What Is a Gap Analysis and Why It Matters Before Certification

When first looking to conform to ISO 9001, seeking certification or perhaps looking to upgrade your system to a new revision of the standard an ISO 9001 gap analysis comes up in conversations. This article outlines what a gap analysis is, what goes into it and why it matters.

Defined plainly, it is a structured comparison of your current Management System (MS) against ISO 9001 requirements, clause by clause. Think of it as a practice exam before the main exam that gives you insights into where your weaknesses are so you can improve on them. It is not a full audit of your system. More a diagnostic check. In a gap analysis no nonconformities are “issued,” just gaps identified.

Not knowing where your weaknesses in the management system lie can impact your operations by letting risks go unnoticed and unaddressed. Further it may result in certification delays especially if any non-conformities identified are major. In a few cases the major non-conformities may require a secondary onsite visit, that is an additional cost. If your business contracts and contingent upon certification being achieved, then an ISO 9001 gap analysis helps. It doesn’t guarantee a clean audit, but it de-risks it significantly.

It is a small cost to incur to avoid a failed external audit and certification delay. Other intangible costs are also incurred such as a hit to team morale and loss of faith in the system approach.

The 10-Clause Framework: Walking Through ISO 9001 Section by Section

With the harmonization to a uniform structure ISO 9001 and its 10 clauses are not aligned to the Plan-Do-Check-Act cycle. This allows for easier implementation and integration with other management systems. As a note, clauses 1-3 (scope, normative references, terms) are non-auditable but set context for the standard and its why.

Perhaps the best approach to the gap analysis is to use the clause structure of the standard as a starting point. The challenge often lies in assessing processes and connecting internal requirements to the language of ISO. Clauses 4 through 10 are the real “meat” of the standard.

  • Clause 4 — Context of the organization – Evidence for this clause is often found with the leadership and requires their involvement and engagement.
  • Clause 5 — Leadership – The clauses under 5 require leadership awareness of what the system needs from them as also the assignment of a clear vision via the policy and clear responsibilities and authorities.
  • Clause 6 — Planning – This clause requires the organization to assess the risks to meeting its goals (including customer satisfaction and continual improvement) and identify controls that will enable mitigation of these risks.
  • Clause 7 — Support (resources, competence, documented info) – While perhaps the easiest clause of the standard, documentation control is often the biggest weakness in systems and in audits.
  • Clause 8 — Operation – Clause 8 is the “meat” of any organizations operations and will perhaps take the longest time during the gap analysis.
  • Clause 9 — Performance evaluation – Here is where the organizations determine what they are going to monitor and how they monitor it.
  • Clause 10 — Improvement – Check whether your system has avenues for identifying and acting on improvement opportunities including identifying and taking action on non-conformities.

A simple was to look at each requirement is to ask, “What does this clause require? Do we have evidence? Is it followed consistently?”. If you struggle to identify a suitable checklist for the gap you can simply use the clause structure as a gap analysis checklist itself. Reach out to [email protected] should you want a checklist you can use.

 

Context of the organization: what most SMBs overlook in clause 4

SMBs often treat 4.1 (internal/external issues) as a one-time exercise, and not a living document. For micro business with only a few employees there may be no need to document the context. I say no need as the ISO 9001 standard does not require the context to be documented. It is best practice though as the company grows in locations, personnel and/or operations. Contextual issues are really business 101. An organization must determine what is going to impact them and what actions they should be planning to mitigate any negative impact while building on the positive ones. Penning them down helps keep track of them and review them later.

While leadership may know who the interested parties are what their needs are often internal parties get overlooked such as employees, and certain external parties such as suppliers and insurers. Interested parties are often thought of as customers and perhaps rightly so as they are probably the largest for a business. When reviewing the scope statement make sure it covers what you are seeking to get certified. While generally the limit of the actual site/process boundaries is common don’t use it as a means to exclude areas/processes that must be included.

Clause 4.4 is often a weakness in systems QMII has worked on. The clause requires the organization to determine the sequence and interaction of the processes. SMBs often have documented procedures but no process interaction map. QMII often captures this as a core process for its clients.

Pro tip: tie context review to a real business planning input (e.g., strategic planning meeting) so it doesn’t feel like a paperwork exercise

How to Score Your Gaps: A Simple Red/Amber/Green Method

A simple was to score your gap analysis is using the RAG logic:

  • Red = requirement not met at all, no evidence
  • Amber = partially met, inconsistent, or undocumented but practiced
  • Green = fully met with objective evidence

While it is easy to score the entire clause, QMII recommends scoring each requirement at the sub-clause level, for accuracy. In addition to the requirement in one column, additional columns may include current state evidence, RAG, actions needed to conform, action owner and target date.

Remember it is a system and you are identifying risks. As such even though an area/requirement may be conforming and green your ISO 9001 gap analysis should identify process risks such as when reliant on one person or no document exists, only tribal knowledge. This gives the leadership visibility on the risk and they can make a decision to accept it or not.

Pro Tip on prioritization: fix all Reds first, especially in clauses tied to product/service conformity (clause 8) since those tend to trigger major NCs

Common Gaps Found in US Manufacturing Plants (and How to Close Them Fast)

Below is a list of common gaps found across systems that QMII has helped implement and get through first time certification:

  • Calibration records incomplete or gauges past due date – Create/update the calibration log and set up a recall/alert system for upcoming due dates.
  • Supplier evaluation not risk-based (approved vendor list exists but no criteria/re-evaluation cycle) – For each supplier determine the evaluation, selection and re-evaluation criteria. Apply them to existing suppliers.
  • Nonconformance and corrective action process exists but isn’t tied back to root cause analysis (people fix symptoms, not causes) – preferably get a few personnel training in problem solving/root cause analysis (RCA) and these will then champion this RCA process.
  • Training records not linked to competency requirements for specific roles – Determine the competency requirements for each role, determine the records needed to prove competency is met, identify where and who will retain the records.
  • Management review meetings happen but don’t cover all required inputs/outputs from clause 9.3 – Review the existing review template against the requirements of Clause 9.3. In addition to the inputs remember to document the decision and actions of leadership.
  • Document control: multiple “current” versions floating on shop floor vs. controlled system – Ask personnel to identify all out-of-date documents either on the desktop or in print and to control them. The primary repository whether in print or electronic should be used each time a document is needed.
  • No core process mapped – map the sequence and interaction of processes.

Each of these while easily fixed are often looked over when a gap analysis is done by someone with little experience of the standard.

Clause 8 operations: where most manufacturers find the most gaps

Below is a list of common items identified during ISO 9001 gap analysis done by QMII:

  • Design and development controls (8.3) often skipped by manufacturers who think they don’t “design” anything, but engineering changes count
  • Control of externally provided processes/products (8.4) inadequate
  • Production and service provision (8.5), where work instructions as documented do not relfect actual practice
  • Control of nonconforming outputs (8.7), disposition process (use-as-is, rework, scrap) not always documented with authority sign-off and often missing a designated area for storage

Pro Tip: walk the actual production floor with the clause 8 checklist in hand rather than reviewing documents at a desk — gaps surface fastest this way

Gap Analysis vs Internal Audit: What’s the Difference and When to Use Each

Below is a handy reference on the difference between an ISO 9001 gap analysis and an internal audit.

  • Gap analysis = readiness check, usually done once before initial certification or major transition
  • Internal audit = ongoing, cyclical, required by clause 9.2 as part of maintaining certification. While the standard does not specify a frequency, mature organization do internal audits at least twice a year and sometimes more often.
  • Gap analysis can be broad-brush; internal audits require formal audit plans, trained iso 9001 lead auditor, and documented findings/CAPAs
  • Use gap analysis when: preparing for first certification, after a major QMS overhaul, after failed audit findings elsewhere or a major customer quality issue.
  • Use internal audit when: maintaining ongoing compliance, meeting the annual audit program requirement, preparing for surveillance audits

Key point: A gap analysis finding should feed into your first internal audit program, not replace it.

How to build a gap closure action plan with owners and deadlines

While the gap analysis is a good starting point failing to take actions timely can leave you too close to the project deadline with important issues unaddressed. Keep in mind that while the ISO project is important, the show must go on. As such personnel in an organization are being pulled in all directions to meet operational needs of getting the products and/or service out the door.

It is therefore imperative to get leadership involvement from the start of the project. For other personnel in the organization to know how important this is to leadership. To agree to deadlines mutually and identify verification methods to know actions items have been closed out effectively. Assign realistic deadlines based on complexity of the issue identified. For example, process redesign may take longer than a documentation fix.

For good measure the verifier must be someone other than the person who “fixed” it should confirm closure. Tie closure plan directly to the certification body’s audit date so there’s a hard deadline forcing prioritization.

Pro Tip: Recommend a weekly stand-up or tracker review cadence leading up to the audit date

FAQs

How long does a gap analysis take?

Typically, 2 days for a single-site SMB, depending on number of processes and whether it’s desk review only or includes floor walks. Larger or multi-site operations can take 1 week or more depending on the size of the sample chosen for the gap.

Who should conduct a gap analysis — internal team or external consultant?

  • Internal team: cheaper, deeper operational knowledge, but risk of blind spots/bias toward “we already do this”
  • External consultant: objective, benchmarked against many other clients, but costs money and takes time to onboard to your processes
  • Hybrid approach often works best: consultant-led framework, internal team fills in evidence

Can a gap analysis replace an internal audit?

No. A gap analysis is a one-time readiness check; internal audit is a mandatory recurring clause 9.2 requirement. Certification bodies will ask for internal audit records, not gap analysis reports, as objective evidence

What does a gap analysis report look like?

Typically, a spreadsheet or short report that includes clause-by-clause RAG score (or another methodology), evidence notes, gap descriptions, recommended actions, and an overall readiness percentage. Some consultants supplement it with an executive summary for leadership

How close do you need to be before scheduling a certification audit?

Rule of thumb: all Red-rated items closed, Amber items with an active action plan and target dates, before booking Stage 1.

About the Author:

Julius DeSilva is CEO of QMII (Quality Management International, Inc.), with more than 25 years of experience in quality management systems, maritime safety and security, and information security. A former seagoing officer and Exemplar Global Certified Lead Auditor (ISO 9001, ISO 27001, ISO 50001, RC14001), he has trained over 1,500 professionals as lead auditors and led consulting and auditing engagements across manufacturing, government, maritime, and aerospace sectors. He holds an MBA from the Darden School of Business, University of Virginia, and is an Associate Fellow of the Nautical Institute.

Recommended Posts