Stage 2: the implementation and evidence audit
Stage 2 is where certification is actually earned or lost. The auditor spends the bulk of the time on-site, interviewing staff at every level, observing processes as they happen, and sampling records against the criteria agreed in Stage 1. The single question behind every Stage 2 interview and document request is the same: is this actually happening, or is it only written down?
Typical Stage 2 activity includes:
- Process interviews and observation — talking to the people who actually do the work, not just the quality manager, and watching the process run rather than being told how it runs.
- Record sampling — pulling recent, real records (training files, calibration logs, incident reports, supplier evaluations, internal audit findings) rather than accepting a verbal assurance.
- Cross-checking consistency — does the training matrix match personnel files? Do corrective actions logged after the last internal audit show an actual effectiveness check, or were they just closed on paper?
- Legal and regulatory evidence — for 14001 and 45001, objective proof that the organisation is meeting the obligations listed in its own legal register, not just that the register exists.
- Top management involvement — a short interview confirming leadership actually engages with the management system rather than delegating it entirely and signing whatever is put in front of them.
At the closing meeting, the audit team presents findings and states whether it will recommend certification, recommend it subject to closing findings first, or not recommend it. The final certification decision is made by the certification body, not the auditor on-site — but the on-site recommendation is decisive in practice.
Common causes of failure at each stage
| Stage |
Typical cause of failure |
Why it happens |
| Stage 1 |
Scope is too vague or doesn't match the actual operation |
Copied from a generic template rather than written for the specific sites and processes involved |
| Stage 1 |
No evidence of a completed internal audit or management review |
Organisation rushed straight from implementation to booking the certification audit |
| Stage 1 |
Legal/regulatory register incomplete or not evaluated |
Common on first-time 14001/45001 certifications where compliance obligations weren't mapped systematically |
| Stage 2 |
Staff don't follow the documented procedure |
The system was written by one person and never trained out to the people who actually do the work |
| Stage 2 |
Records exist but aren't current or complete |
A record was created once to satisfy the audit rather than maintained as routine practice |
| Stage 2 |
No objective evidence behind a "yes, we do that" answer |
Verbal assurance is the single most common thing auditors are trained to push past |
A documented procedure is not evidence that it's followed
Stage 1 checks that the system is written correctly. Stage 2 checks that it's real. Most certification failures happen because organisations prepare thoroughly for the first and assume the second will look after itself.
Practical impact: how to prepare for each stage differently
Treating Stage 1 and Stage 2 preparation as the same exercise is a common mistake. Stage 1 preparation is a paperwork audit of your own paperwork: read your scope statement as a stranger would, confirm every mandatory document actually exists and is current, and make sure at least one full internal audit cycle and one management review are complete and documented before the auditor arrives. Stage 2 preparation is different — it means walking the floor the way the auditor will, asking the people doing the work (not just their managers) to explain the process in their own words, and pulling a real record at random to see if it survives scrutiny. If a supervisor can't find last month's calibration log in under two minutes, neither will the auditor be reassured.
This is also the point where documentation quantity stops mattering and traceability starts to matter more. An auditor who asks "show me the record that proves this happened for the widget line last Tuesday" needs an answer in minutes, not a folder search. Whether that traceability comes from a well-organised binder or from software that can surface the exact clause, procedure and evidence on demand, the underlying requirement — objective evidence, quickly retrievable — is the same one every audit stage tests for.
Common mistakes across both stages
- Booking Stage 2 too soon after Stage 1 — leaving no realistic time to close the gaps Stage 1 identified, which pushes those same gaps straight into Stage 2 as findings.
- Treating Stage 1 as a formality — some organisations under-prepare for Stage 1 because it feels less consequential than the on-site visit, then are surprised when it surfaces enough gaps to delay Stage 2.
- Preparing the same three "audit-ready" processes — polishing the areas the organisation expects to be sampled while leaving others untouched; auditors deliberately sample beyond the obvious.
- Confusing a minor and a major nonconformity — a minor is an isolated lapse; a major is either a systemic failure or the complete absence of a required element, and it can block certification until closed and re-verified, sometimes requiring a follow-up visit.
- No one above the quality manager engages with the system — Stage 2 leadership interviews are brief but pointed, and a management team that can't speak to its own policy or objectives is a recurring finding.
The wider audit programme
Stage 1 and Stage 2 apply to the initial certification audit. Once certified, the organisation moves into an ongoing cycle of annual surveillance audits and a full recertification audit roughly every three years, each checking that the system is still followed rather than re-examining it from scratch. The same "documented vs. real" gap that causes Stage 2 findings is exactly what surveillance auditors return to check year after year. For a clause-by-clause breakdown of what each requirement actually demands, IgeraIndustria's blog carries a dedicated guide for ISO 9001, ISO 14001, ISO 45001, ISO 27001 and ISO 50001, working through every clause in turn.
Frequently asked questions
Can Stage 1 and Stage 2 happen on the same day?
Not for an initial certification audit under ISO/IEC 17021-1 — the standard requires them to be treated as distinct stages, and most certification bodies schedule real time between them so gaps found in Stage 1 can actually be closed before Stage 2. For small organisations the gap may be a few weeks rather than months, but combining them into one continuous visit isn't standard practice.
What happens if we fail Stage 1?
The certification body typically won't proceed to Stage 2 until the gaps identified are addressed. Depending on severity, this can mean a short delay while documentation is corrected, or a more substantial postponement if core elements — such as a completed internal audit or management review — are simply missing. It isn't a "fail" in the same sense as Stage 2; it's a readiness gate.
A major nonconformity generally has to be corrected and its correction verified — often through evidence submission or a follow-up visit — before the certification body will issue the certificate. Timeframes and exact procedures vary by certification body, so confirm the specific process with yours as soon as a major is raised.
Do surveillance audits also have a Stage 1 and Stage 2?
No. The two-stage structure applies to the initial certification audit (and generally to recertification). Surveillance audits, run annually between recertification cycles, are typically a single-stage, narrower-scope audit sampling a subset of the system each year.
Does the same auditor run both stages?
Often, but not always — it depends on the certification body's scheduling and the auditor's availability and competence scope for the standard involved. Either way, the Stage 2 team receives the Stage 1 findings and audit plan as the starting point for their on-site work.
Is a remote Stage 1 normal?
Yes, many certification bodies run some or all of Stage 1 remotely since it's largely a documentation review, reserving on-site time for Stage 2 where physical observation matters most. Confirm the format with your certification body — practice varies.
Does this two-stage process apply the same way to ISO 27001?
Yes — ISO/IEC 27001 certification audits also follow the ISO/IEC 17021-1 two-stage structure, with Stage 1 additionally reviewing the Statement of Applicability and risk treatment plan, and Stage 2 testing whether the selected controls are actually operating as described.
// IgeraIndustria demo — Stage 2 evidence request, on the spot
Auditor: Show me the calibration record for the torque wrench used on line 3 last month.
IgeraIndustria: Torque wrench TW-118, line 3. Last calibration: 2026-08-11, within tolerance, certificate on file. Next due: 2026-11-11. Source: calibration-log-2026.pdf, page 4, uploaded by Maintenance on 2026-08-11.
The gap between Stage 1 and Stage 2 is usually a documentation gap in disguise. IgeraIndustria answers auditor questions directly from your own procedures and records, citing the exact source — no folder search, no "let me check and get back to you."
Explore IgeraIndustria
Part of the Audits content pillar
This article is part of IgeraIndustria's audit series, which ties together the clause-by-clause breakdowns already published for ISO 9001, ISO 14001, ISO 45001, ISO 27001 and ISO 50001 — each standard has its own guide working requirement by requirement from Clause 4 through Clause 10.
Article reviewed by IgeraIndustria Quality Team, updated 2026-09-18. Reference: ISO/IEC 17021-1:2015, Requirements for bodies providing audit and certification of management systems. This article is general guidance, not professional or legal advice, and certification body practices vary — confirm the specific audit process, timelines and nonconformity handling with your own certification body.