Renewing ISO 22000 certification: surveillance and the 3-year cycle
Obtaining ISO 22000 certification is a project; keeping it is a discipline. The certificate lives on a three-year cycle punctuated by annual surveillance audits and a renewal audit — and every year, companies learn the hard way that a system shelved after the initial audit does not survive the next surveillance. Here is how the cycle works, what the auditor checks, and the habits that make a certificate last.
The three-year cycle, concretely
| Milestone | Audit | Purpose |
|---|---|---|
| Year 0 | Initial audit (two stages) | Issue of the certificate |
| Years 1 and 2 | Annual surveillance audits | Check the system keeps operating |
| Year 3 | Renewal audit | Reassess everything and start a new cycle |
Surveillance is not a miniature initial audit: the auditor does not re-run the whole standard every year. They target the vital signs — treatment of previous nonconformities, internal audits and management review, change management, complaints and incidents — and sample the rest. The renewal audit, by contrast, sweeps the complete system across the certified scope.
The mechanics are the same as for the other management standards: our article on renewing ISO 9001 certification describes an identical machinery, transposed here to food safety.
What the surveillance auditor checks first
- The fate of the last audit’s nonconformities. An action plan left dormant is warning signal number one.
- Continuity of steering. Internal audits run at the planned pace, management reviews held with decisions attached — not pro-forma minutes.
- Change management. New product, new line, new equipment, new raw material, regulatory change: each change must have triggered an update of the hazard analysis and, where needed, of the PRPs and the hazard control plan.
- Day-to-day records. CCP monitoring, cleaning verifications, incoming-goods checks, calibration of measuring instruments: gaps in the records show immediately.
- Incidents and complaints. Not their absence — which is suspicious — but their treatment: root-cause analysis, corrective actions, effectiveness checks, and traceability and withdrawal/recall exercises kept up to date.
Why systems decay — and how to prevent it
The classic scenario: the company mobilises everyone for the initial audit, wins the certificate, then the pressure drops. The quality manager changes, internal audits slip, the hazard analysis is three years old. At the next surveillance the findings pile up; at renewal, everything must be rebuilt.
Research sheds light on the phenomenon: the study by Dimitrios Kafetzopoulos, Evangelos Psomas and Panagiotis Kafetzopoulos, published in 2013 in Food Control, shows that the effectiveness of a food safety system depends first on durable management factors — leadership commitment, training, resources — not on the initial documentary effort alone (see the study). In the same vein, the 2015 comparison by Evangelos Psomas and Dimitrios Kafetzopoulos, again in Food Control, between ISO 22000-certified and non-certified dairy companies attributes the certified firms’ advantage to a system genuinely steered over time — hazard identification, control and verification included (see the study). The certificate does not protect against drift; steering does.
Three habits keep the system running:
- set an annual calendar: internal audits spread across the year, a dated management review, traceability and recall exercises scheduled — without waiting for the surveillance to be announced;
- treat every change as a trigger: the question “should the hazard analysis be updated?” must be asked at every new product, process or supplier, not once a year;
- keep the improvement loop alive: complaints, failed self-checks and audit remarks feed actions followed through to effectiveness checks.
Suspension, withdrawal: what really endangers the certificate
Isolated nonconformities are part of the game — they call for an action plan, not a sanction. What threatens the certificate is inertia: major findings unresolved within deadlines, phantom internal audits, surveillance postponed without cause. The certification body can then suspend the certificate, and withdraw it. For a company whose customers require the certification, suspension immediately translates into lost listings — a risk out of all proportion to the system’s upkeep cost, detailed in our article on the ISO 22000 certification budget.
As renewal approaches, also revisit the fundamentals: is the scope still right? Have customer needs shifted towards a GFSI-recognised scheme? Our page on GFSI-recognised schemes helps reassess the trajectory at the right moment — renewal is the natural occasion for that review.
Take action
If your certificate is approaching a surveillance or a renewal, check your vital signs now: nonconformities resolved, internal audit up to date, management review held, hazard analysis refreshed. The ISO 22000 certification page summarises the scheme and its cycle — and its free ebook gives you a working base to put the system back under tension before the deadline.
Frequently asked questions
+How long is the ISO 22000 certificate valid?
Three years, like the other certifiable management standards. The cycle includes annual surveillance audits, which check that the system keeps operating, then a renewal audit that starts a new three-year cycle. The certificate is therefore never a permanent asset: it is maintained continuously.
+What happens if a surveillance audit goes badly?
Nonconformities call for an action plan, with treatment deadlines. Unresolved major findings, a non-existent internal audit or a system visibly at a standstill can lead the certification body to suspend the certificate, then withdraw it if the situation persists. Suspension is formally notified and may have to be disclosed to customers who require the certification — the commercial impact is immediate.
+Is the renewal audit as heavy as the initial audit?
It is generally more thorough than a surveillance, because it reassesses the whole system across the certified scope before starting a new cycle. But for a company whose system has genuinely operated for three years — records kept, regular internal audits, management reviews followed by action — it holds no particular difficulty: most of the work is already done day to day.