Photo: Unsplash
An ISO 17100 audit is where documented intentions meet project reality. Certification bodies do not grade your writing style—they sample whether your translation service provider (TSP) system consistently assigns competent people, captures requirements, performs mandatory second-person revision, and improves when something goes wrong.
ISO 17100:2015 focuses on translation services. Interpreting and raw MT+PE workflows are typically outside the standard’s intended model. Auditors know this, and scope mismatches show up quickly when marketing claims and sampled work diverge.
This guide explains what auditors commonly look for across competence files, project records, agreements, complaints/CAPA, and technical resources—so you can prepare evidence ownership without inventing binders nobody uses.
This guide covers:
- Differences between internal, Stage 1, Stage 2, and surveillance audits
- The evidence packs auditors most often request
- A decision table for “ready / not ready” signals
- How to stay calm under sampling without rewriting your whole TMS overnight

GIF via GIPHY
Related guides:
- ISO 17100 certification checklist
- How to get ISO 17100 certified: step-by-step
- ISO 17100 requirements: a complete breakdown
- ISO 17100 translator and reviser competence requirements
- Maintaining ISO 17100 compliance: ongoing best practices
- Explore the ISO 17100 collection
Key takeaways
- Auditors sample systems through projects—expect end-to-end traces, not policy readings alone.
- Competence files must match assignees on sampled jobs, including freelancers.
- Translation + second-person revision must be obvious in records; self-revision is a frequent finding.
- Agreements, complaints/CAPA, and technical resources round out the typical Stage 2 sample set.
- Internal audits that mimic CB sampling reduce Stage 2 surprises more than last-minute PDF dumps.
Types of ISO 17100 audits
| Audit type | Purpose | What “good” looks like |
|---|---|---|
| Internal audit | Find gaps before the CB | Findings owned, timed, closed with evidence |
| Stage 1 | Documentation / readiness review | Controlled docs, clear scope, known gaps |
| Stage 2 | Implementation sampling | Live projects prove the SOPs |
| Surveillance | Ongoing certificate maintenance | No major process drift since last visit |
| Recertification | Renew the cycle | System still operates at scale |
If you are early in the journey, pair this article with How to get ISO 17100 certified: step-by-step. For ongoing cadence, see Maintaining ISO 17100 compliance: ongoing best practices.
What auditors typically sample
Exact sampling depends on the certification body, your scope, and risk signals. Still, most ISO 17100 audits orbit the same evidence clusters.
Competence files
Auditors commonly pull names from project records and ask for those people’s files—not a random “best” freelancer.
Expect questions around:
- Which qualification path applies (translation degree; other degree + ~2 years’ experience; or ~5 years full-time experience)
- Language pairs and domains authorized
- How reviser competence is demonstrated
- Confidentiality agreements and onboarding
- How you refresh or reassess competence over time
Missing files for subcontractors is a classic finding. Details: ISO 17100 translator and reviser competence requirements.
Project records proving translation and revision
This is the heart of many Stage 2 audits. For sampled projects, be ready to show:
- Client requirements / brief
- Assigned translator and reviser (different people)
- Timestamps or workflow states proving revision occurred
- Queries and client responses
- Delivery / acceptance notes
If your TMS only shows “linguist,” fix role labeling before the audit. Mandatory second-person revision should not require a forensic investigation to prove.
Agreements and client requirements
Auditors typically want to see that work starts from agreed requirements—not informal chat alone. Samples may include SOWs, order confirmations, NDAs, style/terminology instructions, and acceptance criteria.
Where requirements changed mid-project, show how changes were controlled.
Complaints, feedback, and CAPA
A mature system expects friction. Auditors often ask:
- How clients complain or give feedback
- Who triages severity
- What corrective/preventive actions look like
- Whether similar issues reappear
Empty complaint logs can raise as many questions as chaotic ones. Show a believable flow with at least a few closed examples if volume exists.
Technical resources and confidentiality
ISO 17100 expects adequate resources for the services offered. Auditors may sample:
- CAT/TMS and terminology tools in use
- Access control for client materials
- Secure transfer and storage practices
- How freelancers access and return files
Security here supports confidentiality commitments—SecureSlate’s natural angle—without pretending a GRC tool performs linguistic revision.
For the broader requirements map, see ISO 17100 requirements: a complete breakdown. If your organization also holds a general QMS certificate, be ready to explain what is translation-specific versus shared—see ISO 17100 vs ISO 9001: what's the difference?.
How interviews usually go
Auditors commonly interview project managers, vendor managers, and quality owners. Expect scenario questions such as:
- “Show me the last rush job—who translated and who revised?”
- “This freelancer appears on three sampled projects; open their competence file.”
- “A client complained about terminology—walk me through CAPA.”
- “How do remote linguists receive and return confidential files?”
Brief interviewees on where evidence lives. Coached scripts that contradict the TMS create more findings than honest “here is the gap we already logged.”
Audit readiness decision table
Use this table in the week before Stage 2 (or surveillance).
| Question | Ready signal | Not ready signal | Owner |
|---|---|---|---|
| Can we retrieve any recent project end-to-end in minutes? | Packaged sample set | Hunting across email/Slack | Project Mgmt |
| Do translator and reviser differ on those projects? | Clear dual assignment | Same login “revised” own work | Project Mgmt |
| Do competence files exist for every sampled name? | Complete files | Gaps for freelancers | Vendor Mgmt |
| Are agreements aligned to what was delivered? | Specs + change notes | Verbal-only scope | Sales Ops |
| Is CAPA more than a spreadsheet tab? | Closed actions with dates | Open aging items ignored | Quality |
| Can we explain confidentiality controls? | Access reviews + policy | “We use Dropbox” with no rules | Security / IT |
If three or more rows show “Not ready,” delay the CB date. Rushing usually costs more than rescheduling.
How to prepare without over-documenting
- Pick sample projects first, then assemble the related competence files and agreements.
- Run a mock audit using the decision table above—ideally with someone who did not manage the projects.
- Fix systemic issues (role fields, file templates) rather than editing one pretty sample.
- Align marketing scope with the certificate scope statement.
- Brief interviewees on where evidence lives; do not script answers that contradict the TMS.
Cross-check readiness with the ISO 17100 certification checklist. If cost pressure is driving a rushed audit date, read How much does ISO 17100 certification cost? so you budget remediation time, not only CB fees.
Background context: What is ISO 17100:2015? Everything you need to know and Who needs ISO 17100 certification?.
Streamline audit evidence with SecureSlate
Audit week stress usually comes from scattered ownership. SecureSlate helps TSPs keep the control and evidence layer organized so quality leads can answer “where is that?” quickly.
With SecureSlate you can typically:
- Assign evidence owners for competence reviews, CAPA, and management reviews
- Centralize policies for confidentiality, access, and vendor onboarding
- Track recurring audit prep tasks so surveillance is not a fire drill
- Link artifacts to checklist items for Stage 1 and Stage 2 packs
- Keep security-adjacent controls visible alongside quality workflows
SecureSlate does not replace your CB or linguistic QA—it reduces evidence chaos around them.
FAQ: ISO 17100 audit
What is the difference between Stage 1 and Stage 2?
Stage 1 commonly reviews documentation and readiness. Stage 2 commonly samples whether processes operate—especially competence and project revision evidence.
Will auditors read our translations for quality?
They primarily assess the system (competence, process, revision, improvement). Linguistic preference is not the main scoring model, though obvious process failures that harm quality may appear as findings.
How many projects get sampled?
It depends on scope, size, and CB methodology. Prepare several complete packs rather than one showcase project.
Can we refuse to show client content?
Discuss confidentiality with your CB in advance. Redaction strategies and NDAs are common; total refusal usually blocks the audit.
Do freelancers get audited too?
Indirectly—auditors sample their competence files and project roles. Your TSP remains responsible for control of outsourced work in scope.
How do we prepare for surveillance differently?
Focus on changes since last audit: new linguists, process tweaks, open CAPA, and whether revision discipline held under volume pressure.
Disclaimer (legal note)
SecureSlate is not a law firm, and this article does not constitute legal advice, certification advice, or a guarantee of audit outcomes. Certification body practices vary. Confirm requirements against ISO 17100:2015 and with your auditor or qualified counsel. Language here uses “typically/commonly” because sampling plans differ by CB and scope.
Need compliance without the complexity?
SecureSlate automates ISO 27001, SOC 2, GDPR, HIPAA, and more. Built for growing teams. See it in action.
No credit card required
