Stage 1 vs Stage 2 Audits and Non-Conformances Explained
Stage 1 vs stage 2 certification audits explained, plus what a non-conformance is, how major and minor findings differ, and how to close one properly.

Most businesses going through ISO certification for the first time expect a single audit. There are two, and they test different things. Understanding the split — and understanding what a non-conformance is before you are handed one — removes most of the anxiety from the process.
Why certification audits come in two stages
Certification bodies operate under ISO/IEC 17021, the standard governing bodies that audit management systems. It requires an initial certification audit in two stages. The logic is simple: there is no point spending three days assessing whether a system operates in practice if the system does not yet exist on paper.
Stage 1: the readiness audit
Stage 1 checks whether you are ready to be assessed. It is usually shorter, often partly remote, and focused on:
- Documentation review — does your system address every clause of the standard?
- Scope confirmation — are the sites, activities and exclusions clearly and correctly defined?
- Legal and other requirements — have you identified the obligations that apply to you?
- Internal audit and management review — have you run at least one cycle of each? This is a hard requirement, and a common reason stage 1 goes badly.
- Site and resource understanding — the auditor gets to know your operation to plan stage 2 properly.
The output is a report identifying areas of concern that must be resolved before stage 2. These are not usually formal non-conformances; they are warnings. Treat them as the audit plan for stage 2, because that is exactly what they become.
The most common stage 1 failure is having a beautifully documented system with no evidence it has been running. Auditors need records. A system approved last week with no completed internal audit cannot proceed.
Stage 2: the certification audit
Stage 2 is the real assessment: does the system work in practice? Expect the auditor to be on site, sampling across your operations. They will:
- Interview staff at all levels, including people who do not work in quality or safety
- Trace processes end to end — from a customer order or a hazard report through to closure
- Sample records: training, calibration, incidents, corrective actions, supplier evaluations
- Review how you handled the concerns raised at stage 1
- Test leadership involvement by talking to senior management directly
Duration depends on headcount, sites, risk and scope. It ends with a closing meeting where findings are presented.
What is a non-conformance?
A non-conformance (or nonconformity) is a documented failure to meet a requirement — of the standard, of your own system, or of a legal obligation. It is not the auditor's opinion of how you should run your business, and it must be traceable to a specific requirement and specific objective evidence.
There are three levels of finding:
| Finding | What it means | Effect on certification |
|---|---|---|
| Major non-conformance | A requirement is absent, or a failure is systemic, or there is significant risk the system will not deliver | Certification withheld until corrected and verified; may require a follow-up visit |
| Minor non-conformance | An isolated lapse in an otherwise functioning process | Certification can usually proceed once a corrective action plan is accepted |
| Observation / opportunity for improvement | Not a breach, but a risk or an improvement idea | No effect; you may act on it or not |
The major-versus-minor call is where the two-way conversation matters. If a finding is misclassified — an isolated slip written up as systemic — you are entitled to discuss the evidence at the closing meeting. Auditors classify against defined criteria, not by mood.
Closing a non-conformance properly
This is where most organisations do themselves damage. A non-conformance closed with "we retrained the staff member" is almost always rejected, because retraining is a correction, not a corrective action.
The expected sequence is:
- Correction — fix the immediate problem. The uncalibrated gauge is calibrated; the missing record is created.
- Containment — check whether the same problem exists elsewhere. If one gauge was out of calibration, check the register for others.
- Root cause analysis — establish why it happened. Not "the person forgot", but why the system allowed forgetting to result in a failure. Five whys or a simple cause-and-effect analysis is usually sufficient; the depth should match the risk.
- Corrective action — change the system so the cause is removed. An automated reminder, a revised process, a changed responsibility.
- Evidence — supply records showing the action was implemented.
- Verification of effectiveness — after a period of operation, confirm the problem has not recurred.
Timeframes are typically 30 days for a plan on a major finding and up to 60–90 days to demonstrate implementation, though this varies by certification body.
After certification: surveillance and recertification
Certification is not a one-off. The standard cycle is three years:
- Year 1 and 2: surveillance audits, shorter than stage 2, sampling parts of the system plus mandatory elements such as internal audit, management review, complaints and previous findings.
- Year 3: recertification audit, a full reassessment of the whole system.
Certificates can be suspended or withdrawn if major findings are not addressed, or if surveillance audits are refused.
How to make the process painless
- Run a real internal audit programme. The best predictor of a smooth stage 2 is an internal audit programme that finds things. If your internal audits never raise findings, they are not working — see our guide to internal auditor vs lead auditor training.
- Keep evidence as you go. Reconstructing twelve months of records the week before an audit is both painful and visible to an experienced auditor.
- Brief your team honestly. Staff should know an auditor may ask them questions, that "I don't know, but I know where to find it" is a perfectly good answer, and that they are not being individually assessed.
- Do not over-document. Every procedure you write is a promise the auditor can hold you to. Write what you actually do.
- Choose your certification body carefully. Check JAS-ANZ accreditation for your scope, and ask how they classify findings and what support exists between audits. Certifiers vary widely in style; Southpac Certifications is one Australian example that publishes its approach to ISO 9001 certification audits openly, which makes it easier to know what you are signing up for before the stage 1 date is booked.
The mindset that helps
An audit is a sampling exercise conducted by someone who audits systems for a living. They expect to find things. A stage 2 audit with zero findings is rarer than most people assume, and a couple of minor non-conformances is not a failure — it is a normal outcome that gives you a documented improvement list.
The businesses that get value from certification treat findings as information. The ones that resent it spend three years arguing with auditors and learn nothing.
For a broader view of what certification proves and does not prove, start with what ISO actually is.