Blog

What a readiness score out of 100 tells you before an audit

A self assessment is not an audit result. Here is what a readiness score can honestly tell you, and the four things it cannot.

Prem Kumar Dvivedi · 30 Ogos 2026

MSCi — Management System Compliance Incorporation — publishes a free readiness checklist for each of the standards we work on. Answer it and you get a score out of 100, the questions you answered badly ranked by weight, and a set of recommendations. It costs nothing and takes about fifteen minutes.

Before anybody puts that number in a board pack, it is worth being precise about what it means.

What the score is

It is a measure of how much of the standard you can currently answer for, judged by you. Every question carries marks, the marks across a checklist add to exactly 100, and the heavier questions are the ones an auditor is more likely to spend time on. A score of 62 means that, on your own account, you can speak to about 62 marks' worth of what the standard asks.

That is genuinely useful for three things: deciding whether to start now or in six months, working out roughly how much work is ahead, and — most usefully — seeing which parts of the standard you are weakest on rather than which parts you find least interesting.

Why the marks are hidden while you answer

They are not shown during the assessment, and that is deliberate. Somebody who can see that a question is worth four marks answers it differently from somebody reading the question. The score is only worth having if the answers were honest, and hiding the weights is the cheapest way to keep them that way.

Why "not sure" earns something

The four answers are Yes, Maybe or partly, Not sure, and No. They earn the question's full marks, half, a quarter and nothing respectively.

Giving "not sure" a quarter is a considered choice. Not knowing whether a control exists is a smaller gap than knowing it does not — usually it means somebody in the organisation does it and the person answering has not seen the evidence. If not knowing scored zero, people would guess Yes, and the whole exercise would be worthless.

The four things it cannot tell you

Whether you would pass. A certification audit is decided on evidence produced on the day, by an auditor with their own scope and their own sampling. No self assessment predicts that, and a consultancy claiming otherwise is selling you something.

Whether your answers are right. The score reflects what you believe about your organisation. Where belief and evidence part company — and they usually part company somewhere — the score is optimistic. Everything we recommend from a checklist carries that caveat, because the real position has to be established by a gap assessment carried out by an expert, against the evidence.

How long it will take. Two organisations on the same score can be four months apart, depending on how many sites they run, how much of the gap is documentation and how much is behaviour, and whether anybody senior has agreed to own it.

What it will cost. Though it narrows the range considerably, which is the point: a proposal written against a completed checklist prices the work you actually need rather than a package.

What to do with a low score

Not much, immediately. A low score on a first attempt is the normal result for an organisation that has never been certified, and it says more about documentation than about competence. The useful move is to look at the heaviest questions you answered No or Maybe to — the checklist ranks them for you — and ask whether the answer is really No or whether nobody has written down what the company already does.

In our experience that second case accounts for most of the gap, in every one of the six markets we work in: India, Mongolia, Australia, Nigeria, South Africa and the United States.

About the author

Prem Kumar Dvivedi is an auditor with more than forty years in this industry. He has spent that time on both sides of the table — building management systems and auditing them — across quality, environment, health and safety, food safety and information security.

See how this looks as a working system

Reading about a requirement and seeing the documentation that satisfies it are different things. In a short demo we open the actual manual, procedures and records set for ISO 9001, show you how each clause is answered and where your existing way of working already fits. You will know what implementation involves before you commit to it.

Ask us about this

Tell us what is being asked of you and by whom.

What are you looking for?

We reply within one working day. Your details stay with our consultants.

More reading

All articles