Skip to main content
Certification

Readiness Assessment, Internal Audit, Certification Audit: Three Different Things

By Alfred Obeng, Founder, Goldline Consultancy

ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP

6 min read

Contents
    Certification

    Readiness Assessment, Internal Audit, Certification Audit: Three Different Things

    By Alfred Obeng, Founder, Goldline Consultancy

    ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP

    6 min read

    Contents

      Three exercises, three different purposes, and three different answers to the question of who is allowed to perform them. They arrive in a buyer's inbox looking similar because all three produce a report with findings in it, and the reports genuinely do look alike.

      The useful distinction is not what each one costs. It is what each one is evidence of, and who has to be standing behind it for that evidence to count.

      The three, in the order they occur

      Readiness assessmentInternal auditCertification audit
      Question it answersHow far are we from being able to certifyDoes the management system conform, and is it workingDoes this organisation qualify for a certificate
      WhenBefore you build, or early in buildingOnce the system operates, then at planned intervals for as long as you hold the certificateStage 1 and Stage 2, then surveillance
      Required byNothing. It is a decision-making purchaseClause 9.2 of ISO/IEC 27001 or ISO/IEC 42001The certification scheme, if you want the certificate
      Who may perform itAnyone competent, including the firm that will implementThe organisation, through an objective and impartial programmeAn accredited certification body, and nobody else
      What it producesA gap position and a routeAn audit report and nonconformities feeding clause 10 and the management reviewA certification decision
      Is it evidence to a third partyNo. It is evidence to youYes, to your certification bodyYes, to your buyers, insurers and regulators

      The line that cannot be crossed

      Goldline cannot certify anything, in any tense. Neither can any other consultancy. Certification decisions are made by accredited certification bodies, and the separation is structural rather than a matter of preference: the standard those bodies are accredited against restricts them from providing consultancy, and the detail of what it restricts is worth reading if anybody has told you otherwise.

      So of the three exercises above, the third is never available from your consultancy. Any proposal that blurs that line is worth a careful second read.

      Where the confusion actually comes from

      Not from buyers being careless. From the word audit doing three jobs.

      A readiness assessment is often described as a gap audit. A pre-certification rehearsal is often called a mock audit. The clause 9.2 exercise is the internal audit. The certification body performs the certification audit. Four uses of one word, and only two of them are audits in the sense that anything downstream depends on.

      The test that cuts through it: ask what the report is evidence of, and to whom. A readiness assessment is evidence to you, about you. An internal audit is evidence to your certification body that clause 9.2 has been satisfied. A certification audit is evidence to the market. If a proposal does not make clear which of those it produces, that is the question to ask before the price one.

      What each is actually for

      The readiness assessment is a scoping instrument. Its real output is not the gap list, it is the boundary. Most organisations arrive with a scope set far wider than their buyers asked for, and narrowing it is the single largest lever on what everything afterwards costs. Goldline's readiness assessments credit in full against a subsequent Sprint, which is stated on the pricing page along with the current figures.

      The internal audit is a recurring obligation with a real job attached. It exists so that your own management learns the truth about conformity before an external party does. It continues for as long as you hold the certificate, and it is assessed closely at Stage 2.

      The certification audit is the only one that produces a certificate, in two stages, and Stage 1 and Stage 2 test different things.

      The fourth thing, which is none of these

      A pre-certification readiness audit sits between the internal audit and the certification audit, and is neither. It is a rehearsal against Stage 1 and Stage 2 criteria, it carries no independence requirement because it is advisory, and it does not satisfy clause 9.2. That distinction has its own article, because it is the one that costs organisations money most often: internal audit versus pre-certification readiness audit.

      The sequence that works

      Readiness assessment to set the scope and the route. Build. Operate the system long enough that there is something to audit. Internal audit, then remediate through clause 10 and take the results to the management review. Rehearse if the stakes justify it. Then Stage 1 and Stage 2 with an accredited certification body.

      Organisations that compress this usually compress the middle, and the middle is the part the certification body examines most carefully, because it is the only part that tells them whether the management system operates or merely exists.

      Sources

      • ISO/IEC 27001:2022 and ISO/IEC 42001:2023, clause 9.2 internal audit, clause 9.3 management review, clause 10. Not published free of charge and not quoted here.
      • Requirements restricting accredited certification bodies from providing management system consultancy and from providing internal audits to certified clients: ISO/IEC 17021-1:2015 clause 5.2, as reproduced in the Southern African Development Community Accreditation Service assessment checklist SADCAS F 40 (a), Issue 6, dated 23 August 2024. Read 1 September 2026.
      • Published Goldline prices, durations and the readiness assessment credit rule, goldlineconsultancy.co.uk/pricing, read 1 September 2026.

      Alfred Obeng

      Founder of Goldline Consultancy. ISO 42001 Lead Implementer (PECB), ISO 42001 Lead Auditor (PECB), ISO 27001 Senior Lead Implementer (PECB), ISO 27001 Lead Auditor (PECB), CISSP, PMP.

      Related reading

      ISO 42001

      6 min read

      ISO 42001 Internal Audit versus Pre-Certification Readiness Audit

      By Alfred Obeng, Founder and Principal Consultant

      CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

      Bought at the same point, priced similarly, and routinely assumed to be the same thing. One discharges clause 9.2. The other cannot, and the sequencing is where the money leaks.

      • Internal Audit
      • ISO 42001
      • Certification
      ISO 42001

      7 min read

      Who Can Issue an ISO 42001 Certificate in the UK?

      By Alfred Obeng, Founder and Principal Consultant

      CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

      Anyone can issue a certificate. Accredited certification is a different thing, it was unavailable for twenty five months, and no published list stays current. How to check the register yourself.

      • ISO 42001
      • Certification
      • UKAS
      • AI Governance
      ISO 42001

      8 min read

      Can the Consultancy That Built Your AIMS Also Audit It?

      By Alfred Obeng, Founder and Principal Consultant

      CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

      The rule everyone quotes is about your certification body, not your consultant. What ISO/IEC 17021-1 actually restricts, and where the real constraint lands.

      • ISO 42001
      • Internal Audit
      • Certification
      • AI Governance
      ISO 42001

      7 min read

      What a Stage 2 Auditor Asks About Clause 9.2

      By Alfred Obeng, Founder and Principal Consultant

      CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

      Seven questions your internal audit programme has to answer, in the order they become answerable, and the three patterns that draw the most attention.

      • Internal Audit
      • ISO 42001
      • Certification
      • ISO 27001
      ISO 42001

      6 min read

      What ISO 19011 Requires of an Internal Auditor

      By Alfred Obeng, Founder and Principal Consultant

      CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

      Strictly, nothing. It is guidance, not requirements. And the edition most procedures name was withdrawn in May 2026. What actually binds you, and what an internal auditor genuinely needs.

      • Internal Audit
      • ISO 42001
      • ISO 27001
      • Certification

      10 min read

      ISO 27001 Stage 1 vs Stage 2 audits: what to expect

      By Alfred Obeng, Founder and Principal Consultant

      CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

      The difference between Stage 1 and Stage 2 certification audits, what auditors actually look for, common nonconformities, and how to avoid them.

      • ISO 27001
      • Audit
      • Certification

      Alfred Obeng

      Founder of Goldline Consultancy. ISO 42001 Lead Implementer (PECB), ISO 42001 Lead Auditor (PECB), ISO 27001 Senior Lead Implementer (PECB), ISO 27001 Lead Auditor (PECB), CISSP, PMP.

      Related reading

      ISO 42001

      6 min read

      ISO 42001 Internal Audit versus Pre-Certification Readiness Audit

      By Alfred Obeng, Founder and Principal Consultant

      CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

      Bought at the same point, priced similarly, and routinely assumed to be the same thing. One discharges clause 9.2. The other cannot, and the sequencing is where the money leaks.

      • Internal Audit
      • ISO 42001
      • Certification
      ISO 42001

      7 min read

      Who Can Issue an ISO 42001 Certificate in the UK?

      By Alfred Obeng, Founder and Principal Consultant

      CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

      Anyone can issue a certificate. Accredited certification is a different thing, it was unavailable for twenty five months, and no published list stays current. How to check the register yourself.

      • ISO 42001
      • Certification
      • UKAS
      • AI Governance
      ISO 42001

      8 min read

      Can the Consultancy That Built Your AIMS Also Audit It?

      By Alfred Obeng, Founder and Principal Consultant

      CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

      The rule everyone quotes is about your certification body, not your consultant. What ISO/IEC 17021-1 actually restricts, and where the real constraint lands.

      • ISO 42001
      • Internal Audit
      • Certification
      • AI Governance
      ISO 42001

      7 min read

      What a Stage 2 Auditor Asks About Clause 9.2

      By Alfred Obeng, Founder and Principal Consultant

      CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

      Seven questions your internal audit programme has to answer, in the order they become answerable, and the three patterns that draw the most attention.

      • Internal Audit
      • ISO 42001
      • Certification
      • ISO 27001
      ISO 42001

      6 min read

      What ISO 19011 Requires of an Internal Auditor

      By Alfred Obeng, Founder and Principal Consultant

      CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

      Strictly, nothing. It is guidance, not requirements. And the edition most procedures name was withdrawn in May 2026. What actually binds you, and what an internal auditor genuinely needs.

      • Internal Audit
      • ISO 42001
      • ISO 27001
      • Certification

      10 min read

      ISO 27001 Stage 1 vs Stage 2 audits: what to expect

      By Alfred Obeng, Founder and Principal Consultant

      CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

      The difference between Stage 1 and Stage 2 certification audits, what auditors actually look for, common nonconformities, and how to avoid them.

      • ISO 27001
      • Audit
      • Certification

      We use cookies and similar technologies to measure how this site is used, to see which organisations visit, and to measure our advertising. If you accept, we load Plausible, Google Analytics and Google Ads, Microsoft Clarity, which records session replays, and Apollo. Nothing loads until you accept. Read our Cookies policy.