ISO Stage 1 Audit: What Happens and How to Prepare

By July 25th, 2026ISO Audit And Certificate8 min read

ISO Stage 1 Audit: What Happens and How to Prepare

An ISO Stage 1 audit is the first of two mandatory audits that an accredited certification body conducts before issuing an ISO certificate. It is a documentation review and readiness assessment performed on-site or remotely to verify that your management system is designed, documented and ready for the full Stage 2 implementation audit. The Stage 1 audit confirms that the scope of certification is correctly defined, that the required policies and procedures exist, and that the organisation understands the standard’s requirements. Passing Stage 1 does not guarantee certification, but failing it prevents Stage 2 from proceeding.

Published: July 2026  |  Last updated: July 2026  |  Author: Bitrixme Compliance Team

Purpose of Stage 1

The Stage 1 audit serves four specific purposes. First, it reviews the documented management system to confirm it addresses all the requirements of the applicable standard. Second, it evaluates the organisation’s understanding of the standard and its ability to meet the requirements. Third, it verifies that the scope of certification is appropriate and that the site locations included in the scope are correctly identified. Fourth, it identifies potential risks and gaps that must be resolved before Stage 2. The Stage 1 auditor produces a report that lists the findings and indicates whether the organisation is ready to proceed to Stage 2.

What the Auditor Reviews

During Stage 1, the auditor examines the following areas in detail. The documentation must be complete, approved and under document control at the time of the audit. Any missing or draft documents are likely to result in findings that delay Stage 2.

  • Scope of the management system. The boundaries and applicability of the system, including physical sites, organisational units, activities and exclusions.
  • Policy and objectives. The quality, environmental, health and safety or information security policy, and the associated objectives and targets.
  • Risk assessment and treatment. For ISO 27001, the risk assessment methodology, risk criteria, risk register and Statement of Applicability. For ISO 45001, the hazard identification and risk assessment process. For ISO 14001, the environmental aspects and impacts register.
  • Legal and regulatory requirements. The process for identifying, accessing and evaluating applicable legal and other requirements.
  • Documented information. The document and record control procedures, the management system manual (if maintained) and the documented procedures required by the standard.
  • Internal audit programme. Evidence that internal audits have been planned and conducted, with documented results and corrective actions.
  • Management review. Evidence that management review has been conducted at planned intervals, with documented inputs and outputs.
  • Competence and awareness. Training records, competence assessments and evidence that personnel are aware of the policy and their role in the management system.

Documentation Checklist for Stage 1

The following documents should be ready and available for the Stage 1 auditor. Having these organised in advance significantly reduces audit time and demonstrates system maturity.

DocumentRequired ByPurpose
Management system manual (or equivalent)All standardsDescribes the scope, policies, processes and interactions of the management system
Policy statementAll standardsSigned policy approved by top management
Objectives and metricsAll standardsDemonstrates that measurable objectives are set and monitored
Risk assessment methodology and registerISO 27001, ISO 45001, ISO 14001Shows that risks are identified, analysed, evaluated and treated
Statement of ApplicabilityISO 27001Lists Annex A controls and justifies inclusions and exclusions
Legal registerAll standardsIdentifies applicable legal and regulatory obligations
Internal audit reports and scheduleAll standardsEvidence that the internal audit programme is operating
Management review minutesAll standardsEvidence that top management reviews the system
Document and record control proceduresAll standardsDefines how documents are approved, reviewed, updated and retained
Competence and training recordsAll standardsDemonstrates personnel are competent for their roles

Typical Findings in Stage 1

The auditor may raise three categories of finding during Stage 1. Major nonconformities are rare at this stage because the audit is evaluating design and documentation, not implementation. Minor nonconformities or observations are common and typically relate to incomplete documentation, unclear risk criteria, missing legal registers or insufficient internal audit evidence. The auditor may also identify opportunities for improvement, which are not required to be closed but should be considered. The Stage 1 report will state whether the organisation is ready for Stage 2, or whether specific issues must be addressed before the certification body will schedule Stage 2.

Stage 1 vs Stage 2 Audit

Understanding the difference between the two stages is essential for preparation. They evaluate different aspects of the management system and serve different purposes in the certification process.

AspectStage 1Stage 2
LocationOn-site or remoteOn-site (mandatory)
Duration1 – 2 days2 – 8 days depending on scope
FocusDocumentation, scope, readinessImplementation, effectiveness, evidence
InterviewsTop management, management representativeAll levels including operational staff
Site walkthroughBrief, if on-siteFull, including all areas in scope
NonconformitiesRare – findings are observations or recommendationsCommon – both major and minor
OutcomeReadiness assessment reportCertification recommendation or nonconformity report
Can certification be issued?NoYes, after nonconformity closure

How to Prepare for Stage 1

Preparation determines outcome. Organisations that treat Stage 1 as a minor audit rather than a serious assessment often receive findings that delay their certification timeline. The following preparation steps are essential.

  • Complete all documentation before the audit. The management system manual, policies, procedures, risk assessments and records must be finalised and approved. Draft documents indicate the system is not yet ready.
  • Conduct at least one full internal audit. The Stage 1 auditor will expect to see evidence of a completed internal audit cycle, including reports, nonconformities and corrective actions.
  • Hold a management review meeting. A management review must have been conducted before Stage 1. The meeting minutes should address the inputs required by the standard.
  • Prepare the audit trail. Organise documents in a logical structure that the auditor can navigate. Provide a document register or index.
  • Brief top management. The auditor will interview senior management and may ask about their understanding of the management system, their commitment and their involvement in review activities.
  • Arrange logistics. If the audit is on-site, provide a meeting room, access to facilities and a point of contact who can locate documents quickly.

What Happens After Stage 1

The certification body issues a Stage 1 report within two to four weeks of the audit. The report states whether the organisation is ready for Stage 2. If the report identifies gaps, the organisation must address them and provide evidence of closure before Stage 2 can proceed. The typical time between Stage 1 and Stage 2 is 4 to 8 weeks, though some certification bodies allow up to six months. If Stage 2 is not completed within that period, a new Stage 1 may be required. Once Stage 2 is scheduled, the certification body assigns the same or a different audit team to conduct the implementation audit.

Timeline from Stage 1 to Certification

PhaseDuration
Stage 1 audit1 – 2 days
Stage 1 report issued2 – 4 weeks after audit
Gap closure period (if needed)2 – 6 weeks
Stage 2 planning and scheduling2 – 4 weeks
Stage 2 audit2 – 8 days
Nonconformity closure period30 – 90 days
Certification decision1 – 2 weeks after closure
Total from Stage 1 to certificate2 – 6 months

FAQ

What is the purpose of an ISO Stage 1 audit?

The Stage 1 audit verifies that your management system documentation is complete and compliant with the standard, and assesses whether your organisation is ready for the full Stage 2 implementation audit.

Can I fail Stage 1?

Yes. If documentation is missing, incomplete or does not meet the standard’s requirements, the auditor may recommend that Stage 2 be deferred until the gaps are closed. Significant gaps may require a repeat Stage 1.

How long between Stage 1 and Stage 2?

Typically 4 to 8 weeks. The certification body sets a maximum interval, usually six months, after which a new Stage 1 audit would be required if Stage 2 has not been completed.

Is Stage 1 on-site or remote?

It can be either. Many certification bodies now offer remote Stage 1 audits. On-site Stage 1 is still common for high-risk industries or when the auditor needs to observe site conditions.

Do I need an internal audit before Stage 1?

Yes. The Stage 1 auditor will expect to see evidence of at least one completed internal audit cycle, including audit reports, nonconformities and corrective actions.

What happens if Stage 1 identifies major gaps?

The certification body issues a report listing the required corrections. Stage 2 cannot proceed until the gaps are closed and evidence is submitted. Most gaps identified at Stage 1 are documentation-related and can be resolved within two to six weeks.

Ready to begin your ISO certification journey? Contact our compliance team for pre-Stage 1 gap analysis and readiness support, or message us on WhatsApp.