Why the Recertification Audit Is Not Just a Bigger Surveillance Audit
Every three years, your ISO 9001 certificate expires, and the audit that renews it is not the same animal as the two surveillance audits you sat through in the years before it. Under ISO/IEC 17021-1:2015 clause 9.6.3.1, the recertification audit has to evaluate the overall performance of the quality management system over the entire certification cycle, not just the previous twelve months. That single clause changes what your certification body is looking for, and it's the reason organizations that sailed through surveillance audits sometimes get surprised at recertification.
I've sat across the table from clients who treated recertification prep like "surveillance audit, but longer." It isn't. The auditor is required to review your surveillance audit reports, your closed and open corrective actions across the whole cycle, complaints received, and whether the system as a whole has actually improved or just survived. This checklist is built around that three-year lens, organized by the clauses that generate the most recertification findings, with a specific eye toward what a certification body auditor is instructed to check under 17021-1.
When Does the Recertification Audit Happen
ISO/IEC 17021-1 clause 9.6.3.2 requires the recertification audit and the recertification decision to be completed before the certificate's expiration date. Most certification bodies schedule the audit 60 to 90 days before expiration to leave room for closing any findings before the old certificate lapses. If you don't know your exact expiration date, it's printed on your certificate, and your certification body should have already contacted you to schedule. If they haven't and you're inside 120 days of expiration, call them. A lapsed certificate is not a paperwork inconvenience for a contractor whose customers require current ISO 9001 status in their purchase orders.
Surveillance Audit vs. Recertification Audit: What Actually Differs
| Element | Surveillance Audit (Year 1 & 2) | Recertification Audit (Year 3) |
|---|---|---|
| Scope basis | Sample of clauses, mandatory elements | Full QMS reassessment against ISO 9001:2015 |
| Time horizon reviewed | Since last audit | Entire 3-year certification cycle |
| Prior audit reports reviewed | Prior surveillance only | All surveillance audits + initial/previous recert |
| Complaints review | Recent period | Full cycle, including trends |
| Management review evidence | Most recent cycle | Multiple management reviews across the term |
| Internal audit coverage checked | Partial | Confirmation that all clauses/processes were covered at least once across the cycle |
| Typical audit duration | Shorter (per IAF MD 5 formula) | Similar to or slightly less than initial certification audit, per IAF MD 5 |
| Outcome | Continued certification | New 3-year certificate issued or certification withdrawn |
The row that trips people up most is internal audit coverage. Clause 9.2.1 of ISO 9001:2015 requires internal audits "at planned intervals," and most organizations run an annual internal audit program that covers different clauses or departments each cycle rather than everything every year. The recertification auditor will ask to see the three-year internal audit plan and confirm every process and every applicable clause got audited at least once somewhere in that window. A gap in coverage, even if each individual audit was fine, is a finding.
The Recertification Prep Checklist
1. Pull and Reconcile the Full-Cycle Document Set
Before anything else, assemble records spanning the entire certification period, not just the last audit-to-audit window:
- All three years of internal audit reports and the internal audit schedule/plan showing full-cycle coverage
- All management review meeting minutes (ISO 9001:2015 clause 9.3.2 lists required inputs across six categories, from audit results to customer feedback to changes in external and internal issues), plus the outputs and evidence those outputs were acted on
- Every corrective action raised in the cycle (clause 10.2), with status: closed with verified effectiveness, or still open with a documented reason and target date
- Your two prior surveillance audit reports, including how you responded to every nonconformity, observation, and opportunity for improvement
- Customer complaint log and customer satisfaction data (clause 9.1.2) covering the full cycle, with any trend analysis
- Any certificate scope changes, site additions, or major process changes made during the cycle, since these have to align with what's actually printed on the certificate
If your management review minutes read the same in year three as they did in year one, that's itself a signal to the auditor that the review is a formality rather than a governance activity. Auditors are trained to look for evidence that inputs actually changed outputs, not that a meeting happened.
2. Verify Every Prior Nonconformity Actually Closed
This is the single highest-yield thing you can do before recertification. Pull every nonconformity from your initial certification audit and both surveillance audits. For each one, confirm you have:
- The root cause analysis
- The corrective action taken
- Objective evidence the action worked, not just that it was implemented
Clause 10.2.1(d) requires you to review the effectiveness of any corrective action taken, and a recertification auditor will re-test the ones that looked thin the first time. A corrective action that was accepted at surveillance but never actually verified for effectiveness is a very common source of a repeat or escalated finding at recertification.
3. Confirm Risk-Based Thinking Has an Audit Trail
Clause 6.1 requires the organization to determine risks and opportunities and plan actions to address them. Over a three-year cycle, your risk register (formal or informal) should show:
- Risks being reassessed periodically, not just listed once at initial certification and forgotten
- A clear tie between those risks and opportunities and your quality objectives, per clause 6.1.2
4. Reassess Your Context and Interested Parties
Clauses 4.1 and 4.2 require you to determine external and internal issues relevant to your purpose and strategic direction, and the needs and expectations of interested parties. Over three years, markets shift, key customers change their requirements, regulations move. If your documented context analysis from the initial audit hasn't been touched since, the auditor will ask why nothing changed in three years, and "we forgot" is not a good answer in a recertification interview.
5. Re-Run the Internal Audit Coverage Map
Build a simple matrix: rows are ISO 9001 clauses and your key processes, columns are the three years of the cycle, and mark where each was covered by an internal audit. Any blank row is a gap you want to know about before the external auditor finds it. If a gap exists and you can't fix it before the recertification audit, the honest move is to schedule a supplemental internal audit on that process now and have the results ready to show, along with a corrective action if anything turns up.
6. Check Objectives and Their Measurement
Clause 6.2 requires quality objectives to be:
- Measurable
- Monitored
- Communicated
- Updated as appropriate
At recertification, auditors specifically look for whether objectives evolved with the business or sat unchanged for three years while the numbers stopped meaning anything.
7. Review Competence and Training Records for the Full Term
Clause 7.2 requires you to determine necessary competence, ensure people are competent, and retain evidence. Over three years, staff turn over, roles change, and training records can develop gaps that nobody notices until an auditor asks for a specific person's file. Spot-check a sample of employees, especially anyone in a role tied to product or service conformity, and confirm training records are current and retained.
8. Confirm Supplier and Outsourced Process Controls Held Up
Clause 8.4 covers control of externally provided processes, products, and services. During the cycle, check whether you:
- Changed suppliers
- Added subcontractors
- Outsourced a process
If any of those happened, confirm your supplier evaluation records reflect it and that the controls match the risk.
9. Check Scope and Certificate Accuracy
Confirm the scope statement on your certificate still matches what you actually do. If you added a product line, a location, or a service category during the cycle without notifying your certification body, recertification is the point where that mismatch gets flagged, and it can trigger a scope extension audit on top of the recertification audit itself, adding cost and time you didn't plan for.
10. Prepare Your Team for the Interview, Not Just the Paperwork
Auditors interview process owners, not just quality managers. Make sure the people who'll be interviewed can speak to these things in their own words:
- Their process
- Their objectives
- Recent nonconformities
An auditor who gets a blank stare from a production supervisor about a corrective action closed eighteen months ago has reason to question whether the correction actually stuck or whether it was a paperwork exercise done by the quality department in isolation.
What Happens If You Have Open Nonconformities Going Into Recertification
If a major nonconformity from a surveillance audit is still open when the recertification audit starts, most certification bodies will not proceed to a recertification decision until it's resolved. Under the accreditation rules that govern certification bodies, an open major nonconformity is a bar to issuing a new certificate. Minor nonconformities with an accepted corrective action plan generally don't block recertification, but an auditor will check that the plan is actually on track, not just filed and forgotten. If you're carrying an open major, close it before the recertification audit date. If that means requesting the audit be pushed slightly, do it — a delayed but successful audit beats an on-time audit that fails to result in a new certificate.
How Long Does a Recertification Audit Take
Audit duration is calculated per IAF MD 5, which sets audit time based on the number of employees covered by the certificate, the complexity of processes, and the number of sites. Recertification audit duration is typically similar to the initial certification audit, sometimes reduced somewhat to reflect the organization's certification history, but it is not simply a short check-in. Budget the same operational disruption you experienced at initial certification, and don't schedule it during your busiest production period if you have any control over the date.
Frequently Asked Questions
What is the difference between a surveillance audit and a recertification audit under ISO 9001? A surveillance audit samples parts of your quality management system within a given year, while a recertification audit, per ISO/IEC 17021-1 clause 9.6.3.1, evaluates the overall performance of the system across the entire three-year certification cycle, including a review of all prior surveillance audit reports and closed corrective actions.
How often do you need to recertify to ISO 9001? ISO 9001 certificates are issued on a three-year cycle under ISO/IEC 17021-1, with surveillance audits typically in years one and two and a full recertification audit in year three before the certificate expires.
Can you fail a recertification audit? Yes. If a major nonconformity is raised during the recertification audit and not resolved before the certification decision, the certification body will not issue a new certificate, which means the organization loses ISO 9001 certification until the nonconformity is corrected and reverified.
Does the recertification audit take as long as the initial certification audit? Audit duration is calculated per IAF MD 5 based on headcount, process complexity, and number of sites, and recertification audits are generally similar in length to the initial certification audit, occasionally shortened slightly to reflect a clean certification history.
What records should we prepare before a recertification audit? Prepare three years of internal audit reports, management review minutes, corrective action records with effectiveness verification, prior surveillance audit reports and your responses to them, customer complaint and satisfaction data, and any changes to certificate scope made during the cycle.
If your internal audit program has gaps you're not sure how to close before the recertification date, our internal audits resource walks through building a program that actually holds up across a full certification cycle. And if you're weighing whether to prepare for recertification in-house or bring in outside support, the ISO 9001 certification cost guide breaks down where that spend typically goes. We also have deeper guides on risk-based thinking, writing quality objectives, and purchasing controls and supplier evaluation if any of those specific areas need work before your audit.
Last updated: 2026-08-21
Jared Clark
Principal Consultant, Certify Consulting
Jared Clark is the founder of Certify Consulting, helping organizations achieve and maintain compliance with international standards and regulatory requirements.