How to Pass Stage One Audit with Confidence
- Tony Atiba
- Jul 16
- 6 min read
A Stage One audit is not a paperwork exercise or a rehearsal to be taken lightly. It is the point at which an independent certification body establishes whether your management system is suitably developed, understood and ready for a full certification assessment. Knowing how to pass stage one audit means preparing evidence that reflects how your organisation actually operates, rather than assembling documents solely for the auditor’s visit.
For organisations pursuing ISO 9001, ISO 14001, ISO 45001 or ISO/IEC 27001 certification, a well-managed Stage One audit reduces uncertainty before Stage Two. It also gives senior leaders a clear view of any gaps that need attention before certification decisions are based on implementation and effectiveness.
What a Stage One audit is designed to establish
Stage One is commonly described as a readiness review. The auditor reviews the design, scope and documented information of your management system, alongside the context in which it operates. Depending on the standard, sector, risks and audit arrangements, this may include a site visit, remote activities or a combination of both.
The auditor is not expected to confirm full system effectiveness at this point. That is the principal focus of Stage Two. However, they do need enough objective evidence to determine whether the system has been established to the relevant ISO standard and whether Stage Two can proceed productively.
A Stage One audit will usually consider your organisation’s scope, locations, activities and applicable statutory, regulatory and customer requirements. It will also examine whether you have identified interested parties, risks and opportunities, and the processes required to control your operations.
For ISO 9001, that may involve reviewing process controls, quality objectives, customer requirements and arrangements for handling nonconforming outputs. For ISO 14001, the focus includes environmental aspects, compliance obligations and operational controls. ISO 45001 requires clear arrangements for hazard identification, worker consultation and health and safety risk control. Under ISO/IEC 27001, auditors will expect to see the information security management system scope, risk assessment approach, risk treatment plan and Statement of Applicability.
How to pass Stage One audit preparation
The most effective preparation starts with honesty. A management system that exists only in templates is difficult to defend because auditors can identify when documented processes do not match operational reality. Start with your actual business activities, then ensure the system accurately describes the controls, responsibilities and records that support them.
Confirm the certification scope
Your certification scope should be precise, understandable and consistent with the services, products and locations included in the audit. An overly broad scope can create unnecessary complexity, while a scope that excludes relevant activities without justification may raise questions.
Check that the scope is reflected consistently in your management system manual or overview, policies, process maps, risk assessments and public-facing descriptions where relevant. If your business has multiple sites, remote workers, temporary locations or outsourced processes, explain how these are controlled within the system.
Establish context, interested parties and obligations
ISO management systems begin with organisational context for a reason. The auditor needs to understand the issues that influence your ability to achieve intended outcomes. These may include supply-chain dependency, regulatory exposure, skills shortages, customer assurance demands, data protection risks or environmental conditions.
Avoid generic registers copied from another organisation. Identify the interested parties that genuinely matter to your business, such as customers, employees, regulators, contractors, shareholders or local communities. Then record their relevant needs and expectations, including the obligations you must meet.
This work should lead naturally into your risk and opportunity arrangements. If a key customer requires secure handling of information, for example, your information security controls should show how that requirement is addressed. If contractors create significant safety risks, your operational controls and competence arrangements should demonstrate appropriate management.
Make roles and leadership visible
Stage One auditors will look for evidence that the management system has leadership support. This does not mean senior managers need to recite every clause of an ISO standard. It does mean they should understand the system’s purpose, its scope, key risks, objectives and their responsibilities.
Ensure responsibilities are assigned and communicated. Relevant staff should know where to find the procedures that affect their work and what records they are expected to complete. For smaller organisations, one person may hold several responsibilities. That is acceptable where duties are clear and the system remains workable.
Management commitment is often demonstrated through practical decisions: allocating time for internal audits, providing training, reviewing performance, addressing issues and ensuring resources are available. A signed policy alone is not evidence of active leadership.
Prepare the documented information that matters
The required documents vary by standard and by the nature of your organisation. The aim is not to create the largest possible document set. The aim is to maintain controlled, accessible information that supports consistent operation and demonstrates conformity.
Before the audit, check that your documents are current, approved where required and available to the people who use them. Remove obsolete versions from shared folders and work areas. If you use software, spreadsheets or a document management platform, confirm access permissions and version control are functioning as intended.
Your auditor may wish to review documents such as the following:
the scope of the management system and key process descriptions;
policies, objectives and plans for achieving them;
risk assessments, legal or compliance registers and operational controls;
internal audit and management review arrangements;
competence, awareness and communication arrangements; and
standard-specific evidence, such as environmental aspects registers or information security risk treatment records.
Do not mistake this for a universal checklist. The relevant standard, your certification scope and the complexity of your operations determine what is appropriate.
Show that the system has begun to operate
A common Stage One issue is a management system that has been designed but has not yet generated meaningful evidence. Even though Stage Two will test implementation in greater depth, the auditor needs confidence that the system is active and not merely planned.
Where possible, have early records available. These might include completed training records, supplier evaluations, risk reviews, incident reports, quality checks, security awareness communications or monitoring results. Evidence does not need to be extensive, but it should be credible, dated and connected to the processes described in your system.
Internal audit and management review are particularly significant. In many cases, organisations are expected to have completed these activities before Stage Two, and Stage One is the right time to confirm that the programme is realistic. If your system is newly implemented, explain your planned timings and make sure they provide sufficient evidence before Stage Two.
Do not backdate records or manufacture activity to satisfy a perceived expectation. That undermines trust and may create more serious concerns than a straightforward gap would. Certification relies on objective evidence and transparent discussion.
Treat findings as a route to readiness
At the end of Stage One, the auditor will explain their findings and whether the organisation appears ready to progress to Stage Two. Findings may identify concerns that need action before the next audit. This is useful information, not a failure of the certification process.
Respond to each point with a proportionate correction and, where necessary, an assessment of the underlying cause. For example, if training records are incomplete, the answer is not simply to collect missing signatures. Consider whether the induction process, record ownership or document storage arrangements need improvement.
Agree responsibilities and deadlines internally, then retain evidence of actions taken. If a significant issue affects your readiness, it may be sensible to adjust the Stage Two date rather than proceed before your system is capable of demonstrating effective implementation. The right timing depends on the scale of the work, the availability of evidence and the requirements of the applicable standard.
Keep the audit focused and professional
Assign a knowledgeable audit contact who can coordinate the timetable, provide requested information and involve process owners when needed. This person should not attempt to answer every question alone. Auditors gain better evidence when they can speak to the people responsible for key activities.
Prepare a quiet meeting space where appropriate, ensure relevant staff know the audit dates, and have access to records without unnecessary delay. Remote audits require the same discipline, with reliable video access, secure document sharing and sufficient time to navigate systems together.
A good audit is a professional conversation grounded in evidence. Be clear about what is in place, where the system is still developing and how you intend to address identified gaps. An independent certification body is assessing conformity, not writing your management system for you.
Standcert Global approaches certification with a clear, structured process designed to help organisations understand what will be assessed and prepare with confidence. The strongest position remains the same: a management system that is appropriate to your organisation, actively used and supported by demonstrable evidence.
Approach Stage One as an opportunity to test whether your system can withstand objective scrutiny. When your documented arrangements reflect daily practice, your people understand their responsibilities and leaders can show genuine control of risk and performance, Stage Two becomes a far more confident next step.



Comments