Back to library Guide · Sep 2026

3-year audit programme: how to plan the certification cycle

3-year audit programme planning for certification bodies: turn each client's 3-year cycle into a levelled annual plan your auditors can deliver on time.

By Aman Hemchand, Head of AI TransformationPlanning practiceStandardsOperations4 min readIn English
3 yearscertification cycle, ISO/IEC 17021-1
Short answer

3-year audit programme planning is laying out every audit in a client's 3-year certification cycle (two-stage initial audit, two surveillance audits, recertification), then combining all client programmes into one annual plan. ISO/IEC 17021-1 fixes the skeleton. Planners set a target date inside each window, spread process and site coverage across the cycle and level monthly demand against auditor capacity by technical area.

Key takeaways

  1. Build each client's programme from the certification decision date and the expiry date, with a target date and a latest date for every audit.
  2. Decide at the start of the cycle which processes, sites and shifts each surveillance covers, so recertification is not the first full look.
  3. Add all programmes together to see monthly demand in auditor days by technical area, then pull audits earlier inside their windows to flatten peaks.
  4. Work in horizons: a 3-year skeleton, a 12-month allocated plan and a short confirmed period that only changes by exception.

What is 3-year audit programme planning?

3-year audit programme planning covers two jobs. The first is the programme for one client: every audit needed across a full certification cycle, with its timing, duration, scope and team. ISO/IEC 17021-1:2015 (clause 9.1.3) requires a certification body to develop this programme for the full cycle. The second is the body's annual plan: all client programmes added together and set against the auditors you actually have.

Most planning pain comes from treating the two separately. A client programme that ignores capacity creates the same February spike every year. An annual plan built audit by audit, with no programme behind it, drifts a few weeks later each year until audits start to land outside their windows. This guide covers both levels and how they connect. For the mechanics of allocating a single year in one pass, see planning a year of audits in one pass.

What does a 3-year audit programme contain?

Clause 9.1.3.2 sets the skeleton: a two-stage initial audit, surveillance audits in the first and second years after the certification decision, and a recertification audit in the third year before expiry. Surveillance must happen at least once a calendar year outside recertification years, and the first one no more than 12 months after the decision. A note in the standard allows a sector scheme to set a different cycle length, so check the scheme and the current issue of each document.

Illustrative programme: QMS client, 200 people, one site, certification decision 15 March 2026
AuditTiming ruleTargetAudit timeCoverage focus
Stage 1 and stage 2Before the certification decisionJan to Feb 20269 auditor days in total (IAF MD 5 table)Whole system
Surveillance 1Within 12 months of the decisionFeb 2027About 3 daysProduction, purchasing, night shift, previous findings
Surveillance 2Second year after the decision, in calendar year 2028Feb 2028About 3 daysDesign, dispatch, warehouse, complaints
RecertificationAudit, corrective actions and decision before expiryDec 2028 to Jan 2029About 6 days, recalculatedWhole system and performance over the cycle

Two details make the table work. Audit time comes from IAF MD 5: surveillance is about one third of initial audit time each year, and recertification about two thirds of an initial figure recalculated on current client data. And the coverage column is decided at planning time rather than left to the auditor on the day. Surveillance audits need not be full system audits, but the programme must cover representative areas and functions over the cycle, and clause 9.1.3.5 asks for shift work to be considered.

How do you set target dates inside each audit window?

Every audit in the programme needs more than one date. The latest date is fixed by the rules. The target date is where you plan to hold it. The gap between the two is your recovery time when a client postpones or an auditor falls ill, so it should be at least as long as it takes your team to rebook an audit.

01

Latest date

The hard limit: 12 months from the decision for the first surveillance, the calendar-year and cycle rules for the second, and expiry less the time to close major nonconformities for recertification. See surveillance audit frequency.

02

Target date

Usually close to the anniversary of the previous audit. Holding the anniversary stops the slow drift that pushes a programme later each year.

03

Earliest sensible date

How far you can pull an audit forward to level workload without breaking the calendar-year rule or shortening the gap between audits so much that there is little new to audit.

04

Client constraints

Shutdowns, seasonal peaks and shift patterns captured once, at programme level, so every future date respects them.

For recertification, work back from expiry. The audit, verification of corrections and corrective actions for any major nonconformity and the decision must all be complete before the certificate expires, so the target sits months ahead of expiry. Recertification audit timing covers the consequences of cutting it fine.

How do you turn client programmes into an annual audit plan?

Add every target date together and you get demand: auditor days per month. Break it down by standard, IAF code or technical area and region, because capacity is not interchangeable. A flat total can hide a spike in one scarce code, such as construction or food, where only three auditors are qualified.

Initial certifications tend to cluster, and each cluster repeats every year of the cycle. The main levelling tool is pulling audits earlier inside their windows. You can move a March surveillance to January if the rules still hold, but you cannot push it past its latest date. Do this deliberately across the whole plan and test several versions before you commit. Auditor capacity planning covers the supply side of the same sum.

49,000audit-hours scheduled in 12 minutesAENOR, 800 auditors in 12 countries; previously about a month of planning

When a full year can be rebuilt in minutes, levelling becomes something planners try several ways before choosing. ScheduleAI works this way: the whole programme is allocated in one run, and planners review and approve the result.

What does a levelled plan look like week to week?

Once audits have target weeks and provisional teams, the plan becomes a set of auditor diaries. This is where programme decisions show up as practical problems: a recertification sitting close to its latest date, a lead auditor visiting the same client again, a trainee who needs a witnessed audit.

Illustrative week in a levelled plan
MonTueWedThuFriAuditor AClient 12 surveillanceDay 1 of 2Client 12 surveillanceDay 2 of 2Client 31 recertification3 weeks before latest dateAuditor BClient 7 stage 2Lead auditorClient 7 stage 2Lead auditorClient 44 surveillanceSame region as client 7Client 19 surveillanceWould breach scheme rotation limitAuditor CClient 22 surveillancePulled 4 weeks early to level MarchClient 8 site 3Sampled site, multi-site clientAuditor D (trainee)Client 12 surveillanceWitnessed, outside audit timeClient 12 surveillanceWitnessed, outside audit time
  1. MonAuditor AClient 12 surveillanceDay 1 of 2
  2. MonAuditor BClient 7 stage 2Lead auditor
  3. MonAuditor D (trainee)Client 12 surveillanceWitnessed, outside audit time
  4. TueAuditor AClient 12 surveillanceDay 2 of 2
  5. TueAuditor BClient 7 stage 2Lead auditor
  6. TueAuditor D (trainee)Client 12 surveillanceWitnessed, outside audit time
  7. WedAuditor BClient 44 surveillanceSame region as client 7
  8. WedAuditor CClient 22 surveillancePulled 4 weeks early to level March
  9. ThuAuditor AClient 31 recertification3 weeks before latest date
  10. ThuAuditor CClient 8 site 3Sampled site, multi-site client
  11. FriAuditor BClient 19 surveillanceWould breach scheme rotation limit

✓Two items to resolve before dates go to clients: one rotation breach, one recertification with too little buffer

The rotation flag needs a different auditor before the date is offered; auditor rotation rules explain where the limits come from. The late recertification should move earlier or get a named backup auditor now, while there is still room. Trainee time does not count toward audit time, so it sits on top of a fully competent team.

When should each part of the plan be fixed?

A programme works best in horizons. Far-off audits stay flexible and cheap to change. Near audits are fixed so clients, auditors and travel can rely on them. The dates below are sensible starting points to adjust to your own rebooking times. No standard sets them.

  1. At the decisionProgramme skeletonWindows, audit time and coverage for each year of the cycle
  2. 12 to 15 months aheadAnnual allocationEvery audit given a target week and a provisional team
  3. 3 to 6 months aheadClient datesDates inside the window offered to and agreed with the client
  4. 4 to 8 weeks aheadConfirmationAudit plan and team names sent, so the client can object in time
  5. 2 weeks aheadFreezeChanges only by exception, with a named approver
  6. After each auditProgramme reviewNext audit's time, scope and team adjusted from findings and changes

ISO/IEC 17021-1 requires audit dates to be agreed with the client in advance and team names to be provided early enough for the client to object. It sets no fixed number of days. Audit scheduling lead time looks at how far ahead each step should happen.

What changes an audit programme mid-cycle?

A programme is reviewed after every audit. The standard's notes list complaints, changes to the client or its system, combined or integrated audits and changes to requirements as things to take into account. In practice these events force a replan:

Mid-cycle events and what they change in the programme
EventWhat changes
Headcount or site changeAudit time for the next audit, and the site sample for multi-site clients
Scope extensionA special audit or extra time at the next surveillance, and possibly new technical areas for the team
Second standard addedA choice to align cycles now or at recertification; see integrated audit scheduling
Major nonconformityFollow-up verification, and more focus on that process next time
Transfer from another bodyA programme built from the previous body's cycle dates and reports

3-year audit programme planning checklist

Use this list when setting up a new client and when reviewing next year's plan.

  • ✓Store the certification decision date and expiry date on every client, separate from audit dates
  • ✓Calculate a latest date and a target date for every audit in the cycle
  • ✓Plan coverage of processes, sites and shifts across both surveillance audits
  • ✓Recalculate audit time from current client data before each recertification
  • ✓Sum demand by month and by technical area as well as in total auditor days
  • ✓Level peaks by pulling audits earlier inside their windows
  • ✓Allocate the next 12 months and confirm the next quarter
  • ✓Review the programme after every audit and record why it changed

For certification bodies, audit scheduling software that checks competence, rotation and windows on every audit takes most of this work off the planning team.

How ScheduleAI handles this

ScheduleAI builds each client's programme from its certification decision and expiry dates, then allocates the whole year in one run against 35+ scheduling parameters, including competence codes, rotation and audit windows, for planners to review and approve.

Book a demo Estimate your savings

Questions

What is an audit programme under ISO/IEC 17021-1?

The planned set of audits for a client across the full certification cycle: a two-stage initial audit, surveillance audits in the first and second years after the certification decision and a recertification audit in the third year before expiry.

Who is responsible for 3-year audit programme planning?

The certification body. It develops the programme for each client, reviews it after each audit and agrees audit dates with the client in advance.

Can surveillance audits be moved to smooth workload?

Yes, within the rules. Moving a surveillance earlier is usually safe if the calendar-year rule and the first and second year rule still hold across the rest of the cycle.

How far ahead should the annual audit plan be built?

Allocating the next 12 months, with the next quarter confirmed, gives time to level demand and recover from changes. See audit scheduling lead time.

Does the audit programme change after each audit?

It should be reviewed after each audit. Findings, complaints, changes to the client and changes to requirements can alter the next audit's time, scope or team.

How long is each audit in the programme?

For QMS, EMS and OH&S, IAF MD 5 sets surveillance at about one third of initial audit time per year and recertification at about two thirds of a recalculated initial figure.