ISO 9001

ISO 9001 Gap Analysis: How to Assess Your QMS Before Certification

An ISO 9001 gap analysis compares an organization's current practices against the standard's requirements to identify what's missing before pursuing certification. Unlike an internal audit, which tests conformance of a QMS that's already operating, a gap analysis is a readiness assessment — often conducted earlier, while procedures and controls are still being built out.

Certification audits work best when they confirm readiness that's already been genuinely assessed, rather than serving as the first real test of where a QMS actually stands. A structured gap analysis compares current practice against the standard's specific requirements clause by clause, surfacing exactly what's missing while there's still time to close it. This guide covers a practical method for conducting one — how to run the assessment, what gaps show up most often, and how to turn findings into a real action plan — written by Maria Falbo, a Lead Auditor with decades of ISO 9001 experience.

Maria Falbo|Lead Trainer, Logix ISO|August 2026|6 min read

Gap Analysis vs. Internal Audit: What's the Difference

These two activities get confused often, but they answer genuinely different questions. An internal audit, required under Clause 9.2, tests whether an already-operating QMS conforms to requirements — it relies on accumulated evidence: records, data, a track record of the system actually running.

A gap analysis asks a more basic question: does the organization currently have what it needs to meet each requirement? It's typically conducted earlier, sometimes comparing draft procedures or planned controls against the standard rather than months of operating history, because that operating history doesn't exist yet. For the full audit methodology once a QMS is established, see our ISO 9001 Internal Audit: The Complete Guide.

When to Conduct a Gap Analysis

The most common use case is before a first certification audit — confirming readiness rather than finding out about major gaps for the first time when a certification body's auditor shows up. This is typically the natural next step after the implementation work covered in our how to implement ISO 9001 guide, once the QMS has been operating long enough to actually be assessed.

It's also useful before a scheduled recertification, particularly if the organization has changed significantly since the last audit cycle. Organizations transitioning between standard editions benefit from a gap analysis specifically comparing their current QMS against the new edition's requirements — see our ISO 9001:2026 Gap Analysis guide for that specific scenario. A gap analysis is also worth repeating after any major organizational change — a merger, a new facility, a significant process overhaul — where the QMS's coverage may no longer match the organization it's meant to govern.

Prepare for certification with an expert-led gap analysis

Our ISO 9001 consulting services identify exactly where your QMS stands and what still needs to be built.

View Consulting Services

A Practical Method for Conducting One

Work through the standard clause by clause, and for each requirement, honestly assess one of three states: fully in place with evidence to demonstrate it, partially in place but incomplete, or absent. For a full breakdown of what each clause requires, see our ISO 9001 Requirements Explained guide to work through systematically.

This assessment works best combined with direct observation, not just a document review — talking to the people who'd actually be responsible for a given requirement often reveals gaps a document review alone would miss, particularly around whether something genuinely exists versus whether it exists only as an intention.

In Practice

The gap I find gets missed most often in a document-only gap analysis is competence evidence. An organization can point to a training plan and say competence is covered, but a gap analysis that stops there misses the actual question: can the specific people currently doing the work demonstrate the competence the standard requires? A training plan that exists on paper and a workforce that's actually competent are two different things.

Common Gaps Found in Practice

Certain gaps show up repeatedly across gap analyses. Risk and opportunity determination is often present in name but generic, not reflecting the organization's specific operations. Documented information frequently exists in draft form but hasn't actually been formally controlled — no version control, no approval record. Internal audit and management review processes are sometimes planned but haven't actually run yet, meaning there's no evidence they'll function as intended once implemented. Competence evidence, as covered above, is a recurring weak point.

Turning Results into an Action Plan

A gap analysis is only useful if it produces a plan, not just a list of findings. Each identified gap needs an owner, a specific action to close it, and a realistic timeline — with the more foundational gaps (a missing process that other requirements depend on) sequenced ahead of gaps that depend on that foundation already existing.

Resist the temptation to treat every gap as equally urgent. Some gaps represent potential certification blockers; others are refinements that matter but won't stop a certification audit from succeeding. A clear-eyed action plan distinguishes between the two rather than trying to fix everything simultaneously.

In Practice

The difference between a gap analysis that actually gets used and one that gets filed away usually comes down to sequencing. I've seen 40-item gap lists handed to a client with no real prioritization — everything from "no documented quality policy" to "one training record missing" sitting on the same flat list. Compare that to an analysis that opens by identifying the 2 or 3 foundational gaps everything else depends on — say, no internal audit program exists yet, so nothing downstream of it can genuinely be verified — and sequences the rest around fixing those first. The second version gets acted on. The first usually just sits there.

FAQ

Frequently asked questions

How long does an ISO 9001 gap analysis take?

It depends on organization size and QMS maturity, but a thorough gap analysis for a mid-sized organization typically takes one to two weeks, including document review, observation, and interviews.

Can we conduct our own gap analysis without external help?

Yes, provided someone genuinely understands the standard's requirements well enough to assess them honestly. Many organizations use external expertise specifically because an outside perspective is less likely to rate a familiar-but-incomplete practice as "good enough."

Is a gap analysis required by ISO 9001?

No — it's not a formal requirement of the standard. It's a practical readiness step most organizations use voluntarily before pursuing certification.

What's the difference between a gap analysis and a pre-assessment audit offered by certification bodies?

A pre-assessment is typically conducted by the certification body itself, closer to the actual certification audit, and follows a more formal audit structure. A gap analysis is usually earlier, more exploratory, and often conducted by internal staff or a consultant rather than the certification body.

About the Author
Maria Falbo — Lead Trainer, Logix ISO
Maria Falbo
Founder & Lead Trainer, Logix ISO · 25+ Years Global Experience

Maria Falbo has over 25 years of experience working as a Lead Auditor for certification bodies worldwide. She founded Logix ISO with the mission of making expert-level ISO training accessible to organizations of all sizes. Her work spans Quality, Environmental, Occupational Health and Safety, Food Safety, Automotive, and Energy management systems.

Learn more about Maria →
ISO 9001 Consulting Services
Ready for an expert gap analysis of your QMS?

Certification readiness assessment and action planning

View Consulting Services