Back to InsightsCertification

    What Happens After ISO Certification? Surveillance Audits Explained

    A practical guide to ISO surveillance audits, recertification, and maintaining ISO certification in the UK across the full three-year cycle.

    By Ersin CETINPublished

    Getting your ISO certificate is a genuine achievement. But the businesses that get the most value from certification are the ones that understand what comes next — and plan for it properly.

    ISO certification is not a one-time event. It is a three-year cycle of ongoing assessment, with annual surveillance audits and a recertification audit at the end of the cycle.

    How Long Is an ISO Certificate Valid?

    Your ISO certificate is valid for three years from the date of issue. To keep it valid:

    • Year 2: First surveillance audit
    • Year 3: Second surveillance audit
    • End of Year 3: Recertification audit

    Miss a surveillance audit without a valid reason and agreed deferral, and your certificate can be suspended. Fail to complete recertification and it will be withdrawn.

    The certification cycle is consistent across the most common ISO standards used in the UK, including ISO 9001, ISO 14001, ISO 45001, and ISO 27001.

    What Is a Surveillance Audit?

    A surveillance audit is an annual check that your management system is still being maintained and improved. It is shorter and less intensive than your initial certification audit.

    For a UK SME, a surveillance audit typically takes four to six hours and can usually be conducted remotely.

    What surveillance audits focus on:

    • Progress on any non-conformances or observations from the previous audit
    • Whether your internal audit programme has been maintained
    • Whether management review meetings have been held and minuted
    • Progress against your quality, environmental, or safety objectives
    • Any significant changes to your organisation or processes
    • How customer complaints and feedback have been handled

    What Is a Recertification Audit?

    The recertification audit takes place at the end of your three-year certification cycle. It is a more thorough review than a surveillance audit but typically less intensive than your original Stage 2 audit. A successful recertification audit issues a new three-year certificate, resetting the cycle.

    The Secret to Easy Surveillance Audits

    The businesses that find surveillance audits straightforward maintain their management system consistently throughout the year.

    Five habits:

    1. Run your internal audit programme regularly. At least one complete internal audit per year.
    2. Hold your management review — and minute it properly. Calendar it at the start of the year.
    3. Close out non-conformances promptly. Root cause, corrective action, evidence the action worked.
    4. Track your objectives throughout the year. Not just the week before an audit.
    5. Keep records current. Training, supplier evaluations, customer feedback — continuously.

    Budgeting for the Full Three-Year Cycle

    YearAudit TypeTypical Cost for UK SME
    Year 1Stage 1 + Stage 2 initial certification£800–£1,400
    Year 2First surveillance audit£500–£900
    Year 3Second surveillance + recertification£800–£1,400

    For a detailed breakdown by standard and company size, see our ISO certification cost guide →.

    What Happens If You Miss a Surveillance Audit?

    If you are approaching your surveillance due date and have a legitimate reason to defer, contact your certification body in advance. Most certification bodies, including UniCert, will work with you on a revised schedule rather than immediately suspend your certificate.

    What we would never recommend is simply letting the date pass without communication.

    Can You Transfer Your ISO Certificate to UniCert?

    If you are currently certified with another body and want to transfer, this is straightforward. A transfer audit reviews your existing management system and current certificate. If your system is well-maintained, a transfer can typically be completed in a single audit day without losing certification status.

    Contact us to discuss a certificate transfer →

    Frequently Asked Questions

    How often do I need a surveillance audit for ISO certification in the UK?

    Surveillance audits are required annually — once in Year 2 and once in Year 3 of your three-year certification cycle. Missing a surveillance audit without prior agreement can result in certificate suspension.

    What is the difference between a surveillance audit and a recertification audit?

    A surveillance audit is an annual check that your management system is being maintained. It is shorter and more focused than your initial certification audit. A recertification audit takes place at the end of your three-year cycle and is a more comprehensive review, after which a new three-year certificate is issued.

    Can I have my ISO surveillance audit conducted remotely in the UK?

    Yes. UniCert offers remote surveillance audits for most UK businesses. Remote audits are equally valid, reduce disruption to your team, and lower the overall cost of maintaining your certification.

    What happens if I miss an ISO surveillance audit?

    Missing a surveillance audit without prior agreement with your certification body can result in certificate suspension. If you need to defer a surveillance audit for a legitimate reason, contact your certification body in advance to agree a revised schedule.

    UniCert certification services background

    Take the Next Step with UniCert

    From ISO 9001 quality management to cyber security and supply chain assurance – UniCert provides the management system certification you need to unlock global markets.

    Consent to Cookies & Data Processing

    We use cookies for analytics and improving your experience. This consent is voluntary and can be revoked at any time.