← Back to Blog
Platform

Why Small CBs (1–3 Standards) Need Real Software, Not Spreadsheets

2026-06-30 · 8 min read

The "We're Too Small" Misconception

When a small certification body with one or two standards and a handful of auditors evaluates software, the conversation often goes the same way: "We only manage 80 clients. We have four auditors. We can handle it with spreadsheets and email. We don't need a platform."

This reasoning seems logical until you consider what "handling it" actually requires. A CB with 80 clients and one standard still needs to:

  • Maintain signed audit programmes for every client
  • Track surveillance and recertification cycles with correct timing
  • Generate and sign audit plans for every audit
  • Collect signed impartiality declarations from every team member for every engagement
  • Manage nonconformities through a documented lifecycle
  • Route certification decisions through qualified committee members in the correct signing order
  • Maintain a complete, timestamped audit trail of every action
  • Track auditor qualifications and scope coverage
  • Produce consistent, standard-compliant audit reports

These are not optional extras for large CBs. They are accreditation requirements that apply equally to a CB with 80 clients and a CB with 800. The AB assessor who reviews a small CB's files applies the same criteria as they would to a multinational operation.

Less Redundancy Means Higher Risk

In a large CB, if one planner makes a scheduling error, another planner or a supervisor is likely to catch it. If an auditor submits a thin report, the technical reviewer flags it. Multiple layers of oversight compensate for individual mistakes.

In a small CB, there are no layers. The planner is often also the technical reviewer. The certification manager might also serve on the committee. One person's mistake goes uncaught because there is nobody else to catch it.

Consider "Balkan Quality Assessors," a CB accredited for ISO 9001 with 65 active clients and a team of five: a director (who is also the certification manager), two full-time auditors, one part-time auditor, and an administrator.

The administrator manages scheduling, document generation, and client communication using a combination of Excel spreadsheets and a shared Google Drive. The system works, mostly, until the administrator takes two weeks of vacation. The director fills in but is not familiar with the spreadsheet formulas. A surveillance audit is scheduled outside the permitted window. An impartiality declaration is not collected. A client's NC response is filed in the wrong folder.

When the AB assessor arrives for the annual surveillance assessment, these small errors surface. Each one is a finding. Together, they suggest a systemic weakness in the CB's operational controls.

Spreadsheets Do Not Enforce Rules

A spreadsheet can calculate audit time. It can list auditor qualifications. It can track surveillance dates. But it cannot enforce rules.

A spreadsheet will not prevent a planner from scheduling an audit without collecting signed impartiality declarations. It will not block a certification decision when the committee has not reviewed the file. It will not flag that an auditor is assigned to a client in an EA code they are not qualified for.

These enforcement gaps exist in every manual system, but they are more dangerous in small CBs precisely because there is less human redundancy to compensate.

The Specific Risks for Small CBs

Surveillance cycle lapses. With 65 clients and a complex schedule of initial audits, first surveillance, second surveillance, and recertification, the timing must be precise. ISO/IEC 17021-1:2015 specifies that surveillance audits must be conducted within defined windows. Miss a window, and the certification may need to be suspended. In a spreadsheet, tracking 65 overlapping cycles with different start dates is a formula away from failure.

In Certiva, surveillance cycles are tracked automatically. The system alerts the planner when a surveillance window is approaching and flags overdue audits. Certifications that exceed their window are flagged for suspension review.

Incomplete signing chains. A small CB might have the certification manager sign the decision form first because they are available, and then send it to the committee. The signing order is wrong, and the decision is procedurally invalid. In a manual system, nobody stops this. In Certiva, the CM cannot sign until the committee has signed.

Audit trail gaps. When the audit trail lives in email threads, shared drives, and spreadsheets, reconstructing the timeline for a specific audit file requires searching multiple systems. An AB assessor asks, "When was the audit plan sent to the client?" The answer requires finding the email. "When did the client sign?" The answer requires finding the signed PDF in the drive. "When was the NC raised?" The answer requires checking the spreadsheet.

In Certiva, every action is logged in a single, timestamped event log within the audit set. The assessor can see the complete timeline for any audit file in one view.

Committee qualification gaps. Even a small CB must ensure that committee members are qualified for the scope they review. If the CB has two committee members and one is only qualified for manufacturing EA codes, that member should not be reviewing a decision for a services client. In a manual system, this check depends on someone remembering. In Certiva, committee assignment includes qualification validation.

The Cost Argument Is Backwards

Small CBs often view software as an overhead cost. "We can't afford a platform." But the real cost is the operational risk of running without one.

One AB finding can trigger corrective action that consumes weeks of staff time. A surveillance lapse requires client notification, certificate suspension, and potential reputational damage. A procedurally invalid certification decision can cascade into a review of all affected certificates.

For a small CB, these events are not minor disruptions. They are existential risks. A major nonconformity during an AB assessment can threaten the accreditation itself, and for a CB with one or two standards, losing accreditation means losing the business.

What "Real Software" Means for a Small CB

Certiva does not require a large team or a complex implementation. The platform is designed to work for CBs of any size because the workflow is the same regardless of scale. The 14-phase audit pipeline, the signing chains, the NC lifecycle, the committee management, the scope coverage validation, these features apply to the first client just as they apply to the five hundredth.

A small CB using Certiva gets the same operational structure and enforcement as a large one, without needing the staff to manually replicate those controls. The system provides the redundancy that the team cannot.

Small CBs face the same accreditation requirements with fewer people to get them right.

Certiva provides the structure and enforcement that spreadsheets cannot. See how at getcertiva.com.