Back to ISO 17100

ISO 17100 audit: what auditors look for in TSP evidence

Photo: Unsplash

An ISO 17100 audit is where documented intentions meet project reality. Certification bodies do not grade your writing style—they sample whether your translation service provider (TSP) system consistently assigns competent people, captures requirements, performs mandatory second-person revision, and improves when something goes wrong.

ISO 17100:2015 focuses on translation services. Interpreting and raw MT+PE workflows are typically outside the standard’s intended model. Auditors know this, and scope mismatches show up quickly when marketing claims and sampled work diverge.

This guide explains what auditors commonly look for across competence files, project records, agreements, complaints/CAPA, and technical resources—so you can prepare evidence ownership without inventing binders nobody uses.

This guide covers:

  • Differences between internal, Stage 1, Stage 2, and surveillance audits
  • The evidence packs auditors most often request
  • A decision table for “ready / not ready” signals
  • How to stay calm under sampling without rewriting your whole TMS overnight

When paperwork piles up before audit week

GIF via GIPHY

Related guides:


Key takeaways

  • Auditors sample systems through projects—expect end-to-end traces, not policy readings alone.
  • Competence files must match assignees on sampled jobs, including freelancers.
  • Translation + second-person revision must be obvious in records; self-revision is a frequent finding.
  • Agreements, complaints/CAPA, and technical resources round out the typical Stage 2 sample set.
  • Internal audits that mimic CB sampling reduce Stage 2 surprises more than last-minute PDF dumps.

Types of ISO 17100 audits

Audit type Purpose What “good” looks like
Internal audit Find gaps before the CB Findings owned, timed, closed with evidence
Stage 1 Documentation / readiness review Controlled docs, clear scope, known gaps
Stage 2 Implementation sampling Live projects prove the SOPs
Surveillance Ongoing certificate maintenance No major process drift since last visit
Recertification Renew the cycle System still operates at scale

If you are early in the journey, pair this article with How to get ISO 17100 certified: step-by-step. For ongoing cadence, see Maintaining ISO 17100 compliance: ongoing best practices.


What auditors typically sample

Exact sampling depends on the certification body, your scope, and risk signals. Still, most ISO 17100 audits orbit the same evidence clusters.

Competence files

Auditors commonly pull names from project records and ask for those people’s files—not a random “best” freelancer.

Expect questions around:

  • Which qualification path applies (translation degree; other degree + ~2 years’ experience; or ~5 years full-time experience)
  • Language pairs and domains authorized
  • How reviser competence is demonstrated
  • Confidentiality agreements and onboarding
  • How you refresh or reassess competence over time

Missing files for subcontractors is a classic finding. Details: ISO 17100 translator and reviser competence requirements.

Project records proving translation and revision

This is the heart of many Stage 2 audits. For sampled projects, be ready to show:

  • Client requirements / brief
  • Assigned translator and reviser (different people)
  • Timestamps or workflow states proving revision occurred
  • Queries and client responses
  • Delivery / acceptance notes

If your TMS only shows “linguist,” fix role labeling before the audit. Mandatory second-person revision should not require a forensic investigation to prove.

Agreements and client requirements

Auditors typically want to see that work starts from agreed requirements—not informal chat alone. Samples may include SOWs, order confirmations, NDAs, style/terminology instructions, and acceptance criteria.

Where requirements changed mid-project, show how changes were controlled.

Complaints, feedback, and CAPA

A mature system expects friction. Auditors often ask:

  • How clients complain or give feedback
  • Who triages severity
  • What corrective/preventive actions look like
  • Whether similar issues reappear

Empty complaint logs can raise as many questions as chaotic ones. Show a believable flow with at least a few closed examples if volume exists.

Technical resources and confidentiality

ISO 17100 expects adequate resources for the services offered. Auditors may sample:

  • CAT/TMS and terminology tools in use
  • Access control for client materials
  • Secure transfer and storage practices
  • How freelancers access and return files

Security here supports confidentiality commitments—SecureSlate’s natural angle—without pretending a GRC tool performs linguistic revision.

For the broader requirements map, see ISO 17100 requirements: a complete breakdown. If your organization also holds a general QMS certificate, be ready to explain what is translation-specific versus shared—see ISO 17100 vs ISO 9001: what's the difference?.

How interviews usually go

Auditors commonly interview project managers, vendor managers, and quality owners. Expect scenario questions such as:

  • “Show me the last rush job—who translated and who revised?”
  • “This freelancer appears on three sampled projects; open their competence file.”
  • “A client complained about terminology—walk me through CAPA.”
  • “How do remote linguists receive and return confidential files?”

Brief interviewees on where evidence lives. Coached scripts that contradict the TMS create more findings than honest “here is the gap we already logged.”


Audit readiness decision table

Use this table in the week before Stage 2 (or surveillance).

Question Ready signal Not ready signal Owner
Can we retrieve any recent project end-to-end in minutes? Packaged sample set Hunting across email/Slack Project Mgmt
Do translator and reviser differ on those projects? Clear dual assignment Same login “revised” own work Project Mgmt
Do competence files exist for every sampled name? Complete files Gaps for freelancers Vendor Mgmt
Are agreements aligned to what was delivered? Specs + change notes Verbal-only scope Sales Ops
Is CAPA more than a spreadsheet tab? Closed actions with dates Open aging items ignored Quality
Can we explain confidentiality controls? Access reviews + policy “We use Dropbox” with no rules Security / IT

If three or more rows show “Not ready,” delay the CB date. Rushing usually costs more than rescheduling.


How to prepare without over-documenting

  1. Pick sample projects first, then assemble the related competence files and agreements.
  2. Run a mock audit using the decision table above—ideally with someone who did not manage the projects.
  3. Fix systemic issues (role fields, file templates) rather than editing one pretty sample.
  4. Align marketing scope with the certificate scope statement.
  5. Brief interviewees on where evidence lives; do not script answers that contradict the TMS.

Cross-check readiness with the ISO 17100 certification checklist. If cost pressure is driving a rushed audit date, read How much does ISO 17100 certification cost? so you budget remediation time, not only CB fees.

Background context: What is ISO 17100:2015? Everything you need to know and Who needs ISO 17100 certification?.


Streamline audit evidence with SecureSlate

Audit week stress usually comes from scattered ownership. SecureSlate helps TSPs keep the control and evidence layer organized so quality leads can answer “where is that?” quickly.

With SecureSlate you can typically:

  • Assign evidence owners for competence reviews, CAPA, and management reviews
  • Centralize policies for confidentiality, access, and vendor onboarding
  • Track recurring audit prep tasks so surveillance is not a fire drill
  • Link artifacts to checklist items for Stage 1 and Stage 2 packs
  • Keep security-adjacent controls visible alongside quality workflows

SecureSlate does not replace your CB or linguistic QA—it reduces evidence chaos around them.

Get started for free


FAQ: ISO 17100 audit

What is the difference between Stage 1 and Stage 2?

Stage 1 commonly reviews documentation and readiness. Stage 2 commonly samples whether processes operate—especially competence and project revision evidence.

Will auditors read our translations for quality?

They primarily assess the system (competence, process, revision, improvement). Linguistic preference is not the main scoring model, though obvious process failures that harm quality may appear as findings.

How many projects get sampled?

It depends on scope, size, and CB methodology. Prepare several complete packs rather than one showcase project.

Can we refuse to show client content?

Discuss confidentiality with your CB in advance. Redaction strategies and NDAs are common; total refusal usually blocks the audit.

Do freelancers get audited too?

Indirectly—auditors sample their competence files and project roles. Your TSP remains responsible for control of outsourced work in scope.

How do we prepare for surveillance differently?

Focus on changes since last audit: new linguists, process tweaks, open CAPA, and whether revision discipline held under volume pressure.


Disclaimer (legal note)

SecureSlate is not a law firm, and this article does not constitute legal advice, certification advice, or a guarantee of audit outcomes. Certification body practices vary. Confirm requirements against ISO 17100:2015 and with your auditor or qualified counsel. Language here uses “typically/commonly” because sampling plans differ by CB and scope.

Need compliance without the complexity?

SecureSlate automates ISO 27001, SOC 2, GDPR, HIPAA, and more. Built for growing teams. See it in action.

No credit card required

Filed under:

Author: SecureSlate Team

4.7(172 reviews)

Keep reading

Jul 23, 2026 · ISO 17100

How much does ISO 17100 certification cost? A practical breakdown

Jul 23, 2026 · ISO 17100

How to get ISO 17100 certified: a step-by-step guide for TSPs

Jul 23, 2026 · ISO 17100

ISO 17100 certification checklist for translation service providers

View more posts
Jamie
Virtual Agent

Hi! I'm Jamie. Curious about your current compliance challenges and how automation might help your team?