ISO 9001 Surveillance and Recertification Audits
An ISO 9001 certificate is valid for three years. To keep it, you host a surveillance audit in each of the first two years and a recertification audit before the certificate expires. This page explains what the auditor checks and how to prepare.
The ISO 9001 three-year audit cycle
- Initial certification. Stage 1 and Stage 2 audits. The certificate is valid for three years from the certification decision.
- Year 1. First surveillance audit, due within 12 months of the certification decision.
- Year 2. Second surveillance audit.
- Year 3. Recertification audit, completed before the certificate expires.
Between audits, the standard expects internal audits, management review, corrective actions, calibration and document control to continue. In a shop or plant of 10 to 50 people, that work usually falls on one person who also has another job, often the owner or the operations manager.
Surveillance audit vs. recertification audit
| Surveillance audit | Recertification audit | |
|---|---|---|
| When | Years 1 and 2, at least once a year | Year 3, before the certificate expires |
| Typical length for a small shop | About 1 to 2 days | About 2 to 3 days |
| What is covered | A sample of processes and jobs, plus internal audits, management review, corrective actions, complaints and changes | The full quality system and its performance over the three years |
| What happens after | Findings are addressed and the certificate stays in place | The certification body decides whether to renew the certificate for three more years |
The certification body sets audit length based on headcount, number of sites and scope.
What the auditor samples at an ISO 9001 surveillance audit
A surveillance audit does not cover every clause at each visit. Auditors commonly look at:
- Internal audit results. Which processes were covered, who did the audit and whether the findings were closed.
- Management review minutes. The inputs reviewed and the decisions and actions recorded.
- Corrective actions from the last audit. Evidence that each one was completed and worked.
- Customer complaints and returns. How each one was handled and whether it led to a corrective action.
- Changes since the last visit. New equipment, new processes, new customers, changes in key people or changes to the scope.
- A sample of processes and jobs. Jobs traced through travelers, material certs, heat lots, first article, final inspection and calibration records by gauge ID.
Most certification bodies plan their surveillance visits so that every process in your scope is sampled at least once during the three-year cycle.
The ISO 9001 recertification audit
- At an ISO recertification audit, the auditor reviews the full system instead of a sample.
- The audit looks at performance over the three-year cycle: quality objectives, trends in nonconformances and complaints, and whether corrective actions worked.
- The auditor checks that the scope still fits the business if you have added processes, products or sites.
- The recertification audit must be completed, and any major nonconformities corrected, before the expiry date. If not, the certificate lapses. Customers that require ISO 9001 may treat a lapsed certificate the same as no certificate.
What happens with nonconformities
- Minor nonconformity. A single lapse that does not stop the system from working, such as one gauge past its calibration date. You submit a corrective action plan by the deadline the certification body sets, and the auditor checks it at the next visit.
- Major nonconformity. A requirement that is not met at all, or a failure that puts product conformity at risk, such as no internal audit in the cycle or no control of nonconforming parts. It must be corrected by the deadline the certification body sets.
- Follow-up visits. A major can mean a follow-up visit, at extra cost, before the certificate is continued or renewed.
- Opportunities for improvement. These are not nonconformities and do not require a response, though auditors often check them at the next visit.
How to prepare: an ISO surveillance audit checklist
- Complete the internal audit for the year, done by someone who did not audit their own work, and close the findings with evidence.
- Hold management review and record the decisions and actions in the minutes.
- Close the corrective actions from the last external audit and keep evidence that they worked.
- Pull the list of customer complaints and returns since the last visit, with how each one was handled.
- Check calibration: every gauge ID on schedule, with out-of-tolerance reviews recorded.
- Walk the floor: current drawing revisions at the machines, and nonconforming parts tagged and segregated.
- Pick two or three recent jobs and trace them through travelers, material certs, heat lots, first article and final inspection.
- List the changes since the last audit so you can explain them to the auditor.
Our ISO 9001 audit checklist walks through each area in the order auditors commonly check it.
API Q1 and AS9100 audits
- Shops registered to API Spec Q1 or certified to AS9100 follow a similar three-year cycle with yearly audits.
- API Q1 audits go into more detail on risk assessment, contingency planning, management of change and supplier evaluation.
- AS9100 audits add areas such as first article inspection, configuration management and counterfeit part prevention.
How Qualent Advisory helps
We schedule and run your internal audit with an experienced, independent auditor before the surveillance or recertification audit, help close the findings, and keep documents, corrective actions and records current between audits. Learn more about our internal audit service, contact us or call (832) 905-1664.
Common questions about surveillance and recertification audits
How often are ISO 9001 surveillance audits?
At least once a year. You have a surveillance audit in year 1 and year 2 of the certificate, and a recertification audit in year 3. The first surveillance audit is due within 12 months of the certification decision.
How long does a surveillance audit take?
For a 10 to 50 person shop, a surveillance audit usually takes 1 to 2 days on site. The certification body sets the length based on headcount, number of sites and scope. It is typically about a third of the time of the initial certification audit.
What happens if we get a major nonconformity?
You correct it and send evidence within the deadline the certification body sets. The certification body may schedule a follow-up visit to verify the correction, usually at extra cost. If a major is not addressed in time, the certificate can be suspended.
Can our internal audit be outsourced?
Yes. ISO 9001 requires internal audits to be objective and impartial. It does not require the auditor to be an employee. Certification bodies accept outsourced internal audits when the auditor is competent and independent of the work being audited.
What if our certificate has lapsed?
Contact your certification body right away. Some certification bodies can restore a certificate within six months of expiry if the outstanding recertification work is completed. After that, most require at least a new Stage 2 audit.