ISO 18587, ISO 20771, ISO 20228, and ISO 23155, although the evidence required will reflect the scope and service model under assessment.
What Documents Do Auditors Need Before the Audit?
Before a certification or surveillance audit, the certification body commonly requests documents for a document review and audit planning stage. This allows the auditor to understand the organization’s scope, locations, services, structure, and documented management system before sampling operational evidence.
The exact request varies by standard, certification scope, organizational size, and whether the audit is remote or on site. A translation company offering only written translation services will not present the same evidence as an interpreting agency, a localization provider managing multilingual technology workflows, or an institution commissioning language services internally.
At minimum, auditors generally need the organization’s legal and operational profile, the proposed certification scope, an organization chart or description of relevant responsibilities, and the current controlled procedures governing the services within scope. They also need access to records that prove those procedures have been used.
A procedure alone is not sufficient. A well-written supplier qualification procedure has limited audit value if no supplier files, assessment results, or approval decisions can be produced. Conversely, individual records without a defined process may show activity but not a controlled system. Certification assessment considers both design and implementation.
Core Management System Documents
The first evidence category establishes how the organization directs and controls its service delivery. Documentation should be current, approved where required, identifiable by version or revision status, and accessible to the personnel who use it.
Typical management system documentation includes a quality policy or equivalent quality commitment, defined objectives, roles and responsibilities, process descriptions, and document-control arrangements. Auditors will examine whether the organization has established responsibilities for quality, operations, resource management, and the handling of nonconformities.
For a language service provider, a process map can be particularly useful. It should show the sequence from inquiry and quotation through client agreement, project preparation, resource assignment, production, checking or revision, delivery, feedback, and improvement. It does not need to be visually elaborate. It needs to reflect the process actually followed.
Auditors will also review the scope statement carefully. It must accurately describe the services, sites, and functions included in certification. Excluding a critical process merely because it is outsourced, such as translation, revision, post-editing, or interpreting resource management, requires careful treatment. Outsourced processes may remain within the organization’s responsibility and therefore require documented control.
Personnel and Competence Evidence
Competence is central to ISO 17100 and related language-service standards. Auditors need evidence that the organization evaluates and authorizes the people who perform roles affecting service quality.
This evidence commonly includes personnel files or resource profiles for translators, revisers, reviewers, project managers, post-editors, interpreters, and other relevant specialists. Records should demonstrate that the organization has evaluated qualifications, professional experience, subject-matter competence, language competence, and any other criteria applicable to the role.
For external resources, the organization should be able to show how suppliers are selected, approved, monitored, and periodically re-evaluated. A supplier database alone is not enough when it contains only contact details. Auditors may sample individual records to verify that documented criteria were applied and that the resource was approved for the assignments received.
Training records are also relevant, especially when the organization has introduced a new workflow, tool, standard, or client-specific requirement. The evidence should connect the training to the role and demonstrate that personnel understand the process they are expected to follow.
Project Files Are the Strongest Operational Evidence
Project files often provide the clearest evidence of whether a language service provider’s system works in practice. During the audit, the auditor will select a sample of completed or active projects and trace them through the documented workflow.
A complete project file should make it possible to establish what the client requested, what was agreed, how the project was prepared, which qualified resources were assigned, what quality steps occurred, and how the final delivery was authorized. Evidence may be held in a translation management system, a business platform, a secure client portal, or controlled folders. The system used matters less than traceability, security, and retrievability.
Depending on the service and standard, a project sample may include the client request, quotation or order confirmation, specifications, project instructions, resource assignments, translation or interpreting records, revision or review evidence, delivery records, and client feedback. For ISO 18587, evidence must also show how machine translation post-editing requirements, post-editor competence, and client specifications were controlled.
Auditors do not normally need to read every translated segment or view confidential client content in full. They need sufficient evidence to verify conformity. Where confidentiality prevents normal access, the organization should agree a practical method in advance, such as redacted samples, screen sharing, controlled auditor access, or evidence reviewed under confidentiality arrangements. Removing all meaningful evidence from the audit sample, however, can prevent effective assessment.
Monitoring, Improvement, and Corrective Action Records
Certification is not based solely on the ability to deliver individual projects. Auditors also assess whether the organization monitors performance and acts when processes fail or risks emerge.
Relevant records may include client complaints, feedback analysis, quality incidents, missed deadlines, supplier performance evaluations, internal audit reports, corrective action logs, and records of effectiveness checks. The organization does not need to prove that it never receives a complaint. It needs to show that complaints and nonconformities are recorded, investigated proportionately, corrected, and used to prevent recurrence where appropriate.
Management review records are equally significant. These should show that senior management evaluates the suitability and effectiveness of the system at planned intervals. Useful inputs include audit results, performance objectives, client feedback, complaints, resource needs, supplier issues, process changes, risks, and improvement opportunities. Minutes should record decisions and assigned actions, not merely that a meeting occurred.
Internal audit documentation should show an independent and planned evaluation of the relevant processes. In smaller organizations, independence must be managed realistically. A director may not be able to audit their own work without limitation, but the organization can use trained internal personnel from another function or engage an appropriately qualified external auditor.
Four Document-Control Failures That Create Avoidable Findings
Many audit findings are caused not by a missing process, but by weak control of otherwise adequate information. Four recurring failures deserve attention:
- Procedures refer to obsolete versions of standards, forms, or systems.
- Staff use local instructions that conflict with the approved procedure.
- Records are incomplete, undated, or cannot be linked to a specific project or decision.
- Documented processes describe an ideal workflow rather than the workflow used in daily operations.
These issues matter because an ISO audit evaluates consistency. If a procedure states that every translation is revised, project files must show revision evidence or a valid, controlled basis for an applicable exception. If supplier re-evaluation is scheduled annually, the organization must either perform it or formally revise the process based on a justified operational decision.
Preparing Documents Without Creating an Artificial System
The most effective preparation is not to generate large volumes of documentation immediately before the audit. That approach often produces contradictions, unfamiliar procedures, and records that cannot withstand sampling. Instead, organizations should identify the requirements applicable to their scope, map those requirements to existing processes, and close genuine gaps.
Start with a document register that identifies each controlled procedure, form, record type, owner, revision status, and storage location. Then conduct a sample-based readiness review of recent projects. Check whether project managers can retrieve client requirements, prove qualified resource assignment, identify completed quality steps, and explain exceptions. This exercise reveals whether the system is auditable under normal operating conditions.
Document retention periods require judgment. They should account for contractual obligations, client confidentiality, legal requirements, certification needs, and the organization’s ability to investigate issues after delivery. Retaining every record indefinitely is not automatically better; retaining evidence for too short a period can make effective auditing impossible.
For remote audits, preparation also includes confirming secure access to records, availability of system demonstrations, and responsible personnel who can explain the evidence. A remote assessment can be fully effective when the organization’s records are organized, searchable, and protected.
A certification audit should confirm the discipline already present in your operations, not require staff to perform a different process for the auditor. When documentation reflects actual control of language services, it becomes credible evidence for certification, tender qualification, and client assurance long after the audit closes.





Leave A Comment