9.2 Stage 1 Audit: Objectives, Documentation Review & Readiness Assessment
Key Takeaways
- The primary purpose of the Stage 1 audit under ISO/IEC 17021-1 Clause 9.3.1.2 is to evaluate documented information, site-specific conditions, and the organization's overall readiness for Stage 2.
- Stage 1 requires verifying that internal audits (Clause 9.2) and management reviews (Clause 9.3) have been fully planned and performed, demonstrating sufficient management system maturity.
- Auditors must critically evaluate the client's understanding of ISO 45001 core requirements, particularly hazard identification (6.1.2), compliance obligations (6.1.3), and worker consultation (5.4).
- Deficiencies identified during Stage 1 are formally reported as Areas of Concern (AOCs) to notify the auditee of issues that could materialize as nonconformities during Stage 2.
- If documentation is fundamentally incomplete or internal audits have not occurred, the Lead Auditor must recommend postponing the Stage 2 audit rather than setting up the client for failure.
9.2 Stage 1 Audit: Objectives, Documentation Review & Readiness Assessment
Lead Auditor Core Concept: Initial certification to ISO 45001 is a mandatory two-stage process. The Stage 1 Audit is not a superficial paperwork stamp, nor is it a dress rehearsal for Stage 2. Under ISO/IEC 17021-1:2015 Clause 9.3.1.2, Stage 1 is a rigorous readiness gate designed to evaluate management system design, assess site-specific hazard realities, confirm resource allocations, and determine whether the auditee possesses sufficient operational maturity to justify proceeding to Stage 2. Entering Stage 2 without a successful Stage 1 evaluation guarantees audit failure and invalidates certification integrity.
1. Normative Objectives of the Stage 1 Audit (ISO/IEC 17021-1 Clause 9.3.1.2)
Under third-party certification protocols, initial audits are divided into Stage 1 and Stage 2. The Stage 1 audit focuses on system architecture, documentation adequacy, and readiness assessment, pursuing nine mandatory objectives prescribed by ISO/IEC 17021-1:
- Review Documented Information: Audit the client's management system documented information, including scope definitions, OH&S policies, hazard assessment methodologies, operational procedures, and compliance registers.
- Evaluate Site-Specific Conditions: Assess the client's physical operating location, facility boundaries, and site-specific environmental/topographical hazards, and undertake preliminary discussions with client personnel.
- Assess Understanding of Key Requirements: Evaluate the client's status and comprehension regarding ISO 45001 mandates, particularly regarding hazard identification, operational controls, legal requirements, and worker participation.
- Collect Necessary Scoping Information: Collect critical information regarding the scope of the management system, including processes, equipment, operational shifts, hazardous materials, and statutory/regulatory requirements.
- Review Resource Allocation for Stage 2: Review the planned allocation of audit days and auditor competencies, ensuring adequate specialist coverage for high-risk processes.
- Provide Focus for Planning Stage 2: Gain sufficient organizational understanding to select specific processes, shifts, and high-hazard operations for deep sampling during Stage 2.
- Evaluate Internal Audits and Management Review: Verify that internal audits (Clause 9.2) and management review (Clause 9.3) have been planned and performed, and that the implementation level substantiates readiness for Stage 2.
- Determine Stage 2 Readiness: Reach a formal conclusion regarding whether the management system is sufficiently mature to proceed to Stage 2.
- Agree on Stage 2 Logistics: Agree with the client on the scheduling, operational dates, and logistics for the Stage 2 audit.
2. In-Depth Documentation Review of OH&S Core Pillars
The documentation review is an analytical evaluation of the written architecture of the OH&S management system. The Lead Auditor evaluates whether documented processes exist, whether they meet ISO 45001 requirements, and whether they align with the organization's actual operating context.
┌─────────────────────────────────────────────────────────────────────────────┐
│ STAGE 1 DOCUMENTATION REVIEW FOCUS │
├──────────────────────────┬──────────────────────────────────────────────────┤
│ Core OH&S Pillar │ Critical Lead Auditor Verification Checkpoints │
├──────────────────────────┼──────────────────────────────────────────────────┤
│ Scope Definition │ • Are physical, geographical, and organizational │
│ (Clause 4.3) │ boundaries clearly defined? │
│ │ • Are all high-hazard activities within the │
│ │ client's control included? No exclusions! │
├──────────────────────────┼──────────────────────────────────────────────────┤
│ Leadership & Worker │ • Does the OH&S policy commit to eliminating │
│ Consultation (5.2 & 5.4) │ hazards and worker consultation? │
│ │ • Are formal consultation mechanisms established │
│ │ for non-managerial frontline personnel? │
├──────────────────────────┼──────────────────────────────────────────────────┤
│ Hazard Identification & │ • Does methodology account for routine, non- │
│ Risk Assessment (6.1.2) │ routine, emergency, and human factors? │
│ │ • Are risks to contractors and visitors covered? │
├──────────────────────────┼──────────────────────────────────────────────────┤
│ Legal & Other │ • Is there an identified, accessible register │
│ Requirements (6.1.3) │ of statutory safety laws and industry codes? │
│ │ • Has compliance applicability been determined? │
├──────────────────────────┼──────────────────────────────────────────────────┤
│ Governance Loops │ • Have full-scope internal audits been executed? │
│ (9.2 & 9.3) │ • Has top management performed a formal review? │
└──────────────────────────┴──────────────────────────────────────────────────┘
The Prohibition Against Scope Exclusions
Unlike ISO 9001, which permits justified exclusions of specific design or operational requirements under Clause 4.3, ISO 45001 does not permit the exclusion of any clause or requirement. An organization cannot claim: "We exclude Clause 8.2 (Emergency Response) because municipal fire services handle our emergencies." Furthermore, physical boundaries cannot be artificially gerrymandered to carve out high-risk maintenance shops, chemical storage yards, or contractor staging areas that operate under the organization's control.
3. Site-Specific Conditions and Gemba Walkthrough
ISO/IEC 17021-1 emphasizes that Stage 1 typically involves an on-site visit to the client's premises, particularly for high-hazard industrial environments. While desk audits may be justified for purely administrative services, manufacturing, construction, and processing facilities demand physical observation.
Objectives of the Stage 1 Gemba Walkthrough:
- Verify Physical Context: Confirm that the actual facility layout, adjacent facilities, and environmental settings match the organizational context described in documented information;
- Identify High-Hazard Infrastructure: Identify major hazards (e.g., ATEX explosive atmospheres, high-pressure boilers, confined spaces, overhead gantry cranes, radioactive testing sources) that necessitate specialized auditor PPE or technical experts during Stage 2;
- Evaluate Workforce and Shift Dynamics: Observe operational staffing, rotating shift handovers, and contractor presence to confirm that the planned Stage 2 audit duration (IAF MD 5) is adequate;
- Assess Multisite Sampling Eligibility: If certification covers multiple sites (under IAF MD 1), verify that central management controls exist, that internal audits cover all branches, and that branches operate under common procedures to justify statistical site sampling.
4. Mandatory Verification of Internal Audits & Management Review
The most critical gateway condition in Stage 1 is evaluating the internal governance loop under Clause 9.2 (Internal Audit) and Clause 9.3 (Management Review). ISO/IEC 17021-1 Clause 9.3.1.2(f) explicitly mandates that the certification body verify that internal audits and management reviews are being planned and performed, and that the implementation level of the management system substantiates that the client is ready for Stage 2.
Gate Criteria for Stage 2 Readiness:
- Full Internal Audit Execution: The organization must have completed at least one full cycle of internal audits covering all ISO 45001 clauses, all operational processes, and all operating shifts. If only 40% of the system has been audited internally, the organization is not ready for Stage 2.
- Objective Internal Audit Reporting: Internal audit records must show genuine evaluation, including the identification of realistic nonconformities and corrective actions. A "clean bill of health" internal audit report that rubber-stamps 100% compliance across a complex chemical facility indicates an immature audit process.
- Comprehensive Management Review: Top management must have executed at least one formal management review addressing all mandatory inputs (Clause 9.3 a–g) and generating actionable outputs regarding resources, system modifications, and continual improvement.
5. Stage 1 Outputs, Reporting & Areas of Concern (AOCs)
Upon completing Stage 1, the Lead Auditor compiles the official Stage 1 Audit Report. The report communicates whether Stage 1 objectives were achieved, summarizes documentation findings, confirms or adjusts the Stage 2 audit plan and resource allocation, and presents a formal readiness recommendation.
Reporting Deficiencies: Areas of Concern (AOC)
Under standard certification body practices aligning with ISO/IEC 17021-1 Clause 9.3.1.2.2, findings identified during Stage 1 are documented as Areas of Concern (AOCs) or issues of concern. An Area of Concern is a documented condition, missing procedure, or implementation gap that, if left uncorrected, could be classified as a Major or Minor Nonconformity during Stage 2.
Exam Watchpoint: Certification bodies typically do not issue formal nonconformity certificates during Stage 1 because the operational implementation of the system is not yet fully audited. However, identifying an Area of Concern serves as a binding legal warning: the auditee must resolve the issue before Stage 2 commences.
Stage 2 Decision Pathways:
- Path A: Ready for Stage 2 as Scheduled. Documented information is robust, internal audits and management review are complete, and minor Areas of Concern can be readily addressed prior to Stage 2.
- Path B: Ready for Stage 2 Pending Evidence. The client must submit revised documentation or corrective action evidence to the Lead Auditor within a defined window before Stage 2 commences.
- Path C: NOT Ready for Stage 2 (Postponement). Fundamental gaps exist (e.g., unexecuted internal audits, missing legal registers, unresolved severe hazards). The Lead Auditor formally recommends postponing the Stage 2 audit to allow the client sufficient time to implement the system and close gaps. If postponed for more than six months, Stage 1 must generally be repeated.
6. Comparative Analysis: Stage 1 vs. Stage 2 Audits
| Assessment Dimension | Stage 1 Audit (Readiness & Architecture) | Stage 2 Audit (Implementation & Effectiveness) |
|---|---|---|
| Governing Clause | ISO/IEC 17021-1 Clause 9.3.1.2 | ISO/IEC 17021-1 Clause 9.3.1.3 |
| Primary Objective | Evaluate system design, documentation, site context, and readiness for Stage 2. | Evaluate operational implementation, control effectiveness, and compliance with all ISO 45001 clauses. |
| Typical Location | Desktop review combined with on-site facility walk and management interviews. | Comprehensive on-site audit across all physical facilities, operating shifts, and processes. |
| Focus of Inquiry | Management system manuals, hazard methodologies, legal registers, internal audit reports. | Live shop-floor execution, worker interviews, permit-to-work execution, maintenance logs, physical safeguards. |
| Classification of Findings | Areas of Concern (AOCs), issues of concern, opportunities for improvement. | Formal Nonconformities (Major or Minor) and Opportunities for Improvement (OFI). |
| Ultimate Output | Stage 1 Report with readiness recommendation (Proceed, Postpone, Re-audit). | Stage 2 Report with formal certification recommendation to the Certification Decision Committee. |
7. Real-World Audit Scenario: The Premature Stage 1 Application
Audit Context: A medium-sized structural precast concrete manufacturer with 250 workers applies for initial ISO 45001 certification. The Lead Auditor arrives on-site to conduct the Stage 1 audit.
Investigation Findings:
- The Lead Auditor reviews the hazard identification register. The methodology was purchased as a generic off-the-shelf template from an online consultant. It lists generic office slips and trips but completely omits overhead gantry crane operations, high-pressure hydraulic pre-stressing beds, and crystalline silica exposure from concrete grinding.
- The auditor reviews internal audit records. The safety coordinator presents an internal audit report dated two weeks prior. It consists of a single 3-page checklist signed by the safety coordinator herself, evaluating only the corporate administration office. No manufacturing operations, batch plants, or night maintenance shifts were audited.
- Top management states they have not conducted a formal management review because they "wanted to wait until after the certification auditor told them what was wrong."
Lead Auditor Determination & Action: The Lead Auditor issues a formal Stage 1 report classifying the gaps as severe Areas of Concern and issues a determination of NOT READY FOR STAGE 2. The organization has failed to satisfy ISO/IEC 17021-1 Clause 9.3.1.2(c) and (f). The Lead Auditor formally recommends postponing the Stage 2 audit for four months, requiring the auditee to complete hazard assessments covering heavy operations, conduct full-scope internal audits using independent auditors, and execute a comprehensive management review before Stage 2 can be scheduled.
8. Common Exam Traps and Candidate Errors
- Trap 1: Believing Stage 1 Can Be Bypassed for "Mature" Companies. Initial third-party certification under ISO/IEC 17021-1 mandates a two-stage process. Even if an organization has been certified to ISO 9001 or ISO 14001 for twenty years, its initial ISO 45001 certification requires a distinct Stage 1 audit.
- Trap 2: Assuming Stage 1 Must Be Strictly Off-Site. While documentation can be read remotely, ISO/IEC 17021-1 explicitly notes that Stage 1 should include an on-site component to evaluate site-specific conditions, verify plant layout, and assess the operational reality of hazardous activities.
- Trap 3: Issuing Certification Directly from Stage 1. A Lead Auditor cannot recommend certification following Stage 1, regardless of how pristine the documentation appears. Certification requires verified operational effectiveness during Stage 2.
- Trap 4: Allowing Stage 2 to Proceed Without Internal Audits. Candidates often think an auditor can grant an exception if the client promises to complete internal audits next month. Under ISO/IEC 17021-1, lack of completed internal audits and management review is an absolute bar to proceeding to Stage 2.
According to ISO/IEC 17021-1 Clause 9.3.1.2, which set of activities represents the primary normative purpose and focus of a Stage 1 certification audit?
During a Stage 1 audit of an engineering fabrication firm, the Lead Auditor reviews documented information and learns that while the organization drafted its OH&S manual and hazard registers six months ago, it has not yet conducted any internal audits under Clause 9.2 or a management review under Clause 9.3. What conclusion and recommendation must the Lead Auditor record in the Stage 1 report?
During a Stage 1 documentation review, the Lead Auditor identifies that an auditee's hazard identification procedure fails to account for routine contractor activities and temporary agency workers, directly omitting a core requirement of Clause 6.1.2.1. How should this finding be formally communicated in the Stage 1 audit output under standard certification body protocols?