Before you chase an ISO 9001 certificate, find out exactly where you stand. Here is how to run a gap analysis and turn it into a plan that closes the gaps.
A gap analysis is the honest first step toward ISO 9001. It compares what the standard requires against what your organization actually does, and produces a prioritized list of what is missing. Done well, it saves months of wasted effort — you fix real gaps instead of rewriting documents you already had.
Start with the actual text of ISO 9001:2015 and a clear scope statement: which sites, products, and processes the certification will cover. A vague scope leads to a vague assessment. Decide what is in and what is out before you look at a single requirement.
ISO 9001 is organized by clause (context, leadership, planning, support, operation, performance evaluation, improvement), but your company runs on processes. Build a simple matrix that connects each requirement to the process and person that owns it. Where a requirement has no owner, you have found your first gap.
For each requirement, ask the harder question: can we show it is done? Pull the records — procedures, meeting minutes, audit reports, corrective actions, training logs. "We do that" is not evidence. A dated record that an auditor could read is.
Score every requirement on a simple scale so the picture is clear at a glance:
Partials are where most organizations actually live, and they are what quietly cause audit findings.
Not every gap is equal. A missing internal-audit program is a bigger problem than an out-of-date form. Rank gaps by how much they affect product quality, customer requirements, and audit risk, so you work the important ones first.
Turn the list into a plan: each gap gets an owner, an action, and a due date. This is the deliverable that actually moves you toward certification. Without owners and dates, a gap analysis is just a report that sits on a shelf.
Once the actions are closed, run an internal audit against the same requirements to confirm the fixes held. Registrars expect at least one full internal audit and a management review before they will certify you, so this step does double duty.
For a small to mid-sized organization, a focused gap analysis usually takes a few days to a couple of weeks, depending on how many processes and sites are in scope and how accessible your records are. The follow-on work to close the gaps is what varies most.
No, you can run one internally if someone knows the standard well and can be objective about your own processes. Many companies bring in outside help precisely because it is hard to audit yourself honestly and because an experienced eye spots gaps faster.
They overlap but differ. A gap analysis measures you against the full standard before you have a system in place, to build a plan. An internal audit checks an existing system for conformity on an ongoing schedule. You need both on the path to certification.
We help teams turn a checklist into a passing audit — practical, right-sized, and led by a Six Sigma Black Belt with 15+ years in regulated industries.
Talk to us about a gap assessment