ISO/IEC 17021 audit scheduling requirements: what the standard expects
ISO/IEC 17021 audit scheduling requirements explained: audit programme, competence, impartiality, team selection and records, met on every booking.
Key takeaways
- ISO/IEC 17021-1 doesn't mention software, but many of its requirements are met at the moment an audit is scheduled.
- The audit programme covers the full three-year cycle, with surveillance and recertification timing.
- Team selection must cover the competence the audit needs; technical experts work under an auditor's direction.
- Impartiality rules, such as excluding recent consultants, must be applied before allocation.
ISO/IEC 17021-1 audit scheduling requirements cover the audit programme over the certification cycle, the timing of surveillance and recertification audits, selecting an audit team with the right competence, safeguarding impartiality, and keeping records that show how each decision was made. Scheduling is where many of these requirements are met or broken.
Where scheduling meets the standard
ISO/IEC 17021-1 sets requirements for bodies that audit and certify management systems. It is written for certification bodies, not software vendors, and it never tells you how to schedule. But look at what it asks for, and a large share of it is decided at the moment an audit is booked: who goes, when, for how long and with what safeguards.
That makes scheduling one of the most assessed activities in a certification body, even if it is rarely called that. Accreditation assessors sample audit files and ask how the team was chosen and why the date was right.
Much of ISO/IEC 17021-1 is met, or broken, when an audit is booked.
The requirements that touch scheduling
- An audit programme for the full certification cycle, covering initial certification, surveillance and recertification.
- Surveillance at least once a calendar year outside recertification years, with the first within 12 months of the certification decision.
- Recertification completed in time for a decision before the certificate expires.
- An audit team whose combined competence meets the requirements for the audit, with a team leader.
- Technical experts working under the direction of an auditor, and trainees under supervision.
- Impartiality safeguards, including not using personnel who provided management-system consultancy to the client within the last two years.
- Records showing who was assigned, and on what basis.
How to meet them in practice
| Requirement | Scheduling rule | Evidence |
|---|---|---|
| Programme for the cycle | Plan all audits for three years when the certificate is issued | Programme record with dates and windows |
| Surveillance timing | Hold each audit's window as a hard rule | Audit dates inside windows |
| Team competence | Match competence per standard and technical area; form teams when needed | Allocation record with the competence used |
| Technical experts and trainees | Pair with a qualified auditor or team leader | Team composition in the audit plan |
| Impartiality | Exclude declared conflicts and recent consultancy relationships | Conflict check logged before allocation |
| Records | Log every allocation, change and override with a reason | Audit trail |
Impartiality, the easiest rule to break
Impartiality failures in scheduling are rarely deliberate. An auditor's declaration of a past consultancy relationship sits in an HR file; the planner doesn't see it; the booking goes ahead. Rotation limits set by schemes are remembered by one planner and forgotten by another.
The fix is to treat conflicts and rotation as data the scheduling engine reads, so an excluded auditor is never proposed and any override needs a named person and a recorded reason.
MythImpartiality is a quality-team matter, not a planning one.
RealityThe planner is the person who applies it, audit by audit. Rules need to live where allocations are made.
MythIf nobody raised a conflict, there wasn't one.
RealityDeclarations need to be checked at every allocation, not remembered.
A pre-booking compliance checklist
- ✓The audit sits inside its window in the programme.
- ✓The duration matches the days determined under IAF MD 5 or your procedure.
- ✓The team's combined competence covers every standard and technical area in scope.
- ✓A qualified team leader is assigned.
- ✓Technical experts and trainees are paired with an auditor.
- ✓No declared conflict or recent consultancy relationship exists with the client.
- ✓Scheme rotation limits are respected.
- ✓The allocation and any override are recorded with a reason.
Run manually, this checklist takes several minutes per audit and depends on the planner remembering to do it. Run by software, it takes milliseconds and happens every time.
Related IAF mandatory documents
IAF MD 5
Determines audit duration for quality, environmental and occupational health and safety systems. Scheduling honours the resulting days.
IAF MD 1
Governs sampling for multi-site organisations. See multi-site audit scheduling.
IAF MD 11
Covers audits of integrated management systems, which often need combined teams.
IAF MD 4
Covers the use of information and communication technology, including remote auditing.
Each of these affects the scheduling problem: how many days, which sites, which team and whether an auditor needs to travel at all. For competence in detail, see auditor competence verification.
For certification bodies, audit scheduling software that checks competence, rotation and windows on every audit takes most of this work off the planning team.
Does ISO/IEC 17021-1 require scheduling software?
No. It requires outcomes and evidence. Software helps by enforcing the rules on every booking and keeping the records assessors ask for.
What do assessors usually sample?
Audit files, with the programme, the team, the competence basis for each member and any changes. A clear audit trail answers most questions quickly.
ScheduleAI turns ISO/IEC 17021-1 requirements into scheduling rules: windows, competence per standard, team formation, impartiality checks and a full audit trail of every allocation and override.
Book a demo Estimate your savingsQuestions
What does ISO/IEC 17021-1 require for audit scheduling?
An audit programme for the cycle, surveillance and recertification timing, a competent audit team, impartiality safeguards and records of how assignments were made.
How often must surveillance audits happen?
At least once a calendar year outside recertification years, with the first within 12 months of the certification decision.
Can an auditor audit a client they consulted for?
Not within two years of providing management-system consultancy to that client, under ISO/IEC 17021-1 impartiality requirements.
How can we prove compliant scheduling at assessment?
Keep a record of each allocation with the competence used, the conflict check and any override with its reason.