+31 (0)73 - 220 2000 | info@brandcompliance.com
English
  • Dutch
  • English
  • Beglië
  • Dutch
  • English
  • Beglië
Brand Compliance
  • Certify
    • ISO 9001
    • ISO 22301 (BCM)
    • ISO 19770-1 (IT-assets)
    • ISO 27001
    • ISO 27017 and ISO 27018
    • BIO
    • ISO 27701 (Privacy)
    • NEN 7510
  • IT Assurance
    • SOC 2
  • Vacancies
  • Knowledge base
  • BC Academy
Contact
  • Information security
    • ISO 19770-1
    • ISO 27001
    • ISO 27017 and ISO 27018
    • ISO 27799
    • BIO
    • NEN 7510
    • SOC 2
    • ISAE 3402
  • Privacy
    • Whitepaper BC 5701
    • AVG standard BC 5701:2023 NL
    • GDPR standard BC 5701:2023 EN
    • GDPR standard BC 5701:2024 EN
    • BC 5701
    • ISO 27701
  • Quality
    • ISO 9001
    • ISO 14001
    • ISO 22301
  • Knowledge base
  • News
  • Academy
    • NIS2 training course
    • ISO 27001 training courses
    • BC 5701 training courses
  • About us
    • Start your certification journey
    • Accreditations
    • Compliment, complaint or tip
    • Privacy Statement
    • Vacancies
    • Contact

Certification process

10
  • Checklist certification
  • Do you have your first audit soon?
  • How long does ISO certification take?
  • What is a certification cycle?
  • Applying for a certification process
  • Initial audit Stage 1
  • Initial audit Stage 2
  • Nonconformities management system
  • Certificate suspended or revoked? This is how you solve it!
  • Transfer of certification

BC 5701

5
  • BC 5701 certification: where do you start?
  • Your record of processing activities and the GDPR
  • Your Data Protection Officer and the GDPR
  • Checklist for your BC 5701 certification
  • Data breach: What is it and how do you prevent it?

General

9
  • SOC 2 or ISAE 3402: which standard suits your organization?
  • The Traffic Light Protocol (TLP): what does it mean for you?
  • The Brand Compliance glossary
  • What is a management system?
  • Internal or external audit?
  • Find out more about internal audits
  • Tips to describe a proper scope
  • Accreditation versus certification
  • The use of certification logos

ISO 27001:2022

3
  • Operational Capabilities: The Backbone of Information Security
  • ISO 27001:2022 – FAQ transition
  • ISO 27001:2022 – Transition process

Whitepapers

2
  • Whitepaper management system audits
  • Whitepaper GDPR Certification Standard and Criteria BC 5701

Best practices

3
  • Mastering GDPR compliance: best practices
  • Excelling in information security: best practices
  • Quality Management: best practices for success

NEN 7510

4
  • Transition to NEN 7510-1:2024
  • NEN 7510 without healthcare institution?
  • How to expand with NEN 7510
  • The differences between ISO 27001 and NEN 7510

NIS2 Directive

2
  • NIS2 liability
  • NIS2 & the Belgian CyberFundamentals
View Categories

Initial audit Stage 2

2 min. leestijd

In this article we would like to share our experiences with the Initial audit stage 2 audit, the second part of the audit of the certification process for a management system audit.

Looking back

During Stage 1, it was assessed whether your organization is prepared for audit stage 2. In the closing meeting any areas of concerns within your management system were explained by the auditor. You have been given the opportunity to resolve the areas of concern in the period between the stage 1 and stage 2 audit. It is important that these are resolved in order to start stage 2 well prepared.

Initial Audit Stage 1

Ready for Stage 2

The stage 2 audit takes more time than the stage 1 audit. This is because the auditor assesses the implementation and effectiveness of the management system during stage 2. Are all processes performed as described? Is the policy complied with? Are employees aware of their contribution to the management system? Do you actively check the operation of the management system, and do you know to what extent the management system works effectively?

Focal points in preparation for a stage 2 audit

Several components are essential during the initial audit stage 2. They are explained below.

  1. Ensure that you can substantiate compliance with the requirements of the standard with supporting documents;
  2. Ensure that you can inform the auditor about your performance control, measurement, reporting and assessment of the established performance objectives and targets. Ensure that you can substantiate this with supporting documents;
  3. Ensure that you can demonstrate that the management system is capable of fulfilling the requirements of legislation and regulations and contractual demands;
  4. Ensure that you can prove that you are in control of operational processes;
  5. Ensure that your internal audits and management reviews demonstrably contribute to the requirements and effectiveness of the management system;
  6. Finally, it is important that you can demonstrate that management takes responsibility for the adopted policy.

The methods used during the audit to obtain information include interviews with staff members, observations of processes and activities, and assessing documents, records and systems.

Completion of Stage 2

After completing the initial audit stage 2, the auditor and your organization will start with the follow-up process.

What will the auditor do?

After the audit, the auditor prepares a report. An internal review is performed on the audit report before it is sent to you. In case nonconformities have been identified, so-called ‘nonconformity forms’ are prepared for you to complete.

What can you do?

The good news is, in the meantime, you do not have to wait to resolve the identified nonconformities. During the closing meeting, nonconformities and possibilities for improvement are explained to you by the auditor. It is wise to immediately start formulating and implementing corrections and corrective measures. This way the process runs as smoothly as possible.

Certificate

The auditor will nominate you for certification when you have resolved any nonconformities satisfactorily. The nomination will be presented to a Certification Committee that independently assesses your file. In case the Certification Committee comes to the same conclusion as the auditor, the file is transferred to the certification decision-maker for a final decision. After this, a certificate will be made based on the information from the audit report submitted to you. It is therefore advisable to check all the data on the report carefully, to ensure correct information on your certificate.

Finally

This article intends to explain the process during and after the initial audit stage 2. You can use this article to prepare your organization for the audit. If you have any questions about the process, the audit cycle or further preparations to the audit, please get in contact with one of Brand Compliance’s Customer and Project Coordinators.

Share This Article :
  • Facebook
  • X
  • LinkedIn
Updated on 22 January 2025
Initial audit Stage 1Nonconformities management system

Accreditation

RvA C548Brand Compliance B.V. has accreditation (C548) to certify ISO 27001, ISO 27701 NEN 7510 and ISO 9001 scope 33 information technology and 35 other services.

Brand Compliance B.V.

Hambakenwetering 8D2
5231 DC ‘s-Hertogenbosch

+31 (0)73 220 2000
info@brandcompliance.com

Chamber of Commerce nr.: 32101659
VAT nr.: NL8130.78.854.B01

Brand Compliance Belgie B.V.

Uitbreidingstraat 66
2600 Berchem (Antwerpen)

+32 (0)14 48 0730
be-info@brandcompliance.com

VAT nr.: BE0735.675.516

Brand Compliance Nordics AB

Vasagatan 16 2 TR
111 20 Stockholm

+31 (0)73 220 2015
info@brandcompliance.com

Org.nr: 559238-1387

© Copyright 2025 Brand Compliance