What is a registrar?
A registrar, or certification body, is the independent accredited organization that audits your quality system and issues your ISO 9001 certificate. It cannot consult on the system it certifies.
If you are asking because you expected your registrar to help you close its own findings, start with Can't our registrar just tell us what to fix?
What it is
A registrar is the company that audits your quality management system against ISO 9001 and decides whether you get the certificate. The standard's own vocabulary calls it a certification body. In American manufacturing, people say registrar, and the two words mean the same organization.
The names you will meet in a mid-market plant are the large international bodies (BSI, DNV, SGS, Bureau Veritas, TUV) and a long tail of smaller accredited bodies that compete hard on price and scheduling. Any of them can issue a certificate that an OEM will accept, provided the body itself is accredited.
A registrar does three things across a three-year cycle. It runs your initial audit in two stages. It returns for a shorter surveillance audit in each of the next two years. In year three it recertifies you, and the cycle starts over.
When you will hear it
Most often, in a customer's supplier requirements. Flowdown language rarely says "get certified" in the abstract. It says your quality system must conform to ISO 9001 as documented by a third-party registrar, and it reserves the right to ask for a copy of your certificate. Northrop Grumman's supplier quality document uses close to exactly that wording.
You will also hear it when the invoice arrives. Registrar fees are separate from anything you pay a consultant, and they recur: an initial audit, then a surveillance fee each year, then recertification. A consultant who quotes you a single all-in number without naming the registrar's fees separately is describing a cost you do not have.
What the auditor expects to see
This term is about the auditor, so the expectation runs the other way: here is what you should expect from them.
A defensible finding. Every nonconformity should name the requirement, the objective evidence the auditor saw, and the gap between them. A finding that says only "management review inadequate" is not usable and you can ask for it to be written properly.
A conflict-of-interest position they will show you. Registrars publish these because their own accreditation depends on them. ISO/IEC 17021-1 clause 5.2.5 bars a certification body from providing management system consultancy, and 5.2.6 bars it from running your internal audits.
Audit time that matches the rules. Audit days are set by the IAF MD5 tables from your effective headcount, not negotiated down because the schedule is tight. A body offering to certify you in a fraction of the calculated time is telling you something about the certificate you would receive.
Common mistakes
Expecting the registrar to fix what it finds. It cannot, and the reason is the point of the certificate. That confusion is common enough that it has its own page.
Treating all certificates as equal. An unaccredited certificate costs less and is worth less. Supplier quality teams at the primes check accreditation, and finding out at that stage is expensive.
Choosing on price alone. Price is the most-cited reason companies switch registrars, and it is a fair reason. Auditor quality and scheduling reliability are the other two, and they matter more when your customer audit calendar is already tight.
Forgetting the clock after a major finding. A major nonconformity has to close inside the body's window, typically 60 to 90 days. That window belongs to the registrar, not to your production schedule.
FAQ
Is a registrar the same as an accreditation body?
No. The registrar audits you. The accreditation body audits the registrar. In the United States that is usually ANAB, and its oversight is what gives your certificate standing with a customer.
Can we change registrars mid-cycle?
Yes, and companies do, most often over price. The new body will review your existing certification history, and switching close to a surveillance date is harder than switching just after one.
Does the registrar tell us which auditor is coming?
Yes, in advance, along with the audit plan and the clauses in scope. If the assigned auditor lacks experience in your sector you may raise it before the visit.
How much of the cost is the registrar?
At a single site of around 100 people, published and derived figures put the initial audit near $9,500 to $11,200 plus travel, surveillance around $3,100 to $3,700 a year, and recertification around $6,300 to $7,500. Those are the registrar's own fees and sit on top of any prep work.
Tell us which audit is on your calendar.
A gap assessment is a flat-fee, on-site project led by a certified ISO 9001 lead auditor. Three founding-client spots are open for the quality practice.
We prepare you for certification. We never issue it. Your registrar's independence is the point.