Back to library Article · Jan 2026

Surveillance audit frequency and timing under ISO/IEC 17021-1

Surveillance audit frequency under ISO/IEC 17021-1: the calendar-year rule, the 12-month first surveillance limit, audit time and planning windows.

By Aman Hemchand, Head of AI TransformationStandardsPlanning practiceCompliance3 min readIn English

Key takeaways

  1. Surveillance audit frequency is at least once a calendar year, except in recertification years.
  2. The first surveillance audit must fall within 12 months of the certification decision date, not the stage 2 audit date.
  3. The calendar-year rule and the first and second year rule apply together, so both need checking when you move a date.
  4. IAF MD 5 sets surveillance time at about one third of the initial audit time per year.
Short answer

Under ISO/IEC 17021-1:2015, surveillance audits must take place at least once a calendar year, except in recertification years, and the first surveillance audit after initial certification must be no more than 12 months from the certification decision date. The audit programme includes surveillance in the first and second years after the decision, then recertification in the third year.

What is the required surveillance audit frequency?

The surveillance audit frequency for accredited management system certification is set by ISO/IEC 17021-1:2015. Clause 9.1.3.3 requires surveillance audits at least once a calendar year, except in recertification years. The date of the first surveillance audit after initial certification shall not be more than 12 months from the certification decision date.

Clause 9.1.3.2 sets the shape of the cycle: a two-stage initial audit, surveillance audits in the first and second years following the certification decision, and a recertification audit in the third year before certification expires. Sector schemes can add stricter rules, so check the scheme and the current issue of 17021-1 for each client.

The three-year certification cycle
  1. Initial auditStage 1 and stage 2
  2. Certification decisionStarts the cycle clock
  3. Surveillance 1Within 12 months of decision
  4. Surveillance 2Second year after decision
  5. RecertificationThird year, before expiry

When is the first surveillance audit due?

The anchor is the certification decision date. This is the most common planning error: counting 12 months from the last day of the stage 2 audit. If stage 2 ends on 20 January and the decision is taken on 15 March, the first surveillance is due by 15 March of the following year. Counting from stage 2 wastes almost two months of window. Counting from the certificate print date, if it differs from the decision, can push you past the limit.

Illustrative first surveillance window (decision 15 March 2026)
Typical planning band, months 9 to 121234
Decision, 15 Mar 202615 Mar 2027
  1. 1Certification decision
  2. 2Target date, mid-Dec 2026
  3. 3Client asks to postpone
  4. 412-month limit

A sensible target is a date near the anniversary, with a buffer before the limit. That buffer is what absorbs a client postponement, an auditor illness or a site shutdown. Plan to the limit and any slip becomes a late audit.

How do the calendar-year and cycle rules interact?

Two rules apply at once. The cycle rule places surveillance in the first and second years after the certification decision. The calendar-year rule needs at least one surveillance audit in every calendar year that is not a recertification year. A plan can pass one and fail the other.

Illustrative plans for a certification decision on 15 March 2026
PlanSurveillance 1Surveillance 2Result
AFeb 2027Feb 2028One audit in 2027 and 2028, both within the first and second years. Compliant.
BDec 2026Mar 2028No surveillance in calendar year 2027. Fails the calendar-year rule.
CFeb 2027Nov 2028Second surveillance falls in the third year after the decision. Fails the cycle rule.

Plan B is the usual trap. A client wants an early first surveillance to fit a quiet month, then the second slips into spring. Check both rules every time a date moves. Our guide to audit due date tracking shows how to hold these limits in a planning system.

How long should a surveillance audit be?

For QMS, EMS and OH&S, IAF MD 5:2023 says the total time spent on surveillance each year should be about one third of the initial certification audit time (stage 1 plus stage 2). The starting figure comes from the IAF MD 5 audit time calculation, so errors in the initial count carry through the cycle.

Annual surveillance time as about one third of initial QMS audit time (auditor days)
26 to 45 people (initial 4)about 1.3 days
176 to 275 people (initial 9)about 3 days
876 to 1,175 people (initial 13)about 4.3 days

Initial figures from Table QMS 1, IAF MD 5:2023, before any adjustment.

Surveillance audits are on-site audits, but ISO/IEC 17021-1 notes they are not necessarily full system audits. The programme must cover representative areas and functions on a regular basis. Clause 9.6.2.2 lists what every surveillance must include, such as internal audits and management review, action on previous nonconformities, complaints handling, progress on objectives and continual improvement, operational control, changes and use of marks.

What happens if a surveillance audit is missed?

ISO/IEC 17021-1 clause 9.6.5.1 requires the certification body to suspend certification when the certified client does not allow surveillance or recertification audits to be conducted at the required frequencies. When a client keeps postponing, the certificate itself is at stake.

Write this into your contract terms and your date request process. When a client asks for a date beyond the limit, the answer should be a date inside the window, with the consequence stated. For multi-site clients, the number of sites to visit each year also follows IAF MD 1 sampling, so a late surveillance can mean several late site visits.

MythThe first surveillance is due 12 months after stage 2.

RealityIt is due within 12 months of the certification decision date.

MythOnce a calendar year means any date in the year is fine.

RealityThe cycle rule also applies. Surveillance falls in the first and second years after the decision.

MythA remote audit does not count as surveillance.

RealityRemote techniques can form part of an audit under IAF MD 4 when planned and justified. See remote audits under IAF MD 4.

How to plan surveillance audit frequency across a programme

At programme level, surveillance audit frequency turns into a monthly demand curve. Clients certified in a busy month create a busy month every year after. Two habits help planners keep that under control.

  • ✓Store the certification decision date on every client, separate from audit dates
  • ✓Calculate the latest date for each surveillance from both rules
  • ✓Set a target date with a buffer of weeks before the latest date
  • ✓Request client dates early enough to rebook inside the window
  • ✓Flag any move that breaks the calendar-year or cycle rule before accepting it
  • ✓Review next year's monthly demand against auditor capacity each quarter

Spreading demand is legitimate within the window, for example pulling a surveillance a month earlier to fit a regional trip. Doing it deliberately, rather than audit by audit, is what audit programme planning is for.

See how ScheduleAI's audit scheduling software applies these rules across a whole programme in minutes.

How ScheduleAI handles this

ScheduleAI holds each client's audit window from the certification decision date and only proposes dates inside it, and its AI agents answer client date requests with options that keep the audit compliant, for planners to approve.

Book a demo Estimate your savings

Questions

How often are surveillance audits required?

At least once a calendar year, except in recertification years, under ISO/IEC 17021-1:2015 clause 9.1.3.3. Sector schemes may set stricter rules.

When is the first surveillance audit due?

No more than 12 months from the certification decision date. Count from the decision, not from the stage 2 audit or the certificate print date.

Can a surveillance audit be done early?

Yes, as long as the plan still meets both the calendar-year rule and the first and second year rule for the rest of the cycle.

How long is a surveillance audit?

For QMS, EMS and OH&S, IAF MD 5 sets annual surveillance time at about one third of the initial audit time. See what an audit man-day is for how days are counted.

What if the client refuses a surveillance date?

ISO/IEC 17021-1 requires suspension when a client does not allow surveillance or recertification audits at the required frequencies.

Is the recertification audit a surveillance audit?

No. Recertification replaces surveillance in the third year. See recertification audit timing.