Surveillance audit frequency and timing under ISO/IEC 17021-1
Surveillance audit frequency under ISO/IEC 17021-1: the calendar-year rule, the 12-month first surveillance limit, audit time and planning windows.
Key takeaways
- Surveillance audit frequency is at least once a calendar year, except in recertification years.
- The first surveillance audit must fall within 12 months of the certification decision date, not the stage 2 audit date.
- The calendar-year rule and the first and second year rule apply together, so both need checking when you move a date.
- IAF MD 5 sets surveillance time at about one third of the initial audit time per year.
Under ISO/IEC 17021-1:2015, surveillance audits must take place at least once a calendar year, except in recertification years, and the first surveillance audit after initial certification must be no more than 12 months from the certification decision date. The audit programme includes surveillance in the first and second years after the decision, then recertification in the third year.
What is the required surveillance audit frequency?
The surveillance audit frequency for accredited management system certification is set by ISO/IEC 17021-1:2015. Clause 9.1.3.3 requires surveillance audits at least once a calendar year, except in recertification years. The date of the first surveillance audit after initial certification shall not be more than 12 months from the certification decision date.
Clause 9.1.3.2 sets the shape of the cycle: a two-stage initial audit, surveillance audits in the first and second years following the certification decision, and a recertification audit in the third year before certification expires. Sector schemes can add stricter rules, so check the scheme and the current issue of 17021-1 for each client.
- Initial auditStage 1 and stage 2
- Certification decisionStarts the cycle clock
- Surveillance 1Within 12 months of decision
- Surveillance 2Second year after decision
- RecertificationThird year, before expiry
When is the first surveillance audit due?
The anchor is the certification decision date. This is the most common planning error: counting 12 months from the last day of the stage 2 audit. If stage 2 ends on 20 January and the decision is taken on 15 March, the first surveillance is due by 15 March of the following year. Counting from stage 2 wastes almost two months of window. Counting from the certificate print date, if it differs from the decision, can push you past the limit.
- 1Certification decision
- 2Target date, mid-Dec 2026
- 3Client asks to postpone
- 412-month limit
A sensible target is a date near the anniversary, with a buffer before the limit. That buffer is what absorbs a client postponement, an auditor illness or a site shutdown. Plan to the limit and any slip becomes a late audit.
How do the calendar-year and cycle rules interact?
Two rules apply at once. The cycle rule places surveillance in the first and second years after the certification decision. The calendar-year rule needs at least one surveillance audit in every calendar year that is not a recertification year. A plan can pass one and fail the other.
| Plan | Surveillance 1 | Surveillance 2 | Result |
|---|---|---|---|
| A | Feb 2027 | Feb 2028 | One audit in 2027 and 2028, both within the first and second years. Compliant. |
| B | Dec 2026 | Mar 2028 | No surveillance in calendar year 2027. Fails the calendar-year rule. |
| C | Feb 2027 | Nov 2028 | Second surveillance falls in the third year after the decision. Fails the cycle rule. |
Plan B is the usual trap. A client wants an early first surveillance to fit a quiet month, then the second slips into spring. Check both rules every time a date moves. Our guide to audit due date tracking shows how to hold these limits in a planning system.
How long should a surveillance audit be?
For QMS, EMS and OH&S, IAF MD 5:2023 says the total time spent on surveillance each year should be about one third of the initial certification audit time (stage 1 plus stage 2). The starting figure comes from the IAF MD 5 audit time calculation, so errors in the initial count carry through the cycle.
Initial figures from Table QMS 1, IAF MD 5:2023, before any adjustment.
Surveillance audits are on-site audits, but ISO/IEC 17021-1 notes they are not necessarily full system audits. The programme must cover representative areas and functions on a regular basis. Clause 9.6.2.2 lists what every surveillance must include, such as internal audits and management review, action on previous nonconformities, complaints handling, progress on objectives and continual improvement, operational control, changes and use of marks.
What happens if a surveillance audit is missed?
ISO/IEC 17021-1 clause 9.6.5.1 requires the certification body to suspend certification when the certified client does not allow surveillance or recertification audits to be conducted at the required frequencies. When a client keeps postponing, the certificate itself is at stake.
Write this into your contract terms and your date request process. When a client asks for a date beyond the limit, the answer should be a date inside the window, with the consequence stated. For multi-site clients, the number of sites to visit each year also follows IAF MD 1 sampling, so a late surveillance can mean several late site visits.
MythThe first surveillance is due 12 months after stage 2.
RealityIt is due within 12 months of the certification decision date.
MythOnce a calendar year means any date in the year is fine.
RealityThe cycle rule also applies. Surveillance falls in the first and second years after the decision.
MythA remote audit does not count as surveillance.
RealityRemote techniques can form part of an audit under IAF MD 4 when planned and justified. See remote audits under IAF MD 4.
How to plan surveillance audit frequency across a programme
At programme level, surveillance audit frequency turns into a monthly demand curve. Clients certified in a busy month create a busy month every year after. Two habits help planners keep that under control.
- ✓Store the certification decision date on every client, separate from audit dates
- ✓Calculate the latest date for each surveillance from both rules
- ✓Set a target date with a buffer of weeks before the latest date
- ✓Request client dates early enough to rebook inside the window
- ✓Flag any move that breaks the calendar-year or cycle rule before accepting it
- ✓Review next year's monthly demand against auditor capacity each quarter
Spreading demand is legitimate within the window, for example pulling a surveillance a month earlier to fit a regional trip. Doing it deliberately, rather than audit by audit, is what audit programme planning is for.
See how ScheduleAI's audit scheduling software applies these rules across a whole programme in minutes.
ScheduleAI holds each client's audit window from the certification decision date and only proposes dates inside it, and its AI agents answer client date requests with options that keep the audit compliant, for planners to approve.
Book a demo Estimate your savingsQuestions
How often are surveillance audits required?
At least once a calendar year, except in recertification years, under ISO/IEC 17021-1:2015 clause 9.1.3.3. Sector schemes may set stricter rules.
When is the first surveillance audit due?
No more than 12 months from the certification decision date. Count from the decision, not from the stage 2 audit or the certificate print date.
Can a surveillance audit be done early?
Yes, as long as the plan still meets both the calendar-year rule and the first and second year rule for the rest of the cycle.
How long is a surveillance audit?
For QMS, EMS and OH&S, IAF MD 5 sets annual surveillance time at about one third of the initial audit time. See what an audit man-day is for how days are counted.
What if the client refuses a surveillance date?
ISO/IEC 17021-1 requires suspension when a client does not allow surveillance or recertification audits at the required frequencies.
Is the recertification audit a surveillance audit?
No. Recertification replaces surveillance in the third year. See recertification audit timing.