Are you ready for the ISO 27001 stage 1 audit?
Stage 1 is a documentation review with a purpose: deciding whether stage 2 can usefully go ahead. This checks what you hold against what the standard requires, gives a verdict, and lists the findings that most often push stage 2 back.
Stage 1 is not a soft opening. The auditor reads your documented information, looks at whether the management system has actually been running, and decides whether stage 2 can proceed as planned. Coming out of stage 1 with a list of areas of concern is normal. Coming out of it with stage 2 postponed is common too, and almost always for one of the same five reasons.
Answer what you hold today rather than what is in progress. The verdict appears on this page. Nothing is emailed anywhere unless you ask for it at the end.
On its way
Check your inbox shortly. If you would rather talk it through, book a time.
What stage 1 is for
The certification body uses stage 1 to understand your management system, check the documented information, confirm the scope makes sense, look at how ready you are for stage 2, and plan the stage 2 visit. It usually runs half a day to a day and a half depending on scope, and it is often done remotely. The output is a report with areas of concern, and a decision on whether stage 2 goes ahead on the date already in the calendar.
| Question | Stage 1 | Stage 2 |
|---|---|---|
| What is examined | Documented information and whether the system exists | Whether the controls and clause requirements operate, sampled against evidence |
| Where the evidence comes from | Documents, the Statement of Applicability, the internal audit and review records | Interviews, system configuration, tickets, logs, records from the period |
| Typical length | Half a day to a day and a half | Two to five days for a small scope |
| What goes wrong | Documents missing, or present but never used | A control described accurately and operated inconsistently |
| Consequence | Stage 2 delayed, usually by four to twelve weeks | Nonconformities to close before the certificate issues |
The gap stage 1 is really measuring
Almost every document on the required list can be written in a week. What cannot be produced quickly is the evidence that the system has been running: an internal audit with findings, a management review with decisions in it, corrective actions at various stages of closure, and records dated across weeks rather than all on the same afternoon. That is the gap stage 1 detects, and it is why buying a document set does not shorten a certification project.
Common questions
Do I have to give an email address to see the result?
No. The verdict, the missing items and the likely findings render on this page as soon as you finish. The field underneath sends a written version with clause references beside each gap, which is useful for handing to the people closing them. Skipping it costs you nothing.
Can we fail stage 1?
There is no pass or fail in the way people expect. The auditor records areas of concern and decides whether stage 2 should go ahead. The bad outcome is not a failure notice, it is stage 2 being pushed back while the certification body keeps the date it had booked for somebody else, which is how a four-week gap becomes a twelve-week one.
How long between stage 1 and stage 2?
Commonly two to twelve weeks. Long enough to close what stage 1 raised, short enough that the auditor's understanding of your system is still current. A gap beyond about six months usually means parts of stage 1 get repeated. What the two audits involve in detail is on the stage 1 and stage 2 page.
How long does the system need to have been running?
There is no number in the standard. In practice auditors want to see records covering a period, and three months of the system operating is the point where the evidence stops looking manufactured. Under a month, an auditor can usually tell, because every record carries a date within the same fortnight.
What should we fix first if stage 1 is close?
The clause requirements, in this order: scope, policy, Statement of Applicability, risk assessment results, internal audit, management review. Control gaps can be recorded as applicable and not yet implemented with an owner and a date, which survives. Missing clause requirements cannot be recorded away. The gap assessment scores both halves.
Close the gaps before the auditor finds them
Tell us where you are and we will put it in front of Canadian firms doing ISO 27001 readiness work.
Get matched