Exemplar Global Certified Courses from USD 99. Ending Soon!

What Is a Gap Analysis? A Plain English Guide for Quality and Safety Managers

AW

Team @ Audit Workshop

13 min read
What Is a Gap Analysis? A Plain English Guide for Quality and Safety Managers

Why Gap Analysis Matters Before Anything Else

If you are about to implement an ISO management system, or you are preparing for a certification audit, the gap analysis is where the real work begins. It tells you where you stand right now versus where the standard says you need to be. Without it, you are guessing.

A gap analysis is a structured comparison between your current practices and the requirements of a specific ISO standard. The output is a clear picture of what is already in place, what is partially done, and what is missing entirely. That picture drives your implementation plan, your resource decisions, and your timeline.

This article explains what a gap analysis is, how it works in practice, what it covers, and how to use the results. Whether you are a Quality Manager preparing for ISO 9001 certification, an HSE Manager working toward ISO 45001, or an Environmental Manager getting ready for ISO 14001, the approach is the same. The details differ, but the logic is identical.

The Definition: What a Gap Analysis Actually Is

A gap analysis is a systematic review that compares your organisation's current state against a defined standard or set of requirements. In the ISO context, the standard is the benchmark. Each clause of the standard describes something your organisation must do, have in place, or be able to demonstrate. The gap analysis asks, for each of those requirements: are we doing this, and can we prove it?

The word gap refers to the distance between where you are and where you need to be. Some organisations have almost no gaps when they start. Others discover that large portions of the standard are not addressed at all. Most fall somewhere in the middle, with strong performance in some areas and significant shortfalls in others.

A gap analysis is not an audit. It is a diagnostic tool. It is used to plan, not to certify. The distinction matters, and we will come back to it shortly.

When Should You Conduct a Gap Analysis?

There are three situations where a gap analysis is genuinely useful.

Before Initial Certification

This is the most common use. An organisation decides to pursue ISO certification and wants to understand what it will take. The gap analysis maps out the effort required and helps prioritise where to focus first. Without this step, implementation projects tend to be reactive and disorganised.

Before a Standard Revision Transition

When a standard is revised, certified organisations must transition to the new version within a defined timeframe. A gap analysis against the new requirements tells you what has changed and what you need to update. For example, with ISO 14001:2026 now published, organisations certified to the 2015 version need to understand exactly what the new edition adds or modifies before their transition audit. You can read more about those changes in our guide to the ISO 14001:2026 transition.

As a Periodic Health Check

Some organisations use a gap analysis as a self assessment tool between certification cycles. It is a way of checking whether the system has drifted from the standard's requirements, particularly in areas that do not get much attention in day to day operations.

How a Gap Analysis Is Structured

A gap analysis follows the structure of the standard itself. ISO management systems standards use the High Level Structure, which means ISO 9001, ISO 14001, and ISO 45001 all share the same clause framework from Clause 4 through to Clause 10. This makes gap analysis tools reasonably transferable across standards, with standard specific content slotted in.

For each clause or sub clause, the gap analysis tool asks a series of questions. The assessor reviews documented information, observes practices, and interviews relevant people to determine the current state. Each requirement is then rated.

Common Rating Scales

Different organisations use different rating scales. The most common approaches are:

  • Three level: Compliant, Partially Compliant, Not Compliant
  • Four level: Fully Met, Mostly Met, Partially Met, Not Met
  • Percentage based: An estimated percentage of the requirement that is currently addressed
  • Traffic light: Green, amber, red, which maps roughly to the three level scale

The specific scale matters less than consistency. Use the same approach throughout so that the results are comparable across clauses.

What You Are Looking For

For each requirement, you are assessing two things. First, is the practice happening? Second, is there evidence that it is happening? A practice with no documentation or record is a partial gap at best. ISO standards require organisations to retain documented information as evidence of conformity. If something is being done but not recorded, the certification auditor will treat it as a gap.

Walking Through a Gap Analysis: A Practical Example

Let us walk through a simplified example using ISO 9001. Imagine a small engineering firm that has decided to pursue certification for the first time.

Clause 4: Context of the Organisation

The assessor asks whether the organisation has identified internal and external issues relevant to its purpose. The operations manager says yes, they do this informally during management meetings. But there is no documented analysis, no record of what was considered, and no formal link to risk management. Rating: Partially Met. The practice exists in spirit but lacks the structure and documentation the standard requires.

Clause 6.1: Actions to Address Risks and Opportunities

The assessor asks whether the organisation has a risk register or equivalent process. The quality manager produces a spreadsheet that lists some operational risks but does not address opportunities, and has not been reviewed in over a year. Rating: Partially Met. The tool exists but the process around it is not functioning as intended.

Clause 8.4: Control of Externally Provided Processes

The assessor asks how the organisation evaluates and monitors its suppliers. The purchasing manager explains that they use the same three suppliers they have worked with for years and have never had a problem. There is no formal evaluation process, no approved supplier list, and no documented criteria. Rating: Not Met. This is a full gap.

By the end of the gap analysis, the firm has a clause by clause picture of where it stands. The Not Met items become the priority implementation tasks. The Partially Met items need to be strengthened. The Fully Met items still need to be verified during the internal audit process before certification.

Gap Analysis vs Internal Audit: Understanding the Difference

People often confuse gap analysis with internal audit. They are related but different activities, and treating them as the same thing causes problems.

A gap analysis is a planning tool. It is typically conducted before the management system is fully implemented, or when assessing readiness for a transition. It is usually done by someone with knowledge of the standard, and the output is a prioritised list of actions. It does not need to follow the formal audit process described in ISO 19011. There is no requirement for auditor independence, formal audit plans, or nonconformity reports.

An internal audit is a formal conformity assessment. It is conducted against implemented requirements, using a defined audit programme, by auditors who are independent of the area being audited. The output is formal audit findings, which may include nonconformities that require corrective action. Internal audits are a mandatory requirement under Clause 9.2 of ISO 9001, ISO 14001, and ISO 45001.

In short: you do a gap analysis to find out what you need to build. You do an internal audit to verify that what you built actually works. Our published article on gap analysis vs internal audit goes deeper into this distinction if you want to explore it further.

Who Should Conduct the Gap Analysis?

This depends on the organisation's resources and the purpose of the exercise.

Internal Assessment

A Quality Manager or HSE Manager with solid knowledge of the relevant standard can conduct a gap analysis internally. The advantage is cost and context. An internal person knows the business, the people, and the existing processes. The disadvantage is that internal assessors may have blind spots or be reluctant to rate their own areas harshly.

External Consultant

An experienced ISO consultant brings objectivity and standard knowledge. They can complete the assessment faster and often identify gaps that internal staff miss. The disadvantage is cost, and sometimes the consultant's assessment reflects a generic understanding of the standard rather than a nuanced understanding of the specific business.

Certification Body Stage 1 Audit

Some organisations use the Stage 1 audit conducted by the certification body as their gap analysis. This is not ideal. The Stage 1 audit is a formal part of the certification process, and findings from it feed directly into the Stage 2 audit. If significant gaps are identified at Stage 1, the certification timeline is delayed. It is far better to identify and address gaps before you engage the certification body.

What a Gap Analysis Report Should Contain

A well structured gap analysis report gives the organisation everything it needs to plan its implementation or transition. It should include the following elements.

Executive Summary

A brief overview of the overall findings. What percentage of requirements are currently met? What are the highest priority gaps? What is the estimated effort to close them? This section is for senior management and should be readable without reference to the detailed findings.

Clause by Clause Findings

The main body of the report. For each clause or sub clause, document the current state, the requirement, the gap rating, and specific observations. Be concrete. Vague statements like partially addressed without explanation are not useful. The person reading this needs to know exactly what is missing and why.

Prioritised Action Plan

A list of actions required to close each gap, with a suggested priority level. Not all gaps are equal. A missing procedure for a low risk process is less urgent than a missing process for managing customer complaints or contractor safety. The action plan should reflect this.

Resource and Timeline Estimate

A realistic estimate of what it will take to close the gaps. This includes time, internal resource, and any external support required. This section helps management understand the commitment involved before the implementation project begins.

Common Gaps Found Across ISO Standards

After conducting hundreds of external audits and gap assessments across Australia and internationally, certain patterns emerge. These are the areas where organisations most commonly fall short during initial gap analysis.

Context and Interested Parties (Clause 4)

Many organisations have never formally documented their context or their interested parties. They may understand these things intuitively, but there is no structured analysis and no documented output. This is almost always a gap for first time implementers.

Risk and Opportunity Management (Clause 6.1)

Risk registers exist in many organisations, but they often do not address opportunities, are not linked to objectives, and are not reviewed at appropriate intervals. The risk process is frequently documented but not functioning.

Competence and Training Records (Clause 7.2)

Organisations often train their people but do not keep adequate records. Or they keep records but have not defined the competence requirements for each role. This is a straightforward gap to close but is consistently found.

Internal Audit Programme (Clause 9.2)

Many organisations have never run a formal internal audit. They may have informal reviews or management walkthroughs, but these do not meet the requirements of Clause 9.2. Building and running an internal audit programme is often one of the largest implementation tasks.

Management Review (Clause 9.3)

Management reviews are sometimes conducted but poorly documented. The minutes do not capture the required inputs, the decisions made, or the outputs required by the standard. This is a common finding in gap analyses and in certification audits alike.

Using Gap Analysis Results Effectively

A gap analysis is only useful if the results drive action. Here is how to make sure that happens.

Assign ownership for each gap. Every action in the plan needs a named person responsible for closing it. Without ownership, nothing gets done.

Set realistic deadlines. Implementation takes longer than people expect. Build in buffer time, particularly for processes that require consultation, training, or system changes.

Review progress regularly. The gap analysis is a living document during the implementation phase. Update it as gaps are closed and new issues are identified.

Use it to brief your internal auditors. When you move into the internal audit phase, your auditors should know which areas were identified as gaps so they can verify closure. If you are building your internal audit capability, our step by step guide on how to become an ISO internal auditor explains what you need to know before you start.

Gap Analysis Tools and Templates

You do not need expensive software to conduct a gap analysis. A well structured spreadsheet is sufficient for most organisations. The key is that the tool maps directly to the standard's requirements, clause by clause, and provides space for ratings, observations, and actions.

Audit Workshop has published gap analysis checklists for the major ISO standards. These are practical tools built around the actual clause requirements, not generic management frameworks. If you are working with ISO 9001, the ISO 9001 gap analysis checklist is a good starting point. Similar resources are available for ISO 14001 and ISO 45001.

The Connection Between Gap Analysis and Auditor Training

If you are the person responsible for conducting the gap analysis in your organisation, you need to understand the standard deeply enough to assess conformity accurately. A surface level reading of the standard is not enough. You need to understand what each clause actually requires in practice, what evidence is needed, and what auditors look for when they assess conformity.

This is exactly the kind of knowledge that internal auditor training develops. Audit Workshop's internal auditor courses for ISO 9001, ISO 14001, and ISO 45001 are built around practical application of the standards, not just theory. Participants learn to read and interpret clause requirements, assess evidence, and identify gaps, which makes them far more effective at conducting gap analyses and internal audits alike.

If you are considering whether to start with a foundation course or go straight to internal auditor training, our article on foundation vs internal auditor course will help you decide which level suits your current experience.

Frequently Asked Questions

A gap analysis compares your organisation's current practices against the requirements of a specific ISO standard. Its purpose is to identify what is already in place, what is partially addressed, and what is missing entirely. The results are used to build a prioritised implementation plan, estimate the resources required, and set a realistic timeline for achieving certification readiness.
Start Learning

Ready to Build Real Audit Skills?

Join practitioners training with ISO auditors who've conducted 500+ external certification audits.

ISO 9001:2015 Lead Auditor

Quality Management Systems (QMS)

Lead AuditorSelf-Paced Online
Digital Badge
Limited timeUSD 199(original price USD 789)
ISO 45001:2018 Lead Auditor

Occupational Health and Safety Management Systems (OHSMS)

Lead AuditorSelf-Paced Online
Digital Badge
Limited timeUSD 199(original price USD 789)
ISO 14001:2026 Lead Auditor

Environmental Management Systems (EMS)

Lead AuditorSelf-Paced Online
Digital Badge
Limited timeUSD 199(original price USD 789)
Exemplar Global Recognised Training Provider digital badge

Audit Workshop is an Exemplar Global Recognised Training Provider

Globally Recognised, Certified Training

Pass an Exemplar Global Certified course and you earn a Certificate of Attainment and an Exemplar Global digital badge. Audit Workshop graduates can apply for third-party Personnel Certification through Exemplar Global.

  • 12 months of Graduate certification
  • Access to Exemplar Global Community
  • Access to self-coaching assessment
  • Access to webinars, events, and online resources
Learn Anytime

No fixed schedule. Start, pause, and pick up exactly where you left off.

Instant Certificate

Download your digital certificate the moment you complete the course.

Practical Content

Every lesson is built from real-world ISO auditing experience.

Lifetime Access

Course materials are yours to keep and revisit long after you complete.