What this is
What is an ISO 14001 readiness audit?
What is an ISO 14001 readiness audit?
It is a clause-by-clause examination of an environmental management system carried out before an external certification event, to find what a certification body would find while there is still time to fix it. It covers context and leadership, planning, support, operation, and performance and improvement, then records each gap with the severity it would attract externally and whether it can close in time. Its output is a recommendation on whether to proceed.
How does it differ from the internal audit required by clause 9.2?
Clause 9.2 requires a programme of internal audits covering the whole system at planned intervals, typically split into process audits across the year. A readiness audit is a single sweep of the whole standard against a fixed external date, trading depth on any one process for coverage of every clause. It can also serve as one of the clause 9.2 audits, but that has to be planned rather than claimed afterwards.
What does readiness actually mean for ISO 14001?
Three things at once, and only the first is about documents. Evidence has to exist for each clause, it has to be contemporaneous rather than assembled in the fortnight before the audit, and the people doing the work have to describe their part of the system when asked. A site can hold a complete manual and still take a major, because the auditor tests the third condition on the shop floor and the second by reading record dates.
Scope
When is an iso 14001 readiness audit required?
This audit sits between the registers that feed it and the findings that come out of it. Its common misuse is being asked to do the work of the instrument on either side, producing a document too shallow to certify against and too broad to act on.
Use this template when
- An initial ISO 14001 certification is booked and the system needs testing against the whole standard before stage 2
- A recertification or surveillance visit is approaching and clause coverage has to be re-established
- A significant change has occurred since the last external audit: a new process, a new permit, an extension or an acquisition
- The aspects or obligations register has been revised and the downstream controls need checking against it
- An external finding elsewhere in the group suggests a systemic gap worth testing here
Do not use it for
- Auditing the occupational health and safety management system, which is the ISO 45001 Readiness Audit (CMP-018) and turns on different registers and failure modes
- Working out what is missing before a system exists at all, which is the Certification Gap Analysis (CMP-020) and starts from the standard rather than from evidence
- Auditing one process in depth, which belongs in the Process Audit Record (CMP-007) or a scoped Internal Audit Report (CMP-002)
- Recording what a certification body actually found, which is the External Audit Record (CMP-021) and drives a formal response with deadlines
- Building the aspects and obligations registers themselves, which are living registers owned by the environmental function and only sampled here
Compliance mapping
Which ISO 14001:2015 requirements does this satisfy?
ISO 14001 is unusual in having a second audience. The certification body checks whether the system meets the standard; the environmental regulator checks whether the site meets its permit, and does not care about the standard at all. The clauses that matter most here are the ones where both look at the same evidence.
| Clause | Requirement | Where it lands |
|---|---|---|
| ISO 14001 cl.4.1, 4.2 and 4.3 | Context and interested parties determined, and the scope of the environmental management system defined, documented and available | Context and leadership |
| ISO 14001 cl.6.1.2 | Aspects determined from a lifecycle perspective, covering abnormal and foreseeable emergency conditions, with criteria for significance | Planning |
| ISO 14001 cl.6.1.3 | Compliance obligations determined, how they apply determined, and the obligations maintained as documented information | Planning |
| ISO 14001 cl.7.2 | Competence determined and achieved for persons whose work affects environmental performance and compliance obligations | Support |
| ISO 14001 cl.8.1 | Operational control for significant aspects, including outsourced processes and requirements communicated to external providers | Operation |
| ISO 14001 cl.8.2 | Emergency preparedness and response established, with periodic testing of the planned response and review after events | Operation |
| ISO 14001 cl.9.1.2 | Compliance evaluated at planned frequencies, knowledge of compliance status maintained, results retained | Performance and improvement |
| ISO 14001 cl.7.3 | Persons aware of the policy, the significant aspects of their work, their contribution, and the implications of not conforming | Evidence quality |
What it does not cover
- The compliance evaluation required by clause 9.1.2, which is a periodic evaluation against each obligation with its own record, sampled here rather than performed.
- The environmental aspects register, which is the output of clause 6.1.2 and a maintained register in its own right; this audit tests whether it is credible, not what it contains.
- Permit and consent obligations, which carry statutory monitoring and reporting duties surviving independently of whether the site is certified.
- Management review under clause 9.3, which requires named inputs including compliance status, and is not discharged by presenting a readiness score.
- Corrective action on the gaps found, which belongs in the finding and CAPA records where root cause and effectiveness verification are held, not in the gap row.
Global
ISO 14001 Readiness Audit requirements by country
No jurisdiction requires ISO 14001. All of them require the underlying environmental compliance, usually through permits with numeric limits and reporting duties, which is why scoring clause 6.1.3 generously stores up a problem with a regulator rather than with a certification body.
Clean Air Act Title V permits; Clean Water Act NPDES permits; RCRA generator standards at 40 CFR part 262
Obligations arrive as permit conditions with self-monitoring, record-keeping and mandatory reporting of exceedances.
Compliance evaluation must reconcile to permit limits and submitted monitoring reports, and a self-identified exceedance is reportable rather than an internal finding.
Environmental Permitting (England and Wales) Regulations 2016; Environmental Protection Act 1990 s.34
Environment Agency permits set conditions and improvement programmes; the waste duty of care runs alongside for every transfer.
Carrier checks and transfer notes are a separate statutory duty, so a strong clause 8.1 score with unchecked waste contractors is a gap the scoring will not show.
Industrial Emissions Directive 2010/75/EU; EMAS Regulation (EC) No 1221/2009
Permits for installations must be set by reference to BAT conclusions; EMAS offers a verified alternative with public reporting.
Where BAT conclusions apply, compliance obligations include emission levels the site did not choose, and an aspects register ignoring them is incomplete at source.
Canadian Environmental Protection Act 1999; provincial approvals and certificates of authorisation
Federal controls on substances and releases combined with provincial permitting and reporting regimes.
The obligations register has to carry both levels for one site, and provincial approval conditions are usually the ones that bite operationally.
Protection of the Environment Operations Act 1997 (NSW); Environment Protection Act 2017 (Vic) general environmental duty
Licensed premises conditions plus a proactive duty to minimise risks of harm so far as reasonably practicable.
A general duty is assessed on what the site knew and could have done, so a register that missed a foreseeable risk becomes evidence against the operator.
ISO 14001:2015; ISO/IEC 17021-1 and IAF mandatory documents
Certification is a two-stage process, with stage 1 examining readiness and stage 2 testing implementation and effectiveness.
Stage 1 exists to find what this template looks for, so a weak readiness audit does not avoid the finding, it moves it to a visit that delays the certificate.
How to complete it
How to complete an iso 14001 readiness audit, step by step
The template produces three percentages and a recommendation. Whether the audit was worth running is decided by four judgements made while it is in progress, none of which appear as a score.
The clause score is downstream of the aspects register and the obligations register, and inherits every omission in them. Take the aspects register into the plant and try to break it: walk the yard, the drainage, the bunds, the waste compound, the abnormal states such as start-up, bypass and spill. A register built from the process flow diagram stops at the factory wall, and everything under operation is then scored against a register that never contained the risk.
A register naming an Act, a regulation or a directive answers a question nobody asked. Clause 6.1.3 requires the organisation to determine how the obligation applies: the permit condition number, the limit, the monitoring frequency, the reporting deadline, the accountable person. Score it against that rather than the existence of a spreadsheet, and trace two or three obligations into the monitoring records to see whether the chain closes.
Evidence quality predicts the external outcome, and it is the section most often completed from the office. External auditors ask front line workers what the significant aspects of their job are and what they would do in a spill; if those answers do not come, documentation will not save the site. Speak to enough people across enough shifts that the number recorded is defensible, and treat night shift as a separate population.
The recommendation on proceeding is the only output anyone acts on, and it should follow the gaps that cannot close before the external date rather than the readiness percentage. One critical gap on aspects or compliance evaluation outranks a good overall score. Completeness percent exists because a high score on a half-completed form is not a high score, and a clause genuinely inapplicable here belongs in the scope statement, not scored fully met.
What auditors find
Most common iso 14001 readiness audit findings
The findings below are the ones certification bodies raise most often at stage 2 on environmental systems, and almost all are visible to an honest readiness audit first.
| Finding | Clause | What fixes it |
|---|---|---|
| Aspects register covers normal operation only; no abnormal conditions or foreseeable emergency situations. | ISO 14001 cl.6.1.2 | Add start-up, shutdown, bypass, spill and failure states and re-apply the significance criteria. |
| No lifecycle perspective; the register begins at goods-in and ends at dispatch. | ISO 14001 cl.6.1.2 | Extend to raw material sourcing, product use and end of life, and record why stages were excluded. |
| Significance criteria not documented, so the same aspect is significant at one site and not another. | ISO 14001 cl.6.1.2 | Write the criteria down, apply them to the whole register in one pass, and record the significant aspects. |
| Compliance obligations register lists legislation without determining how it applies to the site. | ISO 14001 cl.6.1.3 | Convert each entry to the condition, limit, monitoring frequency and accountable owner for this site. |
| Compliance evaluation not performed at a planned frequency, or performed with no record retained. | ISO 14001 cl.9.1.2 | Set a frequency per obligation and retain the result, including the evidence examined. |
| Contractors on site with no environmental requirements communicated and no verification on the ground. | ISO 14001 cl.8.1 | Put environmental conditions in the permit to work and check compliance in the area, not in the file. |
| Emergency response plan exists but has never been tested. | ISO 14001 cl.8.2 | Run a spill or release exercise, record what failed, and revise the plan on the outcome. |
| Monitoring equipment used for compliance data is not calibrated or verified. | ISO 14001 cl.9.1.1 | Bring instruments used for permit or obligation monitoring into the calibration programme. |
| Front line workers cannot describe the significant aspects of their own task. | ISO 14001 cl.7.3 | Deliver awareness at task level, naming the aspect and the action, and verify by asking rather than by attendance. |
| Objectives stated as aspirations, with no measure, no baseline and no owner. | ISO 14001 cl.6.2 | Give each objective an indicator, a baseline, a date and a named owner, and plan the actions to achieve it. |
Case in point
Case in point: eighty-eight per cent ready, and a regulator on site
A packaging plant booked its initial ISO 14001 certification and ran this readiness audit ten weeks out. Context, scope, policy and leadership all scored fully met. The aspects register was thorough, over two hundred entries, and contractor control scored fully met on the strength of a well-organised pack with environmental clauses in every subcontract. Readiness came out at eighty-eight per cent, the likely outcome pass with minors, and the recommendation was to proceed.
Six weeks later a contractor jet-washing the yard before the audit discharged the washings, carrying oil and residue from the compactor bay, into a surface water drain. The site had no current drainage plan, so nobody knew that drain went to the watercourse rather than to foul. The regulator attended, took samples and opened an enquiry. At stage 2 the certification body raised majors against clauses 6.1.2 and 8.1.
The register had two hundred entries and none concerned yard drainage, because it was built from the process flow diagram and the diagram started at goods-in. Contractor control scored fully met because the auditor assessed paperwork rather than watching a contractor work. Both gaps were findable in the readiness audit: one by walking the drains with the register in hand, the other by standing in the yard for twenty minutes. The corrective action was a drainage survey, a register rebuilt from a site walk, and environmental conditions moved into the permit to work.
The template
The template, field by field
The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.
9 sections
- Reference
- CMP-019
- Archetype
- Audit
- Record ID
- AUD-2026-000
- Scoring
- Weighted percent, maturity
- Direction
- High is good
- Singleton
- No
- Basis
- ISO 14001:2015
- Links
- Links Clause Register; feeds Finding
- Tags
- Certification, Environment
- Sections
- 9
- Fields
- 78
- Follow up fields
- 3
- Repeating sections
- 1
- Links out
- 3
Header
13 fieldsAudit ID*
Auto sequence. Format AUD-2026-00000.
The record's own ID. Other templates point at this value.
Status*
Drives who this goes to next.
- Planned2 pts
- In progress2 pts
- Complete3 pts
- Deferred0 pts
- Open0 pts
- Closed3 pts
- Overdue0 pts
Date and Time*
Completed By*
Site*
Site ID*
Format SITE-000.
Links to FDN-001 Site ID
Standard*
Audit Purpose*
Initial certification readiness, recertification readiness, or maintenance check.
Auditor*
External Audit Date
Weeks Until External Audit*
Certification Body
Score Honestly Now Or Fail Later
Environmental systems fail external audit most often on aspects, legal register evidence and operational control of contractors. Score those three hardest.
Context and leadership
6 fieldsContext And Interested Parties Determined*
- Fully met3 pts
- Partly met1 pt
- Not met0 pts
Scope Defined And Documented*
- Fully met3 pts
- Partly met1 pt
- Not met0 pts
Environmental Policy Established*
- Fully met3 pts
- Partly met1 pt
- Not met0 pts
Top Management Demonstrating Leadership*
- Fully met3 pts
- Partly met1 pt
- Not met0 pts
Roles And Responsibilities Assigned*
- Fully met3 pts
- Partly met1 pt
- Not met0 pts
Lifecycle Perspective Applied*
- Fully met3 pts
- Partly met1 pt
- Not met0 pts
Planning
6 fieldsEnvironmental Aspects Identified*
- Fully met3 pts
- Partly met1 pt
- Not met0 pts
Significance Criteria Applied*
- Fully met3 pts
- Partly met1 pt
- Not met0 pts
Abnormal And Emergency Conditions Covered*
- Fully met3 pts
- Partly met1 pt
- Not met0 pts
Compliance Obligations Determined*
- Fully met3 pts
- Partly met1 pt
- Not met0 pts
Risks And Opportunities Assessed*
- Fully met3 pts
- Partly met1 pt
- Not met0 pts
Objectives Established And Measurable*
- Fully met3 pts
- Partly met1 pt
- Not met0 pts
Support
6 fieldsResources Provided*
- Fully met3 pts
- Partly met1 pt
- Not met0 pts
Competence Determined And Achieved*
- Fully met3 pts
- Partly met1 pt
- Not met0 pts
Awareness Across The Workforce*
- Fully met3 pts
- Partly met1 pt
- Not met0 pts
Communication Internal And External*
- Fully met3 pts
- Partly met1 pt
- Not met0 pts
Documented Information Controlled*
- Yes3 pts
- Partly1 pt
- No0 pts
Records Retained And Retrievable*
- Fully met3 pts
- Partly met1 pt
- Not met0 pts
Operation
6 fieldsOperational Planning And Control*
- Fully met3 pts
- Partly met1 pt
- Not met0 pts
Controls For Significant Aspects*
- Fully met3 pts
- Partly met1 pt
- Not met0 pts
Contractor And Outsourcing Control*
- Fully met3 pts
- Partly met1 pt
- Not met0 pts
Procurement And Design Controls*
- Fully met3 pts
- Partly met1 pt
- Not met0 pts
Emergency Preparedness And Response*
- Fully met3 pts
- Partly met1 pt
- Not met0 pts
Emergency Drills Conducted*
- Fully met3 pts
- Partly met1 pt
- Not met0 pts
Performance and improvement
7 fieldsMonitoring And Measurement*
- Fully met3 pts
- Partly met1 pt
- Not met0 pts
Calibration Of Monitoring Equipment*
- Fully met3 pts
- Partly met1 pt
- Not met0 pts
Compliance Evaluation Performed*
- Fully met3 pts
- Partly met1 pt
- Not met0 pts
Internal Audit Programme Operating*
- Fully met3 pts
- Partly met1 pt
- Not met0 pts
Management Review Conducted*
- Fully met3 pts
- Partly met1 pt
- Not met0 pts
Nonconformity And Corrective Action*
- Fully met3 pts
- Partly met1 pt
- Not met0 pts
Continual Improvement Evidenced*
- Fully met3 pts
- Partly met1 pt
- Not met0 pts
Evidence quality
6 fieldsEvidence Located For Each Clause*
- Yes3 pts
- Partly1 pt
- No0 pts
Evidence Would Satisfy An External Auditor*
- Yes3 pts
- Marginal1 pt
- No0 pts
Records Contemporaneous*
- Yes3 pts
- Doubtful1 pt
- Clearly not0 pts
People Can Explain Their Part*
External auditors ask front line workers. If they cannot describe the system, documentation will not save you.
- Yes3 pts
- Partly1 pt
- No0 pts
Front Line Workers Spoken To*
All Shifts Checked*
- Yes3 pts
- Partly1 pt
- No0 pts
Gaps
Repeats6 fieldsClause*
Gap Description*
Severity If Found Externally*
- Observation3 pts
- Minor2 pts
- Major1 pt
- Critical0 pts
Owner*
Closable Before External Audit*
- Yes3 pts
- Partly1 pt
- No0 pts
CAPA ID
Links to FDN-014 CAPA ID
Result
22 fieldsItems Assessed*
Excludes anything marked N/A.
Items Failed*
Score Percent*
Calculated on submission. High is good. N/A items leave the denominator.
Result Band*
- Pass3 pts
- Caution1 pt
- Fail0 pts
Completeness Percent*
How much of the template was actually answered. A high score on a half completed form is not a high score.
Clauses Fully Met*
Clauses Partially Met*
Clauses Not Met*
Readiness Percent*
Likely External Outcome*
- Pass cleanly4 pts
- Pass with minors3 pts
- Majors likely1 pt
- Fail likely0 pts
Recommend Proceeding With External Audit*
- Yes3 pts
- With reservations1 pt
- No0 pts
Gap Analysis ID
Links to CMP-020 Analysis ID
Reaudit Before External*
- Not needed3 pts
- Yes1 pt
Reaudit Date
Action Required*
Raise the action record, then enter its reference here.
- No2 pts
- Yes0 pts
Priority
- High0 pts
- Medium1 pt
- Low3 pts
CAPA ID
Format CAPA-2026-00000.
Links to FDN-014 CAPA ID
Action Owner
Auditor*
Signature*
Site Manager*
Second Signature*
CMP-019 · record IDs look like AUD-2026-000 · Links Clause Register; feeds Finding
Open in KnowellaRun it with agents
From a document you fill in to a programme that runs itself
The audit is a day's work. What fails around it is the aspects register nobody revisits when the site changes, the permit condition living in an inbox, and the gap marked closable that then is not.
Holds the aspects and obligations registers against the site's permits and consents, and flags obligations with no monitoring record behind them.
Places the audit in the programme, tracks each gap to a CAPA with an owner and a date, and keeps the evidence set assembled for the visit.
Carries environmental conditions into contractor approval and the permit to work, so operational control reaches the person doing the job in the yard.

Watches the weeks remaining against open gaps, escalates the ones not closable before the external date, and pulls last cycle's findings into scope.
This template lives in KnowComply — audit and governance. Audit programmes, legal register, management review, risk and certification.
Meet KnowComply→Glossary
ISO 14001 Readiness Audit definitions and key terms
- Environmental aspect
- An element of an organisation's activities, products or services that interacts or can interact with the environment, such as a discharge, an emission or a waste stream.
- Environmental impact
- The change to the environment resulting from an aspect. The aspect is what the site does; the impact is what happens as a result.
- Significant aspect
- An aspect that can have a significant impact, determined by criteria the organisation sets itself, and the trigger for operational control under clause 8.1.
- Compliance obligation
- A legal requirement the organisation must comply with, plus other requirements it chooses or is obliged to meet, such as customer commitments.
- Lifecycle perspective
- Consideration of the stages of a product or service from raw material acquisition to end of life, so far as the organisation can control or influence them.
- Abnormal condition
- A foreseeable operating state outside normal running, such as start-up, shutdown, maintenance or bypass, which must be covered when aspects are determined.
- Operational control
- The controls applied to significant aspects, including engineered controls, procedures and requirements placed on external providers.
- Compliance evaluation
- The planned, recorded check of performance against each compliance obligation, so the organisation maintains knowledge of its compliance status.
FAQ
Frequently asked questions about iso 14001 readiness audit
How far ahead of the external audit should this be run?+
Far enough that gaps can close and then be seen working: eight to twelve weeks for a first certification, six to eight for surveillance. Running it two weeks out produces a document that predicts the outcome without changing it. A short number in weeks until external audit should push the recommendation towards reservations, not towards a remediation sprint.
Can the readiness audit count as the internal audit under clause 9.2?+
Yes, if it was planned that way. It needs to sit in the audit programme, have defined criteria and scope, be conducted by a competent auditor selected to keep the process impartial, and have its results reported to management. What it cannot do is retrospectively become the clause 9.2 audit because nothing else was done that year.
Should the site's own environmental manager run it?+
Only with reservations. The environmental manager built the aspects register, wrote the procedures and owns the objectives, so asking them to audit those things breaks the impartiality every management system standard requires. Better is a trained internal auditor from another function or site, with the environmental manager as auditee. Where that is impossible, record the limitation and have the site manager countersign.
What actually causes majors at stage 2 on environmental systems?+
Three things, in this order: an aspects register that misses something obvious once you are outside, obligations listed rather than interpreted, and operational control that stops at the boundary of directly employed staff. Score those three hardest, and be suspicious of any readiness audit where they came back fully met first time.
Does a good readiness score mean the site is compliant?+
No, and conflating the two is the most expensive mistake available here. ISO 14001 requires a system for determining and evaluating obligations; it does not certify that they are met. A site can hold a clean certificate and breach a permit limit, and can be fully compliant with a weak system. The only clause where the two meet is 9.1.2.
What should happen when the audit recommends not proceeding?+
Move the external date. It is unpopular and cheaper than the alternative, because a major at stage 2 costs a follow-up visit, a corrective action cycle and usually a longer delay than the one avoided. Record the reaudit decision and date, close what cannot close in time, then re-run the affected sections rather than the whole form.
Keep going
Related templates and programmes
Industries this is written for
Programmes this belongs to
Used together in Internal Audit and Certification
Internal Audit Programme
Sets out what will be audited, when, by whom and against which standard, across the year
Internal Audit Report
Records an internal audit against a standard or process, with findings and evidence
Audit Plan
Sets out the scope, criteria, schedule and people involved for a single audit
Audit Finding Record
Records a single audit finding with its evidence, clause reference and classification
Audit Follow Up Record
Checks whether audit findings have actually been closed and the fixes work
Auditor Competency Record
Records an internal auditor's training, experience and audits performed
More in Cert Readiness
ISO 45001 Readiness Audit
Audits the occupational health and safety management system against ISO 45001 ahead of certification or surveillance
Certification Gap Analysis
Identifies what is missing before a first certification attempt
External Audit Record
Records a certification body or customer audit, including findings and the response required

Written and reviewed by
Siddarth Singh
Founder & Chief Executive Officer, Knowella
Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.
- Certified Safety Professional (CSP), Board of Certified Safety Professionals
- MBA, University of Chicago Booth School of Business
- MS and BS, The Ohio State University, Industrial and Systems Engineering
- Six Sigma Black Belt
Sources and last review. Reviewed 16 August 2026 against:
- ISO 14001:2015 clauses 4.1 to 4.3, 6.1.2, 6.1.3, 7.2, 7.3, 8.1, 8.2, 9.1.1, 9.1.2, 9.2 and 9.3
- ISO/IEC 17021-1 and IAF mandatory documents on two-stage initial certification
- Environmental Permitting (England and Wales) Regulations 2016; Environmental Protection Act 1990 s.34
- Industrial Emissions Directive 2010/75/EU and EMAS Regulation (EC) No 1221/2009
- Clean Air Act Title V, Clean Water Act NPDES permitting and RCRA generator standards at 40 CFR part 262 (US)
- Protection of the Environment Operations Act 1997 (NSW); Environment Protection Act 2017 (Vic)
This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.