The certification journey: Stage 1, Stage 2, and the three-year cycle
Lesson 3 of 5 in Certification, Audit, and Integrated Management Systems: ISO/IEC 42006.
Certification is not an event; it is a three-year relationship with a defined choreography. Learn the choreography and you can plan evidence, budget, and nerves around it. Skip a step and you discover it at the worst possible moment — usually mid-audit.
The journey starts long before an auditor arrives. A readiness or gap assessment (internal or bought-in) maps your current state against clauses 4–10 and Annex A. Many organisations then buy an optional pre-assessment from their chosen CB — a dry run that surfaces embarrassments cheaply. Neither is required; both are how experienced teams avoid failing in public.
Then come the two stages that matter. Stage 1 is the documentation and readiness review: the auditor examines your AIMS scope, AI policy, risk and impact assessment methodology, SoA, and — critically — whether your internal audit and management review have actually run. Stage 1 answers one question: is this organisation ready for Stage 2? Stage 2 is the implementation audit: interviews, records, sampled evidence that the system you documented is the system you operate. Findings are classified, corrective actions agreed, and an independent decision-maker at the CB — never the audit team itself, per 17021-1 — grants or withholds the certificate.
From gap analysis to recertification
- AIMS operating
Clauses 4–10 implemented; evidence accumulating. You need months of operating records — an AIMS switched on last week has nothing to audit.
- Gap / readiness assessment
Internal or consultant-led mapping against 42001. Output: remediation list. Optional CB pre-assessment can follow.
- Stage 1 audit
Documentation and readiness review: scope, policy, risk methodology, SoA, evidence that internal audit and management review have run. Often partly remote.
- Ready for Stage 2?
Stage 1 output is a readiness conclusion plus areas of concern. Serious gaps mean fix first — proceeding anyway converts Stage 1 concerns into Stage 2 nonconformities.
- Close readiness gaps
Typical Stage 1 killers: internal audit never performed, management review missing, SoA justifications boilerplate, scope statement vague.
- Stage 2 audit
On-site/remote implementation audit: interviews, record sampling, walkthroughs of lifecycle, data, and supplier controls. Findings classified as major NC, minor NC, or observation.
- Major nonconformities?
Majors block certification until corrected and verified — possibly via a follow-up audit. Minors need an accepted corrective action plan.
- Corrective action + verification
Root-cause analysis, correction, corrective action, evidence of effectiveness — on the clock the CB sets (often 90 days for majors).
- Certification decision
Made by CB personnel independent of the audit team (17021-1). Certificate issued with a precise scope statement; valid three years.
- Surveillance audits (years 1 & 2)
Annual, narrower than Stage 2: mandatory themes (internal audit, management review, complaints, use of marks, changes) plus rotating samples of clauses and controls.
- Recertification (year 3)
Full re-audit before certificate expiry, plus review of the whole cycle’s performance. Then the cycle restarts.
- Certified — and staying certified
Certification is maintained, suspended, or withdrawn based on cycle performance. Suspension for unresolved NCs is real and public.
Three planning realities deserve emphasis.
Evidence has a minimum age. Stage 2 samples operating records: risk assessments performed at planned intervals, impact assessments tied to real systems, monitoring data, a completed internal audit, a management review with genuine outputs. Most organisations need three to six months of AIMS operation before Stage 2 has anything to bite on. Certification-by-Christmas projects fail on this arithmetic, not on ambition.
The gap between Stage 1 and Stage 2 is a gift. CBs typically schedule weeks between stages. Use them: every ‘area of concern’ in the Stage 1 report is a preview of a Stage 2 finding.
Surveillance is not a smaller Stage 2 — it is a memory test. Year-1 and year-2 surveillance audits always check whether internal audits and management reviews kept happening, whether corrective actions from last time were effective, and how the AIMS absorbed change: new AI systems, new suppliers, new regulation. The organisations that struggle at surveillance are the ones that treated certification day as the finish line.
Key terms: stage 1 audit, stage 2 audit, surveillance audit, recertification, certification cycle
Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.