Stage 1 vs Stage 2 — what actually happens
A plain-language walkthrough of initial certification audits so operations and compliance leads know what to staff, what “ready” means, and what is out of the CB’s job.
2026-09-01 · 11 min
Initial certification to an ISO management-system standard is almost always two visits (or two remote/on-site blocks): Stage 1 and Stage 2. Teams that treat Stage 1 as “the real audit’s dress rehearsal” waste a cycle. Teams that treat it as optional paperwork also waste a cycle.
Stage 1 is a design review of the system
The auditor is checking whether you are ready to be audited for implementation. Typical questions:
- Is the scope sane? (sites, processes, exclusions)
- Do documented requirements exist where the standard expects them?
- Have you done internal audit and management review that match this system, not last year’s orphan binder?
- For 27001: is there a Statement of Applicability that looks used?
- For 42001: is there an actual AI management system, or a slide about tools?
Stage 1 can be remote when the CB’s procedures and your risk allow it. Factories with complex processes often still benefit from an on-site Stage 1. That is a scoping conversation, not a moral failing.
You should leave Stage 1 with written findings: gaps that would make Stage 2 premature. If a CB shrugs and books Stage 2 next week despite a hollow internal-audit program, they are optimizing utilization.
Stage 2 is the implementation audit
Stage 2 tests whether the system works. Auditors sample processes, interview people who do the work, and follow evidence. In a plant that means the floor, receiving, calibration, nonconforming product. In an ISMS that means access reviews, incident records, supplier due diligence, backup tests. In an AIMS that means how a model was approved, monitored, and retired — not a vendor demo.
Nonconformities are graded (the labels vary by CB: major/minor is common). You will need root cause and corrective action. Certificates are issued after the CB’s independent review, not by the auditor in the closing meeting.
What you should staff
| Role | Stage 1 | Stage 2 |
|---|---|---|
| Management-system owner | Required | Required |
| Process / control owners | Sample | Heavy |
| Shop-floor or practitioner voices | Light | Required |
| IT / security (27001/42001) | Scope and SoA | Evidence walkthroughs |
| Executive | Opening/closing | Leadership clause |
Do not hide the people who know where the system is weak. Auditors find those people anyway; you lose time.
What the CB must not do
The registrar is not your consultant of record. They can clarify the standard. They should not write your procedures the week before they audit them. If you need implementation help, hire it separately.
After the certificate
Surveillance is not “a lighter Stage 2 you can ignore.” Scope creep, new sites, new AI systems, and expired competence all show up there. Recertification is a full look at continued conformity.
If you are still choosing a CB, start with how to choose a registrar and what quotes include. Then use the directory and Get quotes.