Your organization may have policies and procedures, deliver training, hold regular meetings, and maintain extensive records—and still not be ready for an external assessment leading to ISO certification.
Conversely, it may be closer to readiness than expected. Many management-system requirements may already be embedded in existing operations but require better organization, documentation, integration, or alignment with the relevant standard.
This is where an ISO Gap Analysis becomes valuable.
A Gap Analysis is not intended to prove that an organization is “good” or “bad,” nor is it an exercise in identifying the largest possible number of deficiencies. Its primary purpose is to answer a clear management question:
Where are we now compared with the requirements of the standard, and what must be addressed before proceeding to an external assessment?
At IAC, this concept aligns directly with a core operating principle:
Analysis precedes the solution, and understanding precedes implementation.
What Is a Gap Analysis in ISO Management Systems?
A Gap Analysis is a structured assessment that compares an organization’s current state with the requirements of the target standard.
For example, when an organization is preparing to implement a quality management system, the question is not simply:
“Do we have ISO 9001?”
Instead, each relevant area is examined to determine:
- What is currently in place?
- What already meets the requirement?
- What exists but needs further development?
- What is not being implemented?
- What evidence is available?
- What risks arise from the gap?
- Which issues should be addressed first?
The results should then be converted into an implementation roadmap, rather than remaining a list of observations.
ISO itself refers to Gap Analysis as a practical tool in contexts such as developing management systems and transitioning between editions. For example, when moving to ISO 14001:2026, organizations are advised to review the new edition, conduct a Gap Analysis against their existing system, develop a transition roadmap, and strengthen internal readiness.
Is a Gap Analysis the Same as an Internal Audit?
No.
This distinction is essential before beginning an ISO implementation project.
Gap Analysis
A Gap Analysis primarily asks:
What is the distance between our current state and the requirements we intend to meet?
It is normally used during the diagnostic stage, whether the organization is:
- Building a management system for the first time.
- Improving an existing system.
- Expanding its scope.
- Integrating several standards.
- Transitioning to a new edition.
Internal Audit
An internal audit asks:
Does the management system we have chosen to implement operate effectively and conform to the applicable requirements and the organization’s own arrangements?
ISO classifies internal auditing as a first-party audit, meaning that it is conducted by or on behalf of the organization for its own purposes.
External audits may be conducted as second-party or third-party audits. A third-party audit may lead to certification when it is performed by an independent certification body.
A Gap Analysis should therefore not be used as a substitute for an internal audit.
Guidance from the ISO 9001 Auditing Practices Group also indicates that activities performed before certification should not be treated as replacements for the organization’s internal audit process.
Is a Gap Analysis the Same as a Certification Audit?
Again, no.
A Gap Analysis is a diagnostic activity that helps the organization understand its present condition and determine the work required.
When an organization chooses to obtain certification, the assessment is conducted by an independent Certification Body against the requirements of the relevant standard.
ISO develops and publishes standards, but it does not certify organizations or issue ISO certificates.
The three activities therefore serve different purposes:ActivityPrimary purposeGap AnalysisDiagnose the difference between the current state and the target requirementsInternal AuditEvaluate internally whether the implemented system conforms and operates effectivelyCertification AuditProvide an independent assessment by a certification body
Confusing these activities may lead an organization to begin the certification process before its management system is ready.
Why Conduct a Gap Analysis Before Writing Procedures?
Many organizations already have practices that meet parts of an ISO management-system standard.
They may already have:
- A supplier-evaluation process.
- A mechanism for handling customer complaints.
- A maintenance programme.
- Safety procedures.
- Performance-review meetings.
- Training records.
- Document-control practices.
- Emergency plans.
However, these practices may not yet be managed as an integrated and structured ISO management system.
If the organization begins by writing procedures without understanding what is already in place, it may end up reinventing existing processes.
This leads to one of the most common implementation mistakes:
Building the management system around the wording of the standard instead of integrating the standard into the organization’s operational reality.
The better approach is to understand the current process first and then determine what should be:
- Retained.
- Improved.
- Documented.
- Connected to another process.
- Simplified.
- Replaced or removed.
Step Zero: Confirm the Standard, Edition, and Scope
Before assessing any gaps, define the reference against which the organization will be evaluated.
Start by identifying the target standard, such as:
- ISO 9001.
- ISO 45001.
- ISO 14001.
- Another relevant management-system standard.
Next, confirm the applicable edition that the organization intends to implement.
Then define the scope of the management system.
Will it cover:
- The entire company?
- A single branch?
- One factory?
- Several operational sites?
- Specific products or services?
- Particular business units or processes?
A Gap Analysis cannot produce reliable results when the intended scope is unclear.
In 2026, organizations should also avoid relying on outdated checklists without verifying the current edition of the relevant standard. Several management-system references have recently been updated, including ISO 14001:2026 and ISO 19011:2026.
Step One: Understand the Organization’s Context Before Examining Its Documents
A strong Gap Analysis does not begin by asking:
“Where is the quality manual?”
It begins by understanding the organization itself.
The assessment should consider:
- What products or services does the organization provide?
- Who are its customers and other relevant interested parties?
- What are its principal processes?
- Which legal and regulatory requirements apply?
- What are its principal risks?
- How are decisions made?
- Which locations are included in the system?
- How are responsibilities distributed?
- What current problems led management to pursue ISO implementation?
This information shapes the management system the organization actually needs.
The same standard may apply to two companies, but the structure of their systems, operational risks, documented information, and control requirements may differ substantially.
Step Two: Assess Reality, Not Documents Alone
The weakest Gap Analysis is one conducted entirely inside a meeting room.
The existence of a written procedure does not prove that the process is functioning.
A proper assessment should examine three levels.
1. What Is Written?
This may include:
- Policies.
- Procedures.
- Forms.
- Records.
- Plans.
- Work instructions.
2. What Do Employees and Process Owners Say?
The assessor should determine:
- How do they understand the process?
- Who makes decisions?
- Who provides approval?
- What happens when a problem occurs?
- How are issues escalated?
3. What Actually Happens?
The assessment should include:
- Observing activities.
- Selecting samples.
- Reviewing records.
- Tracing a transaction, product, request, incident, or service from beginning to end.
The comparison should follow this sequence:
Written → Understood → Implemented → Supported by Evidence
If these levels do not correspond, a gap exists even when the formal procedure appears excellent.
Step Three: Evaluate Each Requirement Using Measurable Categories
Instead of classifying requirements only as “implemented” or “not implemented,” use categories that provide more value to decision-makers.
A practical classification may include:
Conforming
The requirement is implemented, and appropriate evidence demonstrates that it operates effectively.
Partially Conforming
Some implementation exists, but it is incomplete, inconsistent, insufficiently controlled, or does not cover the required scope.
Nonconforming
The requirement is not implemented, or sufficient evidence of implementation is unavailable.
Not Applicable
This classification should be used only when the standard permits non-applicability and the organization can justify it properly.
Opportunity for Improvement
The requirement is met, but an opportunity exists to make the process more efficient, effective, or sustainable.
This approach turns the Gap Analysis into a decision-making tool instead of a simple pass-or-fail checklist.
Step Four: Request Evidence Before Assigning a Readiness Rating
An organization should not receive a high readiness rating merely because someone says:
“We always do that.”
The next question must be:
What is the evidence?
Evidence may include:
- A record.
- A report.
- A performance indicator.
- Meeting minutes.
- An inspection result.
- A training record.
- A supplier evaluation.
- A corrective-action record.
- A management-review output.
- A risk register.
- An audit result.
Management-system auditing is based on collecting and evaluating evidence. ISO 19011:2026 provides current international guidance on management-system auditing principles, managing audit programmes, and conducting audits.
IAC’s audit programmes likewise follow an evidence-based approach that includes audit planning, structured checklists, evidence tracing, and the management of nonconformities.
Step Five: Do Not Give Every Gap the Same Weight
Not every deficiency has the same effect on readiness.
There is a substantial difference between:
- A form requiring a minor amendment.
- A critical process that is not controlled.
- The absence of an applicable legal-compliance evaluation.
- Failure to conduct an internal audit.
- A systemic weakness in leadership, responsibilities, or risk management.
The gaps should therefore be prioritized.
A practical classification may include:
Critical
The gap prevents readiness or creates a major risk to the management system, operational control, or compliance.
High Priority
The gap should be addressed before the external assessment.
Medium Priority
The issue requires development under a defined action plan.
Improvement Opportunity
The issue may not prevent readiness but could improve the effectiveness or simplicity of the system.
The objective is not to produce the longest possible list of observations. It is to help management identify:
What must be addressed first?
Step Six: Assess Effectiveness, Not Merely the Existence of Documents
Consider an organization that has a formal complaints procedure.
Does the existence of the procedure mean that the related requirement is fully addressed?
Not necessarily.
The Gap Analysis should ask:
- Are all complaints recorded?
- Are they categorized?
- Is responsibility for handling them clearly assigned?
- Are recurring causes analyzed?
- Are corrective actions taken when needed?
- Are responsible managers informed of complaint trends?
- Is the information used to improve products or services?
If the document exists but the process produces no meaningful result, the organization’s real readiness is lower than its documented readiness.
This is consistent with IAC’s emphasis on creating a “living” management system that supports decisions and performance, rather than a collection of documents prepared solely for certification.
Step Seven: Examine Responsibilities and Authorities
A common gap identified during assessments is that everyone understands the activity generally, but no one formally owns it.
For each process, determine:
- Who is the process owner?
- Who performs the activity?
- Who approves the result?
- Who monitors the performance indicator?
- Who makes decisions when performance deviates?
- Who retains the evidence?
- Who closes the corrective action?
A process without clear ownership remains fragile even when the supporting documents appear complete.
Step Eight: Examine Legal and Regulatory Requirements
This is particularly important for standards such as:
- ISO 45001.
- ISO 14001.
- ISO 22000.
- Other sector-specific management systems.
Maintaining a file titled “Laws and Regulations” is not sufficient.
The organization should be able to determine:
- Which requirements actually apply?
- How are new and amended requirements identified?
- Who monitors regulatory changes?
- How are legal requirements translated into operational obligations?
- What evidence demonstrates compliance?
- How are compliance gaps addressed?
IAC’s management-system services therefore include aligning the system with the organization’s legislative and regulatory context and conducting compliance-related reviews where applicable.
Step Nine: Evaluate Process Performance and Risk
A Gap Analysis should not be limited to the clauses of the standard.
It should also examine the organization’s principal processes.
For every process, ask:
- What is its objective?
- What are its inputs and outputs?
- Who is responsible?
- What are its risks?
- What controls are in place?
- How is performance measured?
- What happens when the process fails?
- What evidence demonstrates its effectiveness?
This changes the exercise from a:
Clause-by-Clause Check
into a:
Management-System Readiness Assessment
The latter is generally more useful to management because leadership needs to know whether the system can operate effectively—not whether employees can recite clause numbers.
Step Ten: Confirm That Internal Auditing Is in Place
Internal auditing is a critical checkpoint before an external assessment.
ISO classifies internal auditing as a first-party audit, while ISO 19011 provides guidance for planning, conducting, and managing management-system audits.
A Gap Analysis should determine:
- Is there an internal audit programme?
- Does it cover the intended scope?
- Is the programme based on process importance, risk, and previous results?
- Are auditors competent for the assigned activities?
- Is sufficient evidence collected?
- Are nonconformities properly documented?
- Are their causes addressed?
- Is the effectiveness of corrective actions verified?
ISO 9001 auditing-practice guidance indicates that risk-based thinking can be used when determining the frequency, duration, scope, and structure of the internal audit programme.
Step Eleven: Examine Management Review
The existence of minutes titled “Management Review” is not enough.
The evidence should demonstrate that top management reviewed the management system and made decisions.
The Gap Analysis should ask whether management considered:
- System performance.
- Audit results.
- Risks.
- Objectives.
- Nonconformities.
- Resources.
- Relevant changes.
- Opportunities for improvement.
The review should produce clear outputs, such as:
Decision → Owner → Target Date → Required Resources → Follow-Up
ISO and IAF guidance concerning the expected outcomes of accredited certification identifies effective internal auditing and management review as important elements of a functioning system, together with monitoring, measurement, analysis, evaluation, and improvement.
Step Twelve: Review Previous Nonconformities and Problems
The way an organization handled previous problems can provide some of the strongest evidence of its actual readiness.
Select samples from areas such as:
- Customer complaints.
- Operational errors.
- Incidents.
- Audit findings.
- Supplier problems.
- Regulatory violations.
- Nonconformities.
Then ask:
- Was only the immediate symptom corrected?
- Was the cause analyzed?
- Was a corrective action defined?
- Was it implemented?
- Was its effectiveness evaluated?
- Did the same problem occur again?
Closing the form does not necessarily mean that the problem has been closed.
How Can ISO Readiness Be Scored?
An organization may create an internal readiness index to help prioritize actions and monitor implementation progress.
The assessment could be distributed across areas such as:
- Organizational context and leadership.
- Planning and risk management.
- Operations.
- Documented information.
- Competence and awareness.
- Monitoring and measurement.
- Compliance evaluation, where applicable.
- Internal auditing.
- Management review.
- Corrective action and improvement.
Different weights may be assigned according to operational importance and risk.
However, the organization should not conclude:
“We achieved 87%, so we will pass the certification audit.”
There is no universal percentage that guarantees a certification decision.
A readiness score is an internal management tool for prioritizing work and measuring progress. It is not a guarantee of certification.
This approach is consistent with IAC’s policy of avoiding guarantees concerning certification, accreditation, or absolute outcomes.
What Should a Gap Analysis Report Contain?
An effective report does not need to contain dozens of pages of general commentary.
For each gap, it should clarify:
Requirement
What does the management system expect?
Current State
What was found during the assessment?
Evidence
What information supports the assessment?
Gap
What is missing, incomplete, or ineffective?
Priority
How significant is the issue?
Recommendation
What action is required?
Proposed Owner
Who should be responsible for implementation?
Target Date
When should the action be completed?
With this structure, the assessment report becomes an actionable implementation plan.
Example of an ISO Gap Analysis Matrix
AreaCurrent stateIdentified gapPriorityRequired actionManagement-system scopeA general scope exists but has not been formally definedIncluded sites, processes, products, or services are unclearHighReview, define, and approve the management-system scopeRisk managementRisk-related practices exist in separate departmentsThere is no unified methodology for assessment, ownership, and follow-upHighDevelop a risk-management methodology and risk registerTraining and competenceTraining-attendance records are availableRoles are not clearly linked to required competenciesMediumDevelop a competency matrixInternal auditNo internal audit has been conductedThere is no evidence that the system has been evaluated internallyCritical before external assessmentDesign and implement an internal audit programmeCorrective actionA corrective-action form existsThe effectiveness of completed actions is not evaluatedHighAdd and implement an effectiveness-verification stageManagement reviewGeneral management meetings are heldMeetings do not systematically address management-system inputs and outputsHighConduct a comprehensive management review
This table is an illustrative example only. The actual assessment criteria will depend on the applicable standard, the management-system scope, the organization’s activities, and its risk profile.
When Is an Organization Clearly Not Ready for an External Assessment?
Several warning signs require attention:
- The system exists mainly in the ISO coordinator’s files rather than in operational processes.
- Employees do not understand their responsibilities.
- Written procedures differ substantially from actual practices.
- No genuine internal audit has been completed.
- Management has not formally reviewed the system.
- Previous nonconformities remain open or continue to recur.
- Applicable legal and regulatory requirements have not been identified.
- Performance indicators exist without reliable data or analysis.
- Most records were created immediately before the scheduled audit.
- Employees expect the quality or ISO coordinator to answer every auditor question.
These signs do not mean that certification is impossible. They indicate that the organization should strengthen the system before proceeding to the external assessment.
When Is an Organization Closer to Readiness?
Readiness is stronger when:
- Processes operate as defined.
- Responsibilities are clear.
- Risks are understood and managed.
- Records are generated naturally through normal operations.
- Employees understand their roles.
- Performance indicators are measured and discussed.
- Applicable legal requirements are identified and evaluated.
- Internal audits reveal actual problems.
- Corrective actions address root causes.
- Management uses system information when making decisions.
The objective is not to create an organization with no problems.
A mature management system does not hide problems. It detects them, addresses them, and learns from them.
What Happens After the Gap Analysis?
A Gap Analysis is not the end of the project.
Its results should be converted into an implementation roadmap.
A practical sequence is:
- Identify the gaps.
- Prioritize them according to risk and significance.
- Design or improve the required processes and controls.
- Implement the changes in actual operations.
- build the capabilities of employees and process owners.
- Collect evidence that the system is operating.
- Conduct the internal audit.
- Address the resulting nonconformities.
- Conduct management review.
- Complete a final readiness review.
The organization can then determine the appropriate time to begin the external assessment process.
This sequence aligns closely with IAC’s methodology:
Objective Diagnosis → Tailored Design → Phased Implementation → Internal Capability Building → Impact Measurement
What Happens During Stage 1 of a Certification Audit?
A Gap Analysis should not be confused with Stage 1 of an initial certification audit.
ISO 9001 auditing-practice guidance describes Stage 1 as a stage intended primarily to understand the management system and its scope and to support planning for the subsequent part of the certification process.
Stage 1 is therefore not the ideal time for the organization to discover for the first time that its system is fundamentally unprepared.
The organization should preferably enter the certification process after it has:
- Addressed the principal gaps.
- Implemented the core system.
- Collected operating evidence.
- Conducted an internal audit.
- Completed management review.
- Addressed significant nonconformities.
Does an Organization Need a Consultant to Conduct a Gap Analysis?
Not necessarily.
If the organization has competent internal personnel who understand the standard, know its operations, and can conduct an objective assessment, the Gap Analysis may be completed internally.
An independent external perspective may nevertheless be useful when:
- The organization is implementing the standard for the first time.
- Several locations or complex processes are included.
- An old system requires significant redesign.
- Nonconformities continue to recur.
- Several standards are being integrated into an IMS.
- Management needs an independent view of its risks and priorities.
The central question is not simply:
“Who conducted the assessment?”
It is:
Was the assessment objective, evidence-based, and capable of producing actionable management decisions?
What Is IAC’s Role in ISO Gap Analysis?
IAC’s official consulting catalogue identifies current-state assessment and Gap Analysis as part of its management-systems consulting pathway.
Depending on the organization’s needs, this may be followed by:
- Management-system design.
- Development of policies, procedures, and operational controls.
- Capability building.
- Internal auditing.
- Management review support.
- Structured preparation for external assessment.
IAC does not treat a gap solely as missing documentation.
Its methodology is governed by four principles:
Analysis before the solution.
Understanding before implementation.
Decision before system design.
Impact as the measure of success.
A useful Gap Analysis should therefore enable management to answer:
- Where are we now?
- What is missing?
- What are the priorities?
- What risks arise from the gaps?
- Who should be responsible?
- What is the realistic path towards an applicable and auditable management system?
Frequently Asked Questions About ISO Gap Analysis
Is a Gap Analysis Mandatory for ISO Certification?
A distinction must be made between a diagnostic tool and the formal requirements of the management system.
Gap Analysis is a practical method for assessing the current state, gaps, and readiness. It should not be confused with an internal audit required by the management system or with the certification body’s assessment.
ISO itself recommends Gap Analysis as a practical tool in contexts such as transitioning to ISO 14001:2026.
What Is the Difference Between a Gap Analysis and a Pre-Audit?
These terms may be used differently by different providers. The scope and purpose of the service should therefore be defined in writing before the engagement begins.
In this article, Gap Analysis means assessing the organization’s current state against the applicable requirements to develop a remediation plan. It is not a certification audit and does not produce a certification decision.
Can a Gap Analysis Be Conducted Before Any Management System Has Been Developed?
Yes.
This is one of its most important applications. It identifies practices that already exist and determines what must be built, improved, connected, or documented.
Can We Use a Checklist Downloaded from the Internet?
A checklist may be used as an organizational aid if it relates to the correct edition of the standard.
However, a checklist alone is insufficient. The assessment must also consider:
- The organization’s context.
- Its processes.
- Its risks.
- Available evidence.
- Actual implementation.
- Process effectiveness.
How Long Does a Gap Analysis Take?
There is no single duration suitable for every organization.
The required time depends on:
- The standard.
- The proposed scope.
- The number of sites.
- The number and complexity of processes.
- The organization’s size.
- The maturity of the existing system.
Does a Gap Analysis Guarantee That We Will Pass the Certification Audit?
No.
A well-conducted Gap Analysis can improve visibility, help the organization address deficiencies, and strengthen readiness. It cannot guarantee the decision of an independent certification body.
Must Every Opportunity for Improvement Be Closed Before the External Assessment?
Not necessarily.
The organization should distinguish between:
- A gap affecting conformity or system effectiveness.
- An opportunity to improve a requirement that is already adequately fulfilled.
Actions should then be prioritized according to risk, significance, and readiness needs.
Conclusion
A Gap Analysis is not an examination intended to produce a score or percentage.
It is an organizational diagnosis that shows the distance between the current reality and the requirements of the intended management system.
An effective analysis does not stop at asking:
Do we have a procedure?
It asks:
- Is the process defined?
- Is it implemented?
- Who owns it?
- What are its risks?
- What evidence is available?
- Is its effectiveness measured?
- What happens when it fails to achieve the intended result?
This is where genuine readiness begins.
Gap Analysis → Remediation Plan → Implementation → Internal Audit → Management Review → Readiness Review → External Assessment
Following this sequence allows ISO certification to become the result of a functioning management system rather than a temporary project for preparing files before the auditor arrives.
To request an initial diagnostic session and Gap Analysis for your organization’s management system, contact IAC to assess the current state, identify remediation priorities, and develop an appropriate readiness roadmap before the external assessment.
