Stage 1 vs Stage 2 Audits and Non-Conformances Explained

Stage 1 vs stage 2 certification audits explained, plus what a non-conformance is, how major and minor findings differ, and how to close one properly.

Stage 1 vs Stage 2 Audits and Non-Conformances Explained

Most businesses going through ISO certification for the first time expect a single audit. There are two, and they test different things. Understanding the split — and understanding what a non-conformance is before you are handed one — removes most of the anxiety from the process.

Why certification audits come in two stages

Certification bodies operate under ISO/IEC 17021, the standard governing bodies that audit management systems. It requires an initial certification audit in two stages. The logic is simple: there is no point spending three days assessing whether a system operates in practice if the system does not yet exist on paper.

Stage 1: the readiness audit

Stage 1 checks whether you are ready to be assessed. It is usually shorter, often partly remote, and focused on:

The output is a report identifying areas of concern that must be resolved before stage 2. These are not usually formal non-conformances; they are warnings. Treat them as the audit plan for stage 2, because that is exactly what they become.

The most common stage 1 failure is having a beautifully documented system with no evidence it has been running. Auditors need records. A system approved last week with no completed internal audit cannot proceed.

Stage 2: the certification audit

Stage 2 is the real assessment: does the system work in practice? Expect the auditor to be on site, sampling across your operations. They will:

Duration depends on headcount, sites, risk and scope. It ends with a closing meeting where findings are presented.

What is a non-conformance?

A non-conformance (or nonconformity) is a documented failure to meet a requirement — of the standard, of your own system, or of a legal obligation. It is not the auditor's opinion of how you should run your business, and it must be traceable to a specific requirement and specific objective evidence.

There are three levels of finding:

FindingWhat it meansEffect on certification
Major non-conformanceA requirement is absent, or a failure is systemic, or there is significant risk the system will not deliverCertification withheld until corrected and verified; may require a follow-up visit
Minor non-conformanceAn isolated lapse in an otherwise functioning processCertification can usually proceed once a corrective action plan is accepted
Observation / opportunity for improvementNot a breach, but a risk or an improvement ideaNo effect; you may act on it or not

The major-versus-minor call is where the two-way conversation matters. If a finding is misclassified — an isolated slip written up as systemic — you are entitled to discuss the evidence at the closing meeting. Auditors classify against defined criteria, not by mood.

Closing a non-conformance properly

This is where most organisations do themselves damage. A non-conformance closed with "we retrained the staff member" is almost always rejected, because retraining is a correction, not a corrective action.

The expected sequence is:

  1. Correction — fix the immediate problem. The uncalibrated gauge is calibrated; the missing record is created.
  2. Containment — check whether the same problem exists elsewhere. If one gauge was out of calibration, check the register for others.
  3. Root cause analysis — establish why it happened. Not "the person forgot", but why the system allowed forgetting to result in a failure. Five whys or a simple cause-and-effect analysis is usually sufficient; the depth should match the risk.
  4. Corrective action — change the system so the cause is removed. An automated reminder, a revised process, a changed responsibility.
  5. Evidence — supply records showing the action was implemented.
  6. Verification of effectiveness — after a period of operation, confirm the problem has not recurred.

Timeframes are typically 30 days for a plan on a major finding and up to 60–90 days to demonstrate implementation, though this varies by certification body.

After certification: surveillance and recertification

Certification is not a one-off. The standard cycle is three years:

Certificates can be suspended or withdrawn if major findings are not addressed, or if surveillance audits are refused.

How to make the process painless

The mindset that helps

An audit is a sampling exercise conducted by someone who audits systems for a living. They expect to find things. A stage 2 audit with zero findings is rarer than most people assume, and a couple of minor non-conformances is not a failure — it is a normal outcome that gives you a documented improvement list.

The businesses that get value from certification treat findings as information. The ones that resent it spend three years arguing with auditors and learn nothing.

For a broader view of what certification proves and does not prove, start with what ISO actually is.