ISO 9001 Gap Analysis: What It Is, How It Works, and What It Actually Finds
The report arrives as a PDF. Forty-seven line items, each mapped to a clause number. Clause 4.1. Clause 7.5. Clause 8.4.1. Half of them reference "documented information" the business apparently should have been keeping. The other half reference processes that do exist, but apparently in the wrong form. The founder reads it twice, still isn't sure what "external context" means in Clause 4.1, and is left wondering why a consultant charged $4,000 to produce a list of things that are missing.
At Kaiso we run gap analyses every week, and that experience, the founder staring at 47 items mapped to clauses they've never read, is almost universal. Gap analysis is genuinely useful. The problem is how it gets delivered: dense, jargon-heavy, and almost never explained. This guide covers what a gap analysis actually is, how it works in practice, what it reliably finds, and what to do with the results once you have them.
What a gap analysis actually is
An ISO 9001 gap analysis is a structured comparison between what a business currently does and what the ISO 9001:2015 standard requires. It maps your existing processes, documentation, and records against the standard's clauses, identifies what's present (including things that exist but aren't documented), and produces a list of gaps requiring attention before certification. It is not an audit, and it does not result in a pass or fail. It is a roadmap.
That distinction matters. A gap analysis tells you what's missing and what's present but undocumented. It cannot tell you whether your processes are good, or whether you will get through the audit. What it can tell you is how far the current state is from the required state, and roughly how much work closes the distance.
Most first-time gap analyses for a 20 to 50 person business identify 15 to 35 gaps. Some of those are genuine absences. Many of them are evidence problems: the process exists, it works, and nobody has written it down in a way the standard recognises.
Gap analysis versus audit: not the same thing
Buyers consistently conflate these two exercises. An audit is a formal, third-party assessment against the standard. It produces a finding: conforming, minor nonconformance, or major nonconformance. It is conducted by an accredited certification body. It has consequences for your certificate.
A gap analysis is internal work, or work commissioned by you to inform your own preparation. No finding is raised. No certificate is at risk. The person conducting it is working on your behalf, not on behalf of the certification body.
Put simply: an audit is something that happens to you. A gap analysis is something you do before the audit, to avoid surprises when it does.
What ISO 9001:2015 actually requires: clause by clause in plain English
The standard runs from Clause 4 to Clause 10. A gap analysis maps your organisation against every one of these, but not all clauses carry the same weight in practice. Here is what each requires, and the gap that commonly surfaces in each.
- Clause 4: Context of the organisation. The standard asks you to understand the internal and external factors that affect your ability to deliver a consistent product or service (4.1), and to identify the interested parties — customers, regulators, employees (whose requirements affect the QMS) (4.2). You also need a documented scope: what the QMS covers and, importantly, what it deliberately excludes and why (4.3). Common gap: businesses have never formally articulated their context or scope in writing. The thinking exists; the document doesn't.
- Clause 5: Leadership. Senior management must demonstrate commitment to the QMS, not delegate it entirely. This means a signed quality policy that states the organisation's quality commitments in plain terms, communicated to the team, and relevant to what the business actually does. Common gap: either no quality policy exists, or the one that does is a generic template with the company name dropped in. Neither impresses an auditor.
- Clause 6: Planning. Risks and opportunities must be formally identified and acted on (6.1). Quality objectives must be set, measurable, and monitored (6.2). Common gap: risk registers and quality objectives are absent or are copied from a template without being connected to real business data. The standard does not prescribe a risk matrix format, but it does require evidence that risks were considered and responses planned.
- Clause 7: Support. The most operationally demanding section. It covers resource adequacy (7.1), competence and training records (7.2), awareness (7.3), communication (7.4), and documented information (7.5). Clause 7.1.5 specifically governs monitoring and measurement equipment. Common gap: Clause 7.2 (competence) and 7.5 (documented information) together account for more gap analysis findings than any other section. See below.
- Clause 8: Operation. How products and services are actually planned, designed, delivered, and controlled. Clause 8.4 governs externally provided processes, products, and services, meaning your subcontractors and key suppliers need to be formally evaluated. Clause 8.5 covers controlled production conditions. Clause 8.7 covers nonconforming outputs. Common gap: supplier evaluation (8.4) is almost universally absent in first-time certifications. Suppliers are known and trusted; the criteria and records are not.
- Clause 9: Performance evaluation. Requires monitoring and measurement of processes (9.1), a scheduled internal audit programme (9.2), and a formal management review (9.3). Common gap: internal audit and management review are procedurally required to have occurred before the Stage 2 audit. They cannot be backdated. Most businesses approaching certification for the first time have never done either.
- Clause 10: Improvement. Nonconformances must be recorded, root causes identified, and corrective actions tracked to closure (10.2). Opportunities for continual improvement must be pursued (10.3). Common gap: customer complaints or quality issues have been handled informally, with no written record of what the root cause was or what was done. The process existed; the evidence didn't.
The three gaps that appear in almost every first certification
Across hundreds of engagements, the same three gaps appear regardless of industry.
- Competency records (Clause 7.2). The team is trained. The skills are real. But the evidence that training happened and was assessed as adequate simply doesn't exist in a retrievable form. Induction checklists are signed and filed nowhere. The new hire who went through a two-week shadowing period has no record of it. The skills are real; the records are not. The fix is a competency matrix that maps roles to required skills and shows, for each person, what training they've received and when it was verified as adequate. Building it retroactively is acceptable; the standard does not require everything to have been documented before you started the process.
- Supplier evaluation records (Clause 8.4). Every business has suppliers they trust and suppliers they don't. The trust is earned from experience. ISO 9001 requires that the basis for that trust is documented: what criteria were applied, how the supplier was assessed, and what performance data supports keeping them on the list. Most businesses coming to certification have never written this down. The approved supplier list exists in someone's head. Getting it out of that person's head and into a document is the gap analysis's job to identify; fixing it is usually one or two hours of structured conversation followed by an afternoon of writing.
- Internal audit records (Clause 9.2). Internal audit is the one gap that cannot be remediated after the fact. The standard requires a completed audit cycle before Stage 2. That means a schedule, an audit plan, a conducted audit against specific clauses, findings documented, and any corrective actions raised and tracked. This is non-negotiable and time-bound. A gap analysis that surfaces this gap in week one of a three-month implementation is useful. A gap analysis that surfaces it six weeks before Stage 2 is a problem.
How a gap analysis works in practice
Three delivery methods exist, and they suit different starting points.
Consultant-led interview and document review. The traditional approach: a consultant spends one to three days on-site, interviewing process owners, reviewing existing documentation, and building a picture of the current state from primary sources. The output is a gap report, usually a spreadsheet or Word document, mapping clause requirements against findings. Cost runs $1,500 to $4,000 for a typical SMB. The consultant brings interpretive experience that a checklist alone cannot replicate, and can probe when an answer doesn't quite make sense. The limitation is that the output is only as good as the conversation. Tribal knowledge that nobody mentions in the interview stays hidden.
Software-driven structured questionnaire. A SaaS platform guides the business clause by clause, collecting evidence and scoring readiness automatically. The output is a coverage dashboard, usually traffic-light rated, typically included in a platform subscription. It is consistent and removes travel costs, but it inherits the same problem as the interview approach in a different form: if someone ticks "yes, we have a documented procedure" for a process that is actually undocumented, the gap does not get flagged. Self-assessment is only as honest as the person filling it in.
AI-assisted document ingestion. The business uploads its existing documentation (SOPs, email procedures, shared drive files, induction checklists, supplier lists, whatever exists) and an AI engine reads each document, maps content against specific clauses, and identifies what's covered and what's absent. The coverage picture comes from the actual documentation rather than from self-reported answers. A procedure buried in a folder from 2019 that nobody has thought about in years gets surfaced and mapped. What AI cannot do is judge adequacy: a document that describes a process in two sentences may or may not satisfy the clause requirement, depending on the risk involved. An expert review of the output is still required to close that interpretive gap.
At Kaiso, our process combines the third approach with that expert review layer. Kobi, the platform's AI engine, ingests the documentation and maps it. A qualified consultant then reviews the output, closes the interpretive gaps that require judgement, and produces the final gap picture. What used to take two to three days of on-site work typically completes in a single session.
What a gap analysis report actually contains
A well-structured gap analysis report covers four things for each finding.
First, the clause reference: which specific clause or sub-clause the finding relates to. "Clause 8.4.1" is more useful than "supplier management" because it tells you exactly where to look in the standard for the requirement, and exactly where the auditor will look during Stage 2.
Second, the requirement in plain language: what the clause actually asks for, stripped of the standard's formal phrasing. "You must define criteria for evaluating and selecting external providers based on their ability to supply conforming products" is what Clause 8.4.1 requires. That sentence is more useful than citing the clause and leaving the reader to interpret it.
Third, the current state: what exists right now, including things that are present but undocumented. "Business uses three primary subcontractors for electrical work; selection is based on historical relationship and pricing; no formal evaluation criteria documented" is a useful current-state description. It tells you this is a records problem, not a process problem.
Fourth, the remediation note: what needs to happen to close the gap. Simple, direct, proportionate. Not every gap requires a new document. Some require a conversation that gets written down. Some require a register entry. The remediation note tells you which.
A gap analysis report that contains only a clause reference and a finding, with no current-state description and no remediation guidance, is not a gap analysis. It is a list of clauses. The $4,000 question from the opening of this piece is usually about exactly that gap between what was delivered and what was useful.
Clause 7.5: the one that catches everyone
Documented information deserves its own section because it generates more findings than any other clause.
The 2015 revision of ISO 9001 removed the requirement for a Quality Manual. This is often misunderstood as meaning the standard requires less documentation than it used to. It does not. What changed is the prescription: the standard no longer tells you what to call things or how to structure them. It does still require that you maintain and retain the documented information needed to support the operation of your processes and to demonstrate that what was planned is actually happening.
In practice, this means two categories of documented information. Maintained information includes procedures and work instructions: documents that describe how things are done, updated when processes change, and controlled so everyone is working from the current version. Retained information includes records: evidence that activities were carried out, results were achieved, products were inspected. A calibration certificate is retained information. A completed inspection checklist is retained information. A training record is retained information.
The gap that surfaces in almost every first certification is the second category. Processes are described. Records of those processes being followed are not kept consistently, not kept at all, or kept informally in a way that cannot be retrieved during an audit. "We do that every week" is not evidence. The record that it happened is evidence.
What to do with the findings: the gap-to-document workflow
A gap report is not a to-do list. Working through it as if every item has equal urgency is the fastest way to run out of runway before Stage 2.
The triage question for each finding is: is this a process gap or a records gap? Process gaps (where no control actually exists) require a new procedure or work instruction. Records gaps (where the process exists but isn't captured) require a record-keeping practice, a template, and some retrospective evidence where records can legitimately be reconstructed.
After triage, sequence the work by audit risk. The findings that will stop a Stage 2 audit if unaddressed go first. These are: any clause requiring evidence of a time-bound activity that cannot be backdated (internal audit, management review), any clause the auditor will sample directly from records (calibration, competency, corrective action), and the scope, quality policy, and quality objectives, which form the backbone of every auditor's opening walk-through.
The findings that can wait: quality objectives measurement detail, the customer satisfaction process, the risk register format. All required, but all buildable progressively during the implementation period. A first internal audit that raises these as findings and tracks them to closure is actually evidence the system is working.
How AI changes gap analysis
The traditional gap analysis is a slow exercise because it depends on information transfer. The consultant asks. The client answers. The consultant asks someone else. The answer contradicts the first answer. Three days later, the consultant has a picture of the current state that is probably about 70% accurate.
AI document ingestion inverts this. Instead of starting with questions, it starts with the documentation itself. Every SOP, every email procedure saved as a Word file, every policy written three years ago and sitting in a shared drive folder nobody has opened since, gets read and mapped to relevant clauses. The coverage picture comes from the actual documentation rather than from a self-assessment.
The practical implication: businesses typically have more coverage than they think. Processes that the operations manager would have said "we don't have documented" turn out to be described in a supplier onboarding email from 2022, or in a project manager's handover notes, or in a laminated procedure sheet in the back room. AI finds these. The interview-based approach often doesn't, because nobody remembers to mention them.
What AI cannot do is judge adequacy. A document that describes a process in two sentences may cover the clause requirement. Or it may not, depending on the complexity of the process and the risk involved. That judgement requires someone who has read a lot of ISO 9001 audit findings and knows what an auditor will push on. Understanding what auditors actually look for in Stage 2 is a separate skill from mapping documents to clauses, and it is not a skill that can be automated away.
Two to three days of consultant interviews to produce a gap picture. A few hours with AI ingestion. For the business commissioning the work, that difference shows up directly in the cost.
When to run a gap analysis
Three situations warrant a formal gap analysis rather than an informal self-assessment.
First certification. The obvious case. If you have never been certified to ISO 9001, a gap analysis is the foundation of the implementation. It tells you where to direct effort, in what order, and roughly how long the implementation will take. Running it at the start saves the common mistake of spending six weeks building documentation for clauses that are already covered, while the clauses that actually need work sit unaddressed.
Surveillance audit preparation. Certified businesses are typically audited annually. The surveillance visit is not a re-certification; it is a check that the QMS is still functioning and being maintained. A focused gap analysis three to four months before a surveillance visit identifies evidence that has lapsed, clauses where coverage has thinned, and corrective actions from the previous audit that have not been closed. The alternative is finding out about these on audit day, which is a more expensive discovery.
ISO 9001:2026 transition. The standard is being revised. ISO 9001:2026 is expected to introduce changes to climate-related context, risk-based thinking requirements, and some of the documented information provisions. Businesses currently certified to ISO 9001:2015 will need to transition. A gap analysis between the two versions will be the starting point for every organisation managing that transition, even those with well-maintained systems. The scope of the changes is not yet fully public, but the transition period will be time-limited once the new standard is published.
What a first gap analysis costs
A standalone gap analysis commissioned from a consultant typically costs $500 to $2,000 for an SMB, depending on the complexity of the operation and whether the engagement is conducted remotely or on-site. Some consultants include it as part of a broader implementation engagement; others price it separately as a first step.
At Kaiso, the gap analysis is the starting point of every engagement rather than a separate line item. It runs during the initial document ingestion and produces the implementation roadmap that shapes the rest of the project. It is included in the fixed price, which means no separate charge and no discovery that the gap is bigger than the consultant's initial estimate suggested.
A worked example: what a 30-person construction company found
A construction business, 30 people, tenders for government contracts. One of those contracts required ISO 9001 certification. They had never been certified. Their documentation lived in a combination of a server folder, a project manager's SharePoint, and a health and safety management system implemented three years earlier.
The gap analysis, run via document ingestion, found the following.
Already covered, often better than expected: project delivery procedures (covered Clause 8.5), subcontractor documentation requirements in project contracts (partial coverage of Clause 8.4), induction checklists for site workers (partial coverage of Clause 7.2), and the existing H&S system, which overlapped with risk identification requirements under Clause 6.1 to a significant degree.
Genuine gaps: no formal supplier evaluation criteria or approved supplier register (Clause 8.4.1 gap); training records existed for H&S but not for role-specific quality competencies (Clause 7.2 gap); no internal audit had ever been conducted against the QMS (Clause 9.2 gap); management review minutes did not exist in the form the standard requires; project review meetings happened but their outputs were not documented against the required inputs (Clause 9.3 gap); no quality objectives had been set with measurable targets (Clause 6.2 gap).
Total findings: 23. Of those, 8 were genuine process gaps requiring new documentation. 15 were records gaps where processes existed but evidence was inconsistent or informal. The implementation took nine weeks from gap analysis to Stage 2 audit. They passed.
The pattern is consistent across most first certifications: more is covered than the business expected, less remediation is needed than the clause count suggests, and the implementation is completable in weeks rather than months when the work is sequenced correctly. If you want to know what that sequencing looks like for your business, Kaiso's fixed-price engagements start with exactly this exercise.
Frequently asked questions
How does ISO 9001 gap analysis work and what does it identify?
An ISO 9001 gap analysis compares your current processes, documentation, and records against the requirements of ISO 9001:2015 clause by clause. It identifies three categories of output: what is present and compliant, what is present but undocumented (a records gap), and what is genuinely absent (a process gap). The output is a prioritised list of findings that forms the implementation roadmap for certification. It does not result in a pass or fail — it is a diagnostic tool, not an assessment.
Can I do a gap analysis without a consultant?
Yes, with caveats. The standard is publicly available and the clause requirements can be read directly. A business with someone who has read the standard and understands how to map existing processes against it can conduct an internal gap analysis using a structured checklist. The risk is in the interpretation: knowing what a clause requires in formal language and knowing what an auditor will accept as evidence are different skills. An internal gap analysis often misses records gaps because the person conducting it is too close to the operation to see what is absent. An external review, even a brief one, tends to surface gaps that internal self-assessment misses.
How long does a gap analysis take?
A consultant-led gap analysis typically takes one to three days for an SMB: a day of interviews and document review, a day of analysis, and delivery of a report. An AI-assisted gap analysis based on document ingestion can produce an initial coverage picture in a few hours, with an expert review layer adding another half-day. The time from initiating the process to having an actionable gap report is usually two to five business days in either case, depending on how quickly documentation can be assembled.
What happens after a gap analysis?
The gap report becomes the implementation plan. For each finding, the remediation path needs to be identified: new procedure, updated record-keeping practice, one-off evidence collection, or scheduled activity (internal audit, management review). Findings are then sequenced by audit risk, with time-bound activities scheduled first. The implementation period between gap analysis and Stage 2 audit is typically eight to sixteen weeks for a first certification, depending on business complexity and the size of the gap.
What is the most common finding in a gap analysis?
Competency records under Clause 7.2 appear in almost every first gap analysis. The team has been trained, the skills are demonstrably present, and the processes work. The evidence that training was assessed as adequate for each role simply does not exist in retrievable form. Internal audit under Clause 9.2 is the most time-sensitive finding: it requires a completed audit cycle before Stage 2, which cannot be backdated, and must therefore be scheduled from the beginning of the implementation.
Does the ISO 9001 standard require a Quality Manual?
No. ISO 9001:2015 removed the requirement for a Quality Manual that existed in earlier versions of the standard. The 2015 revision requires "documented information" — maintained documents describing how processes work, and retained records showing that those processes were followed — but does not prescribe a specific document hierarchy or require a document called a Quality Manual. Many businesses choose to maintain one for clarity. It is not a certification requirement.
How much does a gap analysis cost?
A standalone gap analysis commissioned from a consultant typically costs $500 to $2,000 for an SMB, depending on business size and whether the engagement is remote or on-site. AI-assisted approaches included within a broader implementation platform are usually priced as part of a fixed-fee engagement rather than billed separately. Kaiso includes the gap analysis within its fixed-price certification engagements at $2,999 (DIY) and $4,999 (Managed), with no separate charge and no hourly billing if the analysis takes longer than expected.