Surveillance Audits: The Compared Calendar of Eight Certifications
A certification is not a diploma. It is a cycle. The certificate you obtain at the end of an initial audit does not attest to a permanent achievement: it attests that, on a given date, your organisation met the requirements of a framework. The whole purpose of the surveillance audit is to check that this compliance holds between two deadlines — when nobody is watching any more.
It is also the number-one source of confusion for organisations juggling several schemes. “Annual surveillance audits” is a true statement for some certifications, false for others, and downright misleading for a third group that works through a full recertification every year. Here is the compared calendar, scheme by scheme, with sources.
The common principle: surveillance is not starting over
Three logics coexist.
The multi-year cycle with intermediate surveillance. A heavy audit opens the cycle, one or more lighter audits punctuate it, a heavy audit closes it. That is the model of the ISO standards and of Qualiopi certification.
The long-validity qualification with declarative follow-up. The title is granted for several years, but keeping it requires a periodic refresh of the file. That is the model of the French construction-trade qualifications.
The short recertification. There is no “surveillance” audit: there is a full audit, every year or every six months. That is the dominant model of private food-safety standards.
The distinction matters, because it radically changes the effort to budget for. An ISO surveillance audit does not mobilise the same auditor-days as an annual IFS recertification.
The comparison table
| Scheme | Cycle length | Surveillance frequency | What the auditor looks at first |
|---|---|---|---|
| Qualiopi certification | 3 years | One surveillance audit between the 14th and 22nd month following the award (French order of 6 June 2019) | Continued application of the framework, the follow-up given to earlier non-conformities, reports received by the certification body |
| ISO 9001, 14001, 45001, 27001 (under ISO/IEC 17021-1) | 3 years | At least one audit per calendar year, except in recertification years; the first no later than 12 months after the certification decision | How the management system actually runs, internal audits, management review, handling of deviations |
| ISO 22000 | 3 years | Same annual surveillance logic, within the accreditation framework specific to food safety | The HACCP plan, its updating, hazard control and traceability |
| Qualibat qualification | 4 years of validity | Annual declarative follow-up: questionnaire, updated company information, current insurance certificates | The continued existence of the human, technical and insurance resources that justified the qualification |
| MASE | 1 year or 3 years, duration decided by the steering committee | No documented intermediate external audit in the ISO sense; half-yearly reporting filed by the company on the MASE portal; audit request to be submitted 4 months before expiry | Management commitment, competences, work organisation, system effectiveness and continuous improvement |
| Organic certification (EU 2018/848) | Certificate tied to the annual control | At least one control per year, including a physical on-the-spot inspection; additional and unannounced controls depending on risk | Compliance of practices with the specification, traceability, consistency between inputs and outputs |
| IFS Food (v8) | 12-month certificate | Full annual recertification audit; at least one audit in three carried out unannounced | Food safety, authenticity, compliance with KO requirements and quality culture |
| BRCGS Food Safety (v9) | Certificate of 6 or 12 months depending on the grade | Full audit at each deadline; unannounced audit programme set out in the protocol | Major non-conformities, the fundamentals of the standard, how robust the system is when the audit is not prepared for |
Two reading precautions. First, MASE durations and the exact follow-up arrangements come under association rules that may vary locally: check with your local MASE association. Second, for every scheme, the contract signed with your certification body prevails over generalities: it is what sets your real dates.
For the detail of the Qualiopi cycle itself — differences between initial, surveillance and renewal audits — we devote a dedicated article to it, complemented by our guide to the Qualiopi surveillance audit. For construction-trade annual follow-up, see our article on renewing a Qualibat qualification.
What triggers an off-calendar audit
The contractual calendar is no guarantee of a quiet life. Several events open the door to an unplanned audit:
- a complaint or a report sent to the certification body — explicitly one of the cases provided for in Qualiopi surveillance;
- a substantial change in the organisation: change of director, of quality manager, restructuring;
- a change of scope: new activity, new audience, new product range;
- the opening of a site, or bringing an establishment into the certified scope;
- a change of certification body, which implies taking over the file and sometimes a transfer audit;
- an unannounced audit programme, mandatory in food standards aligned with the GFSI benchmarking requirements.
The practical rule: anything that changes in the scope must be reported to the certification body before the next audit, not during it. A gap between the declared scope and the real scope is one of the quickest ways to turn a routine audit into a major non-conformity.
What happens when surveillance is missed
The consequences unfold in three stages, under almost every scheme: non-conformity, suspension, withdrawal. An audit postponed beyond the planned window is not a mere administrative slip; it puts the certificate in an irregular position.
The blind spot is the rescheduling lead time. Cancelling an audit three weeks before the date often means losing two to three months — and that stretch can be enough to overshoot the deadline. Good practice therefore treats the scheduling date as the deadline, not the regulatory cut-off.
What the research says about losing a certificate
Is losing a certification financially catastrophic? The answer deserves more nuance than is usually assumed. Carlos J. F. Cândido, Luís M. S. Coelho and Rúben M. T. Peixinho published in 2016, in the International Journal of Operations & Production Management, an event study covering 143 Portuguese companies that had lost their ISO 9001 certification, matched against comparable firms. The result: they find no statistically significant difference in financial performance — return on assets, return on sales, sales growth — between decertified companies and their twins (see the study). The authors explain it by the partial internalisation of the standard’s practices into management: the company loses the paper, not the habits.
The nuance is essential — and it has sharp limits. That finding holds for a certificate that plays the role of a market signal. It no longer holds at all when the certificate conditions an access. That is precisely the case for several rows in the table above: without certification, access to public training funding closes, a lost qualification excludes you from contracts, a withdrawn food-safety certificate ends a customer listing overnight. There, the loss is immediate and measurable, whatever the real quality of internal practices.
Building a single quality calendar
When you stack schemes, the only method that holds is to merge the deadlines into a single calendar, kept by a named person. Three principles are enough:
- One line per deadline, with a reminder at minus six months. Not the audit date: the date by which the audit must have been booked.
- One owner per scheme. The calendar is shared, the responsibility is not.
- A short quarterly review sweeping open deviations across all schemes at once.
On pooling evidence, resist the temptation of a documentary white elephant. Some elements share naturally across frameworks: document control, competence and authorisation management, complaint handling, internal audits, management review, corrective action tracking. Write them once, in a neutral format, and maintain a simple mapping table to each framework’s requirements.
What does not pool, by contrast, is the technical evidence specific to a scheme: the HACCP plan for ISO 22000, the health-safety-environment risk assessment for MASE, input traceability for organic certification, evidence of individualised learning pathways for Qualiopi certification. Forcing them into a common mould costs more than managing them separately.
Take action
Open a one-sheet spreadsheet, list your current certifications, and for each note the certificate expiry date, the window for the next audit and the owner’s name. If a cell stays empty, call that certification body today: that is the cell that will produce the nasty surprise. For the general framework of the most cross-cutting standard in the table, see our guide to ISO 9001 certification.
Frequently asked questions
+Are surveillance audits always annual?
No, it depends on the scheme. Management system standards certified under ISO/IEC 17021-1 require an audit in each calendar year, except in recertification years. Qualiopi provides for a single surveillance audit across a three-year cycle, carried out between the 14th and the 22nd month. Other schemes work through a full annual recertification rather than through surveillance.
+What happens if I miss my surveillance audit?
The certificate is not maintained automatically: depending on the scheme's rules, the certification body may suspend and then withdraw the certification. The consequence is not merely documentary, it is commercial as soon as the certificate conditions an access — funding, a contract, a customer listing. Rescheduling a cancelled audit often takes several weeks: that lead time, not the expiry date itself, is what needs anticipating.
+Can you be audited outside the planned calendar?
Yes, under most schemes. A complaint sent to the certification body, a significant change of scope or organisation, the opening of a site or a report can trigger an additional audit. Several private food standards also impose a share of unannounced audits, and organic certification provides for additional controls without prior notice.