8.3 Certification Cycles & Audit Types under ISO/IEC 17021-1

Key Takeaways

  • Audits are classified by organizational relationship: 1st Party (internal), 2nd Party (supplier/contractor by customer), and 3rd Party (independent certification and accreditation).
  • Combined audits evaluate two or more management systems (e.g., ISO 45001 and ISO 14001) simultaneously under one lead auditor, whereas joint audits involve two or more auditing bodies collaborating to audit a single auditee.
  • Under ISO/IEC 17021-1:2015, initial certification requires a two-stage process: Stage 1 evaluates documentation and site readiness, while Stage 2 assesses full on-site implementation and effectiveness.
  • The accredited certification lifecycle spans three years, requiring Surveillance Audits in Years 1 and 2—with the first surveillance audit strictly mandated within 12 months of the certification decision—and Recertification before expiration.
  • Special audits may be initiated at short notice or unannounced to investigate major workplace fatalities, serious safety complaints, significant facility changes, or to follow up on suspended certificates.
Last updated: September 2026

8.3 Certification Cycles & Audit Types under ISO/IEC 17021-1

Lead Auditor Core Concept: Third-party management system certification is governed internationally by ISO/IEC 17021-1:2015. A Lead Auditor must distinguish between internal, supplier, and certification audits, and master the three-year lifecycle—especially the operational boundaries between Stage 1 readiness reviews and Stage 2 on-site conformity assessments.


1. Taxonomy of Management System Audits

Audits are categorized by the organizational relationship between auditor, auditee, and client:

1st Party Audits (Internal Audits)

Conducted by or on behalf of the organization for internal purposes: self-assessment, verifying conformity, evaluating effectiveness, and providing inputs to Top Management Review (Clause 9.2). Generates internal corrective action requests (CARs) and continual improvement initiatives.

2nd Party Audits (Supplier & Contractor Audits)

Conducted by interested parties, such as customers or enterprises auditing outsourced suppliers and on-site contractors. Evaluates supply chain compliance, verifies contractor safety capabilities (Clause 8.1.4), and establishes approved vendor ratings.

3rd Party Audits (Certification & Accreditation Audits)

Conducted by independent Certification Bodies accredited by national Accreditation Bodies under the International Accreditation Forum (IAF). Evaluates conformity against consensus standards like ISO 45001:2018 to grant, maintain, renew, suspend, or withdraw accredited certification. Statutory safety inspectorates also conduct 3rd party audits.

Combined Audits vs. Joint Audits

  • Combined Audit: A single audit team evaluates two or more management system standards simultaneously (e.g., ISO 9001 and ISO 45001) for one auditee, reducing duplication and audit fatigue.
  • Joint Audit: Two or more separate auditing organizations collaborate to audit a single auditee (e.g., a registrar and a statutory safety regulator auditing together).

2. The ISO/IEC 17021-1 Three-Year Certification Lifecycle

Accredited certification operates on a three-year cycle comprising Initial Certification (Stage 1 and Stage 2), Year 1 Surveillance, Year 2 Surveillance, and Recertification.

Phase 1: Initial Certification Audit (Two-Stage Process)

ISO/IEC 17021-1 Clause 9.3 mandates a two-stage initial audit:

Stage 1 Audit: Readiness Review

  • Purpose: Assess readiness for Stage 2, review documented information, evaluate site conditions, and confirm understanding of requirements.
  • Key Verifications: OH&S policy, organizational context (Clause 4), scope boundaries, hazard identification methods, legal registers, worker consultation mechanisms (Clause 5.4), and verification that internal audits (9.2) and management review (9.3) are completed.
  • Site Requirement: For OH&S, Stage 1 should include on-site walkthroughs to evaluate physical hazards and facility layouts.
  • Critical Restriction: Certification CANNOT be granted or recommended at Stage 1. The deliverable is a Stage 1 report identifying "areas of concern." Organizations typically have 30–90 days (maximum 6 months per IAF rules) to resolve concerns before Stage 2.

Stage 2 Audit: On-Site Conformity Assessment

  • Purpose: Evaluate complete implementation, operational effectiveness, and legal compliance across all operating shifts and facilities.
  • Key Verifications: Operational controls and hierarchy of controls (8.1.2), emergency drills (8.2), worker competence (7.2), contractor controls (8.1.4), compliance evaluations (9.1.2), incident investigations (10.2), and worker interviews.
  • Outcome: Findings categorized as Major Nonconformities, Minor Nonconformities, or Opportunities for Improvement (OFIs). The lead auditor recommends certification status.
  • Governance Rule: The audit team does not grant certification; the decision is made independently by an authorized technical reviewer or committee within the certification body.

Phase 2: Surveillance Audits (Years 1 and 2)

Surveillance audits occur at least once per calendar year:

  • Strict 12-Month Rule: Surveillance Year 1 must occur within 12 months of the initial certification decision date (ISO/IEC 17021-1 Clause 9.1.3.3). Exceeding this deadline risks certificate suspension.
  • Scope: Sampled operational areas and mandatory core elements: internal audits, management reviews, actions on previous nonconformities, complaints, legal compliance, and use of certification marks.

Phase 3: Recertification Audit (Year 3)

  • Timing: Completed before certificate expiration to ensure continuous validity.
  • Scope: Full reassessment of the entire management system, equivalent to Stage 2, evaluating historical performance, continual improvement, and objective achievement across the full three-year cycle.

3. Special Audits, Sanctions & Certificate Transfers

  • Short-Notice / Unannounced Audits (Clause 9.5.2): Conducted to investigate fatalities, toxic releases, serious complaints, significant restructuring, or to verify remediation of suspended status.
  • Suspension vs. Withdrawal: Suspension is a temporary sanction (maximum 6 months) for unclosed Major Nonconformities, missed surveillance deadlines, or mark misuse. Certified status cannot be claimed during suspension. Withdrawal permanently cancels certification if deficiencies remain uncorrected.
  • Certificate Transfer (IAF MD 2): Transfers valid, accredited, unsuspended certificates between bodies following a pre-transfer review of audit histories and closure of major nonconformities.

4. Comparative Matrix: Certification Audit Parameters

Audit TypeGoverning ClausePrimary ObjectivePhysical Site Tour Required?Can Grant Certification?
Stage 1 (Readiness)ISO/IEC 17021-1 (9.3.1.2)Review documentation, evaluate site layout, verify internal audits and MRYes, strongly recommended for OH&S hazardsNO. Only identifies areas of concern
Stage 2 (Conformity)ISO/IEC 17021-1 (9.3.1.3)Comprehensive assessment of implementation, controls, and complianceMANDATORY. Across all shifts and processesNO. Recommends; decision is independent
Surveillance (Y1/Y2)ISO/IEC 17021-1 (9.1.3.3)Sampled verification of system maintenance and mandatory core clausesMANDATORY. Targeted operational samplingNO. Recommends maintaining validity
RecertificationISO/IEC 17021-1 (9.6)Full system reassessment and 3-year performance review for renewalMANDATORY. Comprehensive facility evaluationNO. Recommends 3-year renewal
Special / Short-NoticeISO/IEC 17021-1 (9.5.2)Investigate fatalities, serious complaints, or verify suspension closeoutsMANDATORY. Focused on incident/deficiencyNO. Recommends lifting or withdrawing

5. Real-World Audit Scenario: Managing Stage 1 Deficiencies

Audit Context: A Lead Auditor conducts a Stage 1 audit of a ship-breaking yard seeking ISO 45001 certification.

Audit Findings:

  1. The yard drafted procedures, but internal audits (9.2) and management review (9.3) have never been conducted.
  2. The client requests proceeding directly to Stage 2 in two weeks, promising to perform internal audits in the interim.
  3. During the site walkthrough, workers are observed torch-cutting ship bulkheads in enclosed fuel tanks without ventilation or gas detection.

Lead Auditor Evaluation & Required Actions:

  • The auditor must issue a Stage 1 report stating the client is NOT ready for Stage 2. Under ISO/IEC 17021-1 Clause 9.3.1.2.2, internal audits and management reviews must be completed prior to Stage 2.
  • The dangerous confined space conditions constitute severe areas of concern that would trigger immediate Major Nonconformities in Stage 2. The auditor advises postponing Stage 2 by 60–90 days to execute governance reviews and implement operational controls under Clause 8.1.2.

6. Common Exam Traps & Candidate Pitfalls

  • Lead Auditor Decision Fallacy: Believing the audit team grants certification. The team only recommends; an independent technical reviewer or panel makes the decision.
  • Stage 1 Certification Trap: Believing certification can be awarded at Stage 1 if documentation is perfect. Certification requires Stage 2 on-site operational verification.
  • Surveillance Timing Error: Assuming Surveillance Year 1 can occur anytime in the second year. It must occur within 12 months of the initial certification decision date.
  • Combined vs. Joint Confusion: A combined audit is one team auditing multiple standards; a joint audit is multiple audit organizations auditing one client.
Loading diagram...
ISO/IEC 17021-1:2015 Three-Year Accredited Certification Lifecycle
Test Your Knowledge

Under ISO/IEC 17021-1:2015, what is the primary objective of a Stage 1 initial certification audit for an OH&S management system?

A
B
C
D
Test Your Knowledge

An organization receives initial ISO 45001 certification on October 15, 2024. According to ISO/IEC 17021-1:2015, what is the mandatory deadline by which the first surveillance audit (Surveillance Year 1) must be conducted?

A
B
C
D
Test Your Knowledge

Under what circumstance is an accredited certification body mandated by ISO/IEC 17021-1:2015 to consider conducting a short-notice or unannounced special audit of a certified organization?

A
B
C
D