Maintaining and renewing your certification

The audit is approaching and you know the system has not been fed the way it should have been. I put the cycle back in order and get you into a state to pass.

  • Surveillance audit
  • Recertification
  • Closing findings
  • Version change

What the work involves

A certification is rarely lost all at once. It is lost because the system stopped being fed, the internal audits were not carried out, the management review kept being postponed, and nobody noticed before the audit.

Surveillance and recertification audit preparation

Checking that every obligation of the cycle has been met, rebuilding missing evidence, updating documentation and preparing the people who will be interviewed.

Closing findings

Root cause analysis, definition of a corrective action that addresses it, and assembly of the response file within the deadline set by the certification body.

Restarting a dormant system

Taking back the steering, restarting indicators, delivering the overdue internal audits, holding the management review and relaunching day-to-day engagement.

Standard version change

Gap analysis between the old and the new version, targeted adjustment of the affected elements, with no unnecessary rebuild.

Understanding your cycle

A certificate is not secured for three years: it is re-examined every year. Missing a single surveillance audit is enough to suspend it.

The three-year ISO certification cycleA horizontal timeline showing four audits: initial certification, two annual surveillance audits, then recertification at three years.12 months12 months12 monthsCertificationInitial auditYear 1Surveillance auditYear 2Surveillance auditYear 3Recertification
Typical cycle for ISO management system standards. Qualiopi, MASE and label schemes follow their own rhythms.

What you receive

  • A status report on the cycle obligations and what is missing
  • The overdue internal audits, delivered and recorded
  • Preparation and facilitation of the management review
  • A reasoned, documented response file for the findings
  • Documentation updates targeted on what has changed
  • Preparation of the people the auditor will interview

When this is not the right service

If the audit is three weeks away and nothing has been kept up across the whole cycle, the work becomes damage limitation rather than preparation. I will say so rather than sell you an engagement that will not change the outcome.

Frequently asked questions

Our system has not run for two years. Is that recoverable?

In most cases yes, provided you start a few months before the audit. A dormant system wakes up faster than a new one gets built, because the architecture exists. The challenge is rebuilding the evidence that it operated.

We received major findings. What happens now?

The certification body sets a deadline for you to evidence corrective action. The classic mistake is to answer the symptom without addressing the cause, and the finding then returns at the next audit. I help you build a response that holds.

The standard has moved to a new version. Do we start again?

Almost never. A version change calls for a targeted gap analysis, adjustment of the affected elements and updated evidence. Rebuilding everything is an unnecessary cost, though some providers will propose exactly that.

Tell me the date of your next audit

From that date and the real state of your system, I will tell you what has to be done, in what order, and whether the timeline holds.