HomeResources › Consulting
Guide · Quality Management

ISO 9001 gap analysis: a step-by-step guide

Before you chase an ISO 9001 certificate, find out exactly where you stand. Here is how to run a gap analysis and turn it into a plan that closes the gaps.

By Continuum Improvement · Updated 2026-07-03

A gap analysis is the honest first step toward ISO 9001. It compares what the standard requires against what your organization actually does, and produces a prioritized list of what is missing. Done well, it saves months of wasted effort — you fix real gaps instead of rewriting documents you already had.

The goal is not a perfect binder. It is a quality management system that runs the same whether or not an auditor is in the building. The gap analysis just shows you the shortest path there.

1. Get the standard and define your scope

Start with the actual text of ISO 9001:2015 and a clear scope statement: which sites, products, and processes the certification will cover. A vague scope leads to a vague assessment. Decide what is in and what is out before you look at a single requirement.

2. Map the clauses to your processes

ISO 9001 is organized by clause (context, leadership, planning, support, operation, performance evaluation, improvement), but your company runs on processes. Build a simple matrix that connects each requirement to the process and person that owns it. Where a requirement has no owner, you have found your first gap.

3. Gather evidence, not opinions

For each requirement, ask the harder question: can we show it is done? Pull the records — procedures, meeting minutes, audit reports, corrective actions, training logs. "We do that" is not evidence. A dated record that an auditor could read is.

4. Rate each requirement

Score every requirement on a simple scale so the picture is clear at a glance:

  • Conforms — in place and evidenced
  • Partial — exists but inconsistent, undocumented, or not followed everywhere
  • Gap — missing entirely

Partials are where most organizations actually live, and they are what quietly cause audit findings.

5. Prioritize gaps by risk

Not every gap is equal. A missing internal-audit program is a bigger problem than an out-of-date form. Rank gaps by how much they affect product quality, customer requirements, and audit risk, so you work the important ones first.

6. Build a corrective plan with owners and dates

Turn the list into a plan: each gap gets an owner, an action, and a due date. This is the deliverable that actually moves you toward certification. Without owners and dates, a gap analysis is just a report that sits on a shelf.

7. Re-check before the certification audit

Once the actions are closed, run an internal audit against the same requirements to confirm the fixes held. Registrars expect at least one full internal audit and a management review before they will certify you, so this step does double duty.

The gaps we find most often

  • Internal audits that never find anything (a sign the program is not rigorous)
  • Corrective actions closed with "retrained the operator" instead of a real root cause
  • Quality objectives that are not measured or reviewed
  • Risk and opportunity (clause 6.1) treated as a one-time form rather than ongoing thinking
  • Document control that cannot show which version is current
FAQ

Frequently asked

How long does an ISO 9001 gap analysis take?

For a small to mid-sized organization, a focused gap analysis usually takes a few days to a couple of weeks, depending on how many processes and sites are in scope and how accessible your records are. The follow-on work to close the gaps is what varies most.

Do I need a consultant to do a gap analysis?

No, you can run one internally if someone knows the standard well and can be objective about your own processes. Many companies bring in outside help precisely because it is hard to audit yourself honestly and because an experienced eye spots gaps faster.

Is a gap analysis the same as an internal audit?

They overlap but differ. A gap analysis measures you against the full standard before you have a system in place, to build a plan. An internal audit checks an existing system for conformity on an ongoing schedule. You need both on the path to certification.

Want a hand with this?

We help teams turn a checklist into a passing audit — practical, right-sized, and led by a Six Sigma Black Belt with 15+ years in regulated industries.

Talk to us about a gap assessment