What this is
What is a certification gap analysis?
What is a certification gap analysis?
A certification gap analysis is an assessment that tests a management system's readiness against a chosen standard before the site commits to a certification audit. It scores each clause as fully, partly or not in place, rather than pass or fail, because the output is a plan, not a certificate decision.
How is a gap analysis different from a readiness audit?
A gap analysis runs earlier and produces an implementation plan with owners, effort and dependencies. A readiness audit runs later, closer to the real certification visit, and checks whether that plan actually got done. Confusing the two produces a plan document dressed up as an audit report, or an audit report standing in for a plan.
Why does who carries out the analysis change the result?
Internal staff, a consultant and a certification body's pre-assessment carry different levels of candour, and the same system can score very differently depending on which one ran the exercise. An internal assessor grading their own programme has the least distance from the answer they are hoping to find.
Scope
When is a certification gap analysis required?
This assessment is one step in a larger programme. Using it for work that belongs to a neighbouring template produces records that are hard to report on later.
Use this template when
- A first certification attempt is being planned against a new standard
- A second standard is being added to an existing certified system
- The site is recovering after a failed or heavily-criticised external audit
- A scope extension, a new site, process or product range, needs its readiness checked
- A certification body pre-assessment has been commissioned to test readiness before the real visit
Do not use it for
- ISO 45001 Readiness Audit, which audits a live occupational health and safety management system against ISO 45001 ahead of certification or surveillance.
- ISO 14001 Readiness Audit, which audits a live environmental management system against ISO 14001 ahead of certification or surveillance.
- External Audit Record, which records a certification body or customer audit that has already happened, including its findings and the response required.
- Unannounced Audit Readiness Check, which checks day-to-day readiness for an audit arriving with no notice, not readiness for a planned first certification.
- Anything outside KnowComply, which belongs in the workspace that owns that process
Compliance mapping
Which ISO 19011 requirements does this satisfy?
ISO 19011 is a method standard rather than a certifiable one, so a gap analysis under it maps its findings against whichever management system standard is actually being pursued. The clauses below are the recurring points a first-time certification gap analysis has to cover, whichever standard sits behind it.
| Clause | Requirement | Where it lands |
|---|---|---|
| ISO 19011 cl.4 | Findings rest on evidence that can be verified, not on impression or assertion | Gaps |
| ISO 19011 cl.5.2 | The objective of the exercise, new certification, added standard, recovery, or scope extension, is fixed before work starts | Header |
| ISO 19011 cl.5.4 | Whoever carries out the assessment has the competence to judge maturity against the standard, and the programme's resourcing is planned rather than assumed | Header |
| ISO 19011 cl.6.4 | Evidence of implementation, not just a documented process, is checked against each requirement | Gaps |
| ISO 19011 cl.5.5 | Programme results and records, the gap list, owners and target dates, are managed and retained as the exercise runs | Plan |
| ISO 19011 cl.5.7 | The resulting plan is reviewed, and resources and management approval confirmed, before it is treated as final | Plan |
| ISO 19011 cl.5.3 | Programme risk, external support required, estimated cost and effort, is evaluated as part of planning | Summary |
What it does not cover
- A gap marked 'Fully in place' with no evidence of use recorded, which means the current-state judgement rests on a document existing rather than on practice an auditor can actually sample.
- An effort estimate of 'Months' with no dependency flagged, which means the plan cannot say whether that gap sits on the critical path or can run in parallel with everything else.
- A 'Would Be A Major If Found' gap left without an owner or target date, which means the item most likely to fail a real audit has no one accountable for closing it.
- An implementation plan created without resources committed or management approval, which means the certification date on the form is an aspiration rather than a plan anyone has funded.
- An internal Carried Out By assessment with zero gaps recorded, which means the analysis was either run by someone unable to see their own system's blind spots, or not run with enough rigour to find anything.
Global
Certification Gap Analysis requirements by country
A certification gap analysis is graded against whichever standard the site is pursuing, but the accreditation body behind the eventual certificate decides how much benefit of the doubt an assessor gets, and how the resulting certificate is recognised elsewhere.
UKAS accreditation of the certification body
UKAS accredits the certification bodies that issue ISO management system certificates in the UK market
A gap analysis run ahead of a UKAS-accredited audit should assume examiners expect objective evidence of use, not policy alone; UKAS periodically re-witnesses certification body auditors on exactly this point.
ANAB accreditation
ANAB is the US accreditor for ISO management system certification bodies
US sites adding an ISO standard to an existing programme should expect the same evidence bar as a UKAS-accredited audit; the accreditation body, not the standard, sets how strictly 'partly in place' gets tested.
IAF Multilateral Recognition Arrangement (MLA)
The IAF MLA is what makes a certificate issued under one accreditation accepted by customers who audit against another
A gap analysis that under-counts gaps to protect a certification date risks a certificate a customer's second-party auditor later disputes, because MLA recognition assumes the underlying audit met IAF-endorsed rigour, not a lighter local practice.
How to complete it
How to complete a certification gap analysis, step by step
Most of the fields here are quick to fill in once the workshop is done. The judgement is in what gets written as 'partly in place', how effort gets estimated before anyone has scoped the work, and whether the plan that comes out the other end gets funded.
Partly in place scores 1 against fully in place's 3, but it hides two very different situations: a control that is documented and used inconsistently, and one that is used everywhere but never written down. The gap description has to say which, because the fix, write it up, or enforce it, is completely different work.
Days, weeks or months is asked before most gaps have been scoped in any detail. An estimate given without at least a rough idea of what building the control involves just becomes a number project sponsors anchor to and then miss.
A gap marked as a blocking dependency on another gap changes the realistic certification date more than any single major gap does. If the plan does not sequence blocking items first, the target date in Summary is fiction regardless of how many other gaps close in parallel.
Action Required tends to default toward No once the Plan section is filled in, but a plan approved while a 'would be a major if found' gap is still open should still carry an action. Closing the sign-off loop early is the fastest way to walk into a failed pre-assessment.
What auditors find
Most common certification gap analysis findings
The patterns below come up across gap analyses regardless of which standard sits behind them; they are about how the exercise gets run, not the requirements of any one scheme.
| Finding | Clause | What fixes it |
|---|---|---|
| Gap analysis run entirely by the person who owns the system being assessed | ISO 19011 cl.5.4 | Pair an internal assessment with at least a sampled review by a consultant or the certification body's pre-assessment before treating the gap count as final. |
| Effort recorded as 'weeks' or 'months' with no supporting scope note | ISO 19011 cl.5.3 | Require a one-line scope statement alongside every effort estimate so the number can be checked, and re-estimated, once the gap is actually worked. |
| 'Fully in place' scored against a documented process with no evidence of use tested | ISO 19011 cl.6.4 | Change the current-state judgement to partly in place unless someone has actually sampled the record or observed the practice, not just read the procedure. |
| Gaps marked 'would be a major if found' with no owner or target date set | ISO 19011 cl.5.5 | Force owner and target date as required fields whenever the major flag is set, ahead of every other gap in the queue. |
| Implementation plan approved by management with resources only 'partly' committed | ISO 19011 cl.5.7 | Treat partly committed resourcing as an open risk on the realistic certification date, and restate the date once resourcing is confirmed rather than leaving the original estimate standing. |
| Dependency between gaps left blank because the two items were logged by different people | ISO 19011 cl.5.4 | Review the gap list as a set before it goes to management, specifically to spot dependencies that individual gap owners would not see from their own item. |
Case in point
Case in point: the pre-assessment that found what the internal analysis missed
A site preparing for its first ISO 45001 certification ran an internal gap analysis and recorded four gaps, all scored as weeks of effort, with the safety manager marking their own risk assessment process as fully in place because the procedure had been rewritten six months earlier.
The certification body's paid pre-assessment, run as a second Carried Out By pass before the real audit was booked, found the same four gaps plus three more, including that the rewritten risk assessment procedure had never actually been used in two of the site's five departments. The realistic certification date moved back a full quarter, but it moved back before the certification body's own auditor found it live, not after.
The template
The template, field by field
The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.
4 sections
- Reference
- CMP-020
- Archetype
- Assessment
- Record ID
- CGA-2026-000
- Scoring
- Gap count by clause
- Direction
- High is bad
- Singleton
- No
- Basis
- ISO 19011
- Links
- Links Clause Register
- Tags
- Certification, Planning
- Sections
- 4
- Fields
- 43
- Follow up fields
- 3
- Repeating sections
- 1
- Links out
- 2
Header
10 fieldsAnalysis ID*
Auto sequence. Format CGA-2026-000.
The record's own ID. Other templates point at this value.
Status*
Drives who this goes to next.
- Planned2 pts
- In progress2 pts
- Complete3 pts
- Deferred0 pts
- Open0 pts
- Closed3 pts
- Overdue0 pts
Date and Time*
Completed By*
Site*
Site ID*
Format SITE-000.
Links to FDN-001 Site ID
Standard*
Analysis Purpose*
Carried Out By*
Internal, consultant, or certification body pre-assessment. Each brings a different level of candour.
Effort, Not Just Gaps
A gap list without effort estimates cannot be planned. State for each gap what has to be built, who builds it and roughly how long it takes.
Gaps
Repeats10 fieldsClause*
Requirement*
Current State*
- Fully in place3 pts
- Partly in place1 pt
- Nothing in place0 pts
Gap Description*
What Needs To Exist*
A documented process, a record, evidence of use, a competence, or a physical control.
Effort*
- Days3 pts
- Weeks2 pts
- Months0 pts
Owner*
Dependency On Other Gaps
- None3 pts
- Some1 pt
- Blocking0 pts
Target Date*
Would Be A Major If Found*
- No3 pts
- Yes0 pts
Summary
9 fieldsClauses Assessed*
Gaps Identified*
Major Gaps*
Estimated Effort Days
External Support Required*
- No3 pts
- Some2 pts
- Extensive0 pts
Estimated Cost
Realistic Certification Date*
Existing System Covers Most Requirements*
Most sites already do the things. What is missing is usually the evidence and the linkage, not the activity.
- Yes3 pts
- Partly1 pt
- No0 pts
Documentation Burden Reasonable*
- Yes3 pts
- Heavy1 pt
- Excessive0 pts
Plan
14 fieldsImplementation Plan Created*
- Yes3 pts
- No0 pts
Resources Committed*
- Yes3 pts
- Partly1 pt
- No0 pts
Approved By Management*
- Yes3 pts
- No0 pts
Readiness Audit Scheduled*
- Yes3 pts
- No0 pts
Certification Body Selected
Next Review Due*
Action Required*
Raise the action record, then enter its reference here.
- No2 pts
- Yes0 pts
Priority
- High0 pts
- Medium1 pt
- Low3 pts
CAPA ID
Format CAPA-2026-00000.
Links to FDN-014 CAPA ID
Action Owner
Compliance Lead*
Signature*
Site Manager*
Second Signature*
CMP-020 · record IDs look like CGA-2026-000 · Links Clause Register
Open in KnowellaRun it with agents
From a document you fill in to a programme that runs itself
The form is the easy part. Keeping it current, routing it to the right owner and holding the evidence together is the work that actually slips.
Holds the certification gap analysis library against your registers, routes each record to its owner, and keeps the evidence trail together across whichever standard the site is pursuing.
Feeds ISO 45001 gap analyses from the live incident, hazard and permit registers, so 'evidence of use' can be checked against records that already exist rather than reconstructed for the assessment.
Links ISO 9001 and food safety scheme gaps back to the nonconformance and CAPA history, so a 'fully in place' claim can be checked against how the process actually performed.

Coordinates the crew, rolls completion and exceptions into one view, and holds every write for your approval before it touches a record.
This template lives in KnowComply — audit and governance. Audit programmes, legal register, management review, risk and certification.
Meet KnowComply→Glossary
Certification Gap Analysis definitions and key terms
- Gap analysis
- An assessment run against a standard's requirements before certification is sought, to find what is missing rather than to score a live audit.
- Pre-assessment
- An optional paid visit from the certification body, ahead of the real certification audit, that tests readiness with the same rigour as the eventual audit.
- Major nonconformity
- A finding serious enough, on its own or combined with others, to stop a certificate being issued or maintained until it is closed.
- Management system standard
- A certifiable ISO standard, such as ISO 9001, ISO 14001 or ISO 45001, that sets requirements for how an organisation runs a particular area, rather than for a product.
- Scope extension
- Adding a site, process or product range to an existing certificate, which typically needs its own gap analysis against the extended scope.
FAQ
Frequently asked questions about certification gap analysis
Does a gap analysis replace the certification audit?+
No. It is preparation work that estimates readiness and produces a plan; only the certification body's audit can actually award or maintain the certificate.
Should the gap analysis use the exact clause numbers of the target standard?+
Yes, the Clause and Requirement fields should reference the actual standard being pursued, ISO 45001, ISO 9001 and so on, even though the method behind how the analysis is run follows ISO 19011.
Who should carry out the gap analysis if the site has never been audited before?+
A first-time site benefits most from a certification body pre-assessment or an external consultant, because an internal assessor with no reference point for what 'fully in place' looks like in practice tends to under- or over-state readiness.
What happens if the realistic certification date keeps slipping?+
It usually means gaps were scoped optimistically, or a blocking dependency was not sequenced first. The fix is to re-run the effort and dependency fields against what has actually been learned, not to just push the date.
Does every gap need an implementation plan of its own?+
No, the Plan section covers the programme as a whole; individual gaps only need their own action record raised when Action Required is set to Yes.
How does this differ from an internal audit?+
An internal audit tests a live management system against its own procedures and reports findings; a gap analysis tests readiness against a standard nobody has been certified to yet, and its output is a plan rather than a scored audit.
Keep going
Related templates and programmes
Industries this is written for
Programmes this belongs to
Used together in Internal Audit and Certification
Internal Audit Programme
Sets out what will be audited, when, by whom and against which standard, across the year
Internal Audit Report
Records an internal audit against a standard or process, with findings and evidence
Audit Plan
Sets out the scope, criteria, schedule and people involved for a single audit
Audit Finding Record
Records a single audit finding with its evidence, clause reference and classification
Audit Follow Up Record
Checks whether audit findings have actually been closed and the fixes work
Auditor Competency Record
Records an internal auditor's training, experience and audits performed
More in Cert Readiness
ISO 45001 Readiness Audit
Audits the occupational health and safety management system against ISO 45001 ahead of certification or surveillance
ISO 14001 Readiness Audit
Audits the environmental management system against ISO 14001 ahead of certification or surveillance
External Audit Record
Records a certification body or customer audit, including findings and the response required

Written and reviewed by
Siddarth Singh
Founder & Chief Executive Officer, Knowella
Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.
- Certified Safety Professional (CSP), Board of Certified Safety Professionals
- MBA, University of Chicago Booth School of Business
- MS and BS, The Ohio State University, Industrial and Systems Engineering
- Six Sigma Black Belt
Sources and last review. Reviewed 16 August 2026 against:
- ISO 19011:2018 — Guidelines for auditing management systems
- ISO 45001:2018 — Occupational health and safety management systems
- ISO 9001:2015 — Quality management systems
- ISO/IEC 17021-1:2015 — Conformity assessment, requirements for bodies providing audit and certification of management systems
This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.