Spire Safety
    Blog

    Stage 1 vs Stage 2 ISO Audit: What Actually Happens & What to Prepare

    Securing ISO certification is a major milestone for any business in Australia. Understanding the initial certification audit phases helps management teams reduce stress and avoid unnecessary delays

    August 10, 20267 min read(1,205 words)
    Explaining Stage 1 vs Stage 2 ISO audit phases: your guide to 2026 preparation.
    Mastering ISO audit stages: a guide to Stage 1 and Stage 2 preparation for 2026.

    Securing ISO certification is a major milestone for any business in Australia seeking to demonstrate operational excellence.

    Understanding the initial certification audit phases helps management teams reduce stress and avoid unnecessary delays during the formal assessment.

    TLDR

    • Stage 1 focuses on document readiness and system design compliance.

    • Stage 2 evaluates the practical implementation and effectiveness of the system.

    • Successful audits require clear evidence for every mandatory standard clause.

    • Major non-conformances in Stage 2 can delay your final certification.

    The Purpose of Initial Certification Audit Phases

    The certification process is divided into two distinct parts to ensure the organisation is actually ready for a full assessment.

    This structure prevents businesses from failing a high-stakes audit due to basic administrative errors or missing documentation.

    An external auditor from a JAS-ANZ Accredited body will typically conduct both stages.

    While Stage 1 is often shorter and more analytical, Stage 2 is an intensive deep dive into your daily operations.

    Stage 1 ISO Audit Preparation: The Desktop Review

    Stage 1 is primarily a readiness review to confirm your management system meets the minimum requirements of the chosen standard.

    Initial certification audit phases: Stage 1 vs Stage 2 ISO audit explained

    Understanding the purpose of initial certification audit phases, from Stage 1 to Stage 2.

    The auditor focuses on your manuals, policies and high-level risk assessments to ensure no mandatory elements are missing.

    Morning Session: Documentation and Scope

    The day begins with an opening meeting where the auditor confirms the scope of your certification.

    They will examine your ISO 45001 or 9001 manuals to ensure they align with your actual business activities.

    Expect the auditor to sample key documents such as your scope statement, quality or safety policy and documented objectives.

    Stage 1 typically takes 1-2 audit days depending on organisation size and scope complexity (Source: www.glocertinternational.com).

    The auditor will also check that responsibilities and authorities are defined and that resources are allocated to meet objectives.

    Afternoon Session: Risk and Compliance

    In the afternoon, the focus shifts to how you identify legal requirements and manage operational risks.

    For WHS systems, this involves checking your hazard registers and consultation records to confirm compliance with Australian regulatory expectations.

    The auditor reviews internal audit results and management review minutes to confirm prior oversight and corrective action processes.

    Demonstrating internal audits that verify previous findings adds weight to your readiness evidence (Source: www.iso-9001-checklist.co.uk).

    End of Day: The Readiness Report

    At the end of Stage 1, you will receive a report indicating if you are ready to proceed to Stage 2.

    If the auditor finds significant documentation gaps, they will recommend delaying Stage 2 until those gaps are closed.

    Transitioning Between Stages

    There is usually a gap of several weeks between the two stages to allow for corrections.

    ISO audit stage 1 preparation: Desktop review examining documentation for compliance.

    Stage 1 ISO audit preparation involves a thorough desktop review of your organisation's documented management system.

    Use this time to close identified issues and to collate on-site evidence the auditor will request during Stage 2.

    For safety systems, you should conduct internal checks to confirm that physical controls match your paperwork.

    This internal verification ensures what the auditor sees on-site aligns with your written procedures.

    Stage 2 ISO Audit Requirements: Implementation in Action

    Stage 2 is where the auditor looks for ISO audit evidence that your system is used by staff in daily operations.

    Diagram illustrating the transition between ISO audit stages, showing key requirements.

    Visualising the crucial steps and evidence required when transitioning between ISO audit stages.

    This stage is interactive and includes interviews, site walks and sampling of operational records.

    Duration of Stage 2 is based on organisation size.

    Small organisations commonly require 2–3 days while larger operations may need 6–10+ days (Source: www.glocertinternational.com).

    Day 1 Morning: Operational Controls

    The auditor will start by observing your primary business processes in real time.

    They may watch a production line, visit a site or sit with a project manager to see how work is planned and executed.

    Auditors check that staff follow procedures documented during Stage 1.

    If your policy states staff must wear specific PPE, the auditor will verify actual use on the floor.

    Day 1 Afternoon: Competence and Training

    The afternoon is frequently dedicated to human resources and training records sampling.

    The auditor will select employees at random and request induction records, certifications and training histories.

    Interviewing staff gauges their awareness of quality or safety policies across the organisation.

    Internal audit teams should include staff from various levels to demonstrate objectivity and competence (Source: www.iso-9001-checklist.co.uk).

    Day 2: Monitoring, Measurement, and Improvement

    On subsequent days, the auditor examines how you handle problems and improvements.

    They review your non-conformance handling and corrective action process to confirm root-cause investigations take place.

    The auditor will also verify monitoring records such as calibration logs and customer feedback.

    This confirms your Plan-Do-Check-Act cycle is operational across the business.

    Evidence Requirements for a Successful Audit

    Auditors rely on objective evidence rather than verbal promises.

    Stage 2 ISO Audit: Demonstrating effective implementation of your management system.

    See your Stage 2 ISO audit requirements in action with practical implementation examples.

    You must have a filing system that allows quick retrieval of requested records during interviews.

    Typical evidence you must have ready includes signed meeting minutes with attendance sheets.

    Include incident reports and investigation files for any relevant events.

    Provide verified training certificates for high-risk tasks and maintenance logs for critical plant and equipment.

    Also have proof of steps taken after safety incidents available for review (Source: www.glocertinternational.com).

    Managing Audit Findings

    At the Stage 2 closing meeting, the auditor presents findings and states whether they recommend certification.

    Findings are typically classified as major non-conformances, minor non-conformances, or opportunities for improvement.

    A major non-conformance means a mandatory requirement of the standard is not met.

    All major non-conformances for initial certification must be corrected and evidence submitted within 90 days to avoid re-audit (Source: www.glocertinternational.com).

    Minor non-conformances usually do not block certification but require documented corrective plans and evidence.

    Using a pre-audit WHS gap analysis can highlight issues before the formal assessment and reduce surprises.

    Common questions auditors ask (and what to have ready)

    What documents will the auditor request first?

    Have your scope, policy, objectives, risk register and last management review ready for immediate review.

    What records prove staff competence?

    Gather inductions, role-specific training records and competency assessments for sampled employees.

    How long do we have to close findings after Stage 2?

    For initial certification, non-conformities must usually be closed within 90 days to avoid re-audit (Source: www.glocertinternational.com).

    How long does the full certification process take?

    The full ISO 9001 certification process typically takes six to 12 months from initial engagement to certificate issuance (Source: www.glocertinternational.com).

    How long is the certificate valid?

    An ISO certificate is commonly valid for three years, with annual surveillance audits and a recertification audit at expiry (Source: www.glocertinternational.com).

    Quick hour-by-hour checklist for your audit days

    Before the auditor arrives: assemble a dedicated evidence folder for each clause you expect to discuss.

    Morning opening meeting: provide scope and key documents; confirm daily schedule.

    Mid-morning: make records for operational processes and control points available for walk-throughs.

    Afternoon: ensure staff selected for interviews are briefed, and their records are accessible.

    Late afternoon: present corrective action logs and recent management review minutes.

    Closing meeting: record the auditor's findings and confirm timelines for any required evidence submission.

    If you would like a printable evidence checklist tailored to ISO 9001, ISO 45001 or ISO 14001, we can prepare one for your organisation.

    FAQ

    Frequently asked questions

    01How long is the gap typically between a Stage 1 and Stage 2 ISO audit?
    The time between a Stage 1 and Stage 2 audit should be sufficient to address any non-conformances identified in Stage 1, but typically should not exceed six months. This allows organisations to implement corrective actions effectively without losing momentum.
    02Can a Stage 1 ISO audit be conducted remotely in Australia?
    Yes, in many cases, a Stage 1 ISO audit can be conducted remotely, particularly if the audit primarily involves a desktop review of documented policies, procedures, and management system records. This flexibility can be beneficial for businesses across Australia.
    03What happens if our organisation receives a 'major non-conformance' during a Stage 2 audit?
    A major non-conformance means a significant failure to meet a requirement of the ISO standard or the management system. If issued during a Stage 2 audit, you will need to implement corrective actions and have them verified by the auditor, which will delay your certification until the issue is resolved.
    04How are the audit days calculated for Stage 2 ISO audits for Australian businesses?
    The duration of a Stage 2 audit is calculated based on factors like the organisation's size (effective number of personnel), complexity of processes, the number of sites, and the scope of the management system. Larger, more complex organisations require more audit days.
    05Are there specific legal or regulatory requirements for ISO certification that apply only in Australia?
    While ISO standards are international, their implementation in Australia must always consider local legal and regulatory frameworks, especially for standards like ISO 45001 (WHS) and ISO 14001 (Environmental). Auditors will verify that your system effectively addresses all applicable Australian laws and regulations.

    Share this article

    Free WHS Templates

    Download free checklists, risk assessments and forms.

    Browse Free Resources

    Get Expert Advice

    Speak with a certified WHS consultant about your workplace.

    Contact Us

    or call 1300 891 503