PJR

Audit Time & Quotation Engine

IAF MD5:2023 · MD11:2023 · MD4:2022 · ISO/IEC 17021-1:2015

Audit Templates

Save the current scope settings, standards, personnel and pricing as a reusable template — load it any time to skip manual entry.

No templates yet — save the current scope above to reuse it later.

Scope classification

Type what the organisation actually does. The EA code is selected automatically and can be overridden.

Organisation being quoted — makes the quote easy to find in Saved Calculations

e.g. 'we powder coat and anodise metal parts' or 'cloud payroll software'

Populated from the EA code; select the closest division.

Standards in scope

Effective number of personnel

IAF MD5:2023 cl. 4. Classify each role, then group repetitive roles that genuinely perform the same activity.

RoleHeadcountClassificationActivity group

Rounding down requires a recorded justification.

Tick only where shift processes are identical.

MethodEffective personnelInitial daysDefensibilityAccreditation risk
per role2613.5StrongLow
grouped2410.5StrongLow
pooled1810.5WeakHigh

Square root applied to 4 homogeneous activity group(s). MD5 cl. 4.4 permits grouping where personnel perform the same or similar repetitive activity under the same processes, controls and competence requirements. Grouping rationale must be recorded on the application review form.

Step 2 — Adjustments

Factors that affect audit time calculation.

Stage 2 and recertification add the certification fee.

Transfer or prior accredited certificate.

Additive increase for interpretation requirement.

ANAB: 0.5 days offsite per phase (carved if multi-day, added if single).

Integrated audit settings — IAF MD11:2023

Only used when two or more certifiable standards are selected.

0% = entirely separate; 100% = fully integrated.

Between 1 and 3.

IAF MD11:2023 combined audit reduction of 16% applied. Basis: 100% level of integration (common policy, objectives, processes, documented information, internal audit and management review) and an average of 2 standard(s) per auditor. MD11 cl. 5.1.3 caps the combined reduction at 20% of the sum of individual audit times. Reduction is not applied to non-certifiable guidance services.

ISO/IEC 27001 (ISMS) — scope confirmation

Reductions follow ISO/IEC 27006-1 guidance.

Risk level per standard

Justification is mandatory for anything other than medium.

Individual standard discounts

Applied on top of the automatic reductions. The MD5 30% net cap still applies. A quote cannot issue while a justification is blank or 'N/A'.

ISO 9001 (QMS)
ISO 14001 (EMS)
ISO/IEC 27001 (ISMS)

Delivery mode risk assessment — IAF MD4:2022

Hybrid — 52% remote / 48% onsite

Delivery mode determined as Hybrid (52% remote / 48% onsite) following a documented risk assessment under IAF MD4:2022 cl. 5.2. Documented information, records and centrally managed controls will be sampled using ICT; observation of activities, site conditions and shop-floor interviews will be conducted on site. Remote delivery exceeds 30% of total audit time — IAF MD4 cl. 5.4 and the PJR UK ICT procedure require the risk assessment to be reviewed and approved by the Technical & Compliance Director, and the proportion of remote activity to be recorded on the audit plan and in the certification records.

  • -28 Nature of operations (EA code) — EA code not selected; conservative default applied.
  • -30 Standards requiring observation of operational control — ISO 14001 (EMS) require direct observation of activities, workplace conditions, emergency preparedness and interviews at the point of work. These elements cannot be verified remotely.
  • +10 Client ICT capability — Client confirmed capable of supporting ICT audit techniques: stable connectivity, screen sharing, and electronic access to records.

Design: Design exclusion accepted. EA - does not typically involve design responsibility. Record the justification on the application review; the certificate scope statement must not imply design capability.

Calculated quotation

Effective personnel

24

of 80 total staff

Initial (S1+S2) days

10.5

Stage 1 + Stage 2 days

10.5

Fee

£10,600

10.5 days @ £1000 + £100 cert

StandardTable daysIncreasesReductions appliedDays
ISO 9001 (QMS)3+0%−15%2
ISO 14001 (EMS)4+0%−10%3
ISO/IEC 27001 (ISMS)7+0%−10%5.5

Discount register — defensible basis for every reduction

  • ISO 9001 (QMS) · 10.0% · IAF MD5 cl. 5.3
    Risk/complexity assessed as low for ISO 9001 (QMS): stable, low-hazard, non-regulated processes with a mature control environment.
  • ISO 9001 (QMS) · 5.0% · ISO 9001 cl. 4.3 / IAF MD5 cl. 5.3 (c)
    Design and development is not applicable and is excluded from scope with a documented justification; clause 8.3 requires no audit time.
  • ISO 14001 (EMS) · 10.0% · IAF MD5 cl. 5.3
    Risk/complexity assessed as low for ISO 14001 (EMS): stable, low-hazard, non-regulated processes with a mature control environment.
  • ISO/IEC 27001 (ISMS) · 5.0% · ISO/IEC 27006-1 Annex B
    No client-operated data centre in scope; physical and environmental security (A.7) is inherited from a certified provider and verified by supplier assurance records rather than site inspection.
  • ISO/IEC 27001 (ISMS) · 5.0% · ISO/IEC 27006-1 Annex B
    Fewer than three IT platforms/operating systems in scope; technical control sampling is materially reduced.
Remote delivery — Delivery mode determined as Hybrid (52% remote / 48% onsite) following a documented risk assessment under IAF MD4:2022 cl. 5.2. Documented information, records and centrally managed controls will be sampled using ICT; observation of activities, site conditions and shop-floor interviews will be conducted on site. Remote delivery exceeds 30% of total audit time — IAF MD4 cl. 5.4 and the PJR UK ICT procedure require the risk assessment to be reviewed and approved by the Technical & Compliance Director, and the proportion of remote activity to be recorded on the audit plan and in the certification records.

Quote can be issued. The calculation record above satisfies ISO/IEC 17021-1 cl. 9.1.4.2.