Section 7.2: Accredited Certification Audits and the Certification Cycle (ISO/IEC 17021-1)

Key Takeaways

  • Third-party certification operates on a continuous 3-year cycle, comprising initial certification (Stage 1 and 2), annual surveillance audits, and a recertification audit.
  • The Stage 1 audit acts as a readiness review to evaluate documented information and system maturity before committing to the full on-site Stage 2 audit.
  • Surveillance audits are conducted at least annually, verifying that key elements like internal audits and management reviews remain functional.
  • Under IAF MD 1, multi-site organizations may utilize sampling, with the minimum sample size typically calculated as the square root of the total number of sites.
Last updated: July 2026

Section 7.2: Accredited Certification Audits and the Certification Cycle (ISO/IEC 17021-1)

Accredited certification of a Quality Management System (QMS) to ISO 9001:2015 is governed by international standards that ensure consistency, impartiality, and competence. The primary standard directing Certification Bodies (CBs) is ISO/IEC 17021-1:2015 (Conformity assessment — Requirements for bodies providing audit and certification of management systems). Lead Auditors conducting third-party certification audits must strictly adhere to the protocols established under this standard.


1. The 3-Year Certification Cycle

Third-party certification operates on a continuous three-year cycle. The cycle begins with the certification decision and ends three years later, provided the organization successfully maintains its QMS.

[Initial Certification] ──> [Year 1 Surveillance] ──> [Year 2 Surveillance] ──> [Year 3 Recertification]
  • Initial Certification: Divided into two distinct stages (Stage 1 and Stage 2).
  • Surveillance Audits: Conducted at least once a year in the first and second years following the certification decision. The first surveillance audit must take place within 12 months of the Stage 2 audit decision date.
  • Recertification Audit: Conducted in the third year, prior to the expiration of the certificate, to renew certification for another three years.

2. Initial Certification Audit: Stage 1 vs. Stage 2

The initial certification audit is a two-stage process designed to minimize risk and ensure that the Stage 2 audit is productive and focused.

Stage 1 Audit (Readiness Review)

The primary objective of Stage 1 is to determine the organization's readiness for the Stage 2 audit. It is typically a document review, though it may include an on-site visit.

  • Key Objectives:
    • Review the client's documented QMS information against ISO 9001:2015 requirements.
    • Evaluate the client's site-specific conditions and obtain information regarding the scope.
    • Verify if internal audits and management reviews are being planned and performed (a mandatory readiness requirement).
    • Assess the client's understanding of the standard's requirements, particularly concerning key performance or significant aspects and processes.
    • Agree on the details and logistics for the Stage 2 audit.
  • Output: A formal report identifying areas of concern that could be classified as nonconformities during Stage 2. No formal nonconformities are issued in Stage 1, but readiness gaps must be addressed before proceeding.

Stage 2 Audit (The Registration Audit)

The Stage 2 audit evaluates the implementation and effectiveness of the client's QMS. It must be performed on-site at the organization's facilities.

  • Key Objectives:
    • Gather audit evidence of conformity to all requirements of ISO 9001:2015.
    • Monitor process performance, measuring, reporting, and reviewing against key objectives.
    • Evaluate the organization's internal auditing, management review, and corrective action processes.
    • Verify statutory, regulatory, and contractual compliance.
    • Assess operational control of processes (Clause 8).
  • Output: The audit report, which includes a recommendation for or against certification. If any Major Nonconformities are identified, certification cannot be granted until the nonconformity is resolved, corrective action is verified, and the CB conducts a follow-up review. For Minor Nonconformities, certification may be recommended subject to the client submitting an acceptable corrective action plan (CAP).

3. Surveillance and Recertification

Once certified, the organization must demonstrate ongoing conformity.

Surveillance Audits

Surveillance audits are onsite audits but are not full-system audits. Instead, they sample specific parts of the QMS.

  • Mandatory Elements: Every surveillance audit must review:
    • Internal audits and management review (Clause 9.2 and 9.3).
    • Actions taken on nonconformities identified during the previous audit.
    • Complaint handling (Clause 8.2 and 9.1.2).
    • Effectiveness of the management system with regard to achieving objectives.
    • Progress of planned activities aimed at continual improvement.
    • Use of marks and/or any other reference to certification.

Recertification Audits

The recertification audit evaluates the continued conformity and effectiveness of the QMS as a whole.

  • Scope: Unlike surveillance audits, a recertification audit is a full-system audit that evaluates all ISO 9001:2015 clauses, processes, and sites.
  • Timing: It must be completed, and the certification decision made, before the current 3-year certificate expires. If it expires before the recertification decision, a gap in certification occurs, and the organization may be forced to undergo a full initial certification (Stage 1 and Stage 2) again.

4. Multi-site Sampling and Certification Rules (IAF MD 1)

Organizations with multiple locations may qualify for multi-site sampling under the International Accreditation Forum (IAF) Mandatory Document 1 (IAF MD 1).

  • Eligibility:
    • All sites must operate under a single, centrally controlled QMS.
    • Internal audits and management reviews must be managed centrally.
    • All sites must have a legal or contractual link to the central office.
  • Sampling Methodology:
    • For standard organizations, the CB can sample a subset of sites. The minimum sample size is typically the square root of the number of sites ($y = \sqrt{x}$), rounded up to the nearest whole number.
    • For high-risk operations or complex organizations, the sampling rate is increased.
    • The central office must be audited during every initial, surveillance, and recertification audit.

5. Certification Status Actions

The Certification Body has the authority to change the status of an organization's certification based on audit findings or administrative issues.

  • Suspension: Temporarily invalidating certification (typically up to 6 months) due to failure to resolve major nonconformities, failure to allow surveillance audits, or misuse of certification logos.
  • Withdrawal: Terminating certification entirely. The organization must remove all references to certification. Re-entry requires a full initial audit.
  • Reduction of Scope: Excluding product lines or sites where the QMS consistently fails to meet requirements.

6. Real-World Scenario: Transitioning from Stage 1 to Stage 2

A manufacturing firm scheduled their Stage 1 audit for June 1st and Stage 2 for July 15th. During the Stage 1 document review, the lead auditor discovered that the firm had not conducted a full cycle of internal audits (violating ISO 9001 Clause 9.2) and had not held a management review (violating Clause 9.3) utilizing the output of those audits.

The lead auditor documented this as an 'area of concern' in the Stage 1 report and advised that proceeding to Stage 2 on July 15th would result in an automatic Major Nonconformity, preventing certification. The organization deferred the Stage 2 audit by two months, enabling them to complete the internal audits, conduct the management review, and implement corrective actions. Because of the Stage 1 warning, they successfully passed their rescheduled Stage 2 audit with only two minor nonconformities.

This scenario highlights the value of the Stage 1 readiness check, which serves as a gateway to verify that the core structural elements of the QMS are functioning before dedicating the resources required for a comprehensive Stage 2 audit.

Test Your Knowledge

An organization successfully passes its Stage 2 certification audit and is issued an ISO 9001:2015 certificate on September 15, 2026. What is the latest acceptable date for the Certification Body to conduct the first surveillance audit?

A
B
C
D
Test Your Knowledge

During a Stage 1 audit of a service organization, the lead auditor finds that the organization has documented its procedures but has not yet performed any internal audits or management reviews. How should the auditor proceed?

A
B
C
D
Test Your Knowledge

An organization has 25 retail distribution centers operating under a single centralized QMS. Under IAF MD 1, what is the minimum number of sites that the Certification Body must sample and audit during the initial certification audit?

A
B
C
D
Congratulations!

You've completed this section

Continue exploring other exams