Readiness Assessment, Internal Audit, Certification Audit: Three Different Things
By Alfred Obeng, Founder, Goldline Consultancy
ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP
6 min read
Contents
Three exercises, three different purposes, and three different answers to the question of who is allowed to perform them. They arrive in a buyer's inbox looking similar because all three produce a report with findings in it, and the reports genuinely do look alike.
The useful distinction is not what each one costs. It is what each one is evidence of, and who has to be standing behind it for that evidence to count.
The three, in the order they occur
| Readiness assessment | Internal audit | Certification audit | |
|---|---|---|---|
| Question it answers | How far are we from being able to certify | Does the management system conform, and is it working | Does this organisation qualify for a certificate |
| When | Before you build, or early in building | Once the system operates, then at planned intervals for as long as you hold the certificate | Stage 1 and Stage 2, then surveillance |
| Required by | Nothing. It is a decision-making purchase | Clause 9.2 of ISO/IEC 27001 or ISO/IEC 42001 | The certification scheme, if you want the certificate |
| Who may perform it | Anyone competent, including the firm that will implement | The organisation, through an objective and impartial programme | An accredited certification body, and nobody else |
| What it produces | A gap position and a route | An audit report and nonconformities feeding clause 10 and the management review | A certification decision |
| Is it evidence to a third party | No. It is evidence to you | Yes, to your certification body | Yes, to your buyers, insurers and regulators |
The line that cannot be crossed
Goldline cannot certify anything, in any tense. Neither can any other consultancy. Certification decisions are made by accredited certification bodies, and the separation is structural rather than a matter of preference: the standard those bodies are accredited against restricts them from providing consultancy, and the detail of what it restricts is worth reading if anybody has told you otherwise.
So of the three exercises above, the third is never available from your consultancy. Any proposal that blurs that line is worth a careful second read.
Where the confusion actually comes from
Not from buyers being careless. From the word audit doing three jobs.
A readiness assessment is often described as a gap audit. A pre-certification rehearsal is often called a mock audit. The clause 9.2 exercise is the internal audit. The certification body performs the certification audit. Four uses of one word, and only two of them are audits in the sense that anything downstream depends on.
The test that cuts through it: ask what the report is evidence of, and to whom. A readiness assessment is evidence to you, about you. An internal audit is evidence to your certification body that clause 9.2 has been satisfied. A certification audit is evidence to the market. If a proposal does not make clear which of those it produces, that is the question to ask before the price one.
What each is actually for
The readiness assessment is a scoping instrument. Its real output is not the gap list, it is the boundary. Most organisations arrive with a scope set far wider than their buyers asked for, and narrowing it is the single largest lever on what everything afterwards costs. Goldline's readiness assessments credit in full against a subsequent Sprint, which is stated on the pricing page along with the current figures.
The internal audit is a recurring obligation with a real job attached. It exists so that your own management learns the truth about conformity before an external party does. It continues for as long as you hold the certificate, and it is assessed closely at Stage 2.
The certification audit is the only one that produces a certificate, in two stages, and Stage 1 and Stage 2 test different things.
The fourth thing, which is none of these
A pre-certification readiness audit sits between the internal audit and the certification audit, and is neither. It is a rehearsal against Stage 1 and Stage 2 criteria, it carries no independence requirement because it is advisory, and it does not satisfy clause 9.2. That distinction has its own article, because it is the one that costs organisations money most often: internal audit versus pre-certification readiness audit.
The sequence that works
Readiness assessment to set the scope and the route. Build. Operate the system long enough that there is something to audit. Internal audit, then remediate through clause 10 and take the results to the management review. Rehearse if the stakes justify it. Then Stage 1 and Stage 2 with an accredited certification body.
Organisations that compress this usually compress the middle, and the middle is the part the certification body examines most carefully, because it is the only part that tells them whether the management system operates or merely exists.
Sources
- ISO/IEC 27001:2022 and ISO/IEC 42001:2023, clause 9.2 internal audit, clause 9.3 management review, clause 10. Not published free of charge and not quoted here.
- Requirements restricting accredited certification bodies from providing management system consultancy and from providing internal audits to certified clients: ISO/IEC 17021-1:2015 clause 5.2, as reproduced in the Southern African Development Community Accreditation Service assessment checklist SADCAS F 40 (a), Issue 6, dated 23 August 2024. Read 1 September 2026.
- Published Goldline prices, durations and the readiness assessment credit rule, goldlineconsultancy.co.uk/pricing, read 1 September 2026.
Alfred Obeng
Founder of Goldline Consultancy. ISO 42001 Lead Implementer (PECB), ISO 42001 Lead Auditor (PECB), ISO 27001 Senior Lead Implementer (PECB), ISO 27001 Lead Auditor (PECB), CISSP, PMP.
Related reading
6 min read
ISO 42001 Internal Audit versus Pre-Certification Readiness Audit
By Alfred Obeng, Founder and Principal Consultant
CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP
Bought at the same point, priced similarly, and routinely assumed to be the same thing. One discharges clause 9.2. The other cannot, and the sequencing is where the money leaks.
- Internal Audit
- ISO 42001
- Certification
7 min read
Who Can Issue an ISO 42001 Certificate in the UK?
By Alfred Obeng, Founder and Principal Consultant
CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP
Anyone can issue a certificate. Accredited certification is a different thing, it was unavailable for twenty five months, and no published list stays current. How to check the register yourself.
- ISO 42001
- Certification
- UKAS
- AI Governance
8 min read
Can the Consultancy That Built Your AIMS Also Audit It?
By Alfred Obeng, Founder and Principal Consultant
CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP
The rule everyone quotes is about your certification body, not your consultant. What ISO/IEC 17021-1 actually restricts, and where the real constraint lands.
- ISO 42001
- Internal Audit
- Certification
- AI Governance
7 min read
What a Stage 2 Auditor Asks About Clause 9.2
By Alfred Obeng, Founder and Principal Consultant
CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP
Seven questions your internal audit programme has to answer, in the order they become answerable, and the three patterns that draw the most attention.
- Internal Audit
- ISO 42001
- Certification
- ISO 27001
6 min read
What ISO 19011 Requires of an Internal Auditor
By Alfred Obeng, Founder and Principal Consultant
CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP
Strictly, nothing. It is guidance, not requirements. And the edition most procedures name was withdrawn in May 2026. What actually binds you, and what an internal auditor genuinely needs.
- Internal Audit
- ISO 42001
- ISO 27001
- Certification
10 min read
ISO 27001 Stage 1 vs Stage 2 audits: what to expect
By Alfred Obeng, Founder and Principal Consultant
CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP
The difference between Stage 1 and Stage 2 certification audits, what auditors actually look for, common nonconformities, and how to avoid them.
- ISO 27001
- Audit
- Certification
