Teammate App
Certification11 min readUpdated August 2026

What certification auditors actually check

Auditors are not trying to catch you out. They are sampling for evidence, in a fairly predictable order — which means you can look at what they will look at, first.

Stage 1 and Stage 2 are different audits

Organisations often prepare for certification as though it were a single event. It is two, with different purposes, and understanding the difference removes most of the surprise.

Stage 1 asks whether you are ready. The auditor reviews your documented information, confirms the scope makes sense, checks that internal audits and management review have happened, and identifies anything that would make Stage 2 pointless. It is a readiness check, and failing it costs time rather than the certificate.

Stage 2 tests whether the system operates. The auditor goes looking for evidence in the field: interviews people, follows records, samples processes, and forms a judgement about effectiveness. Documentation matters here only as far as it matches what is actually happening.

The most common Stage 1 outcome

Not a failure — a delay. The system is well designed but has been running for three weeks, so there is nothing to sample. Records are the constraint, and the only cure for it is time. Start operating early.

What gets opened first

There is a consistent opening sequence, because these documents reveal quickly whether a system is real. Look at yours in this order and you will see what the auditor sees.

  1. 1.The scope statement. Everything that follows is bounded by it, and an unclear scope makes every subsequent sample ambiguous.
  2. 2.The internal audit programme. Not the reports — the programme. It shows whether coverage was planned by risk or invented retrospectively.
  3. 3.The last management review. Auditors read the outputs, looking for decisions and resources. A review with no decisions is a formality, and it is treated as one.
  4. 4.The corrective action register. Open items, overdue items, and whether anything was verified as effective rather than merely marked closed.
  5. 5.The risk or aspects register. Whether it connects to anything downstream: controls, objectives, training, monitoring.
  6. 6.The competence and training records. Usually sampled against the people the auditor is about to interview.
  7. 7.Legal and other requirements, with evidence of evaluation. Determining obligations is not enough; the standard asks you to evaluate compliance and keep the result.

Notice what is not in that list: policies, procedures and manuals. They get referenced, but they are rarely where an audit is won or lost.

How sampling actually works

An auditor cannot examine everything, so they pull threads. The characteristic move is to take one real event and follow it end to end across every part of the system it touched. One incident becomes: the initial report, the notification decision, the investigation, the corrective actions, the training that resulted, the document that changed, the effectiveness check, and the management review where it was discussed.

This is why fragmented systems struggle. If each of those steps lives in a different place, the auditor watches you assemble the trail by hand, and each handoff is a place where the record is thin or the dates do not line up.

  • Expect the thread to start from something real: a recent incident, a customer complaint, a new starter, a piece of plant.
  • Expect interviews with people who do the work, not just the system owner. Auditors compare what workers say with what the documentation claims.
  • Expect the awkward corners: night shift, the remote site, the newest contractor, the process that changed last quarter.
  • Expect previous findings to be revisited. An unclosed finding from last year is a much more serious signal than a new one.
An incident record in Teammate with its investigation, corrective actions and evidence linked
The thread an auditor pulls — assembled as it happened rather than reconstructed on the day.

The findings that recur

Across sectors and standards, the same handful of findings appear again and again. All of them are visible internally before the auditor arrives.

  1. 1.Corrective actions closed without verification. Something was done, nobody checked it worked, and the same issue reappears.
  2. 2.Internal audit programme not risk-based. Coverage mirrors the clause list rather than the operation.
  3. 3.Management review missing required inputs. The standard lists them explicitly, and the omitted one is usually customer feedback or the status of previous actions.
  4. 4.Competence assumed rather than evidenced. Experienced people doing work with no record of how competence was determined.
  5. 5.Documents in use that are not the current version. Almost always found in the field, not in the document system.
  6. 6.Objectives without measurement. Set annually, never tracked, restated the following year.
  7. 7.Contractor requirements not verified. Prequalification on file, nothing showing the work was monitored.

The four weeks before

The month before an audit is better spent testing than tidying. Tidying makes documents look consistent; testing finds what will actually be sampled.

  1. Week 4Run the thread yourself. Pick a recent real event and follow it end to end exactly as an auditor would. Where you have to ask someone for a file, that is a finding.
  2. Week 3Close the register. Verify effectiveness on everything marked closed in the last year. Overdue and unverified actions are the highest-yield thing to fix.
  3. Week 2Check the field, not the folder. Walk the site looking for superseded documents, missing records and controls that exist on paper only.
  4. Week 1Brief the people who will be interviewed. Not with scripts — with the truth. Workers should know what the system is for, what they raised recently, and that saying "I don’t know, I’d ask X" is a perfectly good answer.
Four weeks of testing rather than tidying. Everything here is something the auditor would otherwise find first.

One last thing worth saying plainly: findings are normal. A certification audit that raises no findings at all is uncommon, and a small number of honest minors closed properly is a healthier signal than a spotless report that nobody quite believes.

Questions we get asked

What is the difference between Stage 1 and Stage 2?

Stage 1 is a readiness review — documentation, scope, internal audit and management review — and identifies anything that would make Stage 2 unproductive. Stage 2 tests whether the system operates in practice, through interviews, field observation and sampling of records. Stage 1 failures usually cost time; Stage 2 findings affect the certificate.

What is the difference between a major and a minor nonconformity?

A minor is an isolated lapse against a requirement. A major is a systemic failure, an absent requirement, or a group of minors that together show a process is not working. Majors normally have to be resolved with evidence before certification is granted; minors are typically closed out on a timetable.

Can we fail a certification audit?

You can be found not ready, which is different from a pass-fail exam. In practice, unresolved majors mean the certificate is not issued until they are addressed and verified. The most common cause is not a bad system but an immature one — too little operating history to sample.

How long does the audit take?

Audit duration is calculated from your headcount, number of sites, scope complexity and risk, using the certification body’s published rules rather than negotiation. A small single-site organisation might see two to three days across both stages; multi-site operations are considerably longer and may involve sampling of sites.

How much history do auditors want to see?

Enough to sample meaningfully — commonly around three months of operation, with at least one full internal audit cycle and one management review completed. Systems switched on weeks before Stage 2 tend to be deferred, because there is simply nothing to examine.

General guidance drawn from common certification practice across ISO 9001, ISO 14001 and ISO 45001. Individual certification bodies vary in approach, and their published rules and your accreditation requirements take precedence.

Keep reading

AuditsAudits and inspections that find real problemsRead it QualityImplementing ISO 9001 without a consultantRead it

Pull the thread before the auditor does.

Bring a real event from the last quarter. We will follow it end to end and show you where the trail goes thin.

Book a demo Teammate and the ISO standards