Skip to content
VISCOUNTQuality Certifications

Guidance

Recertification: what a year-three audit checks, and when to book it

A recertification audit assesses the whole management system and its performance across three years. What it checks, and why the expiry date is the deadline.

A recertification audit renews your certificate for a further three years, and it examines the whole management system together with how that system performed across the cycle that is ending. A surveillance audit samples the part of the system due for coverage that year; recertification covers the system in its entirety and the record it produced since the last certification decision. Plan it far enough ahead of your expiry date that a major nonconformity can be corrected and verified before the certificate expires. The expiry date printed on your certificate holds whatever happens in the audit.

What the audit examines

The input that distinguishes recertification is three years of performance rather than conformity on the day. We ask for the internal audit results and management review outputs from across the cycle, the monitoring and measurement data clause 9.1 requires you to analyze and evaluate, and the objectives set under clause 6.2 with whatever progress was recorded against them. Clause 10.3, continual improvement, is audited against that record.

The nonconformities raised at your certification audit and at both surveillances come back into the audit as well. What matters at recertification is whether their causes stayed closed. A corrective action verified as effective in year one, followed by a similar finding in year three, describes a system that has been treating symptoms for a cycle.

Three years of change get read against the certificate: sites opened or closed, activities added, the legal entity, and for ISO 14001 and ISO 45001 the compliance obligations evaluated under clause 9.1.2. ISO/IEC 17021-1, the standard our certification activity is accredited to, requires the previous surveillance reports to feed the recertification plan, and it provides for a Stage 1 where changes since the last cycle have been significant. An organization that has doubled its sites can therefore find a document review back in the plan.

Audit duration is recalculated rather than carried over. It follows from the standard, headcount, number of sites and the processes in scope, collected in the questionnaire before any proposal, so an organization that has grown across the cycle can be quoted more time for recertification than it was for its original certification.

The expiry date is the deadline

Where the recertification activities are not finished before the expiry date, including verification of corrections for any major nonconformity, ISO/IEC 17021-1 leaves nothing to negotiate: recertification cannot be recommended, and the validity of the existing certification cannot be extended. This is the constraint organizations discover latest, and it is not ours to waive.

What a lapse costs depends on how long it runs. ISO/IEC 17021-1 allows certification to be restored within six months of expiry once the outstanding recertification activities are completed. Beyond that window, at least a Stage 2 audit is required, and you are buying an initial certification rather than a renewal.

The register shows the lapse while it lasts. A certificate that passes its expiry date without a decision reads as expired, and a buyer checking it during the gap sees expired whatever audit is under way. During a normal renewal the entry reads renewing instead, and the certificate remains in force until the expiry date shown. Where a contract depends on continuous certification, the register entry is what the other side reads.

The margin you need is set by the sequence after the audit, not by the audit itself. Findings are issued in writing with a window to respond, your corrective action needs time to be planned and implemented, and we then have to verify it. We schedule the year-three audit with room for that sequence, which is why the audit plan is issued in advance and why the date is worth agreeing early in the third year.

Where recertification audits go wrong

The internal audit program that covered the same three processes every year is the most common. Clause 9.2 asks the program to account for the importance of the processes concerned, changes in the organization and the results of previous audits, and a recertification auditor reads it across the cycle rather than one year at a time. Clauses and sites that were never internally audited in three years produce a finding against the program itself.

Objectives are the second. Clause 6.2 requires objectives that are measurable, monitored and updated, and a set of objectives that has not changed since the certification audit, with no measurement recorded against them, gives us nothing to assess improvement with. The management review record is usually where this becomes visible, because clause 9.3 puts the extent to which objectives have been met on the agenda.

The third is growth that was never reported. The renewed certificate can name only the sites and activities we audited, so a branch opened in year two and mentioned for the first time at the closing meeting stays off the certificate and off the register entry until it has been audited. The three-year cycle has surveillance visits in it partly so that this surfaces at the time.

The recertification decision is taken the same way as the first one. The audit team recommends, and a reviewer who did not conduct the audit decides, reading the file for the whole cycle. Where the decision is positive, a new certificate issues for the next three years and the register entry updates with its validity dates and the standard edition it was audited against.