Skip to main content
Services
Audit & Certification
ISO Gap AnalysisInternal AuditAudit PreparationAfter the AuditClose Nonconformities
Standards
ISO 9001 Quality ManagementISO 9001:2026 TransitionISO 14001 Environmental ManagementISO 45001 Occupational Health & SafetyISO 27001 Information SecurityISO 42001 AI ManagementISO 13485 Medical Devices
Industries & Support
Industry SolutionsMedical DevicesMechanical Engineering & ProductionIT, SaaS & AIManagement System MaintenanceExternal QMRQM Training
Industries
All IndustriesMechanical Engineering & ProductionAutomotive SuppliersLaser Optics, Photonics & SemiconductorsIndustrial Service ProvidersMedical DevicesIT, SaaS & AI
FundingFAQKnowledgeAboutContactSend emailCall now
DE/EN
Free Consultation
Certification & Audits Published: 2 July 2026

Certification Audit Process: Stage 1, Stage 2 and What Must Be Ready Beforehand

How an ISO certification audit works: preparation, Stage 1, Stage 2, nonconformities, certificate and surveillance audits.

A certification audit checks whether a management system fulfills the requirements of the selected standard and is applied effectively in daily operations. The typical process consists of preparation, Stage 1, correction of open points, Stage 2 and the certification decision. After that, annual surveillance audits follow and recertification takes place after three years.

This article explains the process using ISO management systems such as ISO 9001, ISO 14001, ISO 45001, ISO 27001, ISO 13485 or ISO 42001 as examples. Depending on the industry and certification scheme, additional requirements may apply. The basic logic remains similar: the certification body reviews evidence, speaks with responsible people and evaluates whether the system is conforming and robust.

What Is a Certification Audit?

A certification audit is an external audit by an independent certification body. For management systems, certification bodies follow ISO/IEC 17021-1, the international requirements standard for bodies that audit and certify management systems. In Germany, DAkkS accredits management system certification bodies on this basis.

The audit does not evaluate documents only. The decisive question is whether processes are understood, implemented, monitored and improved. A good certification audit therefore follows an audit trail: the auditor takes real business cases, reviews the related evidence and speaks with the people who actually perform the process.

The Process at a Glance

Initial certification normally runs through several phases. Audit time is planned by the certification body. IAF MD 5 provides a framework that considers Stage 1, Stage 2, surveillance and recertification audits, among other factors.

Table 1: Certification Audit Process: Stage 1, Stage 2 and What Must Be Ready Beforehand
Phase Objective Typical Evidence
Preparation Make the system audit-ready Process map, documented information, internal audits, management review, action status
Stage 1 Check readiness for Stage 2 Scope, context, standard comparison, audit program, management system structure
Stage 2 Evaluate effectiveness and conformity Interviews, samples, process records, KPIs, complaints, corrective actions
Certification decision Release the certificate or clarify conditions Audit report, nonconformities, corrective actions, evidence of closure
Surveillance and recertification Maintain the certificate in the three-year cycle Annual system maintenance, new risks, objectives, internal audits, management review

What Should Be Ready Before Stage 1

Stage 1 is not a trial run without consequences. The certification body checks whether your management system is basically ready for the actual certification audit. If essential foundations are missing, Stage 2 may be postponed or planned only with high risk.

Before Stage 1, at least these points should be reliable:

  • Scope: Which sites, services, processes and standards are included in certification?
  • Context and interested parties: Which internal and external issues affect the management system?
  • Process landscape: How do core, leadership and support processes interact?
  • Documented information: Which documents and records are necessary based on the standard or risk?
  • Internal audits: Has the system been audited internally and have findings been addressed?
  • Management review: Has top management reviewed the system with real inputs, results and decisions?
  • Open actions: Are priorities, owners and deadlines traceable?

If you are unsure whether these foundations are sufficient, an ISO gap analysis before the certification body becomes involved is useful. It shows early whether gaps are critical or can be closed in a controlled way before Stage 2.

Stage 1: Readiness and Audit Planning

In Stage 1, the certification body primarily checks system readiness. Depending on the standard, industry and certification body, this part may take place remotely, on site or as a combination. The auditor reviews documentation, scope, site conditions, understanding of the standard, legal requirements and the plan for Stage 2.

Typical Stage 1 questions include:

  • Is the scope clear and realistic?
  • Have internal audits and management review already been performed?
  • Are there significant gaps that would endanger Stage 2?
  • Are processes, responsibilities and interfaces traceable?
  • Which sites, shifts, projects or processes must be audited in Stage 2?

The result is usually a Stage 1 report with notes, open points and the decision whether Stage 2 can take place as planned. Stage 1 is therefore the right moment to close critical points properly before the actual certification audit begins.

Between Stage 1 and Stage 2

The time between Stage 1 and Stage 2 is often decisive. Companies should not waste it on new documentation projects, but should address the points the auditor marked as critical. Evidence of effectiveness is especially important, not just new templates.

In practical terms, this means: complete actions, prepare process owners, organize evidence, update KPIs and close open findings from internal audits in a traceable way. Focused audit preparation can help when Stage 2 is already scheduled and the team still reacts uncertainly to typical audit questions.

Stage 2: The Actual Certification Audit

Stage 2 checks implementation and effectiveness of the management system. The auditor speaks with top management, the QMR or management system representative, process owners and selected employees. This is combined with document review, sampling, process walkthroughs and a comparison between the documented approach and actual practice.

In Stage 2, these points matter particularly:

  • Leadership: Top management must be able to explain objectives, risks, resources and responsibilities.
  • Process control: Processes do not have to be documented perfectly, but they must be clearly controlled and demonstrably effective.
  • Evidence: Audit reports, training records, inspections, releases, complaints and actions must be findable.
  • Improvement: Nonconformities, customer feedback, KPIs and opportunities must lead to traceable decisions.
  • Legal and customer requirements: Where relevant, the company must show how requirements are identified and implemented.

The most common mistake before Stage 2 is not a missing form, but missing consistency: documents say something different from processes, actions remain open or responsible people cannot explain their role plausibly.

Nonconformities: What Happens When Findings Are Raised?

An audit does not have to be free of findings to be successful. The severity of the nonconformities and the robustness of the company's response are decisive. Certification bodies typically distinguish between major nonconformities, minor nonconformities and observations or opportunities for improvement. The exact terms may vary by body.

For a minor nonconformity, a traceable action plan with cause, correction, owner and deadline is often sufficient. For a major nonconformity, robust evidence is usually required before the certificate is issued, showing that the nonconformity has been corrected and the cause understood. If several systematic major nonconformities are found, a follow-up audit may be necessary.

Certification Decision and Certificate

After Stage 2, the auditor prepares a report. The certification body makes the certification decision based on it. The certificate is not "awarded" by the auditor on the audit day; it is released after internal review. Scope, standard, sites and any exclusions must be represented correctly on the certificate.

After receiving the certificate, check in particular:

  • Is the company name correct?
  • Are site addresses and scope described correctly?
  • Is the standard edition correct?
  • Are certification body and accreditation reference traceable?
  • Does the validity period match the agreed certification cycle?

After Certification: Surveillance and Recertification

A management system certificate is usually part of a three-year cycle. After initial certification, annual surveillance audits follow. In the third year, the system is recertified. These audits are not a formality: the certification body checks whether the system continues to be applied, changes are controlled and improvements are evidenced.

Many companies lose momentum after receiving the certificate. This is exactly where risks for the next surveillance audit arise. A maintained audit program, ongoing action tracking and an annual management review keep the system alive.

Typical Mistakes in the Certification Process

  • Internal audit too late: If the internal audit takes place shortly before Stage 2, there is no time for corrective actions.
  • Management review without decisions: A pure minutes exercise does not convince auditors.
  • Unclear scope: Wrong site or process boundaries lead to questions and delays.
  • Documentation without practical relevance: Extensive templates help little if employees do not know or use them.
  • Open nonconformities without cause: Actions must address causes, not only symptoms.
  • Certification body involved too late: Audit times, scope and dates require lead time.

How Sternberg Consulting Supports You

We support SMEs pragmatically before and during the certification audit: with gap analysis, internal audits, audit preparation, management review, action plans and support through Stage 1 and Stage 2. If sufficient quality management capacity is not available internally, we take on the ongoing role as external QMR and keep the system audit-ready between certification and surveillance audits.

Frequently Asked Questions About the Certification Audit

Is Stage 1 already part of the certification audit?

Yes. Stage 1 is part of initial certification and checks whether the management system is ready for Stage 2. It is not a non-binding pre-test, even though the focus is more strongly on documentation, scope and audit planning.

Must internal audit and management review be completed before Stage 1 or only before Stage 2?

For a robust Stage 1, internal audit and management review should already have been performed. Stage 1 assesses certification readiness; many certification bodies explicitly check whether internal audits and management review have not only been planned but demonstrably carried out. Creating these records only between Stage 1 and Stage 2 risks postponements or additional questions.

Can a certification audit take place remotely?

Partly yes, depending on standard, scope, risk, certification body and audit program. Many audits combine remote document review with on-site sampling. The certification body makes that decision.

What happens if a major nonconformity is found?

The certification body usually requires robust corrective actions and evidence before the certification decision. Depending on severity, a follow-up audit may be required.

How long is an ISO certificate valid?

Management system certificates typically run in a three-year cycle with annual surveillance audits and recertification in the third year. The concrete period is stated on the certificate and in the contract with the certification body.

Jonathan Sternberg
About the Author
Jonathan Sternberg is a certified internal auditor and external quality management representative with experience in the automotive industry, semiconductors, laser optics and medical devices. Through Sternberg Consulting, he supports companies with practical implementation of ISO 9001, ISO 14001, ISO 45001, ISO 13485, ISO 27001 and ISO 42001.
Next step

Let's talk.

Tell me where you stand and what you need.

Within 24 hours you receive a first assessment and a concrete meeting proposal — free and without commitment.

  • Reply within 24 hours
  • Personal assessment of your project
  • Funding eligibility checked on request

By submitting you agree to the processing of your details for answering your enquiry.