Certification Ongoing Support

Have you achieved your Certification to one or more ISO Management System Standards, but are not sure what’s required to maintain it?

Book in a FREE Strategy Session to find out how we can take the pressure off you by helping with the ongoing activities!

What’s involved in maintaining Certification to an ISO Management System Standard?

Once Certification is achieved, the 3-year cycle starts. This means that every year your Certifier will come back to audit again and check in if your system is still up to date and all ongoing activities required are completed and documented.

Throughout this process, we can help you to maintain your certification by assisting you and your team with these required activities.

Download our FREE Certification Ongoing Process Diagram flowchart to understand what’s involved in maintaining your ISO Certification!

Certification Ongoing Process

Get your FREE Certification Ongoing Process Diagram today!

What are the benefits of Ongoing Certification Support?

Save time and resources

Clear your team’s workload, while also ensuring your Management System is still operating effectively with our expert consultants looking after it.

Always be audit ready

We will manage your internal audit program to ensure all your Management System and Certification ongoing requirements are met prior to your external audits.

Unbiased perspective

Benefit from getting expert, objective, and unbiased feedback regarding your Management System for continual improvement.

Get a Free Initial Assessment of
your Organisation’s Certification
Readiness via the Form Below

Get a Free Initial Assessment of
your Organisation’s Certification
Readiness

Frequently Asked Questions for Certification Ongoing Support

ISO Certification is valid for a three-year cycle. However, it is not simply a matter of passing once and forgetting about it for three years. The validity of your certificate is strictly conditional on maintaining your system and meeting the implementation requirements of the relevant ISO Standard(s). Here is how the three-year ISO Certification cycle works:

Year 1 (Initial Certification): You pass your Stage 1 and Stage 2 certification audits, and the Certification Body awards your ISO certificate(s).

Years 1 & 2 (Surveillance Audits): To ensure your organisation is still meeting the requirements and continually improving, the Certification Body will return every 12 months to conduct a “Surveillance Audit.” If you fail to conduct these, or if the results are unsatisfactory, your certifier can suspend or cancel your ISO certification(s) before the three years are up.

Year 3 (Recertification): At the end of the three-year cycle, you must undergo a more comprehensive “Recertification Audit.” If successful, your certification is renewed, and a new three-year cycle begins.

In short: you get certified for three years at a time, but you must prove you continue to meet the relevant requirements every single year to keep it valid.

No, you are not obligated to keep paying an external consultant once you achieve certification, unless that’s what you’ve agreed to with the consultant. Consulting support is optional. You can choose to continue to engage an external consultant to assist with ongoing management activities and, in this case, you will need to pay in accordance with the agreed contract.

Once your system is certified, you can choose to handle all the ongoing requirements yourself, or engage consulting assistance. Keeping your certification(s) valid requires continuous actions (like tracking your progress against set objectives and targets, reviewing risks and the ongoing effectiveness of controls, conducting internal audits, and ensuring documented information keeps pace with operational improvements) to ensure you pass your annual Surveillance Audits.

Yes, absolutely. Internal audits are not a one-time event; they are a mandatory, ongoing requirement to keep your certification valid. Here is why you must continue to conduct Internal Audits:

  • It is a Requirement: All ISO Management System standards strictly require you to conduct internal audits at planned intervals (at least annually). If you stop doing them, you will fail your external audits.
  • Preparation for Surveillance: You must prove to your external auditor during your annual Surveillance Audit that your system is still active and improving. Your internal audit records are the primary evidence they will ask for.
  • Internal Audits facilitate business improvement: Routine internal audits allow you to find and fix non-conformances with the Standard(s), process gaps, operational issues or bad habits internally before an external auditor spots them and raises a formal issue.

Yes, Management Reviews are a mandatory, ongoing requirement to maintain your ISO certification(s).

Here is why you must continue to conduct them:

  • It is a Requirement: All ISO Management System standards explicitly require top management to review the organisation’s system at planned intervals to ensure it remains effective.
  • Mandatory Evidence: During your annual external ISO Surveillance Audit, the auditor will specifically ask to see the records of decisions made and action items from your latest Management Review. Failing to provide this is a quick way to receive a major non-conformance.
  • Management Reviews drive continual improvement: Management Review, as required by ISO Management System Standards, is the formal mechanism for leadership to review audit results, assess risks, review feedback from customers and other business stakeholders, and allocate resources, in order to make decisions based on evidence and improve the business.

The exact time depends on the size and complexity of your organisation, but it generally breaks down into three levels:

  • Day-to-Day Operations (Minimal extra time): Routine tasks like completing safety checklists or logging issues should blend seamlessly into your staff’s normal work. If it feels like a heavy burden, your system needs improvement.
  • Periodic Management (A few hours a month): Your Internal Lead needs dedicated time to update documents, track non-conformances, and ensure staff are maintaining their records.
  • Annual Milestones (Dedicated blocks of time): You must schedule time each year for the “heavy lifting.” This includes conducting Internal Audits, conducting your Management Reviews, and having your annual ISO audit (Surveillance or Recertification).

The Takeaway: If your internal team is too busy to handle the monthly and annual tasks, your system will quickly fall out of conformance. This is exactly when businesses choose to hire a consultant for ongoing support to take the heavy lifting off their plates.

Because your Management System is designed to be a “living” framework, it must evolve alongside your business. If your organisation undergoes significant changes, here is what needs to happen:

  • Update Your System: Your team (or your consultant) must update your existing policies, procedures, risk registers and any other affected documented information to reflect the changes.
  • Notify Your Certifier: You are obligated to inform your Certification Body about major changes. This includes moving to a new address, changing your legal business name, or adding entirely new products and services.
  • Audit Adjustments: Depending on the change, your certifier might simply update the details on your certificate (like a change of address). However, for major operational changes (like expanding your scope of certification), they may need to add extra time to your next Surveillance Audit or conduct a special audit to assess the changed areas.
  • Management Review: Significant changes to your size, scope, or location should be formally assessed during a Management Review to ensure leadership has assessed any new risks or required resources.

In short: your system and certification(s) can adapt to your business growth or changes, but you must keep both your internal documentation and your external certifier completely up to date.

Have a question we didn’t answer here? Visit our full FAQ page.