Registrar Index

Guides

Stage 1 vs Stage 2 — what actually happens

A plain-language walkthrough of initial certification audits so operations and compliance leads know what to staff, what “ready” means, and what is out of the CB’s job.

2026-09-01 · 11 min

Initial certification to an ISO management-system standard is almost always two visits (or two remote/on-site blocks): Stage 1 and Stage 2. Teams that treat Stage 1 as “the real audit’s dress rehearsal” waste a cycle. Teams that treat it as optional paperwork also waste a cycle.

Stage 1 is a design review of the system

The auditor is checking whether you are ready to be audited for implementation. Typical questions:

  • Is the scope sane? (sites, processes, exclusions)
  • Do documented requirements exist where the standard expects them?
  • Have you done internal audit and management review that match this system, not last year’s orphan binder?
  • For 27001: is there a Statement of Applicability that looks used?
  • For 42001: is there an actual AI management system, or a slide about tools?

Stage 1 can be remote when the CB’s procedures and your risk allow it. Factories with complex processes often still benefit from an on-site Stage 1. That is a scoping conversation, not a moral failing.

You should leave Stage 1 with written findings: gaps that would make Stage 2 premature. If a CB shrugs and books Stage 2 next week despite a hollow internal-audit program, they are optimizing utilization.

Stage 2 is the implementation audit

Stage 2 tests whether the system works. Auditors sample processes, interview people who do the work, and follow evidence. In a plant that means the floor, receiving, calibration, nonconforming product. In an ISMS that means access reviews, incident records, supplier due diligence, backup tests. In an AIMS that means how a model was approved, monitored, and retired — not a vendor demo.

Nonconformities are graded (the labels vary by CB: major/minor is common). You will need root cause and corrective action. Certificates are issued after the CB’s independent review, not by the auditor in the closing meeting.

What you should staff

Role Stage 1 Stage 2
Management-system owner Required Required
Process / control owners Sample Heavy
Shop-floor or practitioner voices Light Required
IT / security (27001/42001) Scope and SoA Evidence walkthroughs
Executive Opening/closing Leadership clause

Do not hide the people who know where the system is weak. Auditors find those people anyway; you lose time.

What the CB must not do

The registrar is not your consultant of record. They can clarify the standard. They should not write your procedures the week before they audit them. If you need implementation help, hire it separately.

After the certificate

Surveillance is not “a lighter Stage 2 you can ignore.” Scope creep, new sites, new AI systems, and expired competence all show up there. Recertification is a full look at continued conformity.

If you are still choosing a CB, start with how to choose a registrar and what quotes include. Then use the directory and Get quotes.