External Audits: The Certification Cycle, the Audit Day, and What Preparation Actually Changes
Almost every article about external audits carries the same sentence: the certificate is valid for three years, with an annual surveillance audit in between. It appears in dozens of variants online, almost never with a source — and it is wrong in three separate ways. The rules are not in ISO 9001 at all. They sit in ISO/IEC 17021-1:2015, the standard for certification bodies [1].
What follows is the actual mechanism with clause references, what changed on the accreditation side on 1 January 2026, and which preparation moves the outcome.
Who Certifies — and Who Explicitly Does Not
ISO certifies nobody. On its own certification page the organization states that it “does not perform certification or issue certificates, and it does not permit anyone to use the ISO logo in connection with certification”; certification is done by external certification bodies, so a company cannot be certified by ISO [2]. Anyone advertising as “ISO certified” over an ISO logo has a problem before the audit starts.
The same page settles a second point consultancy literature routinely gets wrong: accreditation is not compulsory, and an unaccredited body is not necessarily disreputable [2]. It still matters commercially, because customers and supplier approvals ask for it — but it is not a requirement.
Customer audits are a different animal: a supplier audit is a second-party assessment against a contract, with no bearing on your certificate. Certifying a management system is third-party conformity assessment, and that is what ISO/IEC 17021-1:2015 governs — competence, consistency and impartiality of the body doing the auditing [1].
The Certification Cycle Under ISO/IEC 17021-1
The cycle is not a certificate validity period. It is an audit programme. Clause 9.1.3.1 has the certification body plan that programme for the full cycle, and 9.1.3.2 describes the initial programme as a three-year arrangement: a two-stage initial audit, surveillance in years 1 and 2, recertification in year 3 before expiry.
The starting point is what everyone gets wrong. The cycle begins with the certification decision — with the recertification decision for later cycles. Not with the last audit day, and not with the issue date on the certificate.
| Phase | Clause | What actually happens | Where |
|---|---|---|---|
| Stage 1 | 9.3.1.2 | readiness assessment: documented information, site conditions, understanding of the requirements, interval to stage 2; conclusions documented | partly on site — the client must be informed of on-site activities, so not a pure desk review |
| Stage 2 | 9.3.1.3 | evaluation of implementation including effectiveness | at the site |
| Surveillance | 9.1.3.3, 9.6.2 | at least once per calendar year, except in the recertification year; the first no more than 12 months after the certification decision | on site (9.6.2.1.2); need not be a full system audit |
| Recertification | 9.6.3 | evaluation before expiry; a stage 1 only on significant changes (9.6.3.1.3); majors closed before expiry (9.6.3.2.2) | on site (9.6.3.2.1) |
Three corrections to the standard sentence follow from that table.
First, the three years describe a cycle, not a promise of validity. Because recertification may anchor the new expiry date to the existing one (9.6.3.2.3), consecutive certificates often run for less than three years.
Second, a cycle contains two surveillance audits, not three — there is none in the recertification year. And the obligation attaches to the calendar year, not to a rolling twelve-month interval. The European co-operation for Accreditation addresses this clause in FAQ 37.12 and states that deferring an audit due in year n+1 into year n+2 is not acceptable [3]. Letting a December date slip costs you more than a few weeks of slack; it breaks the calendar-year condition.
Third, surveillance is an on-site audit. It may be narrower than a full system audit, but it is not a remote document review.
Assessment: Clause 9 of ISO/IEC 17021-1:2015 sits behind a paywall. The numbering above is not quoted from ISO’s text but cross-checked against two primary sources on the accreditation side — the EA FAQ above [3] and the International Accreditation Service’s overview of section 9 [4]. No normative wording is reproduced here.
What Changed in 2026: From the IAF to Global ACI
Here is the part almost nobody has written up. The institution that issued the binding implementation documents for certification bodies for two decades no longer exists.
The International Accreditation Forum ceased operations on 1 January 2026 [5]. Its role, and ILAC’s, passed to the Global Accreditation Cooperation Incorporated (Global ACI), operational from the same date [6].
Day to day that changes surprisingly little, which is the good news. Resolutions 2025-25 and 2025-29 record that the existing IAF Mandatory Documents, the ILAC P-series and the joint A-series remain in force until equivalent Global ACI documents are adopted [7]. “IAF MD 5:2023” is still the correct citation — the authority behind it is simply a different organization now.
Where it bites is the migration to ISO 9001:2026. That deadline is not ISO’s to set; it belongs to the accreditation side. And as of 27 August 2026 it does not exist: in Global ACI’s own resolutions the relevant document is still listed as “IAF MD XX Transition Requirements for ISO 9001” — literally unnumbered, because it is still being drafted [7]. In parallel, ISO 9001 edition 6 remains at stage 60.00, “under publication”, dated 2026-09 [8].
Assessment: The figure circulating everywhere — three years, ending September 2029 — traces back to no primary source. It extrapolates the transition periods of earlier revisions: a reasonable expectation, not a rule. Anyone planning a 2027 or 2028 recertification slot against that number is planning against an estimate. What is actually settled about the new edition is covered in the article on all the changes in ISO 9001:2026, and the consequences for question catalogues in the article on ISO 9001:2026 and internal audits.
Automotive is a special case, where the IATF sets its own cycle and timing rules; the differences are in the article on IATF 16949 audit requirements.
The Shape of the Audit Day
The cycle is the frame. The audit day has its own choreography, and it is remarkably consistent across certification bodies.
Assessment: what follows is practitioner observation, not a requirement. ISO/IEC 17021-1 governs the programme and the decisions, not the choreography of a day.
It opens with the opening meeting: the plan, confidentiality, points of contact, how findings will be handled. After that the auditor does not march through clauses 4 to 10 in order. They follow trails. A typical chain: pick a customer complaint from the current year, follow it into the cause analysis, from there into the corrective action, from the action into the effectiveness review — and finally ask whether the result reached the management review.
That trail rarely breaks on the requirement. It breaks on evidence: the action exists, and the effectiveness check happened verbally.
Running alongside is the sampling logic. Four to six records per process, pulled from live operations rather than a prepared folder: calibration certificates past their interval, a batch release with no documented incoming inspection, a supplier evaluation carrying the same score two years running. In the closing meeting findings are presented, graded and justified — usually with room to clear up an obvious misunderstanding the same day if you can produce the record.
How Nonconformities Are Graded — and Who Decides
A stubborn myth says “major” and “minor” are the certification body’s house style, or come from an IAF document. Neither is true. Both are defined terms in ISO/IEC 17021-1:2015, and clause 3 is freely readable on the ISO Online Browsing Platform [9].
- 3.11 nonconformity — non-fulfilment of a requirement.
- 3.12 major nonconformity — a nonconformity that “affects the capability of the management system to achieve the intended results”.
- 3.13 minor nonconformity — a nonconformity that does not affect that capability.
The criterion is single and precise: effect on the system’s capability to achieve its intended results. Not the count of records, not gut-feel severity, not whether a customer noticed. A note to 3.12 adds that several minor nonconformities against the same requirement can demonstrate a systemic failure and together amount to a major [9].
That gives you a solid basis for a disagreement. When a finding is graded major, the question is not “isn’t that a bit harsh?” but: what link between this non-fulfilment and the system’s capability is being asserted? The definition protects the auditor from negotiation pressure as much as it protects you from an arbitrary grade.
The consequences are regulated too. Before the certification decision, majors must be closed while minors need a reviewed corrective action plan (9.5.2). If the corrections for a major cannot be verified within six months of the last day of stage 2, another stage 2 becomes necessary (9.5.3.2) [3][4]. Building the path from finding to demonstrated effectiveness is covered in the article on findings management, and the mechanics of treating causes in the article on the CAPA process.
The Most Common Preparation Mistakes
Evidence is not linked to requirements. When process owners spend minutes hunting for the document that satisfies a requirement, it does not just stretch the audit. It shifts the sample: an auditor who comes up empty on three requirements digs deeper on the fourth.
Internal audits run as a box-ticking exercise. An internal audit programme under 9.2.2 is the only instrument that finds findings before the external auditor does. Run formally, it produces none — and an internal audit report with zero findings is itself a signal. How to build a risk-based programme is set out in the audit programme planning guide, and the depth of testing per clause in the internal audit checklist for ISO 9001.
Documentation and practice have drifted apart. The most common cause of findings is not a bad process. It is a work instruction describing an approval step nobody has performed since the system migration.
Subject-matter teams are unprepared. The audit does not test the quality team; it tests the person at the inspection station. Someone who cannot describe their own process in their own words signals process immaturity even when the process works.
Open actions from last year. The most expensive of the five, because it maps straight onto a requirement. ISO 9001:2015 requires in 10.2.1 d) that the effectiveness of any corrective action taken be reviewed, and in 10.2.2 that documented information be retained as evidence both of the nature of the nonconformities and any subsequent actions taken and of the results of any corrective action [10]. An action flagged “implemented” with no documented effectiveness review does not satisfy 10.2.1 d), however good the action was — and the finding then lands on the corrective action system itself, not on the original process.
Preparation That Actually Works
Four weeks out: a short internal audit of the likely focus areas. Those are not a secret. They sit in the certification body’s audit plan, in last year’s findings, and in whatever changed since the previous visit.
Then a pass through every open finding, one question per item: is there evidence the action worked — a metric, a follow-up audit, a fresh sample? If not, the finding is not closed, whatever status the system displays.
A week out, brief the subject-matter teams. Not to rehearse answers, but to explain the process: the auditor may inspect records, “I don’t know, but Sabine in metrology can” is a correct answer, and dressing things up surfaces in the sample anyway.
And on the day: keep evidence retrievable, not pre-sorted. A perfectly curated folder makes an experienced auditor more suspicious, not less.
That chain — finding, cause, action, evidence of effectiveness, link back to the requirement — is what audit management in qportal is built around; the audit itself is covered in the qportal documentation on audit fieldwork.
Conclusion
An external audit is not an exam date. It is a sample drawn from a cycle that runs three years and begins with a decision, not with a date printed on a piece of paper. Knowing the mechanism changes how you plan: the first surveillance audit hangs on twelve months from the certification decision, a slipped December date breaks a calendar-year condition, and the grade on a finding rests on a criterion you can argue about on the merits.
On the ISO 9001:2026 transition the position is simple. Anyone who gives you a date today is giving you an expectation. The document that will set it does not yet have a number.
Sources
Primary sources — standards and accreditation bodies
- ISO/IEC: ISO/IEC 17021-1:2015 — Conformity assessment. Requirements for bodies providing audit and certification of management systems. Part 1: Requirements. Edition 1, published 2015-06, 48 pages, ISO/CASCO, stage 90.60 (confirmed 2020). https://www.iso.org/standard/61651.html (accessed 2026-08-27)
- ISO: Certification. Official information page. https://www.iso.org/certification.html (accessed 2026-08-27)
- European co-operation for Accreditation, Certification Committee: Question 37.12 — ISO/IEC 17021-1:2015 clause 9.1.3. FAQ. https://european-accreditation.org/sp_accordion_faqs/question-37-12-iso-17021-12015-clause-9-1-3/ (accessed 2026-08-27)
- International Accreditation Service: ISO/IEC 17021-1:2015 Section 9: Process Requirements. https://www.iasonline.org/wp-content/uploads/2021/02/17021-1-2015-Section-9.pdf (accessed 2026-08-27)
- International Accreditation Forum: notice on the cessation of operations as of 1 January 2026 and the transfer to the Global Accreditation Cooperation Incorporated. Legacy site. https://iaf.nu/en/home/ (accessed 2026-08-27)
- Global Accreditation Cooperation Incorporated (Global ACI): organisational information and FAQ; operations began 1 January 2026. https://www.global-aci.org/ and https://global-aci.org/en/faq/ (accessed 2026-08-27)
- Global Accreditation Cooperation Incorporated: Resolutions — including Resolutions 2025-25 and 2025-29 on the continued force of the IAF Mandatory Documents, and Resolution 2025-18 naming “IAF MD XX Transition Requirements for ISO 9001”; the same register carries Global ACI-FMRA-001 v3.2 of 5 August 2026. https://global-aci.org/en/global_aci-documents/resolutions/ (accessed 2026-08-27)
- ISO: ISO 9001 — Quality management systems. Requirements. Edition 6, stage 60.00 (International Standard under publication), publication date 2026-09. https://www.iso.org/standard/88464.html (accessed 2026-08-27)
- ISO/IEC: ISO/IEC 17021-1:2015, clause 3 “Terms and definitions”, terms 3.11 to 3.13. ISO Online Browsing Platform (freely available section). https://www.iso.org/obp/ui/en/#!iso:std:iso-iec:17021:-1:ed-1:v1:en (accessed 2026-08-27)
- ISO 9001:2015, Quality management systems — Requirements, clauses 9.2.2, 10.2.1 and 10.2.2. German edition consulted: DIN EN ISO 9001:2015-11, Beuth Verlag, Berlin.
Note on the evidence for clause 9
Clause 9 of ISO/IEC 17021-1:2015 is not freely available. Clause numbers and the substance of the requirements in this article are cross-checked against the accreditation-side primary sources [3] and [4] and paraphrased; no normative wording is reproduced. Only clause 3, freely readable on the ISO Online Browsing Platform, is quoted directly [9]. Consultancy, certification-body and content-marketing pages are not cited. Where this text goes beyond the documented evidence, it is marked as an assessment.
Frequently asked questions
- How long is an ISO 9001 certificate valid?
- The better question is how long the cycle runs. ISO/IEC 17021-1:2015 sets out a three-year certification cycle in 9.1.3.2, and that cycle starts with the certification decision — not with the audit and not with the date printed on the certificate. Because recertification may anchor the new expiry to the existing one (9.6.3.2.3), subsequent certificates are frequently shorter than three years.
- How many surveillance audits are there in a certification cycle?
- Two, not three. Clause 9.1.3.3 requires surveillance at least once per calendar year, except in the recertification year, where the recertification audit takes its place. The first surveillance audit after initial certification must fall no more than twelve months after the date of the certification decision. Surveillance audits are on-site audits, not remote document reviews.
- What is the difference between a major and a minor nonconformity?
- Both are defined terms in ISO/IEC 17021-1:2015. A major nonconformity (3.12) affects the capability of the management system to achieve the intended results; a minor one (3.13) does not. The test is systemic effect, not auditor discretion or house style. Several minor nonconformities against the same requirement can demonstrate a systemic failure and together constitute a major.
- What happens if a certification audit raises a major nonconformity?
- The certification decision is held. Under 9.5.2, major nonconformities must be closed before the decision; minor ones need a reviewed corrective action plan. If implementation of the corrections for a major nonconformity cannot be verified within six months of the last day of stage 2, clause 9.5.3.2 requires another stage 2 audit.
- How long is the transition period to ISO 9001:2026?
- As of 27 August 2026 it has not been published. Transition periods are set by the accreditation side, not by ISO — since 1 January 2026 that is the Global Accreditation Cooperation Incorporated. In its resolutions the relevant document still appears as "IAF MD XX Transition Requirements for ISO 9001", literally without a number. The widely quoted "three years, September 2029" has no primary source.