The mistakes that actually lead to losing certification
Certificates are rarely lost because of one dramatic failure. They are lost through a predictable, gradual pattern that auditors have seen many times before:
- Treating the QMS as an audit-week exercise. Procedures get dusted off the week before the auditor arrives instead of being used day to day. Auditors can tell — inconsistent records, gaps in dates, and staff who can't explain the procedure they supposedly follow are the giveaway.
- Not closing corrective actions on time. A minor nonconformity left open past its agreed deadline typically escalates in severity at the next audit. Repeated unresolved findings signal a management commitment problem, which is a Clause 5 issue, not just a paperwork issue.
- Skipping or watering down internal audits. Internal audits are your own early-warning system. Organisations that stop running them, or run them as a formality without real findings, walk into surveillance audits blind — and so does the external auditor, who will dig deeper when internal audit evidence looks thin.
- Ignoring documentation after staff turnover. A quality manager leaves, the QMS owner changes, and nobody updates the document control log, training records, or competence matrix for months. Clause 7.2 (competence) findings are common in this scenario.
- Uncontrolled change. A new production line, ERP system, or supplier is introduced without updating the relevant procedures or risk assessment. The QMS documentation stops matching reality — a major nonconformity risk.
- Not tracking customer complaints properly. A complaints log that is incomplete, or complaints that never trigger root-cause analysis, is one of the most common findings at surveillance stage.
When a major nonconformity is raised, the certification body sets a correction deadline — commonly around 90 days, though the exact period depends on the certification body's procedures and the severity of the finding. If it isn't closed in time, the certificate can be suspended; if suspension isn't resolved, it can be withdrawn entirely, meaning you start the initial certification process again from scratch.
Two audits a year, every year
Under ISO/IEC 17021-1 rules that certification bodies must follow, surveillance audits are required in years one and two of every three-year cycle — there is no version of ISO 9001 certification that skips them.
Preparing for recertification in year three
The recertification audit is close in depth to the original certification audit — the certification body needs to re-confirm your QMS meets ISO 9001:2015 across the full scope, not just the clauses sampled during surveillance. Good preparation starts long before the audit date:
- Review the full three-year audit history. Pull every finding from the initial audit and both surveillance visits, and confirm each one has closed, evidenced corrective action — not just a note that says "fixed."
- Run a genuine internal audit covering the whole QMS scope in the months before recertification, not just the clauses that are easy to check.
- Hold a management review with real inputs (audit results, KPI trends, complaint trends, risk register updates) and real outputs (decisions, resourcing, objectives for the next cycle).
- Reconcile documentation with reality. Any process, supplier, site, or product change since the last full audit needs its procedures and risk assessments updated to match.
- Check competence records are current for all staff in scope — training certificates, inductions, and the competence matrix required under Clause 7.2.
Where the ongoing cost and effort really goes
Most organisations budget carefully for the initial certification cost but underestimate the ongoing internal labour of staying audit-ready across three years — someone has to keep hundreds of procedures, forms, and records current, findable, and reviewed on schedule between audits. If you are still scoping the investment, it's worth using the ISO 9001 certification cost calculator to calculate the exact cost for your company, including the ongoing surveillance-audit and documentation-maintenance effort most quotes leave out.
IgeraIndustria indexes your full QMS — procedures, work instructions, forms, and records — so quality managers can instantly find the current approved revision of any document, check when a procedure was last reviewed, and pull evidence for an auditor's question in seconds instead of searching shared drives. That matters most in the months between audits, when documentation drift is easiest to let happen unnoticed.
// IgeraIndustria RAG demo — surveillance audit prep query
Quality Manager: Our year-2 surveillance audit is in three weeks. Which corrective actions from last year's audit are still open, and when was our internal audit programme last completed?
IgeraIndustria: Two corrective actions from your year-1 surveillance audit remain open: CA-2025-014 (Clause 8.5.1, production control record gap, due 2026-06-30, currently overdue) and CA-2025-019 (Clause 7.1.5, calibration record for gauge G-22, due 2026-08-15). Your internal audit programme (IA-SCHED-2026) shows Clauses 4, 6, and 9 completed on 2026-03-10; Clauses 7 and 8 are scheduled but not yet marked complete. Recommend closing CA-2025-014 and completing the remaining internal audit before the surveillance visit.
Practical tips to stay audit-ready year-round
- Treat internal audits as a genuine check, not a formality — findings are a good sign, not a failure.
- Close corrective actions against their deadline, not against the next audit date.
- Hold management review on schedule even in quiet quarters — it's easy to skip and hard to fake retroactively.
- Update the competence matrix whenever staff join, leave, or change roles — not just before an audit.
- Log every customer complaint, even minor ones, and review the pattern quarterly.
- When a process changes, update the procedure the same week — not "when we get time."
Frequently asked questions
How often are ISO 9001 surveillance audits carried out?
Once a year, in year one and year two of each three-year certification cycle. Some certification bodies offer six-monthly surveillance for higher-risk sectors or larger, multi-site organisations, but annual is the standard model under ISO/IEC 17021-1.
Can I lose ISO 9001 certification between audits, not just at a surveillance visit?
Yes, in specific circumstances — for example if you fail to pay certification fees, fail to notify the certification body of significant organisational changes as required, or if a customer complaint or incident triggers an unannounced or short-notice audit that uncovers serious nonconformities. Suspension and withdrawal are governed by the certification body's procedures, which themselves follow ISO/IEC 17021-1 rules.
A minor nonconformity is an isolated lapse that doesn't undermine the QMS's ability to deliver its intended results — for example, one missing signature on a form. A major nonconformity indicates a systemic failure, an absence of a required process, or several related minor findings that together show the system isn't working — for example, no evidence that internal audits happened all year. Major nonconformities carry a stricter closure deadline and put certification at real risk if unresolved.
Does recertification cost the same as the initial certification?
Recertification audits are generally similar in scope and duration to the initial Stage 2 audit, so day rates are comparable, though the exact fee depends on the certification body, your organisation's size, and whether your scope or site count has changed since the last full audit. It is usually less expensive than initial certification because there is no Stage 1 gap-analysis audit, but it is not a token fee — budget for a comparable audit duration.
If we change certification body mid-cycle, do we restart the three-year clock?
Transfer of accredited certification between certification bodies is possible under IAF rules and, when done correctly, preserves your original certification date and cycle rather than restarting it. The receiving certification body will typically review your existing certificate, audit history, and any open corrective actions before accepting the transfer.
Staying audit-ready shouldn't mean searching shared drives before every visit. IgeraIndustria indexes your QMS so any question has a cited answer in seconds.
Explore IgeraIndustria for ISO 9001
Continue reading — ISO 9001 series
Article reviewed by IgeraIndustria Quality Team, updated 2026-08-02. References: ISO 9001:2015 Quality management systems — Requirements; ISO/IEC 17021-1 Conformity assessment — Requirements for bodies providing audit and certification of management systems; IAF Mandatory Documents on certification transfer and MLA scope.