Congratulations — you passed your certification audit. But ISO certification is not a one-time achievement. It is a 3-year commitment with annual checkpoints, and failing to maintain it can cost you more than the certificate itself: lost tenders, suspended supplier approvals, and the expense of recertifying from scratch.
This guide explains the full ISO certification lifecycle — from your first surveillance audit through recertification — so you know exactly what to expect, what to prepare, and what to avoid.
The 3-Year ISO Certification Cycle
Every ISO certificate follows the same lifecycle, regardless of the standard (ISO 9001, ISO 14001, ISO 45001, ISO 22000, or any other) and regardless of which certification body issued it.
| Timeline | Event | What Happens |
|---|---|---|
| Month 0 | Initial Certification Audit (Stage 1 + Stage 2) | Certificate issued, valid for 3 years |
| Month 12 | 1st Surveillance Audit | Partial system review — selected clauses and processes |
| Month 24 | 2nd Surveillance Audit | Partial system review — remaining clauses and processes |
| Month 33–36 | Recertification Audit | Full system review — all clauses. New 3-year certificate issued |
The two surveillance audits together should cover all clauses and all processes — the certification body plans which areas to cover in each surveillance. High-risk areas, areas with previous findings, and areas that changed significantly may be audited in both surveillance visits.
Surveillance audits must be conducted within a specific window — typically within 3 months either side of the anniversary date. Missing this window can trigger suspension. Plan your audit date at least 2–3 months in advance and confirm it with your certification body in writing.
What Happens During a Surveillance Audit?
A surveillance audit is shorter than your initial certification audit — typically 1–2 days depending on company size and scope. The certification body auditor will focus on:
Mandatory Items (Every Surveillance)
- Internal audit programme and results — Did you conduct internal audits as planned? Were findings addressed?
- Management review — Was it conducted with all required inputs? Were actions assigned and tracked?
- Corrective actions — Are nonconformities from the previous audit closed? Is there evidence of effectiveness?
- Customer complaints and feedback — How are complaints handled and trended?
- Use of the certification mark — Is the ISO logo used correctly on marketing materials, letterheads, and proposals?
- Changes to the management system — Any major process, scope, or organisational changes since the last audit?
Possible Outcomes
| Outcome | What It Means | What You Need to Do |
|---|---|---|
| Certification continued | No major nonconformities found; minor findings (if any) addressed satisfactorily | Continue operating your system; prepare for the next audit |
| Minor nonconformity raised | A specific requirement is not fully met, but does not affect system effectiveness | Submit a corrective action plan within 30 days; implement and provide evidence |
| Major nonconformity raised | A significant failure in your system — a required element is missing or completely ineffective | Implement corrective action immediately; a follow-up audit may be required within 90 days |
| Certificate suspended | System failures are too severe or corrective actions are not provided within the required timeframe | Resolve all issues and undergo a special audit to lift suspension |
How to Prepare for Your Surveillance Audit
The companies that pass surveillance audits smoothly are the ones that maintain their management system continuously — not the ones that scramble to prepare two weeks before the auditor arrives. Here is a practical preparation timeline:
8 Weeks Before: Conduct Your Internal Audit
This is the most critical step. Your internal audit is your dress rehearsal. It should cover all the areas the certification body will examine, and any findings must be addressed with corrective actions before the external audit.
6 Weeks Before: Hold Your Management Review
The management review meeting must be conducted before the surveillance audit — the auditor will want to see current minutes and evidence that actions are being tracked. Ensure all required inputs are covered: internal audit results, customer feedback, process performance, corrective actions status, changes affecting the system, and improvement opportunities.
4 Weeks Before: Close Open CARs
Review all open corrective action requests (CARs) from your internal audit and from the previous certification body audit. Every CAR should be closed with evidence of implementation and, critically, evidence that the action was effective in preventing recurrence. Open CARs are one of the most common audit findings.
2 Weeks Before: Document Review
Verify that all controlled documents are current, approved, and accessible. Check that records required by the standard are being maintained — training records, calibration certificates, inspection records, complaints log, objectives tracking. Ensure the certification mark is used correctly and that your scope statement matches what is on your certificate.
1 Week Before: Brief Your Team
The auditor will interview staff at various levels. Ensure employees can explain the company policy in their own words, describe their role in the management system, explain what they would do if something goes wrong, and demonstrate awareness of the objectives relevant to their work.
Auditors are not trying to trick anyone. They want to see that the system is understood and working. Employees should answer honestly, show the auditor how they actually do their work (not how the procedure says they should), and say "I don't know, but I can find out" rather than guessing. Demonstrating real practice is always better than reciting procedures.
Recertification: Renewing Your ISO Certificate
At the end of the 3-year cycle, a full recertification audit is required. This is essentially a complete system review — similar in scope to the initial certification audit, but with the advantage that you now have 3 years of system maturity, records, and improvement evidence to demonstrate.
How Recertification Differs from Surveillance
| Aspect | Surveillance Audit | Recertification Audit |
|---|---|---|
| Scope | Selected clauses and processes | All clauses and all processes |
| Duration | 1–2 days | 2–4 days (depending on size and standards) |
| Stage 1 required? | No | Sometimes — if significant changes or gaps identified |
| Outcome | Certificate maintained | New 3-year certificate issued |
| Planning | Schedule annually | Begin planning 3–4 months before certificate expiry |
Recertification Cost in Malaysia
Recertification audit fees are paid to your certification body and typically range from RM 5,000 to RM 15,000 for a single standard, depending on your company size and number of sites. For an Integrated Management System covering ISO 9001 + ISO 14001 + ISO 45001, a combined recertification audit is significantly more cost-effective than certifying each standard separately. See our ISO certification cost guide for detailed fee breakdowns.
If your recertification audit is not completed before your certificate expires, you lose your certification status. This means you cannot bid on tenders requiring ISO certification, cannot display the certification mark, and may lose approved supplier status with key clients. Planning the recertification audit 3–4 months before expiry gives you a buffer for any nonconformity closure needed after the audit.
Switching Your Certification Body
You are not locked into your certification body. Companies switch for several reasons: better pricing, improved service, a certification body with specific industry accreditation required by their clients, or simply better rapport with the audit team.
The transfer process involves:
- Contacting the new certification body and providing your current certificate, audit history, and any open nonconformities
- The new body conducts a transfer audit — reviewing your documentation and verifying system effectiveness
- If successful, the new body issues a certificate continuing your existing certification cycle
- The transfer can happen at any point — it does not need to coincide with a surveillance or recertification audit
Cari Consultancy can advise on choosing an accredited certification body that fits your industry and client requirements. We work with SIRIM QAS International, Bureau Veritas, SGS, TÜV SÜD, BSI, and other accredited bodies operating in Malaysia.
What If Your Certificate Has Already Expired?
We regularly work with Malaysian companies whose ISO certificates have lapsed — sometimes for months, sometimes for years. The path back to certification depends on how long it has been and what state the management system is in:
| Scenario | Typical Approach | Expected Timeline |
|---|---|---|
| Expired within 6 months, system maintained | Recertification audit with the same or new certification body | 4–8 weeks |
| Expired 6–12 months, system partially maintained | Gap analysis → remediate gaps → initial certification audit | 2–3 months |
| Expired over 12 months or system collapsed | Fresh implementation with consultant support → initial certification audit | 3–6 months |
The good news is that re-certification is almost always faster than the original implementation — your team already understands the standard, documentation exists (even if it needs updating), and the culture of systematic management is usually still in place.
5 Tips for Keeping Your System Alive Between Audits
- Run monthly mini-reviews: A 30-minute check on KPIs, open CARs, and any process changes keeps everything current without a major effort.
- Keep records in real time: Training records, calibration logs, complaints, and inspections should be recorded when they happen — not reconstructed before an audit.
- Act on findings immediately: When an internal audit or customer complaint reveals a problem, address it within days. A quick fix now prevents a nonconformity later.
- Update documents when processes change: If you change a supplier, modify a production process, or restructure a team, update the relevant procedures and records immediately.
- Engage a maintenance retainer: Many Malaysian SMEs find it cost-effective to engage their consultant on a retainer basis — quarterly visits, internal audit support, and on-call advisory keep the system healthy at a fraction of the cost of emergency remediation.
Frequently Asked Questions
An ISO certificate is valid for 3 years from the date of issue. During this period, your certification body will conduct surveillance audits — typically at 12 months and 24 months after initial certification. At the end of the 3-year cycle, a recertification audit is required to renew the certificate for another 3 years.
If you miss or postpone your surveillance audit beyond the scheduled window, your certification body may suspend your certificate. Suspension means you cannot claim ISO certification or use the certification mark until the audit is completed and any nonconformities are resolved. If suspension continues beyond 6 months, most certification bodies will withdraw the certificate entirely, requiring a full recertification process.
Yes. You can transfer your ISO certificate to a different accredited certification body at any point during the certification cycle. The new body will conduct a transfer audit — reviewing your existing certificate, audit history, and system documentation. Common reasons for switching include cost savings, better service, or a certification body with specific industry recognition required by your clients.
Recertification audit fees typically range from RM 5,000 to RM 15,000 depending on company size (number of employees), number of sites, and the standard(s) being recertified. This is the fee paid to your certification body. If you also engage a consultant to help prepare, consultancy fees are separate. An Integrated Management System recertification covering multiple standards in a single audit is more cost-effective than certifying each standard separately.
Not necessarily. If your certificate expired recently and your management system is still largely in place, a recertification audit may still be possible — though your certification body may treat it as an initial audit. If the system has deteriorated significantly, a gap analysis followed by remediation work may be needed before the recertification audit. Cari Consultancy regularly helps companies with expired certificates get re-certified efficiently.
Preparing for your next audit? Start with our ISO Internal Audit Checklist and review the 10 Most Common Audit Findings so you know what to fix before the external auditors arrive.
Keep Your ISO Certificate Active
Cari Consultancy helps Malaysian companies maintain their ISO certification — surveillance preparation, internal audits, system maintenance, and recertification support.
Get a Free Quote Maintenance Services