How often internal, surveillance and recertification audits happen for ISO 9001, 14001, 45001, 27001 and 22301, whether certificates expire, and what a missed audit costs.
People ask how often ISO audits happen for ISO 9001, then again for ISO 14001, ISO 45001, ISO/IEC 27001 and ISO 22301, as if each standard had its own rule. They mostly do not. The answer splits into two parts, and once you separate them it is the same for all five.
Internal audits are yours. You decide how often they happen, within some rules. Certification audits belong to the certification body, and their timing is fixed by ISO/IEC 17021-1:2015, the standard every accredited certification body works to, whichever management system standard it is certifying.
Internal audits: as often as you plan, but you do have to plan
Every standard built on the ISO harmonised structure has the same clause 9.2. It requires internal audits “at planned intervals” to show whether the management system meets the organisation’s own requirements and the standard, and whether it is effectively implemented and maintained. None of them puts a number on it.
What the standard does require is an audit programme. Under clause 9.2.2 that programme sets the frequency, methods, responsibilities and reporting, and it has to take into account how important each process is and what previous audits found. ISO 19011:2018, the guidance standard on auditing, adds further factors in clause 5.4.3: the number and complexity of activities and locations, concerns raised by interested parties, and significant changes to the organisation or its risks.
In practice that produces a pattern most auditors will recognise as sound:
- The whole scope is covered at least once in each three-year certification cycle. Many organisations do it every year.
- Higher-risk processes are audited more often. For ISO 45001 that might be contractor control or permit to work; for ISO/IEC 27001, access management; for ISO 22301, the testing of business continuity plans.
- Anything that went wrong gets revisited. A process with open findings, incidents or complaints moves up the programme.
- The audits are spread through the year, not compressed into the week before the certification body arrives.
ISO 45001:2018 adds one thing the others do not. Clause 5.4 requires the organisation to consult non-managerial workers on planning and maintaining the audit programme, and clause 9.2.2 requires relevant audit results to be reported to workers and, where they exist, workers’ representatives.
Internal auditors must also be objective and impartial, which in practice means nobody audits their own work. That is one reason many organisations bring in an independent internal auditor.
The three-year certification cycle
ISO/IEC 17021-1:2015 sets out the audit programme for an accredited certificate in clause 9.1.3.2. It is the same for every management system standard.
| When | Audit | What it decides |
|---|---|---|
| Before certification | Initial audit in two stages: stage 1 (readiness) and stage 2 (implementation) | Whether to grant certification. The three-year cycle starts on the date of that decision. |
| Year 1 | First surveillance audit, no more than 12 months after the certification decision | Whether certification is maintained |
| Year 2 | Second surveillance audit, in the next calendar year | Whether certification is maintained |
| Year 3 | Recertification audit, before the certificate expires | Whether to renew for another three years. The new cycle starts from the recertification decision. |
Clause 9.1.3.3 sets the frequency: surveillance audits at least once a calendar year, except in recertification years, and the first no more than 12 months from the certification decision. A note allows the frequency to be adjusted for things like seasonal operations or a certificate of limited duration, such as a temporary construction site.
“At least once” is a floor. Some organisations and some certification bodies agree six-monthly surveillance, which spreads the audit days and keeps the system under steadier pressure. What cannot happen is a calendar year passing with no surveillance in a year that is not a recertification year.
Some standards add rules on top of ISO/IEC 17021-1. Certification bodies certifying ISO/IEC 27001, for example, also work to ISO/IEC 27006-1:2024. The cycle itself does not change.
Surveillance versus recertification
A surveillance audit is a sample. It does not have to cover the whole standard every time, but under clause 9.6.2.2 every surveillance has to include continuing operational control, and auditors routinely look at internal audit results, the management review, the closure of previous findings and how complaints and changes have been handled.
A recertification audit looks at the whole system over the whole cycle. The question is not only “does it work today?” but “has it worked, and improved, for three years?” That is why a system that is only tidied up before each visit tends to struggle at recertification.
Does ISO certification expire?
Yes. An accredited certificate is valid for three years from the certification decision, and it expires unless a recertification decision is made before that date.
Two clauses of ISO/IEC 17021-1:2015 cover what happens at the edge:
- Clause 9.6.3.2.4. If recertification is not completed, or the certification body cannot verify the correction of any major nonconformity, before the expiry date, recertification is not recommended and the validity is not extended.
- Clause 9.6.3.2.5. After expiry, the certification body can restore certification within six months, provided the outstanding recertification activities are completed. Otherwise at least a stage 2 audit is needed. The restored certificate takes effect on or after the recertification decision, and its expiry date stays on the original cycle.
So a late recertification does not buy extra time. It leaves a gap in which the organisation is not certified, and European Accreditation’s guidance (FAQ 47.5, September 2024) is that once six months have passed without the recertification activities being completed, the certification body must treat the organisation as a new client.
What happens if you miss a surveillance audit?
A certified organisation that does not allow surveillance or recertification audits to take place at the required frequency is one of the standard grounds for suspension under ISO/IEC 17021-1:2015 clause 9.6.5. The others include a system that has persistently or seriously failed to meet requirements, and a voluntary request from the organisation itself.
While a certificate is suspended it is invalid. It cannot be used in advertising, and the certification body will tell anyone who asks that it is suspended. Certification bodies’ published procedures commonly cap suspension at six months. If the reason for suspension is not resolved in that time, certification is withdrawn, or the scope is reduced.
Multi-site certificates: any site can be next
An organisation with several sites under one certificate is audited under IAF MD 1:2023, the international rules for multi-site certification. The International Accreditation Forum ceased operations on 1 January 2026 and its role passed to Global Accreditation Cooperation Incorporated, but IAF’s resolution on closing confirmed that its remaining documents, which include MD 1, stay valid until further notice.
The rules that matter in practice:
- The central function is audited at every audit, initial, surveillance and recertification.
- The sites are sampled. The sample is sized from the square root of the number of sites. Surveillance samples are smaller, 0.6 times the square root, and recertification samples larger, 0.8 times the square root.
- Different sites each year. Where MD 1 section 6.2.1 applies, 30% of sites, rounded up, are covered in each calendar year’s surveillance, and the sites chosen for the second surveillance are normally different from those chosen for the first.
- Sampling is only allowed where sites run substantially similar processes. Where they do not, every site is audited.
The certification body picks the sample. The site that was quiet last year can be the one the auditor drives to next year, which is why every site needs to be run to the same standard all the time, not only the ones expected on the plan.
When the standard itself changes
Standards are revised, and a revision brings a transition. ISO 14001 was republished in April 2026, and certificates to the 2015 edition have three years to move to the new one. ISO 45001 is also under revision: the draft reached the DIS ballot stage in 2026 and a new edition is expected in 2027. The current edition remains ISO 45001:2018, read together with Amendment 1:2024, which added climate change to clauses 4.1 and 4.2 and which certification bodies have audited since its publication in February 2024.
A transition does not reset the three-year cycle. It adds work that has to be audited inside it, so it is worth planning for well before the deadline.
A year that works
For a single-site organisation with one standard, a calm year looks something like this:
- Internal audits spread across the year to a programme that covers the scope and weights the riskier processes.
- Findings closed with evidence within the timescales you set.
- A management review that considers the audit results and records decisions, held before the surveillance audit rather than the morning of it.
- The surveillance audit on its agreed date, in its calendar year.
Where several standards are held, one combined internal audit programme and one management review usually does the job, and the certification body can audit them together. We explain how in integrated management systems.
For ISO 45001 specifically, two areas get most attention at surveillance: whether changes have been controlled, which we cover in ISO 45001 management of change, and whether leadership is genuinely engaged, which we cover in our introduction to ISO 45001.
How ESGweise helps
We run independent internal audits for ISO 9001, ISO 14001, ISO 45001, ISO/IEC 27001 and ISO 22301, prepare organisations for certification, and for organisations with several sites we run the certified system month by month so that every site is ready whenever the auditor arrives. We are not a certification body and do not issue certificates.
Frequently asked questions
How often are ISO internal audits required?
At planned intervals that the organisation decides for itself. Clause 9.2 of ISO 9001, ISO 14001, ISO 45001, ISO/IEC 27001 and ISO 22301 all use the same wording and none of them sets a fixed frequency. The audit programme has to take account of how important each process is and what earlier audits found, so higher-risk areas are audited more often. Most organisations audit their whole scope at least once in every three-year certification cycle and the riskier processes every year.
How often are ISO surveillance audits?
At least once every calendar year, except in a recertification year. That rule comes from ISO/IEC 17021-1:2015 clause 9.1.3.3, the standard accredited certification bodies work to, and it applies to every management system standard they certify. The first surveillance after initial certification must be held within 12 months of the certification decision. Some organisations choose six-monthly surveillance, which is allowed, but once a year is the minimum.
Does ISO certification expire?
Yes. An accredited ISO certificate is valid for three years from the certification decision. To keep it, the organisation must pass a recertification audit and receive a recertification decision before the expiry date. If that does not happen, the certificate lapses. The certification body can restore it within six months of expiry if the outstanding recertification work is completed, but the organisation is not certified in the gap, and after six months it is treated as a new applicant.
What is the difference between a surveillance audit and a recertification audit?
A surveillance audit is a partial check held in the first and second years of the cycle. It samples the system and confirms that it is still operating, that controls are working and that previous findings have been closed. A recertification audit in the third year looks at the whole system against the standard over the full cycle and decides whether the certificate is renewed for another three years.
What happens if a surveillance audit is missed?
Not allowing a surveillance audit at the required frequency is one of the grounds on which certification bodies suspend a certificate. While suspended, the certificate is invalid and cannot be advertised or relied on by customers. Certification bodies commonly limit suspension to six months; if the cause is not resolved in that time, the certificate is withdrawn.
How are multi-site ISO certificates audited?
Under IAF MD 1:2023, the certification body audits the central function at every audit and a sample of the sites, sized from the square root of the number of sites. Surveillance samples are smaller than the initial sample and recertification samples are larger. The certification body chooses which sites to visit, so every site has to be ready all the time.