Stage 1 Audit
Definition
The documentation review phase of the initial certification audit. The auditor checks that the ISMS documentation exists, the scope is defined, the risk assessment has been performed, and the organisation is ready for a Stage 2 on-site assessment.
- Focus
- ISMS documentation review
- Checks
- Scope definition, risk assessment, documentation existence
- Precedes
- Stage 2 on-site audit
- Standard
- ISO/IEC 27001 certification process
Common questions
What happens if an organisation fails Stage 1?+
The certification body typically identifies the documentation gaps and the organisation must address them before Stage 2 can proceed, since Stage 2 assumes the documented ISMS foundation Stage 1 is meant to confirm exists.
Is Stage 1 conducted on-site?+
It can be conducted remotely or on-site depending on the certification body's practice, since its focus is reviewing documents rather than observing operational controls in action, which is reserved for Stage 2.
Related terms
- Accreditation Body (AB)
- A national body that assesses and formally recognises the competence of certification bodies. Notable examples: UKAS (UK), DAkkS (Germany), COFRAC (France), NABCB...
- Certification Body (CB)
- An independent third-party organisation accredited to audit and certify that an ISMS conforms to ISO 27001. Examples include BSI, Bureau Veritas, DNV,...
- Major Nonconformity
- A finding that indicates the ISMS is absent in a required area or has failed systemically. Must be resolved with verified evidence...
- Minor Nonconformity
- A single lapse or gap that does not indicate systemic failure. The organisation must provide a corrective action plan and close the...
- Stage 2 Audit
- The on-site certification audit. The auditor tests whether controls described in the documentation are implemented and operating effectively. A Stage 2 pass...