Why the Two Stage Process Exists
When an organisation applies for ISO certification for the first time, the certification body does not simply show up and start auditing. The process is split into two distinct stages, and each one serves a different purpose. Understanding the difference between a Stage 1 and Stage 2 audit is important whether you are preparing your organisation for certification, working as a quality manager, or training to become a lead auditor.
On this page
The two stage approach comes from ISO 17021, the standard that governs how certification bodies operate. It exists because jumping straight into a full on site audit without any prior review is inefficient and risky for both parties. The Stage 1 gives the auditor enough information to determine whether the organisation is actually ready for the Stage 2. It protects the organisation from going through a full audit only to discover that significant gaps remain.
This article walks through what happens at each stage, what auditors are looking for, how the two stages differ in scope and depth, and what happens between them. If you are preparing for a certification audit or helping your organisation get audit ready, this is the foundation you need.
What Is a Stage 1 Audit?
The Stage 1 audit is sometimes called a documentation review or a readiness review, but those terms undersell what it actually involves. It is a formal audit activity conducted by the certification body auditor, and it has specific objectives that go beyond simply reading your documents.
The Primary Purpose of Stage 1
The core purpose of a Stage 1 audit is to assess whether the organisation is ready for the Stage 2. The auditor is trying to answer one central question: has this organisation implemented a management system that is sufficiently developed and operational to warrant a full certification audit?
To answer that question, the auditor will typically review the scope of the management system, check that the organisation understands its context and the needs of interested parties, confirm that key documented information is in place, and assess whether internal audits and management reviews have been completed. These are the minimum indicators that a system is actually running, not just designed on paper.
Where Stage 1 Usually Takes Place
Stage 1 is often conducted remotely or at the organisation's premises, depending on the certification body and the complexity of the system. For straightforward single site organisations, a remote document review followed by a brief on site visit is common. For larger or more complex operations, the auditor may spend a full day on site during Stage 1.
Even when Stage 1 is conducted remotely, it is still a formal audit. The auditor records findings, raises concerns, and produces a report. It is not an informal conversation.
What the Auditor Checks at Stage 1
During Stage 1, the auditor is specifically looking at the following areas:
- Scope of the management system: Is it clearly defined? Does it reflect the actual activities, products, and services of the organisation?
- Context and interested parties: Has the organisation identified the internal and external issues relevant to its purpose, and understood the needs and expectations of relevant interested parties?
- Policy and objectives: Is there a documented policy appropriate to the standard? Are quality, environmental, or safety objectives established and measurable?
- Documented information: Are the mandatory documents and records required by the standard in place and controlled?
- Internal audit: Has at least one internal audit cycle been completed? Are the results documented?
- Management review: Has a management review been conducted? Are the outputs recorded?
- Significant aspects, risks, or hazards: Depending on the standard, has the organisation identified its significant environmental aspects, key quality risks, or OH&S hazards?
The auditor is not conducting a deep dive into operational processes at this point. They are checking whether the foundations are in place.
Stage 1 Findings and Their Consequences
At the end of Stage 1, the auditor produces a report that identifies any concerns. These concerns are typically documented as areas that need to be addressed before Stage 2 can proceed. In some cases, they are raised as nonconformities. In others, they are documented as areas requiring clarification or development.
If significant gaps are found at Stage 1, the certification body may delay the Stage 2 audit until those gaps are resolved. This is not a failure. It is the system working as intended. The Stage 1 is specifically designed to surface these issues before they become major nonconformities at Stage 2.
Exemplar Global Recognised Training ProviderRTP No. 310970What Is a Stage 2 Audit?
The Stage 2 audit is the main event. This is where the certification body auditor conducts a thorough on site assessment of the management system to determine whether it conforms to the requirements of the relevant ISO standard and whether it is being effectively implemented.
The Primary Purpose of Stage 2
Where Stage 1 asks whether the system is ready, Stage 2 asks whether the system is working. The auditor is looking for evidence that the management system is not just documented but genuinely operational and effective across the organisation's processes and functions.
This is a significant distinction. An organisation can have beautifully written procedures and a complete set of documented information, and still fail Stage 2 because the people doing the work are not following those procedures, or the system is not producing the outcomes it was designed to achieve.
How Stage 2 Is Conducted
Stage 2 is always conducted on site. The auditor, or audit team for larger organisations, will spend time across the organisation observing work being done, interviewing personnel at all levels, reviewing records, and tracing processes from inputs to outputs. This is process based auditing in practice.
The auditor will typically follow an audit plan that maps out which processes, departments, and clauses will be covered, who will be interviewed, and what records will be reviewed. The plan is shared with the organisation in advance so that the right people are available at the right times.
A Stage 2 audit for a small to medium organisation might take one to two days. Larger or more complex organisations may require three to five days or more, depending on the number of sites, the complexity of the processes, and the number of standards being audited simultaneously.
What the Auditor Checks at Stage 2
At Stage 2, the auditor goes deep. They are checking every applicable clause of the standard against actual evidence from the organisation. This includes:
- Leadership and commitment: Is top management genuinely involved in the management system, or is it delegated entirely to the quality or safety manager?
- Operational controls: Are the processes that deliver products and services controlled in the way the system says they are? Is there evidence of consistent practice?
- Competence and training: Are people doing the work competent to do it? Is there evidence of training, evaluation, and ongoing development?
- Monitoring and measurement: Is the organisation measuring what it said it would measure? Are the results being used to drive decisions?
- Nonconformity and corrective action: When things go wrong, does the organisation identify the issue, investigate the root cause, and take action to prevent recurrence?
- Continual improvement: Is there genuine evidence that the system is improving over time, not just maintaining the status quo?
The auditor is gathering objective evidence throughout. Everything they record as a finding must be supported by evidence, not opinion. If you want to understand what auditors are specifically looking for, the article on what auditors look for in an ISO 9001 quality management system goes into this in detail.
Stage 2 Findings and Their Consequences
Findings at Stage 2 are classified as major nonconformities, minor nonconformities, or observations and opportunities for improvement. The classification matters enormously.
A major nonconformity is a significant failure of the management system. It means the system either does not meet a requirement of the standard, or a requirement is so poorly implemented that it cannot achieve its intended outcome. A major nonconformity will prevent certification from being granted until it is resolved. The organisation must address the root cause and provide evidence of corrective action before the certification body can make a certification decision.
A minor nonconformity is a lapse or isolated failure that does not represent a systemic breakdown. Certification can still be granted with minor nonconformities outstanding, but the organisation must resolve them within a defined timeframe, typically before the first surveillance audit.
Observations and opportunities for improvement are not nonconformities. They are the auditor's way of flagging areas where the system could be strengthened, without raising a formal finding.
Key Differences Between Stage 1 and Stage 2
To summarise the distinctions clearly, here is how the two stages differ in practice:
- Focus: Stage 1 assesses readiness. Stage 2 assesses conformity and effectiveness.
- Depth: Stage 1 is a review of the system structure and documentation. Stage 2 is a full assessment of implementation across all processes.
- Location: Stage 1 can be remote or on site. Stage 2 is always on site.
- Duration: Stage 1 is typically shorter, often half a day to one day. Stage 2 is longer, scaled to the size and complexity of the organisation.
- Output: Stage 1 produces a readiness assessment. Stage 2 produces a certification recommendation.
- Consequence of findings: Stage 1 findings delay the Stage 2. Stage 2 findings determine whether certification is granted.
The Gap Between Stage 1 and Stage 2
There is always a gap between Stage 1 and Stage 2. How long that gap is depends on what was found at Stage 1 and how quickly the organisation can address any concerns raised.
ISO 17021 recommends that Stage 2 should be conducted within a reasonable timeframe after Stage 1, typically no more than six months. If the gap is too long, the Stage 1 findings may become outdated and the certification body may require a repeat of some Stage 1 activities before proceeding to Stage 2.
For organisations that are well prepared, the gap between Stage 1 and Stage 2 might be as short as four to eight weeks. This gives the organisation time to review the Stage 1 report, address any identified concerns, and prepare for the more intensive Stage 2 assessment.
During this gap, the organisation should not be idle. Use the time to brief your team on what to expect, ensure that internal audit and management review records are complete and accessible, confirm that corrective actions from Stage 1 concerns are documented, and make sure that the people who will be interviewed during Stage 2 understand their roles in the management system.
Common Mistakes Organisations Make at Each Stage
Mistakes at Stage 1
The most common mistake at Stage 1 is submitting documentation that has been written for the audit rather than for the organisation. Auditors see this regularly. The procedures are perfectly formatted, the policies use all the right language, but when the auditor asks a few questions, it becomes clear that no one in the organisation has actually read them.
Another common issue is conducting an internal audit too close to the Stage 1, without allowing time for corrective actions to be implemented. The internal audit is not just a box to tick. It needs to have been completed, findings need to have been raised, and actions need to have been taken and verified. An internal audit completed the week before Stage 1 with no corrective actions closed is a red flag.
Mistakes at Stage 2
At Stage 2, the most common mistake is over preparing the wrong things. Organisations spend enormous effort making sure their documents are perfect, and not enough time making sure their people can talk about the system confidently. Auditors interview workers, supervisors, and managers. If the person doing the work cannot explain what the procedure is, cannot locate the relevant record, or has never heard of the management review, that is a finding regardless of how good the documentation looks.
Another frequent issue is not being able to demonstrate that the system has been running for long enough to show a pattern of operation. A management system that was only implemented two weeks before Stage 2 will struggle to demonstrate the evidence of monitoring, measurement, and continual improvement that the standard requires. Most experienced consultants and quality managers recommend allowing at least three to six months of genuine operation before scheduling Stage 2.
For a detailed look at what to do when a major issue surfaces during a certification audit, the article on what happens when an internal audit finds a major nonconformity is worth reading, as the same principles apply to external audit findings.
Exemplar Global Recognised Training ProviderRTP No. 310970What Happens After Stage 2?
If Stage 2 is completed successfully, the auditor submits a recommendation to the certification body. A technical reviewer within the certification body reviews the audit report and, if satisfied, approves the issuance of the certificate. This review process typically takes one to three weeks.
Once certified, the organisation enters the three year certification cycle. This includes surveillance audits, typically conducted annually in years one and two, and a recertification audit in year three. The Stage 1 and Stage 2 process is only required for the initial certification. Subsequent certifications involve a recertification audit that is closer in nature to Stage 2, with some Stage 1 elements incorporated.
It is also worth noting that if significant changes occur within the organisation after certification, such as a major expansion of scope, a change in ownership, or a significant restructure, the certification body may require additional audit activities outside the normal surveillance cycle.
Implications for Auditor Training
Understanding the Stage 1 and Stage 2 process is not just useful for organisations seeking certification. It is essential knowledge for anyone training as an ISO auditor. Lead auditor courses cover the certification audit process in depth, including how to plan and conduct both stages, how to classify findings, and how to make certification recommendations.
If you are working through an ISO auditor career path, understanding external certification audits is one of the core competencies you need to develop. Internal auditing experience is valuable, but the external certification audit operates under a different set of rules, with different accountability and a different relationship between auditor and auditee.
At Audit Workshop, the Lead Auditor courses for ISO 9001, ISO 14001, and ISO 45001 cover the full certification audit process, including Stage 1 and Stage 2 requirements, audit planning, evidence gathering, finding classification, and closing meeting conduct. The training is built around real audit scenarios, not just theory, so you understand not just what to do but why each step matters in practice.













