The Three Year Clock Is Running
If your organisation holds ISO certification, you are operating on a three year cycle. Surveillance audits happen in years one and two. Then, at the end of year three, your certification body returns for something more substantial: the recertification audit. This is where your certificate is either renewed for another three years or placed at risk.
On this page
A recertification audit is not simply a bigger surveillance audit. It has a different scope, a different level of scrutiny, and different consequences if things go wrong. Understanding what it involves, why it matters, and how to prepare properly is essential for any quality manager, HSE manager, or environmental manager who is responsible for maintaining certification.
This article walks through what a recertification audit actually is, how it differs from other audit types in the certification cycle, what auditors are looking for, and how to approach preparation without the last minute panic that derails so many organisations.
What Is a Recertification Audit?
A recertification audit, sometimes called a renewal audit or reassessment audit, is a third party audit conducted by your accredited certification body at the end of a three year certification cycle. Its purpose is to determine whether your management system continues to conform to the requirements of the relevant ISO standard and whether your certificate should be renewed for another three year period.
Under the rules set by accreditation bodies such as JAS ANZ in Australia, ISO certificates are valid for three years from the date of initial certification. Surveillance audits conducted in years one and two maintain ongoing oversight, but they typically cover only a portion of your system. The recertification audit is designed to evaluate the entire management system again, much like the original Stage 2 certification audit.
This distinction matters. During a surveillance audit, your certification body may focus on specific clauses, high risk processes, or areas where previous nonconformities were raised. During a recertification audit, the expectation is that the full scope of the standard is covered across the audit. That means every clause, every process within scope, and the overall effectiveness of the system as a whole.
Exemplar Global Recognised Training ProviderRTP No. 310970How the Recertification Audit Fits Into the Certification Cycle
To understand the recertification audit properly, it helps to see where it sits in the broader certification lifecycle.
Initial Certification: Stage 1 and Stage 2
When an organisation first pursues ISO certification, the process involves two stages. The Stage 1 audit is a documentation review and readiness assessment. The Stage 2 audit is the full on site assessment of the management system in operation. Successful completion of Stage 2 results in the issue of a certificate.
Surveillance Audits in Years One and Two
Once certified, your organisation is subject to surveillance audits, typically conducted annually. These are shorter in duration than the initial certification audit and usually focus on a subset of clauses and processes. Their purpose is to confirm that the system is being maintained and that the organisation remains compliant between recertification audits. If you want to understand how surveillance audits differ from certification audits in more detail, the article What Is a Surveillance Audit covers this well.
Recertification at Year Three
The recertification audit occurs before the current certificate expires. In practice, certification bodies typically schedule this audit several months before the expiry date to allow time for any nonconformities to be resolved without the certificate lapsing. The audit covers the full scope of the standard and results in either renewal of the certificate or, in cases where major nonconformities are unresolved, a decision to suspend or withdraw certification.
For a broader look at how the full three year cycle works, the article The Three Year Certification Cycle Explained provides useful context.
What Auditors Are Looking for in a Recertification Audit
Recertification auditors are not simply checking whether your procedures still exist. They are evaluating whether your management system has continued to function effectively over the past three years and whether it is fit for purpose going forward. There are several specific areas that receive close attention.
Continual Improvement Over the Cycle
One of the clearest signals that a management system is genuinely working is evidence of continual improvement. Auditors will look for trends across the three year period. Has the organisation identified opportunities for improvement and acted on them? Has performance against objectives improved, plateaued, or declined? Are corrective actions being closed out effectively, or are the same problems appearing year after year?
If your nonconformity register shows the same issues recurring across multiple audit cycles without meaningful root cause analysis or systemic change, that is a significant concern. Auditors have seen the surveillance audit reports. They know what was raised before. They will follow up.
Management Review Effectiveness
Management review is one of the areas that gets underestimated by organisations preparing for recertification. The standard requires top management to review the system at planned intervals, and those reviews need to address specific inputs and produce outputs that drive action. Auditors will review management review records from across the three year period and assess whether they reflect genuine engagement from leadership or whether they are paper exercises conducted to satisfy a checklist.
Weak management review records are one of the most common sources of nonconformities at recertification. If the minutes show the same agenda items with the same vague conclusions and no evidence of decisions being implemented, expect a finding.
Internal Audit Programme
Your internal audit programme needs to demonstrate that the full scope of the standard has been covered over the certification cycle. Auditors will check whether internal audits have been conducted at planned intervals, whether the programme has been adjusted based on risk, and whether findings from internal audits have been properly addressed.
A common gap here is organisations that conduct internal audits but fail to close out nonconformities properly, or that audit the same low risk processes repeatedly while avoiding the difficult ones. Auditors notice patterns in your internal audit records, and gaps in coverage will be questioned.
Objectives and Performance Data
Your quality, environmental, or OH and S objectives need to be measurable, and you need to be able to demonstrate how performance has tracked against them over time. Auditors will want to see the data, not just the objectives. If you set an objective three years ago and cannot show what happened to it, that is a problem.
Objectives that have been quietly dropped, changed without documented rationale, or never actually measured are a recurring issue at recertification audits. The system needs to show that objectives are live, tracked, and driving real activity.
Handling of Nonconformities and Corrective Actions
Every nonconformity raised during the three year cycle, whether from internal audits, surveillance audits, customer complaints, or incidents, should have a documented corrective action that addresses the root cause and verifies effectiveness. Auditors will sample corrective action records and assess whether the organisation is genuinely learning from problems or simply closing paperwork.
Changes to the Organisation and the System
Organisations change over three years. New sites, new processes, new products, changes in personnel, changes in the regulatory environment. Auditors will assess whether the management system has kept pace with those changes. If the scope of your system no longer reflects what the organisation actually does, or if significant changes have been made without updating the system accordingly, that creates risk at recertification.
How a Recertification Audit Differs From a Surveillance Audit
The key practical differences between a surveillance audit and a recertification audit come down to scope, duration, and consequence.
Surveillance audits are typically shorter in duration and cover a subset of the standard. Recertification audits are expected to cover the full standard. This means more audit days, more processes sampled, and more clauses examined. Your certification body will calculate the audit duration based on the size and complexity of your organisation, and recertification audits are generally longer than surveillance visits.
The consequence of a major nonconformity at a recertification audit is also more significant. At a surveillance audit, a major nonconformity typically triggers a follow up visit within a defined timeframe. At recertification, an unresolved major nonconformity can result in the certificate not being renewed, which has serious commercial implications for organisations that rely on certification for tendering or contractual purposes.
Preparing for a Recertification Audit
Good preparation for a recertification audit is not something you start three weeks before the audit date. It is something you do across the entire three year cycle. That said, there are specific actions that should be completed in the months leading up to the audit.
Conduct a Pre Recertification Internal Audit
Before the certification body arrives, conduct a thorough internal audit that covers the full scope of the standard. This is not the time for a light touch review. Go through every clause, every process, and every area of the business within scope. Treat it as a dress rehearsal for the recertification audit itself. Any gaps you find internally are far better discovered and addressed before the external auditor arrives.
Review Your Corrective Action Register
Pull together all open corrective actions and assess their status. Any corrective action that has been sitting open for an extended period without progress needs to be addressed urgently. Auditors will look at your corrective action records, and a backlog of unresolved actions sends a clear signal that the system is not being managed effectively.
Check Your Internal Audit Coverage
Review your internal audit records for the past three years and confirm that all clauses and processes have been covered. If there are gaps, schedule audits to address them before the recertification visit. Document the rationale for your audit programme and any adjustments made based on risk.
Prepare Your Objectives Data
Compile performance data against your objectives for the full three year period. Be ready to walk the auditor through trends, explain any periods of underperformance, and demonstrate what actions were taken in response. If objectives were revised during the cycle, have the documented rationale ready.
Brief Top Management
Top management will almost certainly be interviewed during a recertification audit. Brief them on what to expect, what evidence exists regarding their engagement with the system, and what the management review records show. Auditors ask direct questions about leadership commitment, and vague or uninformed answers from senior managers create a poor impression regardless of how well the rest of the system is performing.
Review Scope and Context
Confirm that your scope of certification still accurately reflects the organisation and its activities. If the business has changed significantly over three years, the scope documentation needs to reflect that. Also review your context of the organisation and interested parties analysis to confirm it remains current.
What Happens After the Recertification Audit
At the closing meeting, the auditor will present findings and a preliminary recommendation. If there are no major nonconformities, or if minor nonconformities have been raised and a corrective action plan is acceptable, the auditor will recommend renewal of the certificate. The certification body then conducts an internal review of the audit report before formally issuing the renewed certificate.
If a major nonconformity is raised, you will typically be given a defined period, often 90 days, to provide evidence of corrective action. The certification body will then assess whether the corrective action is adequate before making a final decision on renewal. In serious cases where multiple major nonconformities are raised or the system is fundamentally not functioning, the certification body may decide not to renew the certificate.
If your certificate expires before the recertification process is complete due to outstanding nonconformities, the organisation may need to go through the initial certification process again rather than a simple renewal. This is a significant outcome and one that is entirely avoidable with proper preparation.
Exemplar Global Recognised Training ProviderRTP No. 310970Common Mistakes That Cause Problems at Recertification
Having conducted hundreds of external audits across Australia and internationally, the same patterns emerge when organisations struggle at recertification. The most common issues are not dramatic system failures. They are the result of gradual drift over three years.
- Internal audits conducted but findings never properly closed out
- Management review records that are superficial or incomplete
- Objectives set at the beginning of the cycle and then forgotten
- Corrective actions closed on paper without verifying effectiveness
- Scope and context documentation that no longer reflects the real organisation
- Key personnel changes that have left the system without adequate ownership
- Procedures that have not been updated to reflect how work is actually done
None of these are difficult to fix if caught early. All of them become significant problems if they are only discovered when the certification body arrives.
Building Toward Recertification From Day One
The best approach to recertification is to treat it not as a three yearly event but as the natural conclusion of a well run management system. Organisations that maintain their systems properly throughout the cycle, conduct meaningful internal audits, drive genuine corrective action, and engage top management in regular reviews rarely struggle at recertification. Those that treat the system as a compliance exercise and only engage with it when an external auditor is coming consistently find themselves under pressure.
If you are responsible for managing an ISO certified system and want to build the internal audit skills to maintain it effectively, Audit Workshop offers practical internal auditor and lead auditor training across ISO 9001, ISO 14001, and ISO 45001. The training is built around real audit practice, not theory, and is designed for practitioners who need to apply what they learn immediately. You can explore the available courses at auditworkshop.com.













