An ISO 9001 gap analysis compares an organization's current practices against the standard's requirements to identify what's missing before pursuing certification. Unlike an internal audit, which tests conformance of a QMS that's already operating, a gap analysis is a readiness assessment — often conducted earlier, while procedures and controls are still being built out.
Certification audits work best when they confirm readiness that's already been genuinely assessed, rather than serving as the first real test of where a QMS actually stands. A structured gap analysis compares current practice against the standard's specific requirements clause by clause, surfacing exactly what's missing while there's still time to close it. This guide covers a practical method for conducting one — how to run the assessment, what gaps show up most often, and how to turn findings into a real action plan — written by Maria Falbo, a Lead Auditor with decades of ISO 9001 experience.
These two activities get confused often, but they answer genuinely different questions. An internal audit, required under Clause 9.2, tests whether an already-operating QMS conforms to requirements — it relies on accumulated evidence: records, data, a track record of the system actually running.
A gap analysis asks a more basic question: does the organization currently have what it needs to meet each requirement? It's typically conducted earlier, sometimes comparing draft procedures or planned controls against the standard rather than months of operating history, because that operating history doesn't exist yet. For the full audit methodology once a QMS is established, see our ISO 9001 Internal Audit: The Complete Guide.
The most common use case is before a first certification audit — confirming readiness rather than finding out about major gaps for the first time when a certification body's auditor shows up. This is typically the natural next step after the implementation work covered in our how to implement ISO 9001 guide, once the QMS has been operating long enough to actually be assessed.
It's also useful before a scheduled recertification, particularly if the organization has changed significantly since the last audit cycle. Organizations transitioning between standard editions benefit from a gap analysis specifically comparing their current QMS against the new edition's requirements — see our ISO 9001:2026 Gap Analysis guide for that specific scenario. A gap analysis is also worth repeating after any major organizational change — a merger, a new facility, a significant process overhaul — where the QMS's coverage may no longer match the organization it's meant to govern.
Our ISO 9001 consulting services identify exactly where your QMS stands and what still needs to be built.
Work through the standard clause by clause, and for each requirement, honestly assess one of three states: fully in place with evidence to demonstrate it, partially in place but incomplete, or absent. For a full breakdown of what each clause requires, see our ISO 9001 Requirements Explained guide to work through systematically.
This assessment works best combined with direct observation, not just a document review — talking to the people who'd actually be responsible for a given requirement often reveals gaps a document review alone would miss, particularly around whether something genuinely exists versus whether it exists only as an intention.
The gap I find gets missed most often in a document-only gap analysis is competence evidence. An organization can point to a training plan and say competence is covered, but a gap analysis that stops there misses the actual question: can the specific people currently doing the work demonstrate the competence the standard requires? A training plan that exists on paper and a workforce that's actually competent are two different things.
Certain gaps show up repeatedly across gap analyses. Risk and opportunity determination is often present in name but generic, not reflecting the organization's specific operations. Documented information frequently exists in draft form but hasn't actually been formally controlled — no version control, no approval record. Internal audit and management review processes are sometimes planned but haven't actually run yet, meaning there's no evidence they'll function as intended once implemented. Competence evidence, as covered above, is a recurring weak point.
A gap analysis is only useful if it produces a plan, not just a list of findings. Each identified gap needs an owner, a specific action to close it, and a realistic timeline — with the more foundational gaps (a missing process that other requirements depend on) sequenced ahead of gaps that depend on that foundation already existing.
Resist the temptation to treat every gap as equally urgent. Some gaps represent potential certification blockers; others are refinements that matter but won't stop a certification audit from succeeding. A clear-eyed action plan distinguishes between the two rather than trying to fix everything simultaneously.
The difference between a gap analysis that actually gets used and one that gets filed away usually comes down to sequencing. I've seen 40-item gap lists handed to a client with no real prioritization — everything from "no documented quality policy" to "one training record missing" sitting on the same flat list. Compare that to an analysis that opens by identifying the 2 or 3 foundational gaps everything else depends on — say, no internal audit program exists yet, so nothing downstream of it can genuinely be verified — and sequences the rest around fixing those first. The second version gets acted on. The first usually just sits there.
It depends on organization size and QMS maturity, but a thorough gap analysis for a mid-sized organization typically takes one to two weeks, including document review, observation, and interviews.
Yes, provided someone genuinely understands the standard's requirements well enough to assess them honestly. Many organizations use external expertise specifically because an outside perspective is less likely to rate a familiar-but-incomplete practice as "good enough."
No — it's not a formal requirement of the standard. It's a practical readiness step most organizations use voluntarily before pursuing certification.
A pre-assessment is typically conducted by the certification body itself, closer to the actual certification audit, and follows a more formal audit structure. A gap analysis is usually earlier, more exploratory, and often conducted by internal staff or a consultant rather than the certification body.

Maria Falbo has over 25 years of experience working as a Lead Auditor for certification bodies worldwide. She founded Logix ISO with the mission of making expert-level ISO training accessible to organizations of all sizes. Her work spans Quality, Environmental, Occupational Health and Safety, Food Safety, Automotive, and Energy management systems.
Learn more about Maria →Certification readiness assessment and action planning