Back to library Article · Apr 2026

Unannounced audit scheduling: keeping dates secret and fair

Unannounced audit scheduling across schemes: how to choose dates clients cannot predict, keep them secret inside your own team, and still meet every window.

By Aman Hemchand, Head of AI TransformationPlanning practiceFood safetyCompliance4 min readIn English
4 monthsBRCGS unannounced audit window
18 weeksIFS window: 16 before, 2 after due
5 yearsEU MDR: max gap, unannounced audits
Short answer

Unannounced audit scheduling means choosing a date inside the scheme's window, outside the site's blackout days, that the client cannot predict, and keeping it confidential inside the certification body. Good practice is to draw the date at random from the valid weeks, book a competent and impartial auditor early, hide the client name in shared calendars and keep a buffer to rebook before the due date.

Key takeaways

  1. A fair unannounced date is drawn from every valid week in the window, so clients cannot learn a pattern.
  2. The date should be known only to the people who need it, and shared calendars should show the auditor as busy with no client name.
  3. Competence, impartiality and rotation checks happen before allocation, because the client has no chance to object to the team.
  4. Keep a rebooking buffer before the due date for closures, refused entry and auditor illness.

What is unannounced audit scheduling?

Unannounced audit scheduling is the planning work behind audits where the client does not know the date: GFSI scheme unannounced audits, notified body audits under EU medical device rules, and short-notice audits under ISO/IEC 17021-1. The audit itself is the same work. The planning is different, because the date has to be both unpredictable and inside a fixed window, and it has to stay secret inside your own organisation.

Two things can go wrong. The date leaks, through a shared calendar, a hotel booking or a habit of always auditing in the first fortnight. Or the date is so late in the window that one cancellation pushes the audit past its due date.

What rules set the unannounced audit window?

Each scheme sets its own frequency, window and blackout rules. The main ones planners work with are below; check the current issue of each document before relying on a figure.

  • BRCGS (BRCGS079): at least one unannounced audit every 3 years, any time in the 4 months before the audit due date, with up to 10 non-audit days nominated by the site. The site is told the year, never the date. See BRCGS unannounced audits.
  • IFS Food: at least every third audit unannounced, in a window from 16 weeks before to 2 weeks after the due date, with blackout periods limited in number and length. See IFS unannounced audits.
  • FSSC 22000: at least one unannounced surveillance audit after initial certification and in each 3-year period, with blackout days agreed in advance. See FSSC 22000 unannounced audits.
  • EU MDR (Annex IX): the notified body randomly performs unannounced audits at least once every five years, and must not disclose its plan for them to the manufacturer.
  • ISO/IEC 17021-1: short-notice or unannounced audits for complaints, changes or suspended clients, under conditions published in advance.
Illustrative 4-month window before a due date: where the drawn date should sit
Valid weeks for the random draw1234
Window opensAudit due date
  1. 1Site blackout days
  2. 2Drawn date
  3. 3Rebooking buffer
  4. 4Due date

How do you pick a fair unannounced audit date?

Fair means two things: the client cannot predict it, and the certification body treats every client by the same rule. A written method does both, and it gives you something to show an assessor.

01

Build the valid set

List every week in the window, then remove blackout days, known shutdowns, non-production periods and the buffer weeks at the end.

02

Draw, then check

Pick a week at random from the valid set, then check auditor competence and availability. If no one is free, draw again instead of choosing the easiest week.

03

Avoid patterns

Across your client base, dates should spread through the whole window. If most land in the first month, clients will learn it.

04

Record the method

Keep the draw date, the valid set and who approved the result. Seasonal sites follow their production period; see seasonal production audit planning.

Who inside the certification body should know the date?

Secrecy fails inside the building more often than outside it. Limit the date to the planner, the auditor and whoever books travel, and let everyone else see only that the auditor is busy. The scene shows what each view should contain for the same audit.

Illustrative: one unannounced audit on Wednesday, as each person sees it
MonTueWedThuFriPlannerClient 31 unannouncedfull detail, access-controlledAuditor ATravelprivateAuditprivate eventShared team calendarAuditor A busyno client nameAuditor A busyno client nameClient portalNext audit: this yearno date shownNothing showndate hidden
  1. MonClient portalNext audit: this yearno date shown
  2. TueAuditor ATravelprivate
  3. TueShared team calendarAuditor A busyno client name
  4. WedPlannerClient 31 unannouncedfull detail, access-controlled
  5. WedAuditor AAuditprivate event
  6. WedShared team calendarAuditor A busyno client name
  7. WedClient portalNothing showndate hidden

✓The client and colleagues see the year or a busy block; only the planner and auditor see the date

Travel is the common leak: a hotel booked in the client's town under a client reference, or an invoice sent early. Book under an internal reference and keep the event private. Auditor calendar sync explains how to write private events to Outlook.

How do you choose the auditor for an unannounced audit?

With an announced audit, the client can object to a team member and the problem gets fixed before the day. With an unannounced audit that safety net is gone, and ISO/IEC 17021-1 asks for additional care in choosing the team for exactly that reason. Put these checks before allocation:

  1. Competence for every code and category in scope, including scheme-specific approval.
  2. Impartiality: no recent consultancy, employment or commercial link with the client. See conflict of interest checks.
  3. Rotation limits, which unannounced audits count towards like any other. See auditor rotation rules.
  4. A named backup auditor with the same competence, in case of illness close to the date.
  5. Travel that does not force an arrival time the site would notice as unusual.

Common myths about unannounced audits

These beliefs cause most of the problems planners describe.

MythUnannounced means any date at all.

RealityThe date must sit inside the scheme window and outside agreed blackout days. Random means random within the valid set.

MythThe auditor should find out the day before.

RealityThe auditor needs time to prepare and travel. Keep the date from the client and from colleagues; the auditor needs it.

MythAny free auditor will do.

RealityThe client cannot object, so competence, impartiality and rotation need extra checks.

MythLate in the window is safest because the site is ready.

RealityA late date leaves no room to rebook. Keep a buffer before the due date.

What happens when the auditor arrives and cannot audit?

A site may be closed, not producing the products in scope, or may refuse entry. The schemes treat refused entry seriously and can suspend or withdraw certification, so record the facts on the day and pass them to the certification decision process.

For the planner, the question is time. A genuine closure means rebooking inside what is left of the window, which is why the buffer matters. Track these cases: if one site keeps producing failed visits, review its blackout days and production information before the next draw. BRCGS audit due dates explains what happens when a window runs out.

Unannounced audit scheduling checklist

Run through this for every unannounced audit before the date is fixed.

  • ✓Frequency rule met for the cycle, and the audit type recorded as unannounced.
  • ✓Window dates calculated from the correct due date.
  • ✓Blackout days, shutdowns and production periods received and removed from the valid set.
  • ✓Date drawn at random from the valid weeks, with the method recorded.
  • ✓Auditor checked for competence, impartiality and rotation before allocation.
  • ✓Backup auditor named.
  • ✓Calendar events private, travel booked under an internal reference.
  • ✓Buffer of weeks left before the due date for rebooking.

ScheduleAI applies audit windows, blackout days, competence, conflicts of interest and rotation as scheduling constraints, and planners approve each unannounced date before it is fixed.

ScheduleAI is audit scheduling software built for testing, inspection and certification (TIC) organisations, with a planner approving every plan.

How ScheduleAI handles this

ScheduleAI treats audit windows, blackout days, competence, conflicts of interest and rotation as scheduling constraints for unannounced audits, and planners approve every date before it is fixed.

Book a demo Estimate your savings

Questions

What is unannounced audit scheduling?

Choosing an unpredictable date inside the scheme's window and outside blackout days, allocating a competent and impartial auditor, and keeping the date confidential until the audit.

Should unannounced dates be random?

Yes, within the valid weeks of the window. A written random method stops patterns clients can learn and shows every client is treated the same way.

Who should know an unannounced audit date?

The planner, the auditor and whoever books travel. Shared calendars should show the auditor as busy without the client name.

Can the client object to the auditor on an unannounced audit?

Not beforehand, which is why ISO/IEC 17021-1 asks for additional care when choosing the team for short-notice and unannounced audits.

How many blackout days can a site nominate?

It depends on the scheme. BRCGS allows up to 10 non-audit days; IFS and FSSC 22000 have their own rules. See IFS unannounced audits.

What if the site is closed when the auditor arrives?

Record the facts, pass them to the certification decision process and rebook inside the remaining window, using the buffer you kept.