ISO 9001:2015 · Quality Management

ISO 9001 certification, built to survive the audit, not just pass it.

We design and implement quality management systems for Abu Dhabi and GCC businesses, then walk you through Stage 1 and Stage 2 with an accredited certification body. Led personally by a Chartered Quality Professional, not handed to a junior.

8–16 weeksTypical time to certification
Clauses 4–10Full standard coverage
CQP MCQIChartered practitioner led
Zero NCsAchieved on recertification audits

The short version

  • ISO 9001 proves you control your processes and improve on evidence. It does not dictate how you run your business.
  • A single-site SME typically certifies in 8–16 weeks. The implementation period is the hard floor and cannot be compressed.
  • You pay two separate parties: the certification body for the audit, and a consultant for the system. Never the same organisation.
  • No consultant can guarantee a certificate. Treat anyone who does with caution.

What ISO 9001 actually is

ISO 9001:2015 is the international standard for a quality management system (QMS). It does not tell you how to run your business. It requires you to prove you understand your context, manage risk, control your processes, listen to customers, and improve on evidence rather than instinct. A new edition, ISO 9001:2026, was published in September 2026; 2015 certificates remain valid through a three-year transition: see our ISO 9001:2026 and ISO 14001:2026 transition guide.

The standard is built on seven quality management principles and a risk-based, process-driven structure spanning clauses 4 to 10. In practice, certification means an accredited third party has examined how you work and confirmed it matches what you say you do.

ClauseWhat it requiresWhat auditors actually look for
4: ContextUnderstand your organisation, interested parties and QMS scopeA scope statement that matches what you really do, and no convenient exclusions
5: LeadershipTop management accountability, quality policy, defined rolesWhether the MD can explain the policy without reading it
6: PlanningRisks, opportunities, quality objectives, planning of changesObjectives that are measured, not aspirational slogans
7: SupportResources, competence, awareness, documented informationTraining records that prove competence, not just attendance
8: OperationOperational planning, design, suppliers, production, nonconforming outputEvidence at the coalface: site records, not office folders
9: PerformanceMonitoring, internal audit, management reviewA complete internal audit cycle and a minuted management review
10: ImprovementNonconformity, corrective action, continual improvementRoot cause analysis that goes past “human error”
ISO does not certify anyone

ISO writes the standard. Certification is issued by a certification body, which should itself be accredited, in the UAE typically by EIAC, or internationally by bodies such as UKAS or ANAB. We will help you choose an accredited body and avoid the unaccredited certificate mills that sell paper your clients will not accept.

Who needs ISO 9001 in the UAE

Most of our ISO 9001 clients come to us for one of five reasons:

  • A tender demands it. Government entities, ADNOC group companies, main contractors and large developers routinely make ISO 9001 a pre-qualification condition. No certificate, no bid.
  • A client audit is scheduled. A key customer has announced a supplier audit and the gaps are suddenly visible.
  • The business has outgrown its habits. What worked at twelve people is failing at sixty. Rework, missed handovers and repeat complaints are eating margin.
  • Certification lapsed or is at risk. A previous system was built by someone who has left, and nobody has maintained it since.
  • A parent company or investor requires it as a condition of group reporting or due diligence.

ISO 9001 is sector-agnostic. We have applied it to construction and fit-out contractors, engineering and manufacturing firms, facilities management providers, real estate developers, trading and logistics companies, and professional services businesses.

What we do for you

Everything below is delivered by the same senior consultant from start to certificate. There is no handover to a junior after the sale.

Gap analysis against every clause, with a written findings report and prioritised action plan
Scope definition that is defensible: broad enough to satisfy clients, tight enough to be auditable
Process mapping of how work actually flows, including interfaces and handovers
Risk and opportunity register tied to your objectives, not a generic template
Documented information: manual, procedures, forms and records sized to your business
Quality objectives with measurable targets, owners and review frequency
Supplier and outsourced process controls, including evaluation criteria and re-evaluation
Staff awareness briefings so your team can answer auditor questions confidently
Internal auditor training so the system survives after we leave
Full internal audit cycle covering every clause and every process
Management review facilitation with a compliant agenda and minutes
Certification body liaison: quotation comparison, scheduling and on-site attendance

What you receive

At the end of the engagement you own a complete, editable management system, not a locked PDF and not a template someone else can recognise.

  1. Gap analysis report: clause-by-clause status, risk rating and closure plan.
  2. Quality manual and QMS documentation set in editable format, branded to your company.
  3. Process maps and procedures for each core and supporting process in scope.
  4. Registers: risk and opportunity, legal and other requirements, interested parties, competence, supplier.
  5. Internal audit programme, checklists and completed audit reports for the first full cycle.
  6. Management review pack: agenda, input data and signed minutes.
  7. Corrective action records with root cause analysis evidence.
  8. Audit-day support: we attend Stage 1 and Stage 2 with you and respond to findings.

The certification process, step by step

  1. Free consultation

    Thirty minutes to understand your drivers, deadline and scope. If you do not need a consultant, we will say so.

    30 minutes
  2. Gap analysis

    One to two days on site reviewing documents, walking processes and interviewing staff. You receive a written report.

    Week 1
  3. System design and build

    We develop the documentation with your team, in working sessions rather than by email attachment.

    Weeks 2–6
  4. Implementation

    The system runs live and records accumulate. This phase cannot be shortcut: auditors need to see evidence of operation.

    Weeks 4–10
  5. Internal audit and management review

    Both mandatory before certification. We conduct or facilitate them.

    Weeks 8–12
  6. Stage 1 audit

    The certification body checks readiness and documentation. Findings are usually documentary.

    Week 10–14
  7. Stage 2 audit

    Full assessment of implementation and effectiveness. We attend with you.

    2–6 weeks after Stage 1
  8. Certification and surveillance

    Certificate issued for three years, with surveillance audits in years one and two and recertification in year three.

    3-year cycle
One thing we will not promise

No consultant can guarantee a certificate. The certification body makes that decision independently, and any consultant who guarantees the outcome is either misleading you or steering you toward an unaccredited body. What we do commit to is that you will be genuinely ready, and that we will be in the room when the auditor arrives.

Timeline and investment

Timelines depend far more on your responsiveness than on our capacity. A focused SME with an engaged management team can certify in eight to ten weeks. A multi-site contractor with a complex scope should plan for four to six months.

Organisation sizeTypical durationConsultancy effortMain variable
Under 25 staff, single site8–10 weeksLightSpeed of document approval
25–100 staff, single site10–16 weeksModerateNumber of core processes in scope
100+ staff or multi-site16–24 weeksSubstantialSite coverage and sampling requirements
Adding ISO 9001 to an existing IMS4–8 weeksLightMaturity of the existing system

Your total cost has two separate components, and it is worth understanding them independently:

  • Certification body fees: paid directly to the certification body, priced on employee headcount, number of sites and risk category. These are not paid to us and we take no commission on them.
  • Consultancy fees: paid to Jumbat, quoted as a fixed fee against a defined scope after the gap analysis, so there are no hourly surprises.

We publish a full cost breakdown, including the surcharges most consultants leave out, in our guide to what ISO certification actually costs in the UAE.

Where companies go wrong

Six failures account for most of the delayed certificates we are called in to rescue. Open any one to see how it plays out.

Auditors read a great deal of documentation and recognise generic material instantly. A manual describing a business that is not yours will not survive Stage 2, and the money spent on it is gone.

If the documented process differs from the real one, you have manufactured a non-conformity and handed the auditor the evidence. Either the procedure changes or the practice does, before the audit, not during it.

A rushed internal audit that finds nothing is itself a finding. Certification bodies compare your internal audit results against what they find; a clean internal report followed by a long non-conformity list signals the audit was not real.

Clause 9.3 lists its required inputs and outputs explicitly. Minutes recording only that “quality was discussed” are among the most common major findings, and one of the easiest to avoid: build the agenda from the clause.

An unaccredited certificate costs a fraction and looks identical on the wall. It will be rejected the moment a serious client or tender portal checks, and you will pay again for a real one. Verify accreditation before paying anything.

Clients read scope statements. A certificate that excludes your main activity saves audit days and impresses nobody, and may fail the pre-qualification check it was bought for.

Questions clients ask first

For a single-site SME, eight to sixteen weeks is realistic from gap analysis to Stage 2. The limiting factor is almost always the implementation period: the certification body needs to see the system operating and generating records, which cannot be compressed below roughly four to six weeks.

No, and you should be cautious of anyone who does. The certification body decides independently. What we guarantee is preparation: a complete system, a full internal audit cycle, a documented management review, and our presence at the audit to respond to findings.

Not usually. ISO 9001:2015 removed the mandatory management representative role. Most SMEs assign QMS ownership to an existing manager and use retained support for audits and reviews. We train your nominated person to run the system independently.

Considerably. All modern ISO management system standards share the same high-level structure, so context, leadership, planning, support, performance evaluation and improvement are largely common. Adding a second standard to a mature system typically takes four to eight weeks. See integrated management systems.

Yes. Attendance at Stage 1 and Stage 2 is included. We do not answer on your behalf (auditors need to hear from your people) but we manage the process, clarify findings and draft responses to any non-conformities raised.

The certificate runs three years, with surveillance audits in years one and two. Systems decay quietly between audits, so most clients retain us for an annual internal audit and management review. That is the cheapest insurance against a surveillance finding.

Let’s make your next audit a non-event.

Book a free 30-minute consultation. We will tell you honestly whether you need a consultant, and if you do, exactly what it will take.

Book a free consultation WhatsApp us