Knowella

Certification Gap Analysis

The recurring failure here isn't the gap list itself, it's who wrote it and what happens once it's counted. An internal assessor scoring their own programme too often marks 'fully in place' where a consultant or the certification body's own pre-assessment would flag a gap outright, and a list with no effort, owner or dependency attached never turns into a plan management actually funds, so the certification date slips without anyone deciding to slip it.

KnowComplyAssessmentCMP-02043 fields across 4 sectionsFull researchSee the form

Reviewed by Siddarth SinghCSPLast reviewed 16 August 2026

Basis
ISO 19011
Workspace
KnowComply
Form type
Assessment
Run when
Before a certification attempt, or recovering from a failed one
Owned by
Compliance lead or an external consultant

The short version

  • Gap counts from internal assessors run structurally lower than counts from a consultant or a certification body pre-assessment, because the assessor is grading a programme they own.
  • A gap without an effort estimate in days, weeks or months cannot be scheduled, and the Plan section stalls until every gap carries one alongside an owner.
  • Dependency matters as much as gap count: a gap flagged as a blocking dependency turns a two-week item into the thing that actually decides the certification date.
  • The 'would be a major if found' field only earns its keep if it is scored honestly; marking every gap 'no' defeats the point of flagging what would actually stop certification.

What this is

What is a certification gap analysis?

What is a certification gap analysis?

A certification gap analysis is an assessment that tests a management system's readiness against a chosen standard before the site commits to a certification audit. It scores each clause as fully, partly or not in place, rather than pass or fail, because the output is a plan, not a certificate decision.

How is a gap analysis different from a readiness audit?

A gap analysis runs earlier and produces an implementation plan with owners, effort and dependencies. A readiness audit runs later, closer to the real certification visit, and checks whether that plan actually got done. Confusing the two produces a plan document dressed up as an audit report, or an audit report standing in for a plan.

Why does who carries out the analysis change the result?

Internal staff, a consultant and a certification body's pre-assessment carry different levels of candour, and the same system can score very differently depending on which one ran the exercise. An internal assessor grading their own programme has the least distance from the answer they are hoping to find.

Scope

When is a certification gap analysis required?

This assessment is one step in a larger programme. Using it for work that belongs to a neighbouring template produces records that are hard to report on later.

Use this template when

  • A first certification attempt is being planned against a new standard
  • A second standard is being added to an existing certified system
  • The site is recovering after a failed or heavily-criticised external audit
  • A scope extension, a new site, process or product range, needs its readiness checked
  • A certification body pre-assessment has been commissioned to test readiness before the real visit

Do not use it for

  • ISO 45001 Readiness Audit, which audits a live occupational health and safety management system against ISO 45001 ahead of certification or surveillance.
  • ISO 14001 Readiness Audit, which audits a live environmental management system against ISO 14001 ahead of certification or surveillance.
  • External Audit Record, which records a certification body or customer audit that has already happened, including its findings and the response required.
  • Unannounced Audit Readiness Check, which checks day-to-day readiness for an audit arriving with no notice, not readiness for a planned first certification.
  • Anything outside KnowComply, which belongs in the workspace that owns that process

Compliance mapping

Which ISO 19011 requirements does this satisfy?

ISO 19011 is a method standard rather than a certifiable one, so a gap analysis under it maps its findings against whichever management system standard is actually being pursued. The clauses below are the recurring points a first-time certification gap analysis has to cover, whichever standard sits behind it.

ClauseRequirementWhere it lands
ISO 19011 cl.4Findings rest on evidence that can be verified, not on impression or assertionGaps
ISO 19011 cl.5.2The objective of the exercise, new certification, added standard, recovery, or scope extension, is fixed before work startsHeader
ISO 19011 cl.5.4Whoever carries out the assessment has the competence to judge maturity against the standard, and the programme's resourcing is planned rather than assumedHeader
ISO 19011 cl.6.4Evidence of implementation, not just a documented process, is checked against each requirementGaps
ISO 19011 cl.5.5Programme results and records, the gap list, owners and target dates, are managed and retained as the exercise runsPlan
ISO 19011 cl.5.7The resulting plan is reviewed, and resources and management approval confirmed, before it is treated as finalPlan
ISO 19011 cl.5.3Programme risk, external support required, estimated cost and effort, is evaluated as part of planningSummary

What it does not cover

  • A gap marked 'Fully in place' with no evidence of use recorded, which means the current-state judgement rests on a document existing rather than on practice an auditor can actually sample.
  • An effort estimate of 'Months' with no dependency flagged, which means the plan cannot say whether that gap sits on the critical path or can run in parallel with everything else.
  • A 'Would Be A Major If Found' gap left without an owner or target date, which means the item most likely to fail a real audit has no one accountable for closing it.
  • An implementation plan created without resources committed or management approval, which means the certification date on the form is an aspiration rather than a plan anyone has funded.
  • An internal Carried Out By assessment with zero gaps recorded, which means the analysis was either run by someone unable to see their own system's blind spots, or not run with enough rigour to find anything.

Global

Certification Gap Analysis requirements by country

A certification gap analysis is graded against whichever standard the site is pursuing, but the accreditation body behind the eventual certificate decides how much benefit of the doubt an assessor gets, and how the resulting certificate is recognised elsewhere.

United Kingdom

UKAS accreditation of the certification body

UKAS accredits the certification bodies that issue ISO management system certificates in the UK market

A gap analysis run ahead of a UKAS-accredited audit should assume examiners expect objective evidence of use, not policy alone; UKAS periodically re-witnesses certification body auditors on exactly this point.

United States

ANAB accreditation

ANAB is the US accreditor for ISO management system certification bodies

US sites adding an ISO standard to an existing programme should expect the same evidence bar as a UKAS-accredited audit; the accreditation body, not the standard, sets how strictly 'partly in place' gets tested.

International

IAF Multilateral Recognition Arrangement (MLA)

The IAF MLA is what makes a certificate issued under one accreditation accepted by customers who audit against another

A gap analysis that under-counts gaps to protect a certification date risks a certificate a customer's second-party auditor later disputes, because MLA recognition assumes the underlying audit met IAF-endorsed rigour, not a lighter local practice.

How to complete it

How to complete a certification gap analysis, step by step

Most of the fields here are quick to fill in once the workshop is done. The judgement is in what gets written as 'partly in place', how effort gets estimated before anyone has scoped the work, and whether the plan that comes out the other end gets funded.

Where 'partly in place' actually sits

Partly in place scores 1 against fully in place's 3, but it hides two very different situations: a control that is documented and used inconsistently, and one that is used everywhere but never written down. The gap description has to say which, because the fix, write it up, or enforce it, is completely different work.

Whether the effort estimate is a guess or a scope

Days, weeks or months is asked before most gaps have been scoped in any detail. An estimate given without at least a rough idea of what building the control involves just becomes a number project sponsors anchor to and then miss.

How 'blocking' dependencies get sequenced

A gap marked as a blocking dependency on another gap changes the realistic certification date more than any single major gap does. If the plan does not sequence blocking items first, the target date in Summary is fiction regardless of how many other gaps close in parallel.

Whether 'no action required' really means no action

Action Required tends to default toward No once the Plan section is filled in, but a plan approved while a 'would be a major if found' gap is still open should still carry an action. Closing the sign-off loop early is the fastest way to walk into a failed pre-assessment.

What auditors find

Most common certification gap analysis findings

The patterns below come up across gap analyses regardless of which standard sits behind them; they are about how the exercise gets run, not the requirements of any one scheme.

FindingClauseWhat fixes it
Gap analysis run entirely by the person who owns the system being assessedISO 19011 cl.5.4Pair an internal assessment with at least a sampled review by a consultant or the certification body's pre-assessment before treating the gap count as final.
Effort recorded as 'weeks' or 'months' with no supporting scope noteISO 19011 cl.5.3Require a one-line scope statement alongside every effort estimate so the number can be checked, and re-estimated, once the gap is actually worked.
'Fully in place' scored against a documented process with no evidence of use testedISO 19011 cl.6.4Change the current-state judgement to partly in place unless someone has actually sampled the record or observed the practice, not just read the procedure.
Gaps marked 'would be a major if found' with no owner or target date setISO 19011 cl.5.5Force owner and target date as required fields whenever the major flag is set, ahead of every other gap in the queue.
Implementation plan approved by management with resources only 'partly' committedISO 19011 cl.5.7Treat partly committed resourcing as an open risk on the realistic certification date, and restate the date once resourcing is confirmed rather than leaving the original estimate standing.
Dependency between gaps left blank because the two items were logged by different peopleISO 19011 cl.5.4Review the gap list as a set before it goes to management, specifically to spot dependencies that individual gap owners would not see from their own item.

Case in point

Case in point: the pre-assessment that found what the internal analysis missed

A site preparing for its first ISO 45001 certification ran an internal gap analysis and recorded four gaps, all scored as weeks of effort, with the safety manager marking their own risk assessment process as fully in place because the procedure had been rewritten six months earlier.

The certification body's paid pre-assessment, run as a second Carried Out By pass before the real audit was booked, found the same four gaps plus three more, including that the rewritten risk assessment procedure had never actually been used in two of the site's five departments. The realistic certification date moved back a full quarter, but it moved back before the certification body's own auditor found it live, not after.

The template

The template, field by field

The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.

43fields
4 sections
Reference
CMP-020
Archetype
Assessment
Record ID
CGA-2026-000
Scoring
Gap count by clause
Direction
High is bad
Singleton
No
Basis
ISO 19011
Links
Links Clause Register
Tags
Certification, Planning
Sections
4
Fields
43
Follow up fields
3
Repeating sections
1
Links out
2
Field typesOwn ID, generated on saveCase thread and parentPick list from a registryLinked to another templateFollow up, dashed outlineScored

Header

10 fields
Text

Analysis ID*

Generated on save

Auto sequence. Format CGA-2026-000.

The record's own ID. Other templates point at this value.

Single Choice

Status*

Scored

Drives who this goes to next.

  • Planned2 pts
  • In progress2 pts
  • Complete3 pts
  • Deferred0 pts
  • Open0 pts
  • Closed3 pts
  • Overdue0 pts
Date & Time

Date and Time*

Users

Completed By*

Pick List

Site*

From FDN-001 Site NameFilter: Status is Active
Text

Site ID*

Linked

Format SITE-000.

Links to FDN-001 Site ID

Single Choice

Standard*

ISO 45001ISO 14001ISO 9001ISO 50001BRCGSSQFFSSC 22000
Single Choice

Analysis Purpose*

New certificationAdding a standardRecovering from a failed auditScope extension
Single Choice

Carried Out By*

Internal, consultant, or certification body pre-assessment. Each brings a different level of candour.

InternalConsultantCertification body pre-assessment
Info

Effort, Not Just Gaps

A gap list without effort estimates cannot be planned. State for each gap what has to be built, who builds it and roughly how long it takes.

Gaps

Repeats10 fields
Text

Clause*

Text

Requirement*

Single Choice

Current State*

Scored
  • Fully in place3 pts
  • Partly in place1 pt
  • Nothing in place0 pts
Text

Gap Description*

Single Choice

What Needs To Exist*

A documented process, a record, evidence of use, a competence, or a physical control.

Documented processRecordEvidence of useCompetencePhysical control
Single Choice

Effort*

Scored
  • Days3 pts
  • Weeks2 pts
  • Months0 pts
Users

Owner*

Single Choice

Dependency On Other Gaps

OptionalScored
  • None3 pts
  • Some1 pt
  • Blocking0 pts
Date & Time

Target Date*

Single Choice

Would Be A Major If Found*

Scored
  • No3 pts
  • Yes0 pts

Summary

9 fields
Numeric Answer

Clauses Assessed*

Numeric Answer

Gaps Identified*

Scored
Numeric Answer

Major Gaps*

Scored
Numeric Answer

Estimated Effort Days

OptionalScored
Single Choice

External Support Required*

Scored
  • No3 pts
  • Some2 pts
  • Extensive0 pts
Numeric Answer

Estimated Cost

Optional
Date & Time

Realistic Certification Date*

Single Choice

Existing System Covers Most Requirements*

Scored

Most sites already do the things. What is missing is usually the evidence and the linkage, not the activity.

  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Documentation Burden Reasonable*

Scored
  • Yes3 pts
  • Heavy1 pt
  • Excessive0 pts

Plan

14 fields
Single Choice

Implementation Plan Created*

Scored
  • Yes3 pts
  • No0 pts
Single Choice

Resources Committed*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Approved By Management*

Scored
  • Yes3 pts
  • No0 pts
Single Choice

Readiness Audit Scheduled*

Scored
  • Yes3 pts
  • No0 pts
Single Choice

Certification Body Selected

Optional
YesShortlistedNo
Date & Time

Next Review Due*

Single Choice

Action Required*

Scored

Raise the action record, then enter its reference here.

  • No2 pts
  • Yes0 pts
Single Choice

Priority

OptionalScoredShows if Action Required equals Yes
  • High0 pts
  • Medium1 pt
  • Low3 pts
Text

CAPA ID

OptionalLinkedShows if Action Required equals Yes

Format CAPA-2026-00000.

Links to FDN-014 CAPA ID

Users

Action Owner

OptionalShows if Action Required equals Yes
Users

Compliance Lead*

Signature

Signature*

Users

Site Manager*

Signature

Second Signature*

CMP-020 · record IDs look like CGA-2026-000 · Links Clause Register

Open in Knowella

Run it with agents

From a document you fill in to a programme that runs itself

The form is the easy part. Keeping it current, routing it to the right owner and holding the evidence together is the work that actually slips.

KnowComply

Holds the certification gap analysis library against your registers, routes each record to its owner, and keeps the evidence trail together across whichever standard the site is pursuing.

KnowSafe

Feeds ISO 45001 gap analyses from the live incident, hazard and permit registers, so 'evidence of use' can be checked against records that already exist rather than reconstructed for the assessment.

KnowQuality

Links ISO 9001 and food safety scheme gaps back to the nonconformance and CAPA history, so a 'fully in place' claim can be checked against how the process actually performed.

Ella
Ella

Coordinates the crew, rolls completion and exceptions into one view, and holds every write for your approval before it touches a record.

This template lives in KnowComply — audit and governance. Audit programmes, legal register, management review, risk and certification.

Meet KnowComply→

Glossary

Certification Gap Analysis definitions and key terms

Gap analysis
An assessment run against a standard's requirements before certification is sought, to find what is missing rather than to score a live audit.
Pre-assessment
An optional paid visit from the certification body, ahead of the real certification audit, that tests readiness with the same rigour as the eventual audit.
Major nonconformity
A finding serious enough, on its own or combined with others, to stop a certificate being issued or maintained until it is closed.
Management system standard
A certifiable ISO standard, such as ISO 9001, ISO 14001 or ISO 45001, that sets requirements for how an organisation runs a particular area, rather than for a product.
Scope extension
Adding a site, process or product range to an existing certificate, which typically needs its own gap analysis against the extended scope.

FAQ

Frequently asked questions about certification gap analysis

Does a gap analysis replace the certification audit?+

No. It is preparation work that estimates readiness and produces a plan; only the certification body's audit can actually award or maintain the certificate.

Should the gap analysis use the exact clause numbers of the target standard?+

Yes, the Clause and Requirement fields should reference the actual standard being pursued, ISO 45001, ISO 9001 and so on, even though the method behind how the analysis is run follows ISO 19011.

Who should carry out the gap analysis if the site has never been audited before?+

A first-time site benefits most from a certification body pre-assessment or an external consultant, because an internal assessor with no reference point for what 'fully in place' looks like in practice tends to under- or over-state readiness.

What happens if the realistic certification date keeps slipping?+

It usually means gaps were scoped optimistically, or a blocking dependency was not sequenced first. The fix is to re-run the effort and dependency fields against what has actually been learned, not to just push the date.

Does every gap need an implementation plan of its own?+

No, the Plan section covers the programme as a whole; individual gaps only need their own action record raised when Action Required is set to Yes.

How does this differ from an internal audit?+

An internal audit tests a live management system against its own procedures and reports findings; a gap analysis tests readiness against a standard nobody has been certified to yet, and its output is a plan rather than a scored audit.

Keep going

Related templates and programmes

Siddarth Singh

Written and reviewed by

Siddarth Singh

Founder & Chief Executive Officer, Knowella

Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.

  • Certified Safety Professional (CSP), Board of Certified Safety Professionals
  • MBA, University of Chicago Booth School of Business
  • MS and BS, The Ohio State University, Industrial and Systems Engineering
  • Six Sigma Black Belt
Verify with BCSP →

Sources and last review. Reviewed 16 August 2026 against:

  • ISO 19011:2018 — Guidelines for auditing management systems
  • ISO 45001:2018 — Occupational health and safety management systems
  • ISO 9001:2015 — Quality management systems
  • ISO/IEC 17021-1:2015 — Conformity assessment, requirements for bodies providing audit and certification of management systems

This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.

Start in Minutes, Not Weeks

Launch a Ready-Made Template and Customize It Your Way

Every template is fully editable. Adjust fields, workflows, and branding to match your processes, then deploy to your team instantly.