Еконтроль
Back to Resources

What Happens During Stage 2 ISO Certification Audit: Step-by-Step Guide for Your Team

Stage 2 ISO certification audit with no surprises: hour-by-hour timeline of audit days, auditor questions, traceability tests, person-day calculation per IAF MD 5:2023.

Published May 7, 202611 min read
Stage 2 ISO certification audit opening meeting with lead auditor and company team

Stage 2 Without Stress: Why Sequence Beats Panic

An auditor arrives in 7 days. The team is on edge, the director keeps asking "what if something goes wrong," and the quality manager re-reads procedures one more time. That reaction is normal, but it rests on a myth that Stage 2 is an exam with unknown questions.

In reality, a Stage 2 certification audit is a structured review with a predictable sequence of steps, defined roles and clear rules of engagement for both sides. Those rules sit in ISO/IEC 17021-1:2015, §9.4 "Audit conduct," and every certification body (CB) is bound by them.

Knowing the sequence lets your team prepare without scrambling. Assign roles, place records where the auditor will look for them, and rehearse responses to typical questions. In this article we walk through the hour-by-hour logic of a 2 to 3-day Stage 2 audit, share an auditor time allocation matrix, and as a flagship piece, run a real duration calculation per IAF MD 5:2023 for three company sizes.

This is not textbook theory. It is the sequence we have observed across 200+ supported audits across ISO 9001, ISO 22000, FSSC 22000, ISO 14001, ISO 45001, on single-site and multi-site setups in Ukraine and for Ukrainian exporters.

Stage 1 vs Stage 2: The Key Difference

The certification cycle under ISO/IEC 17021-1 splits into two formal stages. Confusion often starts here: managers prepare for Stage 2 as if it were a continuation of Stage 1. They are different events with different objectives.

Stage 1 is a system readiness review. The auditor judges whether documentation is mature enough, whether Internal Audit and Management Review have already happened, whether the scope is clear, and whether evidence covers the baseline set of requirements. Stage 1 typically ends with a report listing areas of concern. These are not yet nonconformities, but risk signals.

Stage 2 is a review of how effectively the system runs in real operations. The auditor no longer asks "where is your procedure" but checks "how does it work day to day, and how can you prove it with records."

ParameterStage 1Stage 2
FocusSystem readiness: scope, documentation, maturitySystem effectiveness in practice: evidence, traceability
LocationOften off-site (document review) or 0.5–1 day on-siteAlways on-site, across all declared sites
DurationTypically 20–40% of Stage 2 time (per IAF MD 5)Full baseline duration per IAF MD 5:2023 tables
DeliverableStage 1 report with areas of concernStage 2 report with NCR (major/minor) + CB recommendation
Finding typesAreas of concern, opportunities for improvementMajor NC, Minor NC, OFI
ParticipantsTop mgmt + QM + key process ownersTop mgmt + QM + all process owners + operating personnel
OutputReadiness for Stage 2 (go/no-go)Recommendation to the certification body to issue the certificate
Follow-upClosing areas of concern before Stage 2Closing NCs within set deadlines (up to 3 months for major, up to 6 for minor)

If Stage 1 left you with 5+ areas of concern, do not walk into Stage 2 "as is." The risk of a major NC rises sharply, and re-running Stage 2 costs more than postponing. Run a pre-certification readiness assessment and close critical gaps first.

What Precedes Stage 2: Stage 1 Outcomes and the Audit Plan

Two to four weeks before Stage 2 the CB sends you a package: the Stage 1 closing report, an updated audit plan and the agenda. This is not a formality. It is your preparation brief.

How to read the Stage 1 report. Pay attention to the wording of areas of concern. They show where the auditor already sees risk and where they will return at Stage 2. If Stage 1 says "evidence of management review for 2025 not provided," prepare a complete 12-month package with minutes, inputs and outputs, and CAPA records.

How to read the audit plan. A standard Stage 2 plan covers dates, audit team composition, the list of audited processes mapped to clauses, time allocation across days, and the role of each company representative per session. Every line signals which of your people need preparation.

What to do 7 days before Stage 2:

  • Confirm the audit plan and notify the CB about conflicts (top mgmt travel, line stoppage).
  • Send personal briefs to each participant: when their session takes place, which questions to expect, which records to keep at hand.
  • Set up an audit room with internet access, projector and a separate desk for the auditor.
  • Verify all CAPAs from recent internal audits are closed or have a plan with realistic deadlines.
  • Run a short mock session with QM and top mgmt: 30 minutes, 5 typical questions.

The full 90-day preparation cycle is described in our 90-day certification audit preparation plan, covering Stage 2 along with the earlier gap analysis and internal audit phases.

Day 1: Opening Meeting + Initial Documentation Review

The first day is the most intense in terms of impressions and the most important in setting the tone. How the team behaves during the opening meeting shapes the atmosphere of the entire audit.

TimeActivityParticipantsKey artefacts
08:30 – 09:00Opening meetingAudit team + top mgmt + QM + all process ownersAudit plan, scope statement, list of evidence
09:00 – 10:30Top management interview (Leadership, §5)Lead auditor + CEO/directorPolicy, Quality Objectives, KPI, Management Review
10:30 – 12:00Documented information review §7.5Lead auditor + QMProcedure list, document control, version log
12:00 – 13:00Lunch break
13:00 – 15:00QM interview: planning, risks (§6), competence (§7)Lead auditor + QM + HRRisk register, training matrix, competence records
15:00 – 16:30Internal audit + Management Review review (§9)Lead auditor + Internal Auditor + QMIA programme, IA reports, MR minutes, CAPA log
16:30 – 17:00End-of-day debrief (internal for audit team)Audit teamAuditor working notes

Opening Meeting: 30 Minutes That Set the Tone

What the auditor says. The audit team leader introduces the team, confirms scope and audit criteria, reminds everyone about confidentiality and impartiality (a requirement of §5 ISO/IEC 17021-1), describes the sampling method, and explains that not every process will be checked. Sampling is the reason, so the absence of a question does not mean the area is "clean."

What the company says. The top manager opens with "we are ready for the review and open to cooperation." The QM introduces the company team and roles. There is no need to perform: the auditor evaluates the system, not the PR.

Common mistake. The team starts to defend itself before the auditor has even asked anything. Phrases like "well, we are not perfect, but…" create a negative impression before any evidence is reviewed.

At the opening meeting the auditor asks whether you have any impartiality complaints regarding the team. This is a formal requirement of ISO/IEC 17021-1 §5. If the audit team includes someone who consulted on your system within the last 2 years, that is grounds for objection. Do not hesitate to use that right.

Day 1-2: Process Walks and Staff Interviews

After the initial document review the auditor moves to the production floor or the office. This is the largest block of the audit by time, and the most stressful for line staff. Anxiety drops with preparation: when an operator knows 3 to 4 typical questions, they answer with confidence.

Auditor walking production line with process owner during Stage 2 audit
Process walk: the auditor traces actual process flow from input to output, asking the process owner specific questions.
RoleDurationTypical auditor questionsWhat to keep at hand
CEO / Director30 minHow do you demonstrate leadership? What are the system KPIs? When was the last Management Review? What decisions came out of it?Policy, MR minutes, KPI dashboard
Quality Manager / FSMS Manager2 hrsHow do you identify risks (§6.1)? How did you plan changes this year? How do you control documented information?Risk register, change log, document register
HR / Training30–45 minHow do you define competence requirements? How do you keep training records? How do you evaluate training effectiveness?Training matrix, training records, evaluation forms
Internal Auditor45 minHow was the IA programme planned? How were auditors selected? How was impartiality ensured? Are all NCs closed?IA programme, IA reports, auditor competence records
Production Manager1 hrHow do you control process parameters? What happens on deviation? How do you trace a product batch?Process control records, deviation log
Operator at CCP / critical operation30 min × NShow how you fill in this record. What do you do if the temperature falls outside limits? Whom do you notify?A working record, the workplace instruction
Maintenance / Calibration45 minWhat is the calibration plan? How do you identify equipment requiring calibration? What do you do with out-of-tolerance results?Calibration register, equipment list, certificates

What the Auditor Asks Staff and How to Prepare the Team

Questions for operators do not require theoretical knowledge of the standard. They check whether the person understands their operation, its risks and their role in the system. Three typical question formats:

  • Show me how you do it: the operator demonstrates the action (fills in a record, takes a measurement, checks a CCP).
  • What if?: a hypothetical scenario ("what do you do if the cooker temperature drops below 70°C?").
  • Trace it back: the auditor takes a finished-product batch and asks the operator to trace its components, production date, operator and lab control results.

Team preparation: 2 to 3 days before Stage 2, run 15 to 20-minute mock interviews with each key operator. Skip word-for-word rehearsal; teach the structure: "short answer → demonstration → record."

This stage is when auditors most often surface common nonconformities. Reviewing the top 15 typical nonconformities found at certification audits helps you close vulnerable areas before the CB arrives.

Day 2-3: Records Sampling and Traceability Tests

At this stage the auditor shifts from "how do you do it" to "prove with records that this happens every day." Records sampling is not a wall-to-wall check; it is a sample built on risk and representativeness.

Sampling logic. The lead auditor picks 3 to 10 batches, transactions or cases from the last 6 to 12 months. Selection criteria include a sample from a high-risk zone, a sample from a low-risk zone, and a sample from a period of a known event (customer complaint, equipment failure, personnel change).

A typical traceability test for ISO 22000 / FSSC 22000. The auditor takes 3 finished-product batches from different dates and asks you to:

  1. Trace each batch back to raw materials (lot numbers, supplier, CoA).
  2. Show CCP records at the time each batch was produced.
  3. Locate finished-product lab control results (microbiology, physical and chemical).
  4. Confirm training of the operator who performed the critical operation.
  5. Verify calibration of the equipment used.

The time norm for a full traceability test is 2 to 4 hours for 3 batches. If the team cannot pull these records within 30 minutes, this is a signal for a major NC under §8.3 (Traceability).

Before Stage 2, run your own traceability test: pick 2 to 3 batches from the last 6 months and walk the full path back to raw materials. If you find a record gap, that is a near-certain NC at Stage 2. A pre-audit by a consultant surfaces such gaps before the auditor arrives, while you can still close them without formal consequences.

How the Auditor Judges Sample Sufficiency

If the chosen 3 batches come up clean, the auditor will not conclude that "the system works." They add 2 to 3 more samples from adjacent areas. If one sample shows a gap, that is not automatically a major NC, but the auditor expands the sample to 5 to 7 to test whether it was random or systematic. Systematic patterns are what turn a minor into a major.

For ISO 9001 typical sampling looks different: customer orders, production work orders, product nonconformity records, complaints. For ISO 14001, the environmental aspects register, emissions monitoring, permits. For ISO 45001, incident reports, JSAs, occupational health and safety training records.

Final Day: Findings Consolidation and Closing Meeting

The penultimate activity is a closed working session by the audit team, lasting 1.5 to 2 hours without the company present. Auditors consolidate observations, classify them (Major NC / Minor NC / OFI / Strength) and prepare the presentation. Use this window for administrative matters and avoid trying to "learn the findings in advance." That creates pressure and lands badly.

Closing meeting of certification audit with presentation of findings
At the closing meeting the auditor presents findings — this is the moment for clarifying questions, not objections or excuses.
TypeDefinition (per ISO/IEC 17021-1 §9.4.9)Company response
Major NCA systemic failure or absence of a process that calls into question the system's ability to achieve planned resultsAcknowledge understanding, agree on a CAPA plan with deadlines (typically up to 3 months)
Minor NCA localised nonconformity that does not threaten system integrityAcknowledge understanding, agree on a CAPA plan with deadlines (up to 6 months)
OFI (Opportunity for Improvement)Not a breach of requirements, but a suggestion for improvementNote it down; the implementation decision sits with the company
StrengthSystem strengths worth recognisingShare with the team; this is a motivational tool

How to Respond to Findings: 3 Rules

1. Do not deny. Even if you feel the auditor is wrong, do not start arguing at the closing meeting. Say "thank you for the observation, we will review it" and ask for details.

2. Do not justify. Phrases like "we only have one person on this process" or "we discussed this with another auditor last year" work against you. The auditor does not weigh mitigating circumstances; they record a fact.

3. Ask clarifying questions. This is the professional response. "Could you clarify which clause you consider breached?" "What scope of records did you review when forming this conclusion?" "Is this a one-off or a systemic pattern?" Such questions give you information for a quality CAPA, not for an appeal.

If you fundamentally disagree with how an NC was classified, you have a formal right to file an appeal with the CB within the deadline set in the contract (typically 14 to 30 days). That is a different channel, not the closing meeting.

The lead auditor closes the meeting with a recommendation to the CB: "recommend for certification," "recommend for certification subject to closure of NC," or "not recommend." The certificate itself is issued not by the auditor but by an independent certification committee within the CB after CAPA review. This is a requirement of §9.5 ISO/IEC 17021-1.

Auditor Time Allocation Matrix: Where the Auditor's Hours Go

Knowing how the auditor spends their time lets you align your own resources accordingly. The matrix below is based on data from 200+ supported Stage 2 audits and aligns well with ISO 19011:2018 recommendations on the distribution of audit activity.

Activity% of timeWhat the company should prepare
Opening meeting5%Attendee list, conference room, projector
Document review (procedures, policy, evidence)25%Document register with versions, controlled copies
Floor walk / shop floor visit20%Clear walkways, current instructions at workstations, operator readiness
Interviews (top mgmt, process owners, operators)30%Role briefs, people available in declared slots
Records sampling + traceability tests15%Access to 12-month record archive, fast retrieval (5 min per batch)
Closing meeting + closed working session5%The same room, full company attendance

If the audit plan looks unbalanced (for example, 60% of time on document review and 5% on floor walk), that is a reason to ask the lead auditor whether the plan matches the scope. Imbalance often points to an inexperienced auditor or a planning error.

Worked Example: Person-Day Calculation per IAF MD 5:2023

Stage 2 duration is not an arbitrary number. It is calculated by the formula in IAF MD 5:2023 ("Determination of Audit Time of Quality, Environmental, and Occupational Health & Safety Management Systems"). This document is mandatory for all IAF-recognised certification bodies. Unfortunately, only 2 of the top 10 English-language articles on certification cite MD 5 at all, and none of them publishes the formula. Let us walk through it with examples.

Base Formula

H = base table × adjustment factors

Where:

  • Base table: Table QMS-1 / EMS-1 / OHS-1 from MD 5, which gives H in person-days as a function of the effective number of personnel.
  • Adjustment factors: upward (high complexity, new standard, no previous certification) or downward (mature system, recertification, integrated systems).

For Stage 1 + Stage 2 combined, the base table gives total H. Stage 1 typically takes about 30% of the initial certification audit, Stage 2 the remaining 70%.

Effective number of personnel = total headcount minus personnel performing the same functions on the same shifts. So 50 operators across 3 shifts performing the same function count as 50 effective, not 150.

ScenarioEffective personnelBase H (Stage 1 + 2)AdjustmentsFinal person-days
50 employees, ISO 9001 single site, new certification50≈ 3 (Table QMS-1: range 26–65 → 3 days)low complexity (–0%), single site (×1.0)≈ 3 person-days (Stage 1 ≈ 1, Stage 2 ≈ 2)
200 employees, FSSC 22000 multi-site (3 sites of ≈70 people)200≈ 5 (Table FSMS — range 176–275 → 5 days for head office)+ ≈ 1.5 per production site (Annex 3 MD 5) = +3≈ 5 + 3 = 8 person-days (of which Stage 2 ≈ 5.5)
500 employees, integrated 9001 + 14001 + 45001500≈ 8 (Table QMS-1: range 426–625 → 8 days as baseline)EMS +30%, OHS +30%, integrated discount –20%≈ 8 × 1.3 × 1.3 × 0.8 ≈ 11 person-days (Stage 2 ≈ 7.5)

How to Read the IAF MD 5:2023 Tables

Table 1 (QMS-1) and Table 2 (EMS-1) are the base tables for ISO 9001 and ISO 14001. The left column lists ranges of effective personnel; the right column gives H in person-days for the initial audit (Stage 1 + Stage 2 combined).

Table 3 (OHS-1) covers ISO 45001. The calculation works the same way as QMS-1, but with a higher base time due to the specifics of OH&S.

Annex 3 governs multi-site sampling: each additional production site adds about 1 to 2 person-days depending on complexity. If you operate 3 similar warehouses, that is not 3× the time but roughly 1.3× the base H thanks to sampling.

Integrated audit discount: when you certify ISO 9001 + ISO 14001 + ISO 45001 in one go, MD 5 allows a 10–30% reduction in total duration thanks to shared elements (Leadership, Document Control, Internal Audit, Management Review).

Surveillance audits = ⅓ of initial. Recertification audit = ⅔ of initial. Multi-site sampling details are well covered in the European Accreditation FAQ Question 38-2.

If a CB offers a Stage 2 duration significantly below the MD 5 calculation (for example, 1 day for 200 employees), that is a red flag. Either the CB is breaching MD 5 or it has not factored in the scope. The risk that IAF accreditation will refuse to recognise your certificate is real. The certificate may be invalidated within 1 to 2 years following IAF peer review.

Knowing the MD 5 calculation lets you compare commercial proposals from different CBs on solid ground. If the price differs by 20% but person-days differ by 50%, one CB is either underestimating time (a quality risk) or overestimating it (a commercial premium). Order our audit support service and we will check the calculations and surface such discrepancies before you sign the contract.

What Happens After Stage 2

The closing meeting is not yet certification. What follows:

  • 0–14 days: the lead auditor finalises the audit report and submits it to the CB.
  • 14–30 days: you submit a CAPA plan for every NC with root-cause analysis and deadlines.
  • 30–90 days: CAPA implementation, providing closure evidence.
  • 90–120 days: the independent certification committee within the CB reviews the package and makes the certification decision.
  • 120–150 days: issuance of the certificate (typically valid for 3 years on a one-third-yearly surveillance cycle).

Once the certificate is issued, a different phase begins: keeping the system in shape. Annual system support helps avoid losing form between surveillance audits, which is what typically happens to companies in their second year after certification.

If you need to look at the full 3-year cycle or prepare your team for a specific certification under ISO 9001 or ISO 22000, get in touch and we will model the time and budget for your scope.

Frequently Asked Questions

The most common questions about Stage 2 of an ISO certification audit, drawn from the practice of 200+ supported audits and the corresponding Google PAA queries.

Tags

Frequently Asked Questions

Find answers to common questions about this topic