Basically an auditor comes and quizzes you on your own processes. You must show that you have processes which meet ISO criteria, and that you religiously follow those processes.
Basically you have a lot of freedom to develop your business, just be sure you adhere to whatever you put into writing.
But this didn't entirely get the software division off the hook. We still had to be able to show an auditor that we knew our processes were excluded. So there was a special folder containing just one functional page besides the meta-bumf to support it, and it read (in effect) "THE ACTIVITIES OF THE SOFTWARE DEPT ARE EXCLUDED FROM ISO9002 PROCESSES". And we were all trained to be able to produce it upon demand.
We passed the audit. Our letterhead paper gained the magical ISO9002 seal of approval. The administrator who had championed the long and expensive business sprung from its success to a much larger company. In her absence the process documentation for the rest of the company quietly withered and when the follow-up audit came due we quietly neglected to apply for it. The letterhead paper was reprinted with a snazzier logo and no seal of approval. We got back to work, quietly apprehending the next big thing.
I've seen companies pack trunks of cars with unclaimed scrap. Buy a 55' trailer with cash, fill it with stuff, then claim it belongs to the neighbors. Load material onto 30' racks and send the forklift operators home.
It's almost better that your company committed to ISO to kinda get organized and then let it slide afterwards. I'd almost say it's worth it in a medium sized company every 10 years just to stay accountable and organized.
Eh, kind of? I currently work for one and they haven't been audited in over a decade. The history goes: once upon a time, they were seeking certification because $potential_buyer asked about it. They failed the first audit quite miserably, and the next. By the third time, they squeezed by and were certified. The auditors came back 2 times in the next 2 years to make sure they were still compliant, and by the third year the auditors just asked if their processes had changed (without bothering to scrutinize everything again). They had not, and the auditors have not reached out ever since. The company is still certified. I think in theory they've "checked" since then but no one at the company can recall them actually showing up/auditing.