Skip to main content
Rules Mate

Surveillance audits, non-conformances and keeping certification between recertification cycles

Rules Mate Editorial8 min read

How the three-year certification cycle works: surveillance audit scope, major vs minor non-conformances, root cause and corrective action, and suspension or withdrawal.

Getting certified is a project. Staying certified is an operating discipline, and it is where most of the cost and nearly all of the risk sits. An organisation that treats the certificate as a milestone rather than a system typically discovers the gap at the first surveillance audit.

This article covers the mechanics that apply across ISO 9001, ISO 14001, ISO 45001, ISO 27001, ISO 22301 and ISO 37301, because they are all governed by the same certification-body rules.

How the three-year cycle works

Accredited management-system certification runs on a three-year cycle: an initial two-stage certification audit, annual surveillance audits, and a recertification audit before the certificate expires.

The rules governing certification bodies are set out in ISO/IEC 17021-1:2015, which requires the first surveillance audit following initial certification to be conducted within twelve months of the certification decision date, with surveillance audits thereafter at least annually.

Point in cycleAuditPurpose
Year 0Stage 1Readiness and documentation review; scope confirmation
Year 0Stage 2Implementation and effectiveness sampling; certification decision
Year 1First surveillanceWithin twelve months of the certification decision
Year 2Second surveillanceContinued conformity and improvement
Year 3RecertificationFull-system review before certificate expiry

Two dates matter more than organisations expect. The certification decision date starts the twelve-month clock, not the audit date. And the recertification audit must be completed before expiry — if it slips, the certificate lapses, and recovering from a lapse can mean a full initial certification rather than a recertification.

What a surveillance audit covers

A surveillance audit is a sample, not a full re-audit, and the sample is not random.

A surveillance audit will always cover:

  • Internal audits and management review since the last audit.
  • Actions taken on non-conformances raised previously, and verification they were effective.
  • Complaints and how they were handled.
  • Effectiveness of the management system against its stated objectives.
  • Progress on planned improvement.
  • Continued operational control.
  • Any changes to the organisation, its scope, or the legal and other requirements applying to it.
  • Use of certification marks and references to certification in marketing.

Across the cycle, surveillance audits plus recertification must cover the entire management system and full scope. So a topic missed in year one is more likely, not less, to appear in year two. Treating surveillance as a lighter version of certification is a mistake — the audit days are fewer, but the scrutiny of previously raised findings is sharper.

The recertification audit is different in kind. It reviews the performance of the management system across the whole cycle, including the internal audit and management review programme and their effectiveness, and it revisits the continued relevance of the scope. It is closer in intensity to a Stage 2 audit than to a surveillance visit.

Major and minor non-conformances

Findings are graded, and the grade determines what happens next.

A major non-conformance is typically one that affects the capability of the management system to achieve intended results — a requirement of the standard not implemented at all, a total breakdown of a required process, or an accumulation of minor findings against the same requirement indicating systemic failure. Consequences:

  • At initial certification, the certification decision cannot proceed until corrective action is verified.
  • At surveillance, the certificate is at risk. Certification bodies apply defined timeframes for correction and will move to suspension if they are not met.
  • Verification often requires a special visit rather than desktop review, which carries its own cost.

A minor non-conformance is an isolated lapse that does not indicate systemic failure. Consequences:

  • Corrective action must be submitted within the certification body's timeframe.
  • Verification is commonly by document review, or at the next scheduled audit.
  • Repeated minor findings against the same clause escalate to major.

Certification bodies also raise observations or opportunities for improvement, which are not non-conformances and require no formal response — though ignoring them repeatedly is how a minor finding is born.

Closure timeframes are set by each certification body under its accreditation, and they differ. Confirm yours in writing at contract stage rather than discovering it in a findings report, and note that timeframes for major findings after a recertification audit are typically much tighter than after a surveillance audit because the certificate is expiring.

Root cause analysis: where corrective actions fail

The single most common reason a corrective action is rejected — across every standard — is that it corrects the instance without addressing the cause.

Every one of these standards requires the same sequence for a non-conformity: react to it and control and correct it; deal with the consequences; then evaluate the need for action to eliminate the cause so it does not recur or occur elsewhere. That last clause is the one organisations skip.

A corrective action response that passes review contains:

  1. Correction — what was done immediately to fix the instance found.
  2. Containment — what was done about other instances of the same problem that may already exist. If a record was missing in one project, were the other projects checked?
  3. Root cause — the analysis, using a stated method, showing why the process allowed the failure. "Human error" is not a root cause; it is where analysis stops too early.
  4. Corrective action — the change to the process, system or control that removes the cause.
  5. Extent of application — where else the cause could produce the same failure, and what was done there.
  6. Evidence — the records demonstrating the action was implemented.
  7. Effectiveness verification — how and when you will confirm it worked, with the result.

Step 7 is the one auditors return to at the next visit. A corrective action closed without effectiveness verification is a finding waiting to be re-raised, and a re-raised finding escalates in grade.

Suspension, withdrawal and reduction of scope

Certification bodies have three sanctions short of doing nothing, and all three are visible to your customers.

Suspension puts the certificate temporarily out of effect. Triggers include persistent failure to close major non-conformances, failure to allow a surveillance or recertification audit at the required frequency, misuse of certification marks, and a voluntary request. During suspension you must stop making certification claims. There is a defined period to resolve; failure to resolve leads to withdrawal.

Withdrawal ends the certification. Recovering usually means starting again with an initial certification audit, not a recertification.

Reduction of scope removes the parts of the scope that no longer conform. This is the outcome when one site or one service line fails while the rest of the system is sound, and it is often a better commercial outcome than suspension — but it changes the certificate a customer reads.

Two behaviours reliably trigger sanctions. Refusing or deferring audits — including delaying a surveillance audit past its due window for convenience. And misuse of marks — applying a certification mark to a product (management-system certification never certifies a product), or continuing to use marks after suspension.

The maintenance calendar that keeps you audit-ready

Certification maintenance is a small number of recurring obligations. Put them in a calendar with owners, not in someone's memory. The compliance calendar tool and the deadline register are built for exactly this.

  • Internal audit programme — planned so the full system and full scope are covered across the cycle, with auditor independence maintained.
  • Management review — at planned intervals with all required inputs and recorded decisions.
  • Risk or aspects reassessment — annually and on material change.
  • Legal and other requirements register review — the highest-decay item in the whole system, and the source of the most findings.
  • Compliance evaluation — evidence you assessed status, not just that the register exists.
  • Objectives review — measured against baselines.
  • Competence and training refresh.
  • Emergency or continuity exercise, with findings and plan updates.
  • Supplier and contractor reassessment.
  • Corrective action effectiveness verification for every action closed since the last audit.
  • Document and record retention — several standards require retention of specific records, and Australian law imposes its own retention duties; see records retention.
  • Pre-audit self-check four to six weeks before each surveillance audit. For information security systems, re-run the ISO 27001 gap assessment as a structured self-check.

Sequence matters. Internal audit should precede management review so its findings are an input, and both should precede the external audit with enough margin to close anything found.

Changes you must tell your certification body about

Certification bodies require notification of changes affecting the management system or its scope, and failing to notify is itself a finding.

Notify promptly when any of the following occur:

  • Legal or ownership change — acquisition, merger, restructure, change of legal entity name or ABN.
  • Site changes — new sites in scope, closures, relocations.
  • Scope changes — new products, services or activities you want covered, or activities you are ceasing.
  • Significant organisational change — loss of the management representative, major headcount change, restructure of the function that owns the system.
  • Changes to the management system itself that are material.
  • Serious incidents — a major safety incident under ISO 45001, a significant breach under ISO 27001, a serious environmental incident under ISO 14001, a major disruption under ISO 22301.
  • Regulator action — prosecutions, enforceable undertakings, licence conditions or improvement notices relevant to the certified system.
  • Insolvency events.

The reason for the incident and regulator-action notifications is that certification bodies must consider whether the event calls the certification into question, and may bring forward an audit or add a special visit. Concealing a notifiable event and having the certification body discover it independently is far worse than reporting it.

Two related certification cycles worth knowing if they apply to you: NDIS registered providers run their own audit cycle against the NDIS Practice Standards — see the obligation ndis-audit-cycle and certification vs verification audits — and RTOs face regulatory audit by ASQA rather than accredited certification, covered in the ASQA audit guide.

Finally, standard revisions create their own cycle event. When a standard is revised, accreditation practice provides a transition window during which certificates are migrated at a scheduled audit. The environmental standard is mid-transition now, and the quality standard is about to be — see ISO 14001 for Australian operations and ISO 9001 for Australian business. Book the transition into a scheduled audit early rather than competing for audit capacity in the final year.

Frequently asked

How often are surveillance audits required?

The first surveillance audit after initial certification must be conducted within twelve months of the certification decision date, and surveillance audits must be conducted at least annually thereafter. Note that the clock runs from the certification decision date, not the audit date.

What is the difference between a major and a minor non-conformance?

A major non-conformance affects the management system's capability to achieve its intended results — a requirement not implemented, a process that has broken down, or an accumulation of minor findings against the same requirement. A minor is an isolated lapse. Majors put the certificate at risk and often require a special verification visit; minors are usually verified at the next audit.

Why do corrective actions get rejected?

Almost always because they correct the instance without addressing the cause. A response that passes review contains correction, containment of other existing instances, a stated root cause analysis, the process change that removes the cause, the extent of application elsewhere, implementation evidence, and effectiveness verification. Skipping the last step is what causes findings to be re-raised.

What happens if my certificate lapses?

Recovering from a lapse is generally treated as a new certification rather than a recertification, meaning a full two-stage audit. The recertification audit has to be completed before the certificate expires, so the schedule must allow time to close any findings raised. Deferring a recertification audit for convenience is one of the more expensive mistakes available.

Do I have to tell my certification body about incidents and regulator action?

Yes. Certification bodies require notification of changes affecting the management system or its scope, including serious incidents and regulator action such as prosecutions, enforceable undertakings or improvement notices. The body must consider whether the event calls certification into question. Concealment discovered independently is treated far more seriously than disclosure.

When a standard is revised, do I need a new certificate?

No. Accreditation practice provides a transition window — typically three years — during which existing certificates remain valid and are migrated at a scheduled surveillance or recertification audit. Book the transition into an existing audit early; organisations that defer to the final year compete for audit capacity with everyone else who deferred.

Related

Related reading