Earlier quoted context omitted.
Do companies with ISO certifications ever get reviewed after-the-fact? Or do you just have to check the right checkboxes during an initial review process?
I'm pretty sure ISO 9001 companies are audited every 4 years at their own expense. Basically an auditor comes and quizzes you on your own processes. You must show that you have processes which meet ISO criteria, and that you religiously follow those processes. Basically you have a lot of freedom to develop your business, just be sure you adhere to whatever you put into writing.
But this didn't entirely get the software division off the hook. We still had to be able to show an auditor that we knew our processes were excluded. So there was a special folder containing just one functional page besides the meta-bumf to support it, and it read (in effect) "THE ACTIVITIES OF THE SOFTWARE DEPT ARE EXCLUDED FROM ISO9002 PROCESSES". And we were all trained to be able to produce it upon demand.
We passed the audit. Our letterhead paper gained the magical ISO9002 seal of approval. The administrator who had championed the long and expensive business sprung from its success to a much larger company. In her absence the process documentation for the rest of the company quietly withered and when the follow-up audit came due we quietly neglected to apply for it. The letterhead paper was reprinted with a snazzier logo and no seal of approval. We got back to work, quietly apprehending the next big thing.