ISO 29993 assessment: how the audit unfolds, service by service
You have read the text of the standard, aligned your services, compared quotes. What remains is the step that worries people most: the assessment day itself. What will the third party look at, in what order, and for how long? Here is the concrete course of events, as commonly practised for this type of scheme.
Who assesses, and on what basis
A useful reminder before detailing the process: the international standardisation organisation publishes the ISO 29993:2017 text but carries out no assessments itself. It is third-party conformity-assessment bodies — in France, players such as AFNOR Certification or Bureau Veritas offer this type of service — that examine your services against the text and grant, or withhold, certification.
The contract signed with that body sets the exact scope of the assessment: which services, which delivery modes (face-to-face, online, blended), which sites. That scope, negotiated at the quote stage, drives everything else — duration, sampling method, cost. An imprecise description of your activity at this stage is paid for in misunderstandings on assessment day.
The process in two stages
Practices vary from one assessment body to another, but the initial assessment most often follows two distinct stages.
A first, documentary stage — often conducted remotely — checks that your organisation is ready to be assessed on substance: the services concerned are identified, a record exists for every stage of the service cycle, and the people who will be interviewed are available. This stage avoids sending an assessor on-site to face an obviously incomplete file.
The second stage looks at the reality of the services: review of file samples, interviews with the teaching team and sometimes with learners or sponsors, and occasionally observation of a live training session. This is the stage that grounds the certification decision.
What the assessor checks, service by service
The assessment follows the service cycle the standard describes, in the order of the learner’s journey:
- Prior information: do the sales and instructional materials announce objectives, prerequisites and delivery modes that match what the file actually shows?
- Needs analysis: is there a dated record of the learner’s and the sponsor’s needs analysis, predating the design — not reconstructed afterwards?
- Design: do the objectives, methods and materials visibly flow from that analysis, or is this an off-the-shelf programme applied as-is?
- Delivery: is the facilitators’ competence demonstrable (background, experience, updated knowledge), is the training environment suitable?
- Assessment: are acquired skills measured against the stated objectives, beyond a mere hot satisfaction questionnaire?
For each stage, the assessor is looking less for an isolated document than for end-to-end consistency within a single file: what was announced, what was analysed, what was designed, what was delivered and what was assessed must all point back to the same objectives.
How the sample is chosen
The assessor does not review the whole of your activity: they select a sample of services representative of the declared scope — cross-referencing types of services, delivery modes and, where you run several sites, their geographic spread. An organisation that systematically showcased only its best files ahead of the assessment would be taking a risk: sampling exists precisely to limit that selection effect, and an experienced assessor widens the review as soon as a first file raises a doubt.
The risk sampling is designed to catch
This mechanism answers a problem documented in research on third-party certification: the gap between genuine adoption of requirements and purely symbolic adoption, aimed at obtaining the certificate without changing practice. A study by Iñaki Heras-Saizarbitoria and Olivier Boiral, published in 2015 in the International Small Business Journal, uses a sample of SMEs to show that this “façade compliance” risk is real for system certifications, and that it depends heavily on an organisation’s internal motivations, more than on customer or market pressure alone (Heras-Saizarbitoria and Boiral, 2015). Applied to ISO 29993: a training file written up neatly the day before the assessment, with no real use the rest of the year, is exactly what sampling and cross-checking documents are meant to catch.
How long it takes
There is no published reference duration, and any figure quoted without knowing your scope would be invention. Three factors mainly drive it: the range of service types covered, the number of sites or locations, and the volume of activity to sample. A single-site organisation with a narrow catalogue prepares and gets assessed faster than a multi-site network offering several delivery modes. The only way to get a reliable estimate is to ask the assessment body for one at quote stage, once your scope is precisely described.
The most frequent gaps
Some gaps recur more than others against this standard:
- a needs analysis reconstructed after the design phase, with no dated record showing it preceded the instructional choices;
- learning assessment reduced to the satisfaction questionnaire, which measures how participants felt rather than whether the stated objectives were met;
- overly optimistic prior information: duration, content or prerequisites announced that do not match what is actually delivered;
- facilitator competence asserted but untraced — nothing lets anyone verify the claims made about their experience or updated knowledge.
Unsurprisingly, these are exactly the points our guide to the service requirements already flags upstream: addressing them before the assessment costs far less than addressing them after a gap has been recorded.
After the assessment: report, decision, follow-up cycle
The assessment closes with a report documenting what was observed — the points found compliant and any gaps. A significant gap requires a root-cause analysis and a correction before certification can be granted; a minor gap generally does not block the decision but is followed up.
Once obtained, certification sits within a multi-year cycle: maintenance assessments, whose frequency and depth are set contractually with the assessment body, check that the conformity observed initially holds over time. This is a point to negotiate explicitly at quote stage, not to discover after signing.
Take action
Before setting a date with your assessment body, run a dry review on two or three representative services following the service cycle described above: information, needs analysis, design, delivery, assessment. The files that survive this exercise are exactly the ones the assessor will examine. To place ISO 29993 within your broader certification strategy, see the complete overview of the scheme — and if your priority remains access to French training funding, the Kit Certif Complet provides the documentary templates that serve both your Qualiopi process and this assessment.
Frequently asked questions
+Does an ISO 29993 audit look like an ISO 9001 audit?
Not quite. ISO 9001 assesses a management system — processes, governance, management review. ISO 29993 assesses the service itself, cycle by cycle: what the learner actually receives, from prior information to the assessment of what they learned. The assessor therefore spends more time on learner files than on a process map.
+How long does an ISO 29993 assessment take?
There is no published standard duration: it depends on the scope covered (types of services, delivery modes, number of sites), the volume of activity, and the assessment body's own method. The only reliable way to get a figure is to ask for it in the quote, once your scope has been precisely described.
+What happens if the assessor finds a gap?
As with most third-party certification schemes, a significant gap requires a root-cause analysis and a correction before certification can be granted; a minor gap or improvement opportunity generally does not block the decision but is followed up at the next assessment. The exact rules are set by each assessment body, not by the standard itself.