Pre Assessment Audits
ISO pre-assessment audit and gap analysis Bahrain. Identifies missing evidence, implementation gaps and scope issues before the certification audit.
A pre-assessment establishes how far your existing arrangements meet a standard, before the certification audit begins. It is optional, and organisations that skip it often should not have — a major non-conformity at stage 2 stops the certification decision, and closing it means corrective action, evidence of effectiveness, and in some cases a return visit.
What the review covers
- Documented informationWhether the policies, procedures and records the standard requires exist, and whether they describe what the organisation actually does rather than what a template said.
- Implementation on siteWhether documented arrangements are applied in practice. This is where most gaps appear — the system exists on paper and stops at the office door.
- InterviewsDiscussion with the people responsible for each process, since arrangements nobody can describe will not survive a certification audit.
- Scope and boundariesWhether the intended certification scope is accurate, achievable and covers what your clients will expect it to cover.
- Records and evidenceWhether the system has run long enough to have generated the evidence a certification auditor will ask for — internal audits, management review, corrective actions closed out.
- Clause-by-clause gap reportEach relevant clause assessed, with what is in place, what is missing, and an indication of the effort required to close it.
The most common findings
Three gaps account for most delayed certifications, and all three are avoidable. Internal audits not yet conducted, or conducted by people auditing their own work. Management review not yet held, or held without the inputs the standard requires and with no decisions recorded. And a system implemented too recently to have generated evidence — certification auditors need to see the system operating over time, not a folder assembled the week before.
Diagnostic, not corrective
A pre-assessment reports what is missing. It does not design the solution, recommend how to structure your procedures, or write anything for you. That restriction is required by ISO/IEC 17021-1, which prohibits a certification body from consulting on the system it certifies — and it is what allows the same body to carry out both the pre-assessment and the certification audit without compromising the decision.
Organisations sometimes find this frustrating. The alternative is worse: a certification body that helps you build the system and then certifies it has issued a certificate that means nothing to the client who asked for it.
When to commission it
- Ahead of first certification, where nobody in the organisation has been through the process
- Before transition to a revised edition of a standard
- Where a previous certification audit produced major non-conformities
- After significant organisational change — new sites, acquisitions, changed scope
- Where certification is tied to a contract award date and the timeline cannot slip
- Before adding a standard to an existing certified system
Timing
A pre-assessment carried out too early finds gaps in a system still being built, which tells you little. Carried out too late, there is no time to act on it. The useful window is once the system is implemented and has been running long enough to generate records, but with enough time remaining before the certification audit to close what is found — typically two to three months out, longer where internal audits and management review have not yet been held.
What you receive
- A gap report addressing each relevant clause of the standard
- What is in place, what is missing, and what evidence was examined for each
- Gaps prioritised by whether they would result in a major or minor finding
- An indication of the effort required to close each gap
- Assessment of whether the intended certification scope is achievable
- A realistic view on whether the target certification date is attainable
Which standards
Pre-assessment is available against any standard ITMAD certifies, including ISO 9001, ISO 14001, ISO 45001, ISO 22000 and HACCP, ISO 27001, ISO 22301, ISO 50001, ISO 37001 and ISO 22716, and for integrated systems covering more than one standard at once.