wa-img

Stage 1 vs Stage 2 ISO Certification Audit in UAE: What Is the Difference?

A Stage 1 audit evaluates whether an organization's management system, scope, documented arrangements and level of implementation are sufficiently ready for the main certification assessment. Stage 2 is the more detailed certification audit in which auditors evaluate whether the management system is implemented, maintained and effective across the defined certification scope.

In simple terms:

Stage 1 asks: Is the organization ready for the full certification audit?

Stage 2 asks: Does the implemented management system conform to the applicable requirements and operate effectively?

The two stages form part of the initial management-system certification process used by certification bodies operating under applicable conformity-assessment requirements.

Stage 1 vs Stage 2 What Is a Stage 1 ISO Audit?

Stage 1 is the first part of the initial certification audit.

Comparison Stage 1 Audit Stage 2 Audit
Main purpose Evaluate readiness Evaluate conformity and implementation
Audit depth Preliminary and focused Detailed and evidence-based
Management-system status Checks whether the system is sufficiently developed Checks whether the system is effectively implemented
Documentation Reviews key documented information Tests documents against actual practices and records
Site activities May include understanding operations and conditions Detailed evaluation of relevant processes and activities
Internal audit Checks whether internal audit arrangements are established and sufficiently implemented Evaluates internal-audit effectiveness and evidence
Management review Reviews readiness and status Evaluates implementation and effectiveness
Findings May identify areas that could affect Stage 2 readiness Nonconformities may affect the certification decision
Certification decision Normally not made after Stage 1 alone Results contribute to the certification decision

Its purpose is not simply to review documents. It allows the certification body to understand the organization, its activities, management-system scope, processes, locations and level of preparedness before conducting the more detailed Stage 2 assessment.

ISO 9001 Auditing Practices Group guidance describes Stage 1 as useful for understanding the organization's management system and determining whether it is ready for the next stage of certification assessment.

During Stage 1, auditors may examine areas such as:

  • Certification scope;
  • Organizational activities;
  • Sites and locations;
  • Management-system processes;
  • Policies and objectives;
  • Risks and opportunities;
  • Applicable legal or regulatory considerations;
  • Internal audits;
  • Management review;
  • Documented information; and
  • Readiness for Stage 2.

The exact audit trail depends on the standard, organization, industry, size and certification scope.

What Is the Main Purpose of Stage 1?

The main purpose is to determine whether the organization has reached an appropriate level of readiness for Stage 2.

An auditor may therefore consider questions such as:

  • Is the proposed certification scope clear?
  • Are the organization's important processes identified?
  • Has the management system been implemented sufficiently?
  • Have internal audits been conducted?
  • Has management reviewed the system?
  • Are important legal, operational or technical requirements understood?
  • Are there significant gaps that could prevent a successful Stage 2 audit?
  • Is the planned Stage 2 audit duration and audit team appropriate?

Stage 1 can also help the certification body understand where audit time should be focused during Stage 2.

Does Stage 1 Mean a Company Has Passed Certification?

No, Completion of Stage 1 does not mean certification has been achieved.

Stage 1 is part of the initial certification assessment. The organization must still proceed through Stage 2 and the certification body's subsequent independent review and certification-decision process.

This distinction is important because certification is not awarded simply because an auditor has visited the company or reviewed its documents.

What Happens If Stage 1 Identifies Serious Gaps?

If significant readiness issues are identified, they should be addressed before Stage 2.

For example, concerns may arise when:

  • The management-system scope is unclear;
  • Required processes are not implemented;
  • Internal audit has not been conducted;
  • Management review has not taken place;
  • Significant operational controls are missing;
  • The organization has very limited implementation evidence; or
  • Auditors identify inconsistencies between documented arrangements and actual operations.

Depending on the issue, the planned timing of Stage 2 may need to be reconsidered. The objective is to avoid proceeding into the full certification assessment when the management system is clearly not ready.

What Is a Stage 2 ISO Audit?

Stage 2 is the detailed certification assessment. At this stage, auditors evaluate how the management system actually operates across the defined certification scope. The focus moves beyond what procedures say and toward what the organization actually does.

Auditors use objective evidence such as:

  • Operational records;
  • Interviews;
  • Workplace observations;
  • Monitoring data;
  • Inspection records;
  • Competence records;
  • Internal audit results;
  • Corrective actions;
  • Management-review outputs;
  • Process-performance data; and
  • Relevant legal or compliance records.

The auditor may follow an audit trail across several departments rather than reviewing individual clauses in isolation.

What Do Auditors Examine During Stage 2?

The exact evidence depends on the ISO standard being audited. For example, during an ISO 9001 assessment, auditors may evaluate:

  • Customer requirements;
  • Operational controls;
  • Supplier management;
  • Quality objectives;
  • Monitoring and measurement;
  • Nonconforming outputs;
  • Customer feedback; and
  • Continual improvement.

For ISO 14001, evidence may relate to:

  • Environmental aspects;
  • Operational controls;
  • Environmental objectives;
  • Compliance obligations;
  • Emergency preparedness; and
  • Environmental performance.

For ISO 45001, auditors may follow evidence concerning:

  • Hazards and OH&S risks;
  • Operational controls;
  • Worker participation;
  • Competence;
  • Incidents;
  • Emergency arrangements; and
  • Safety-performance monitoring.

This is why Stage 2 should not be approached as a document-checking exercise.

Can Stage 1 and Stage 2 Be Conducted on the Same Day?

The arrangement depends on the certification scheme, organization, risks and certification body's applicable procedures. There needs to be sufficient opportunity to consider Stage 1 conclusions before Stage 2 begins.

If Stage 1 identifies issues that could affect readiness, the organization should have sufficient opportunity to address them before the detailed certification assessment. Organizations should therefore avoid assuming that the two stages can always be combined or conducted immediately one after another.

What Happens After Stage 2?

After Stage 2, the certification process is not automatically complete. Where findings are identified, the organization may need to:

  • Provide correction;
  • Investigate causes;
  • Determine corrective action;
  • Implement actions; and
  • Submit objective evidence.

The certification body then reviews the audit information and applicable corrective-action evidence. Understanding how findings arise during the certification audit is easier when you first understand the difference between the Stage 1 and Stage 2 audit.

NORMEIRA's certification process similarly explains that certification is not granted purely because an audit has been completed. Applicable findings must first be addressed and certification conditions satisfied. A certification decision is then made independently in accordance with the certification body's procedures.

Common Misunderstandings About Stage 1 and Stage 2

“Stage 1 is only a document audit.”

Not necessarily. Documented information is important, but Stage 1 is also concerned with organizational context, scope, processes, implementation status and readiness.

“Stage 2 is just checking ISO clauses.”

A competent management-system audit should follow processes, risks and evidence rather than simply reading clauses from a checklist.

“Passing Stage 1 means certification is almost guaranteed.”

No. Stage 2 provides the detailed assessment of implementation and conformity.

“Auditors will tell us how to fix every gap.”

An independent certification auditor can explain a finding and the requirement involved but should not design the organization's management system or provide consultancy on how to implement the solution.

Frequently Asked Questions

Is Stage 1 required for every ISO audit?

Two-stage auditing is associated with initial management-system certification. Surveillance and recertification assessments follow different certification-cycle arrangements.

Is Stage 2 more difficult than Stage 1?

Stage 2 is generally more detailed because auditors are testing implementation and effectiveness throughout the certification scope.

Should employees be available during Stage 2?

Yes. Auditors may interview personnel performing relevant activities because employee knowledge and actual working practices can provide important objective evidence.

Can nonconformities be identified during Stage 2?

Yes. Where audit evidence demonstrates that a requirement has not been fulfilled, a nonconformity may be raised.