Every initial ISO certification is completed in two audits. Stage 1 checks that you are ready. Stage 2 checks that your management system works in practice.
At a glance
| Stage 1 audit | Stage 2 audit | |
|---|---|---|
| Purpose | Confirm readiness and plan Stage 2 | Evaluate implementation and effectiveness |
| Focus | Documented information, scope, site conditions | People, activities and records across the whole scope |
| Location | Often partly or fully on site | On site |
| Output | Stage 1 report with areas of concern | Audit report with any nonconformities |
| Next | Resolve concerns, then Stage 2 | Close nonconformities, then the decision |
What the auditor checks at Stage 1
- Your scope and whether it matches your activities and sites.
- The documented information the standard requires.
- Key planning elements such as risk assessments and objectives.
- At least one internal audit and management review.
- Site conditions, processes and relevant legal requirements.
Stage 1 records areas of concern: issues that could become nonconformities if not addressed before Stage 2.
What the auditor checks at Stage 2
- An interview with top management.
- Interviews with process owners and the people doing the work.
- Observation of activities on site.
- Sampling of records to confirm the system works over time.
How to prepare
Before Stage 1: finalize your scope statement, approve required documents, and complete an internal audit and management review.
Before Stage 2: close every Stage 1 concern, brief managers and staff, make records easy to retrieve, and confirm logistics.
What happens after Stage 2
Major nonconformities are corrected and verified; minor ones need an accepted action plan. An independent reviewer then makes the certification decision. See the full certification process or request a quote.