top of page
Search

How to Prepare for Stage One Audit Successfully

A Stage 1 audit is where certification plans become reality. To prepare for stage one audit effectively, your organisation needs more than a folder of policies. You need clear evidence that your management system has been designed for the way the business actually operates, that its scope is understood, and that the foundations are in place for a successful Stage 2 assessment.

For many SMEs, the concern is not the audit day itself. It is the uncertainty around what the certification body will expect, whether documentation is sufficiently complete, and how much implementation must be demonstrated before Stage 2. A well-managed Stage 1 audit removes that uncertainty. It gives you a professional assessment of readiness and a practical opportunity to address gaps before certification is decided.

What a Stage 1 audit is designed to establish

Stage 1 is commonly called the readiness review. It is not normally the point at which certification is granted, nor is it a light administrative check. The auditor will review whether your proposed management system meets the applicable ISO standard, whether it is suitable for your organisation, and whether you are prepared to proceed to Stage 2.

The detail will vary by certification body, standard and business complexity. An ISO 9001 review will focus on quality management arrangements, while ISO 14001, ISO 27001 and ISO 45001 will place particular attention on environmental aspects, information security risks, or health and safety hazards respectively. However, the core purpose remains consistent: confirming that the system is sufficiently established, understood and capable of being audited in full.

The auditor is likely to consider your certification scope, sites and activities, relevant legal or contractual obligations, key processes, risk arrangements, documented information, internal audit planning and management review arrangements. They will also want to understand whether the system has had enough time to operate before Stage 2.

Start with scope, context and leadership

A weak or vague scope can create avoidable questions throughout the certification process. Your scope should accurately describe the products, services, locations and activities included in the management system. It must reflect the reality of your operation, rather than being written solely to sound impressive or limit audit effort.

For example, a business delivering software development, hosted support and consultancy should be clear about which services are included and which sites or remote-working arrangements apply. If a process is outsourced, that does not automatically exclude it from the system. The organisation remains responsible for controlling relevant externally provided processes.

Your organisational context should also be meaningful. Identify the internal and external issues that affect your ability to achieve management system objectives, along with the needs and expectations of interested parties. Clients, regulators, employees, suppliers, insurers and certification bodies may all be relevant, but only where their requirements affect your system.

Leadership involvement matters at Stage 1. Auditors do not expect every director to quote clauses from the standard. They do expect senior leaders to understand why certification is being pursued, what the policy commits the business to, what risks and objectives matter, and how they support continual improvement. A management system cannot be delegated entirely to one compliance manager and remain credible.

Review the documented management system

Documentation should give people enough direction to perform work consistently and provide auditors with confidence that key controls have been defined. It should not become a library of generic procedures that staff neither recognise nor use.

Before the audit, review your core documents against the standard and against everyday practice. This generally includes the policy, scope, process map, objectives, risk and opportunity assessment, roles and responsibilities, document control arrangements, competence records, operational procedures and records of monitoring activity.

The right level of documentation depends on your size, complexity and risk profile. A five-person business does not need the same volume of documented procedures as a multi-site organisation. Equally, being small does not remove the need to show control over critical activities. If customer requirements are reviewed before accepting work, explain how that happens. If suppliers affect service quality, security or safety, show how they are selected and monitored.

A useful test is to ask process owners to explain how they carry out their responsibilities using the documents and records available. If the written procedure says one thing but the team describes another, correct the inconsistency before the auditor finds it. The aim is not to create a perfect paper system. It is to ensure documented arrangements are accurate, proportionate and usable.

Make sure records support your claims

Policies describe intention. Records demonstrate that the system is operating. At Stage 1, the auditor may sample evidence such as completed training records, supplier evaluations, risk reviews, customer feedback, calibration records, incident reports or performance reports.

Do not manufacture records simply to appear ready. Auditors can usually identify evidence created retrospectively without genuine operational value. Instead, make sure routine records are retained, legible, controlled and easy to retrieve. Where the system is newly introduced, be open about the implementation period and explain the plan for gathering further evidence ahead of Stage 2.

Confirm risks, legal duties and objectives are active

Risk-based thinking is central to modern ISO management standards. A risk register completed once during implementation is unlikely to provide sufficient assurance. Risks should be linked to your context, processes and objectives, with practical actions to prevent or reduce unwanted outcomes.

For ISO 9001, this may include the risk of missed customer requirements, poor supplier performance or loss of key skills. Under ISO 27001, consider threats to confidentiality, integrity and availability of information. ISO 14001 and ISO 45001 require a structured understanding of environmental aspects, compliance obligations, hazards and operational controls.

Your auditor will look for proportionate reasoning, not an elaborate scoring system for its own sake. A simpler method that is regularly reviewed and understood by managers is more valuable than a complicated spreadsheet that has no influence on decisions.

Objectives should be specific enough to manage. Statements such as “improve quality” or “be more secure” do not provide a reliable basis for measuring performance. Define what improvement means, how it will be measured, who owns it, what resources are needed and when progress will be reviewed. Objectives can include reducing complaints, improving delivery performance, completing competence development or strengthening incident response times.

Complete internal audit and management review activity

This is one of the most common readiness issues. Organisations often build their system well but leave internal auditing and management review until shortly before the certification visit. That approach reduces the value of both activities.

An internal audit should test whether processes conform to your own arrangements and the chosen standard, as well as whether they are effective. It should identify findings objectively, allocate corrective actions and confirm that actions have been followed through. Auditing your system before the certification body does gives you control of the improvement process.

Management review should show that leadership has evaluated performance and made decisions. Consider audit results, objectives, customer feedback, process performance, nonconformities, risks, resources, opportunities and changes affecting the system. The meeting does not need to be overly formal, but the outputs must be clear. Record agreed actions, responsibilities and timescales.

There can be a timing challenge for newly developed systems. Certification bodies may accept that a full annual cycle has not yet occurred, but they will still expect enough evidence to show that internal assurance and leadership oversight are functioning. Confirm expectations with your certification body rather than making assumptions.

Prepare the people the auditor will meet

Stage 1 is not an examination for employees. Staff should not be coached to deliver scripted answers. They should, however, understand the parts of the system relevant to their work.

Process owners need to know their responsibilities, applicable procedures, key risks, performance measures and escalation routes. Employees should be able to explain the policy in practical terms and describe how they report problems, access current information or raise improvement ideas. Senior leaders should be ready to discuss business direction, resources and the value they expect from certification.

Provide the audit plan to relevant colleagues in advance, arrange suitable availability and ensure controlled documents can be accessed during the visit. If the audit is remote or hybrid, test access to shared records and video facilities beforehand. Small operational issues should not distract from the quality of your management system.

Treat Stage 1 findings as a route to stronger certification

At the end of Stage 1, the auditor will provide feedback on readiness and identify issues to address before Stage 2. These may be formal findings, observations or areas requiring clarification. Treat them as useful evidence from an independent professional, not as a setback.

Review each issue carefully, identify its underlying cause and agree corrective action with a realistic owner and deadline. Some points may be resolved quickly, such as clarifying the scope or updating a procedure. Others may require operating evidence over time, particularly where internal audit, performance monitoring or management review has not yet been fully established.

The best preparation is not trying to look flawless. It is building a management system that reflects your business, makes responsibilities clearer and gives leadership reliable information to act upon. With structured preparation and honest evidence, Stage 1 can provide the confidence and direction needed to approach Stage 2 with control.

 
 
 

Recent Posts

See All

Comments


bottom of page