Skip to content
Two paths diverging from one ISO document, one marked self-assessment and the other marked external audit

General7 min read

Self-Assessment vs Third-Party Audit: Which ISO Route Fits?

A self-assessment certificate and a third-party audit are different things. Here is how they differ and how to choose for your business.

By Zertify Redaktion

A self-assessment certificate confirms that you have checked your own practices against an ISO standard. A third-party audit certificate confirms that an external auditor has checked them for you. The first is faster and cheaper to obtain. The second carries more weight when someone outside your company demands proof.

This article explains the difference in plain terms, so you can pick the route that fits your situation instead of the one that sounds more impressive.

The short answer

Both routes start from the same place: an ISO standard with a set of requirements. What changes is who judges whether you meet them.

In a self-assessment, you answer structured questions about how your business works. You review your own processes, documents and responsibilities. You decide where you stand.

In a third-party audit, an independent body sends an auditor. The auditor interviews your people, reads your records and tests whether your system works in practice. The auditor, not you, decides whether you conform.

Neither route is wrong. They answer different questions. A self-assessment answers: "Have we looked honestly at how we work?" An audit answers: "Has someone independent confirmed it?"

What a self-assessment certificate is

A self-assessment certificate rests on your own answers. You work through a questionnaire based on the standard, and the result shows whether your practices meet its requirements as you describe them.

That has real value. Going through the questions forces you to look at things many small businesses never write down: who is responsible for what, how you handle complaints, how you decide what to improve, how you deal with risks. For many owners this is the first time those topics are laid out in order.

It also has clear limits. Nobody outside your company has verified your answers. A customer, a tender office or a regulator may therefore treat the certificate as a statement of intent and good practice, not as independent proof.

This is why we are direct about it at Zertify. A Zertify certificate is issued by SICE (Swiss Institute of Certification and Education) on the basis of a self-assessment. It is not an accredited third-party certification, and we never describe it as one.

What a third-party audit is

A third-party audit is carried out by a certification body that is independent of your company. The auditor reviews evidence: documents, records, processes and what your staff actually say and do.

An audit usually has several stages. There is a document review, an assessment of how the system works in practice, and a decision by the certification body. After certification, the body normally comes back for follow-up audits to check that the system is still maintained.

The benefit is independence. The result does not depend on your own judgement. The cost is time, effort and money. You need to prepare evidence, free up staff for interviews and plan around the auditor's schedule. For a small team, that is a real commitment.

Accredited and non-accredited are not the same

A third-party audit is not automatically accredited. Accreditation means that a national accreditation body has checked the certification body itself and confirmed that it works to recognised rules. Many tenders and regulated sectors rely on this extra layer. If you want the full picture, our guide on accredited or not explains what accreditation changes and who asks for it.

Side-by-side comparison

QuestionSelf-assessmentThird-party audit
Who judges conformity?You, through structured questionsAn independent auditor
Evidence checked by outsiders?NoYes
Effort for a small teamLow to moderateModerate to high
SpeedFastSlower, depends on audit planning
Follow-up auditsNot part of the processUsually required
Weight with sceptical buyersLimitedHigher, especially if accredited
Best useShowing good practice, internal orderMeeting an explicit external requirement

The table simplifies. Individual certification bodies set their own schedules and conditions. The pattern, however, holds: more independence means more effort.

When a self-assessment is enough

A self-assessment is often the sensible choice when nobody has demanded an audited certificate. Typical situations:

  • You want to bring order into your processes and show customers that you work to a recognised framework.
  • You are a small business or start-up and want to document how you operate before you grow.
  • A customer asks whether you follow good practice, but their contract does not name an accredited certificate.
  • You want a first step before deciding whether a full audit is worth it later.

In these cases, a heavy audit process can cost more than it returns. If this is your situation, our page on ISO certification without an audit explains what such a route can and cannot do for you.

The key condition is honesty about what the certificate is. If you present it as a self-assessed certificate, you are on solid ground. Problems start when a self-assessment is passed off as an accredited audit.

When you need an accredited audit

Sometimes the choice is not yours. An accredited third-party audit is the better, and sometimes the only, option when:

  • A tender explicitly requires an accredited certificate.
  • A customer contract names accredited certification as a condition.
  • A regulator or industry body requires independent certification.
  • Your buyers are large organisations whose procurement rules exclude self-assessed certificates.
  • You operate in a field where safety, health or legal exposure is high and independent verification is expected.

Check the wording carefully. Requirements often say "certified to ISO 9001" without saying "accredited". Others say it clearly. When it is unclear, ask the person who set the requirement. A short email now saves you from buying the wrong certificate later.

If the requirement is explicit, do not try to get around it. A self-assessment certificate will not satisfy it, and presenting it as if it did would damage your credibility.

Why the standard's structure matters either way

Most ISO management system standards follow the same high level structure. It runs from clause 4 (Context of the organization) through 5 (Leadership), 6 (Planning), 7 (Support), 8 (Operation), 9 (Performance evaluation) and 10 (Improvement).

This matters for two reasons. First, whichever route you choose, you are working against the same requirements. Good preparation for a self-assessment is also good preparation for a later audit. Second, once you know the structure for one standard, others feel familiar. You can add a second standard without starting from zero.

The difference between the routes is therefore not about the content of the standard. It is about verification.

Checklist: choosing between the two routes

Work through these points before you decide.

How Zertify fits in

Zertify is built for the case where you want a recognised framework and a documented result without the weight of an external audit. You answer a structured self-assessment. If you pass, and after payment, we issue the certificate within 4 hours. SICE issues it, and it is a self-assessment certificate, not an accredited one.

Here is where to go next:

If your tender or contract demands an accredited audit, Zertify is not the right tool for that requirement. We would rather tell you now than have you find out at the bid stage. For everything else, it is a fast and honest way to show that you work to a recognised standard.

A practical way to decide

Start with the requirement, not the product. If someone outside your company has named accredited certification, book an audit with an accredited body. If nobody has, ask what you really need the certificate for.

If the aim is order, transparency and a credible signal to customers, a self-assessment is a reasonable first step. It can also make a later audit easier, because you will already have looked at your processes against the same requirements.

The worst choice is the one made on assumptions. Read the wording, ask one clear question, and then pick the route that matches the answer.

Frequently asked questions

What is the main difference between a self-assessment and a third-party audit?

In a self-assessment, you evaluate your own practices against an ISO standard. In a third-party audit, an independent auditor checks your evidence and decides whether you conform. The audit offers independent verification but takes more time, effort and money.

Is a Zertify certificate an accredited certification?

No. Zertify certificates are issued by SICE (Swiss Institute of Certification and Education) on the basis of a self-assessment. They are not accredited third-party certifications.

When do I need an accredited third-party audit instead?

When a tender, a customer contract or a regulator explicitly requires an accredited or independently audited certificate. In that case a self-assessment certificate will not meet the requirement, and you should contact an accredited certification body.

How quickly does Zertify issue a certificate?

Zertify issues the certificate within 4 hours after you have passed the assessment and paid.

Can a self-assessment help me prepare for a later audit?

Yes. Most management system standards share the same high level structure, so reviewing your processes against the requirements now gives you a useful starting point. It does not replace an audit, but it can make preparation easier.

Keep reading

More articles

Ready for your ISO certificate?

Complete the self-assessment online. If you pass, your certificate arrives within 4 hours.

The certificate is based on a self-assessment and is not an accredited certification.