14.2 Certification Recommendations
Key Takeaways
- Recommendation (audit team) is distinct from certification decision (CB decision function)
- Major NCs typically prevent unconditional recommend-to-certify until CA is verified per scheme rules
- Minor NCs often still allow a positive recommendation with required corrective action timelines
- Stage 1 supports readiness for Stage 2—it is not itself a certification grant recommendation
- Defensible recommendations match scope audited, NC severity, impartiality rules, and clear report evidence
14.2 Certification Recommendations
Quick Answer: The audit team (via the lead auditor) typically makes a recommendation on certification; the certification body (CB) makes the certification decision. Recommendations must reflect Stage 2 conclusions, nonconformity severity, and scheme rules (often aligned with ISO/IEC 17021-1). Majors usually block an unconditional positive recommendation until corrective action is verified; minors may allow recommendation with required CA within defined timeframes.
Certification audits exist to support a competent, impartial decision about whether to grant, refuse, maintain, renew, suspend, or withdraw certification. Lead auditors who confuse "we recommend" with "we certify" fail a core PECB / ISO 19011 / ISO/IEC 17021 competency. Exams probe recommendation logic, major/minor effects, and independence of the decision function.
1. Recommendation vs Decision
| Role | Typical responsibility |
|---|---|
| Audit team / lead auditor | Collect evidence, raise findings, reach conclusions, recommend certification outcome |
| CB decision maker (not on the audit team for that file) | Review report package and decide certification grant/refusal/maintenance/etc. |
| Organization | Implement corrections and corrective actions; does not "vote" on the certificate |
Why separation matters: Impartiality. The people who audited should not be the sole unchecked decision authority for that same certification. Your report must be clear enough that a decision maker who was not on site can understand evidence, NCs, and residual risk.
Exam tip: If a scenario says the lead auditor "issued the ISO 14001 certificate at the closing meeting," that is wrong under normal CB schemes.
2. Common Recommendation Outcomes (Stage 2 / Recertification)
Exact labels vary by CB procedures, but conceptually you will see patterns like:
- Recommend certification — EMS conforms; any NCs are within rules allowing positive recommendation (often minors only, with CA plan/time limits).
- Recommend certification after satisfactory corrective action — Typically when majors (or critical issues) require verified correction/corrective action before a positive decision pathway.
- Do not recommend certification — EMS does not demonstrate conformity/effectiveness to the degree required; fundamental failures, unresolved majors without credible path, or scope not ready.
- Recommend maintaining certification (surveillance) — Continued conformity with CA as required.
- Recommend suspension / withdrawal consideration — Serious breakdowns, misuse of marks, or failure to address prior NCs (decision still with CB).
Always follow the client CB / scheme instructions you are auditing under. Course exams still expect the ISO/IEC 17021-aligned logic: majors are more severe barriers than minors; decisions are independent; recommendations must match evidence.
3. How Nonconformity Classification Drives Recommendations
Major nonconformity
A major typically indicates absence or total breakdown of a system element, or a situation that raises significant doubt about the EMS's ability to achieve intended outcomes (including compliance obligations). Effect on recommendation:
- Usually no unconditional recommend-to-certify until the organization corrects and the CB (or designated verifier) accepts evidence of correction/corrective action per procedures.
- May require on-site follow-up for verification when risk warrants it (e.g., critical operational control failure at a significant aspect).
- Multiple majors, or a major showing systemic collapse, can support a do not recommend outcome.
Minor nonconformity
A minor is a nonfulfillment that does not indicate systemic failure by itself. Effect:
- Often still compatible with a positive recommendation, provided the organization commits to timely corrective action under CB rules.
- Accumulation of many minors in one process can indicate a systemic issue that should have been classified (or reclassified) as major — exams test this judgment.
Opportunities for improvement (OFIs)
OFIs are not nonconformities. They do not, by themselves, block certification recommendations. Do not "punish" with majors where only OFIs exist, and do not hide real NCs as OFIs to force a positive recommendation.
4. Stage 1 vs Stage 2 Recommendation Language
Stage 1 outputs concern readiness for Stage 2 (documentation, understanding, internal audit/management review status, site conditions). You generally do not recommend granting certification after Stage 1 alone.
Stage 2 is where certification recommendation language belongs, based on implementation and effectiveness evidence.
Surveillance recommendations concern continued certification maintenance. Recertification recommendations concern renewal after a full evaluation cycle.
Misapplying Stage 1 "ready for Stage 2" as "recommend certificate" is a classic exam error.
5. Building a Defensible Recommendation
A professional recommendation package typically includes:
- Clear conclusions (Section 14.1)
- Complete NC statements with criteria, failure, and evidence
- Statement of audit objectives, scope, criteria, and dates
- Identification of audit team and competence relevance
- Notes on unresolved issues and limitations
- Explicit recommendation statement aligned to CB template
- Any required comments on use of marks, multi-site sampling, or combined audits
Before you sign:
- Recheck major/minor consistency against risk to intended outcomes.
- Confirm you are not recommending certification for a scope you did not audit.
- Confirm conflicts of interest were managed (previous consulting on the same EMS, etc.).
- Ensure the recommendation can be understood without tribal knowledge of hallway conversations.
6. Corrective Action Timing and Conditional Paths
When majors exist, organizations must address them under CB timelines (commonly on the order of weeks to a few months — follow the scheme). Auditors should explain:
- What evidence of correction (fix the immediate problem) and corrective action (eliminate cause) is expected
- Whether verification will be document review or on-site
- That the CB decides after reviewing the audit package and CA evidence
Do not invent certificate effective dates at the closing meeting. Do not promise that filing a CA plan automatically equals certification.
7. Ethical Red Lines
Never trade a softer recommendation for:
- Future consulting work
- Hospitality or gifts
- Pressure from sales staff to "keep the client happy"
- Auditee threats to complain unless majors are downgraded without evidence
Integrity and independence are audit principles. A recommendation that ignores a major waste-control failure to preserve a sales relationship is not a recommendation — it is a scheme integrity failure.
8. Exam Scenario Pattern
When asked what the team should recommend:
- Identify audit type (Stage 1, Stage 2, surveillance, recertification).
- Inventory majors vs minors and systemic patterns.
- Apply scheme logic (majors → CA verification before positive decision path).
- Separate recommend from decide.
- Choose the option that preserves impartiality and evidence alignment.
If the EMS shows strong documentation but operational controls for significant aspects are absent, a positive Stage 2 recommendation is rarely justified — effectiveness is part of the story, not a footnote.
In a typical ISO/IEC 17021-aligned ISO 14001 certification process, who makes the certification decision?
A Stage 2 audit identifies one major NC in operational control of a significant wastewater aspect and two minor NCs in documented information control. Which recommendation posture is most consistent with common CB practice?
After a Stage 1 EMS audit, the team finds the organization is ready for Stage 2 with only documentation clarifications needed. What should the team recommend regarding certification?
Why must certification recommendations be written so a CB decision maker who was not on site can understand them?