How many stages are in an ISO audit?

Asked by: Kelli Torphy  |  Last update: July 10, 2026
Score: 5/5 (37 votes)

An initial ISO certification audit typically consists of two main, mandatory stages. Stage 1 focuses on reviewing documentation and assessing readiness, while Stage 2 evaluates the actual implementation and effectiveness of the management system on-site. Together, these stages determine if an organization meets the standard for certification.

What are the stages of ISO audit?

The ISO assessment is conducted in two parts, the Stage 1 and Stage 2 Certification Audits, and followed by Surveillance Audits. In this article we'll explain why, and what it means for your business. We'll also take a look at Pre-Certification Assessment and discuss whether they're necessary.

What are the 5 stages of audit?

What happens during an audit? Internal audit conducts assurance audits through a five-phase process which includes selection, planning, conducting fieldwork, reporting results, and following up on corrective action plans.

How long does an ISO audit take?

Over the course of one to three months, your auditor will investigate each of the ISO 27001 requirements and applicable controls to verify whether or not you've implemented the standard properly.

What is a stage 2 ISO audit?

An International Standards Organization (ISO) Stage 2 audit evaluates the implementation and effectiveness of a company's management system.

ISO 9001:2015 Understanding to conduct an audit. Each section of the standard is explained.

40 related questions found

What is a stage 3 audit?

Stage 3 Road Safety Audits should be undertaken when the highway scheme construction is complete and preferably before the works are opened to road users. All highway improvement schemes should be subjected to a Stage 3 Road Safety Audit within one month of opening.

What are the 4 levels of audit?

4 levels of audit opinions

  • Unqualified.
  • Qualified.
  • Adverse.
  • Disclaimer.
  • Beyond the opinion.

Are ISO audits hard?

An ISO certification will require time, effort, and improvement from all areas of the business. However, the steps that must be taken are worth it for any company. It will benefit business owners, employees, and customers.

What are 1st, 2nd, and 3rd party audits?

1st, 2nd, and 3rd party audits categorize audits by who performs them and their purpose: First-party (internal) audits are self-assessments for improvement; Second-party audits are by customers or partners on suppliers to check compliance; and Third-party audits are by independent, external bodies for certification (like ISO) or validation, offering the highest objectivity.

What are the 7 steps in the audit process?

The 7 steps in the audit process generally cover Planning, Risk Assessment, Internal Control Testing, Fieldwork/Evidence Collection, Reporting, and Follow-Up, focusing on a systematic review from initial engagement to ensuring corrective actions are taken for operational improvement. This framework ensures comprehensive evaluation, from understanding the client's business to delivering actionable insights and ensuring accountability for identified issues. 

What are the 6 phases of audit?

The 6 key phases of an internal audit process are: Planning, Preliminary Investigation, Implementation, Quality Assurance, Reporting, and Follow-Up. Each phase includes steps like defining audit procedures, analyzing the audit object, verifying facts, and reviewing outcomes to ensure compliance and improvement.

What are the 5 C's of audit?

The 5 Cs of audit (Criteria, Condition, Cause, Consequence, Corrective Action) are a framework for structuring clear, actionable audit findings, explaining what should be (Criteria), what is found (Condition), why it happened (Cause), what the impact is (Consequence/Effect), and how to fix it (Corrective Action/Recommendation) to drive organizational improvement and compliance.

What is a full audit cycle?

The audit cycle was categorized into six stages4—stage 1, choosing a topic; stage 2, setting target standards; stage 3, observing practice; stage 4, comparing performance with targets; stage 5, implementing change and planning care; stage 6, repeating the audit cycle.

What is an ISO audit checklist?

These checklists help internal auditors maintain focus on the audit objectives, ensure all necessary areas are reviewed, and provide a record of the audit process and findings. An ISO audit checklist typically covers various sections and processes depending on the specific ISO standard being audited.

What are the 7 principles of ISO?

Now let's begin with the 7 principles of ISO 9001, which are Customer Focus, Leadership, Engagement of People, Process Approach, Improvement, Evidence-Based Decision Making, and Relationship Management.

What are the three types of ISO audits?

There are three types of ISO audits: internal audits (first-party audits), supplier audits (second-party audits), and external audits (third-party audits). Your choice of audit type will alter depending on your compliance and certification goals, scope, scale, and budget.

What are the three layers of audit?

Layer 1: Operators and frontline workers conduct daily audits of their own processes. Layer 2: Supervisors perform weekly audits within their departments. Layer 3: Operations managers conduct monthly audits on quality and review LPA reports.

What is a stage 2 audit?

The Stage 2 audit will: evaluate the operational controls of your processes and the overall effectiveness of your management system. gather evidence of your alignment to the requirements of the Standard – this may be through observation, discussions and interviews with employees.

What do ISO auditors get paid?

ISO Auditor average salary in Australia

The average salary for ISO Auditor jobs in Australia is $101,250 per year.

Can you fail an ISO audit?

ISO 9001 lists clear document control requirements and it allows significant flexibility. Unfortunately, many businesses fail audits because they don't have adequate document control and an audit reveals inconsistencies.

What are the three types of ISO?

Three of the main ISO standards include the ISO 9001 for quality management, the ISO 14001 for environmental management, and the ISO 45001 for occupational health and safety management.

What are the 4 C's of auditing?

A successful internal audit function relies on four fundamental pillars, often referred to as the “4 C's”: Competence, Confidentiality, Communication, and Collaboration. These principles guide auditors in delivering meaningful and impactful results. Let's explore each of these elements in detail.

What are the 4 phases of audit?

Although every audit is unique, the audit process usually consists of four stages: Planning, Field work, Reporting and (for some audits) Follow-up. Engagement of the client, or the area being audited, is critical at every stage of the audit process.

What are the red flags during an audit?

Too many deductions taken are the most common self-employed audit red flags. The IRS will examine whether you are running a legitimate business and making a profit or just making a bit of money from your hobby. Be sure to keep receipts and document all expenses as it can make things a bit ore awkward if you don't.