IAF MD 1 – Auditing and certification of management systems in multi-site organisations

If an organisation has at least one further site in addition to its head office and wishes to be certified, specific requirements and aspects arise that must be observed during certification. In addition to the respective standards for the norm to be certified (such as DIN EN ISO 27006 for ISO/IEC 27001), requirements can be found in IAF MD 1:2023 and must be taken into account.

Such an organisation is referred to as a multi-site audit or matrix certification. This means an organisation with a single management system (for example a quality management system to ISO 9001, an information security management system to ISO/IEC 27001, or an integrated management system to ISO 9001 and ISO/IEC 27001) that has a defined head office (not necessarily the organisation's registered office) where certain processes/activities are planned and controlled, as well as a number of sites at which such processes/activities are carried out in whole or in part.

Definition of head office and sites, and effects on certification

IAF MD 1 distinguishes between the head office and permanent, temporary and virtual sites. This distinction is important because the number of sites affects the audit time, and it must be ensured in advance that the full number of sites has been recorded.

The head office is the location from which the operational control and authority of the organisation's top management is exercised over each site – in other words, the location responsible for the management system and exercising central control. It is not necessary for the head office to be located at one of the sites.

Note: The number of sites affects the audit scope and the audit duration.

Requirements for a multi-site organisation

"A multi-site organisation need not be a single legal entity. However, all sites must have a legal or contractual link with the organisation's head office and be subject to a common management system that is defined and established by the head office and is subject to regular surveillance and internal audits by the head office. This means that the head office has the right to require sites to implement corrective actions where this is necessary at a site."

The suitability of a multi-site organisation for certification must be verified in advance by the certification body. RSM Certification GmbH has prepared a separate document for this purpose, which must be completed in advance by the organisation to be certified.

Note: Not every organisation is suitable for a matrix certification.

Which sites are audited? Sampling: applicable or not?

In a multi-site organisation in which each site carries out very similar processes/activities, appropriate samples can be taken (e.g. a chain of franchise stores). If this is not the case and, for example, all sites carry out substantially different processes/activities relating to the scope of the management system, sampling is not applicable and all relevant sites must be audited.

However, there are also organisations in which some sites carry out similar processes/activities while other sites perform very specific processes that are not carried out elsewhere in the organisation. Here, an appropriate sample of sites would be limited to those sites that carry out very similar processes/activities and that belong to the organisation's scope.

Case 1: sampling is applicable

The sample must be determined partly selectively and partly at random. The result must ensure a representative selection of the different sites and that all processes included in the certification scope are audited. At least 25% of the sample must be selected at random. Taking into account the provisions set out below, the remainder must be selected so that the differences between the sites chosen over the validity period of the certificate are as great as possible.

When selecting the sites, the following aspects must be taken into account, among others:

  • results of internal audits at the sites and management reviews, or previous certification audits,
  • records of complaints and other relevant aspects relating to corrective and preventive actions,
  • significant differences in the size of the sites,
  • variations in shift patterns and working procedures,
  • complexity of the management system and of the processes carried out at the sites,
  • geographical distribution of the sites, and
  • whether the sites are permanent, temporary or virtual.

The minimum number of sites to be audited per audit that meet the sampling requirements is determined as follows:

  • Initial certification: the sample size must be the square root of the number of sites (y = √x), rounded up to the next whole number, where y = the number of sites to be included in the sample and x = the total number of sites.
  • Surveillance audit: the size of the annual sample must be the square root of the number of sites multiplied by a coefficient of 0.6 (y = 0.6√x), rounded up to the next whole number.
  • Recertification audit: the sample size must be the same as for an initial certification audit. However, if the management system has proven effective over the certification period, the sample size can be reduced to y = 0.8√x, rounded up to the next whole number.

The head office must be audited during every initial certification, every recertification audit and at least once per calendar year as part of surveillance. The size or frequency of the sample is increased if the certification body's risk analysis for the process or activity covered by the management system to be certified reveals particular circumstances relating to factors such as the size of the sites and the number of employees, the complexity or risk level of the process/activity and of the management system, and records of complaints and other relevant aspects relating to corrective and preventive actions.

Case 2: sampling is not applicable

If sampling is not applicable, an initial and recertification audit must be carried out at all sites. For surveillance audits, 30% of all sites, rounded up to the next whole number, must be audited within a calendar year.

Case 3: sampling is applicable and further sites are added to the management system

When an application is made to add new sites or a new group of sites to an existing certified multi-site organisation, the certification body must determine the necessary activities before the new site(s) can be included in the certificate. This includes considering whether or not the new site(s) must be audited. After the new site(s) have been added to the certificate, the sample size for future surveillance or recertification audits must be determined.

Note: Depending on the number of sites within the management system to be certified and on whether sampling is possible, the audit scope – and thus the audit duration – varies.

Audit scope and audit duration

The audit scope and thus the audit duration for multi-site organisations therefore depends on a wide variety of factors that must be considered in advance. A key criterion for organisations with multiple sites is the applicability of a sampling procedure and thus the number of sites to be audited.

When determining the site-specific audit time, the key criterion is that sufficient confidence must be established in the effectiveness and efficiency of the management system to be audited. Where appropriate, audit time may also be transferred between different sites. In exceptional cases, a further reduction in audit time at sites may be made on the basis of a risk analysis. This must be documented accordingly.

In addition to the requirements of IAF MD 1:2023, there are further specific requirements for the various standards to be audited which must be taken into account and which influence the audit scope and duration – for example DIN EN ISO 27006 in the field of information security, or IAF MD 5:2023 in quality and environmental management.

This entry does not claim to cover all individual requirements of IAF MD 1:2023 in full. Rather, it is intended as a summary of the key requirements – particularly from a customer perspective.

Go back