Certification process
Surveillance & recertification
A certificate is valid for three years, but it is not unconditional for three years. Here is what keeps it live, and the two deadlines that most often put one at risk.
The three-year cycle
What happens, and when
Surveillance audits are shorter than the certification audit but they are not lighter. They sample different parts of your scope each year so the full scope is covered across the cycle.
- 01
Certification (Month 0)
Year 0
Initial certificate issued for a three-year cycle following a successful Stage 2 audit and independent certification decision.
- 02
Surveillance 1 (Month 12)
Year 1
First surveillance audit, conducted within twelve months of the certification decision date. Covers internal audit, management review, complaints, corrective action, mark usage, changes to the system, and a sample of the scope.
- 03
Surveillance 2 (Month 24)
Year 2
Second surveillance audit, sampling different areas of the scope so that the full scope is covered across the cycle.
- 04
Recertification (Month 33–36)
Year 3
A full-scope recertification audit conducted before certificate expiry, evaluating the continued effectiveness of the whole system and its performance across the cycle.
Three things worth knowing
The rules that catch organisations out
None of these are our policy choices. They come from accreditation requirements, which is precisely why we cannot make an exception when the date is missed.
The first surveillance audit must take place within twelve months of the certification decision date — not twelve months from the audit or from the certificate print date. Missing that window puts the certificate at risk of suspension, and the rule is set by accreditation requirements rather than by us.
Recertification must be completed before the certificate expires. If it is not, the certificate lapses and the next audit is a full initial certification, not a recertification — which costs more and takes longer.
You must notify us of significant changes: to the scope, the legal entity, the sites, the management system, the top management, or the activities covered. Some changes require a special audit; most do not, but the decision is ours to make on the facts.
Your obligation
Changes you must tell us about
Certified clients are contractually required to notify significant changes. Most do not require a special audit — but that determination is ours to make on the facts, and we cannot make it if we do not know.
Scope of certification
New activities, products or services you want covered, or activities you have ceased. Extensions require an audit; reductions require a decision.
Legal entity or ownership
A change of legal name, a merger, an acquisition or a restructure. The certificate is issued to a legal entity, and that entity must still exist.
Sites and locations
New sites brought into scope, sites closed, or a relocation. Multi-site sampling plans are built from your site list and have to be rebuilt when it changes.
Top management or the system itself
Significant changes to top management, to the management system, or to the processes the certificate covers.
If a certificate lapses
A certificate that expires before recertification is complete cannot be renewed retrospectively. The next audit becomes a full initial certification rather than a recertification — more audit days, more cost, and a gap in your certification history that customers and tendering authorities can see. We send renewal reminders well ahead of the date, but the obligation to maintain the certificate sits with the certified organisation.
Transferring to us?
Mid-cycle transfers are straightforward
If your certificate is accredited and in good standing, transferring under IAF MD 2 does not restart the cycle or require a full initial audit. We pick it up where your current body left off.