\n\n","wordCount":2546,"timeToRead":"PT7M","keywords":["iso 9001 surveillance audit","maintain iso 9001 certification","iso 9001 recertification","iso 9001 3 year cycle","losing iso 9001 certification","industria","blog","RAG","IA","inteligencia artificial"]}
Industry

Maintaining ISO 9001 certification after year one: surveillance audits explained

IgeraIndustria Quality Team
August 2, 2026
7 min read
Quality auditor reviewing manufacturing documentation during an ISO 9001 surveillance audit

IgeraIndustria Quality Team  ·  Updated 2026-08-02  ·  7 min read

Direct answer

Winning ISO 9001 certification is not the end of the process — it is the start of a three-year cycle. Certification bodies run a short surveillance audit in year one and year two to confirm your quality management system (QMS) is still working, followed by a full recertification audit in year three. Certificates can be suspended or withdrawn between audits if nonconformities from a surveillance visit are not closed out within the agreed deadline, usually around 90 days.

Many organisations treat the initial certification audit as the finish line. It isn't. ISO 9001:2015 certification is only valid for three years, and it stays valid only if you keep demonstrating — twice a year, in front of an external auditor — that the system you built for the initial audit is still alive. Companies that let documentation drift, skip internal audits, or stop reviewing corrective actions are the ones that lose certification mid-cycle, usually at the worst possible moment: right when a key customer asks for proof.

How the three-year certification cycle actually works

A standard ISO 9001 certification cycle runs on a fixed rhythm set by your certification body (BSI, Bureau Veritas, SGS, LRQA, TÜV, DNV, and others all follow the same structure because it is defined by IAF/ISO accreditation rules, not by the certifier):

Year Audit type Typical scope
Year 0 Initial certification (Stage 1 + Stage 2) Full QMS review against all applicable clauses of ISO 9001:2015.
Year 1 Surveillance audit 1 Partial review — sampled clauses, closure of prior findings, internal audit and management review evidence.
Year 2 Surveillance audit 2 Same as year 1, usually different clauses sampled, plus preparation check for recertification.
Year 3 Recertification audit Full QMS review again, similar depth to the initial audit. A new three-year certificate is issued if successful.

Surveillance audits are shorter than the initial audit — often one day for a small site, longer for multi-site or high-complexity operations — because the auditor is sampling, not re-certifying from scratch. But "shorter" does not mean "lighter touch" on the areas it does cover. A surveillance audit that uncovers a major nonconformity can suspend your certificate just as effectively as a failed recertification.

What surveillance auditors actually review

Auditors cannot re-check every clause every year — that is the whole point of sampling across the cycle. But certain elements come up at nearly every surveillance visit because they are the clearest signal of whether the QMS is a living system or a folder that was built once for the initial audit and then abandoned:

  • Closure of previous findings. Any nonconformity or observation raised at the last audit must show documented corrective action, not just a promise it was fixed.
  • Internal audit programme. Did you actually run internal audits during the year, covering the clauses your internal audit schedule said you would? Auditors ask to see records, not just a plan.
  • Management review. Clause 9.3 requires top management to formally review the QMS at planned intervals — inputs like audit results, customer feedback, and process performance; outputs like decisions on improvement and resource needs. Auditors check the review actually happened and produced real outputs.
  • Customer complaints and satisfaction data. Are complaints being logged, investigated, and closed with corrective action where needed?
  • Nonconformity and corrective action records. Are nonconforming products/services identified, controlled, and root-caused — not just quietly reworked and forgotten?
  • Objectives and KPIs. Clause 6.2 quality objectives should be tracked with real data, not left as static numbers nobody has looked at since the initial audit.
  • Document and record control. Are the procedures in use the current approved revision? Auditors regularly find teams working from an outdated printed copy.
  • Changes since the last audit. New product lines, new sites, new suppliers, org changes, or process changes all get scrutiny, because Clause 6.3 requires planned changes to be controlled.

The mistakes that actually lead to losing certification

Certificates are rarely lost because of one dramatic failure. They are lost through a predictable, gradual pattern that auditors have seen many times before:

  • Treating the QMS as an audit-week exercise. Procedures get dusted off the week before the auditor arrives instead of being used day to day. Auditors can tell — inconsistent records, gaps in dates, and staff who can't explain the procedure they supposedly follow are the giveaway.
  • Not closing corrective actions on time. A minor nonconformity left open past its agreed deadline typically escalates in severity at the next audit. Repeated unresolved findings signal a management commitment problem, which is a Clause 5 issue, not just a paperwork issue.
  • Skipping or watering down internal audits. Internal audits are your own early-warning system. Organisations that stop running them, or run them as a formality without real findings, walk into surveillance audits blind — and so does the external auditor, who will dig deeper when internal audit evidence looks thin.
  • Ignoring documentation after staff turnover. A quality manager leaves, the QMS owner changes, and nobody updates the document control log, training records, or competence matrix for months. Clause 7.2 (competence) findings are common in this scenario.
  • Uncontrolled change. A new production line, ERP system, or supplier is introduced without updating the relevant procedures or risk assessment. The QMS documentation stops matching reality — a major nonconformity risk.
  • Not tracking customer complaints properly. A complaints log that is incomplete, or complaints that never trigger root-cause analysis, is one of the most common findings at surveillance stage.

When a major nonconformity is raised, the certification body sets a correction deadline — commonly around 90 days, though the exact period depends on the certification body's procedures and the severity of the finding. If it isn't closed in time, the certificate can be suspended; if suspension isn't resolved, it can be withdrawn entirely, meaning you start the initial certification process again from scratch.

Two audits a year, every year

Under ISO/IEC 17021-1 rules that certification bodies must follow, surveillance audits are required in years one and two of every three-year cycle — there is no version of ISO 9001 certification that skips them.

Preparing for recertification in year three

The recertification audit is close in depth to the original certification audit — the certification body needs to re-confirm your QMS meets ISO 9001:2015 across the full scope, not just the clauses sampled during surveillance. Good preparation starts long before the audit date:

  1. Review the full three-year audit history. Pull every finding from the initial audit and both surveillance visits, and confirm each one has closed, evidenced corrective action — not just a note that says "fixed."
  2. Run a genuine internal audit covering the whole QMS scope in the months before recertification, not just the clauses that are easy to check.
  3. Hold a management review with real inputs (audit results, KPI trends, complaint trends, risk register updates) and real outputs (decisions, resourcing, objectives for the next cycle).
  4. Reconcile documentation with reality. Any process, supplier, site, or product change since the last full audit needs its procedures and risk assessments updated to match.
  5. Check competence records are current for all staff in scope — training certificates, inductions, and the competence matrix required under Clause 7.2.

Where the ongoing cost and effort really goes

Most organisations budget carefully for the initial certification cost but underestimate the ongoing internal labour of staying audit-ready across three years — someone has to keep hundreds of procedures, forms, and records current, findable, and reviewed on schedule between audits. If you are still scoping the investment, it's worth using the ISO 9001 certification cost calculator to calculate the exact cost for your company, including the ongoing surveillance-audit and documentation-maintenance effort most quotes leave out.

IgeraIndustria indexes your full QMS — procedures, work instructions, forms, and records — so quality managers can instantly find the current approved revision of any document, check when a procedure was last reviewed, and pull evidence for an auditor's question in seconds instead of searching shared drives. That matters most in the months between audits, when documentation drift is easiest to let happen unnoticed.

// IgeraIndustria RAG demo — surveillance audit prep query

Quality Manager: Our year-2 surveillance audit is in three weeks. Which corrective actions from last year's audit are still open, and when was our internal audit programme last completed?

IgeraIndustria: Two corrective actions from your year-1 surveillance audit remain open: CA-2025-014 (Clause 8.5.1, production control record gap, due 2026-06-30, currently overdue) and CA-2025-019 (Clause 7.1.5, calibration record for gauge G-22, due 2026-08-15). Your internal audit programme (IA-SCHED-2026) shows Clauses 4, 6, and 9 completed on 2026-03-10; Clauses 7 and 8 are scheduled but not yet marked complete. Recommend closing CA-2025-014 and completing the remaining internal audit before the surveillance visit.

Practical tips to stay audit-ready year-round

  • Treat internal audits as a genuine check, not a formality — findings are a good sign, not a failure.
  • Close corrective actions against their deadline, not against the next audit date.
  • Hold management review on schedule even in quiet quarters — it's easy to skip and hard to fake retroactively.
  • Update the competence matrix whenever staff join, leave, or change roles — not just before an audit.
  • Log every customer complaint, even minor ones, and review the pattern quarterly.
  • When a process changes, update the procedure the same week — not "when we get time."

Frequently asked questions

How often are ISO 9001 surveillance audits carried out?

Once a year, in year one and year two of each three-year certification cycle. Some certification bodies offer six-monthly surveillance for higher-risk sectors or larger, multi-site organisations, but annual is the standard model under ISO/IEC 17021-1.

Can I lose ISO 9001 certification between audits, not just at a surveillance visit?

Yes, in specific circumstances — for example if you fail to pay certification fees, fail to notify the certification body of significant organisational changes as required, or if a customer complaint or incident triggers an unannounced or short-notice audit that uncovers serious nonconformities. Suspension and withdrawal are governed by the certification body's procedures, which themselves follow ISO/IEC 17021-1 rules.

What is the difference between a minor and a major nonconformity?

A minor nonconformity is an isolated lapse that doesn't undermine the QMS's ability to deliver its intended results — for example, one missing signature on a form. A major nonconformity indicates a systemic failure, an absence of a required process, or several related minor findings that together show the system isn't working — for example, no evidence that internal audits happened all year. Major nonconformities carry a stricter closure deadline and put certification at real risk if unresolved.

Does recertification cost the same as the initial certification?

Recertification audits are generally similar in scope and duration to the initial Stage 2 audit, so day rates are comparable, though the exact fee depends on the certification body, your organisation's size, and whether your scope or site count has changed since the last full audit. It is usually less expensive than initial certification because there is no Stage 1 gap-analysis audit, but it is not a token fee — budget for a comparable audit duration.

If we change certification body mid-cycle, do we restart the three-year clock?

Transfer of accredited certification between certification bodies is possible under IAF rules and, when done correctly, preserves your original certification date and cycle rather than restarting it. The receiving certification body will typically review your existing certificate, audit history, and any open corrective actions before accepting the transfer.

Staying audit-ready shouldn't mean searching shared drives before every visit. IgeraIndustria indexes your QMS so any question has a cited answer in seconds.

Explore IgeraIndustria for ISO 9001

Article reviewed by IgeraIndustria Quality Team, updated 2026-08-02. References: ISO 9001:2015 Quality management systems — Requirements; ISO/IEC 17021-1 Conformity assessment — Requirements for bodies providing audit and certification of management systems; IAF Mandatory Documents on certification transfer and MLA scope.

#iso 9001 surveillance audit#maintain iso 9001 certification#iso 9001 recertification#iso 9001 3 year cycle#losing iso 9001 certification

COMPARTIR

Comparte el conocimiento con tu red