The certification journey: Stage 1, Stage 2, and the three-year cycle

Lesson 3 of 5 in Certification, Audit, and Integrated Management Systems: ISO/IEC 42006.

Certification is not an event; it is a three-year relationship with a defined choreography. Learn the choreography and you can plan evidence, budget, and nerves around it. Skip a step and you discover it at the worst possible moment — usually mid-audit.

The journey starts long before an auditor arrives. A readiness or gap assessment (internal or bought-in) maps your current state against clauses 4–10 and Annex A. Many organisations then buy an optional pre-assessment from their chosen CB — a dry run that surfaces embarrassments cheaply. Neither is required; both are how experienced teams avoid failing in public.

Then come the two stages that matter. Stage 1 is the documentation and readiness review: the auditor examines your AIMS scope, AI policy, risk and impact assessment methodology, SoA, and — critically — whether your internal audit and management review have actually run. Stage 1 answers one question: is this organisation ready for Stage 2? Stage 2 is the implementation audit: interviews, records, sampled evidence that the system you documented is the system you operate. Findings are classified, corrective actions agreed, and an independent decision-maker at the CB — never the audit team itself, per 17021-1 — grants or withholds the certificate.

From gap analysis to recertification

  1. AIMS operating

    Clauses 4–10 implemented; evidence accumulating. You need months of operating records — an AIMS switched on last week has nothing to audit.

  2. Gap / readiness assessment

    Internal or consultant-led mapping against 42001. Output: remediation list. Optional CB pre-assessment can follow.

  3. Stage 1 audit

    Documentation and readiness review: scope, policy, risk methodology, SoA, evidence that internal audit and management review have run. Often partly remote.

  4. Ready for Stage 2?

    Stage 1 output is a readiness conclusion plus areas of concern. Serious gaps mean fix first — proceeding anyway converts Stage 1 concerns into Stage 2 nonconformities.

  5. Close readiness gaps

    Typical Stage 1 killers: internal audit never performed, management review missing, SoA justifications boilerplate, scope statement vague.

  6. Stage 2 audit

    On-site/remote implementation audit: interviews, record sampling, walkthroughs of lifecycle, data, and supplier controls. Findings classified as major NC, minor NC, or observation.

  7. Major nonconformities?

    Majors block certification until corrected and verified — possibly via a follow-up audit. Minors need an accepted corrective action plan.

  8. Corrective action + verification

    Root-cause analysis, correction, corrective action, evidence of effectiveness — on the clock the CB sets (often 90 days for majors).

  9. Certification decision

    Made by CB personnel independent of the audit team (17021-1). Certificate issued with a precise scope statement; valid three years.

  10. Surveillance audits (years 1 & 2)

    Annual, narrower than Stage 2: mandatory themes (internal audit, management review, complaints, use of marks, changes) plus rotating samples of clauses and controls.

  11. Recertification (year 3)

    Full re-audit before certificate expiry, plus review of the whole cycle’s performance. Then the cycle restarts.

  12. Certified — and staying certified

    Certification is maintained, suspended, or withdrawn based on cycle performance. Suspension for unresolved NCs is real and public.

Three planning realities deserve emphasis.

Evidence has a minimum age. Stage 2 samples operating records: risk assessments performed at planned intervals, impact assessments tied to real systems, monitoring data, a completed internal audit, a management review with genuine outputs. Most organisations need three to six months of AIMS operation before Stage 2 has anything to bite on. Certification-by-Christmas projects fail on this arithmetic, not on ambition.

The gap between Stage 1 and Stage 2 is a gift. CBs typically schedule weeks between stages. Use them: every ‘area of concern’ in the Stage 1 report is a preview of a Stage 2 finding.

Surveillance is not a smaller Stage 2 — it is a memory test. Year-1 and year-2 surveillance audits always check whether internal audits and management reviews kept happening, whether corrective actions from last time were effective, and how the AIMS absorbed change: new AI systems, new suppliers, new regulation. The organisations that struggle at surveillance are the ones that treated certification day as the finish line.

Key terms: stage 1 audit, stage 2 audit, surveillance audit, recertification, certification cycle

Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.