Back to blog
Audit

Stage 1, Stage 2 and surveillance: the three-year certification cycle explained

Certification is not one audit, it is a cycle - and the years after the certificate is issued are where programmes quietly decay. What happens at each stage, and what each one is really testing.
GRC Copilot Team
Stage 1, Stage 2 and surveillance: the three-year certification cycle explained

An ISO certificate runs on a three-year cycle: an initial two-stage audit, annual surveillance visits, then recertification. Most of the anxiety goes into Stage 2, and most of the failures happen in year two - when the urgency has gone and the recurring controls stop running.

Stage 1 - the readiness review

Usually one to two days, often partly remote. The auditor is establishing whether it is worth proceeding, and examines documentation and design rather than operation:

  • Scope definition, and whether it makes sense.
  • Core documentation - policy, risk assessment, Statement of Applicability, procedures.
  • Whether internal audit and management review have taken place at least once. These two are the most common reason Stage 1 goes badly, because teams treat them as post-certification activities. They must have happened before you are ready.
  • Evidence the management system has been operating long enough to produce records - typically around three months minimum.

The output is a readiness report listing areas of concern. Treat it as a gift: it tells you exactly what Stage 2 will examine, weeks in advance. Organisations that act on it thoroughly rarely have a difficult Stage 2.

Stage 2 - the certification audit

Longer, on site, and focused on operation rather than documentation. The auditor samples evidence, interviews control owners, observes activities and tests whether the system does what it claims. Findings are raised and graded, and any major must be resolved before the certificate is issued.

The gap between stages is typically four to twelve weeks - long enough to address Stage 1 concerns, short enough that the auditor retains context.

Stay audit-ready between visits

GRC Copilot keeps controls, evidence and recurring activities current all year - so surveillance visits are a review of what already exists rather than a month of preparation.

Surveillance - where programmes decay

Years one and two bring shorter visits covering a subset of controls, always including the management system essentials: internal audit, management review, corrective actions, risk treatment progress, and any findings from last time.

What goes wrong is predictable. The certificate is on the website, the project team has moved on, and the recurring activities - quarterly access reviews, the annual policy review, the internal audit programme - stop happening. The first surveillance visit finds a year of missing records, and there is no way to create them retrospectively.

Surveillance is not a lighter version of Stage 2. It is specifically designed to detect whether the system kept running - which is exactly the thing a one-off certification push does not prove.

The defence is a compliance calendar with named owners, established before the certificate is issued rather than after the first uncomfortable surveillance visit.

Recertification

Year three is a full audit of the entire system, comparable in scope to Stage 2 though usually more efficient because the auditor knows you. It also examines the cycle as a whole: has the system improved, were findings genuinely resolved, has it adapted to changes in the business? A programme that has been static for three years attracts attention even when every individual control passes.

Choosing a certification body

  • Accreditation matters more than brand. A certificate from a body accredited by a recognised national accreditation authority carries weight; an unaccredited one may be rejected by customers, which defeats the purpose entirely. Check this before signing anything.
  • Sector experience - an auditor who understands your industry asks better questions and wastes less of your time.
  • Auditor continuity across the cycle, which materially reduces effort at surveillance.
  • Geographic coverage if you have multiple sites.
  • Cost across three years, not the initial quote - surveillance and recertification fees are the larger part.
  • Independence. A body cannot both consult on your implementation and certify it. Firms offering both must keep them strictly separate, and using one for both invites questions.

Multi-framework and transitions

Where you hold several certifications, combined audits covering more than one standard in a single visit reduce cost and duplicate effort considerably - worth asking about explicitly, as it is not always offered.

Standards also revise. When a new version is published there is normally a transition window of two to three years, during which you must move to the new version or lose certification. Plan the transition into a scheduled audit rather than treating it as a separate project.

Frequently asked questions

Can we fail Stage 2?

You can receive majors that prevent certification until resolved - which is a delay rather than a permanent failure. A thorough response to the Stage 1 report is the best protection.

How long must the system have been running?

Around three months of operating records is the usual minimum, and more is better. Controls with quarterly or annual frequency need to have run at least once.

What if we fail a surveillance visit?

Majors can lead to suspension of the certificate if not resolved within the agreed timeframe. Suspension is public and commercially damaging, which is precisely why the calendar matters.

Can we change certification body mid-cycle?

Yes, through a transfer process - the new body reviews your existing certification and findings. It is more straightforward at recertification.

Key takeaways

  • Internal audit and management review must happen before Stage 1, not after certification.
  • The Stage 1 report tells you what Stage 2 will examine - act on all of it.
  • Year two is where programmes decay; a compliance calendar with owners is the defence.
  • Check accreditation before choosing a body, and price the full three-year cycle.
#stage-1 #stage-2 #surveillance #recertification #certification-body #three-year-cycle