← Back to Blog
Accreditation

Surveillance Tracking: Why You Need Yearly Dates, Not Just the Three-Year Cycle

2026-06-28 · 7 min read

The Three-Year Illusion

Most certification body planners understand the three-year certification cycle. A client achieves initial certification, and that certificate is valid for three years. Before expiration, a recertification audit is conducted, and a new three-year cycle begins. This is straightforward and widely understood.

What is less consistently understood — and more frequently mismanaged — is what happens within those three years. The certification cycle is not a single event followed by three years of inactivity and then another event. It contains mandatory surveillance audits that must occur within specific time windows, and those windows are anchored to dates that must be tracked with precision.

What IAF MD 1 Actually Requires

IAF Mandatory Document 1 (MD 1) establishes the rules for audit cycle management. The key requirements that many CBs underestimate:

  • The first surveillance audit must be conducted no later than 12 months after the last day of the Stage 2 audit. Not 12 months after certificate issuance — 12 months after Stage 2. If the Stage 2 audit ends on March 15, 2026, the first surveillance must be completed by March 15, 2027.
  • Subsequent surveillance audits must occur at least once per calendar year. The interval between any two consecutive audits (surveillance or recertification) must not exceed 15 months, though the standard expectation is approximately 12 months.
  • If a surveillance audit is not conducted within the required timeframe, the certificate must be suspended. This is not a recommendation — it is a mandatory requirement. Suspension means the client cannot claim certification, and the CB must formally suspend the certificate in its records and, depending on the AB's requirements, in public registries.

The Common Mistake

Here is where CBs get into trouble: they track the three-year cycle end date and work backward from there, but they do not rigorously track the annual surveillance windows.

Consider Clearwater Certification's situation. They issue a certificate to a client with a Stage 2 completion date of April 10, 2025. They note the certificate expiry as April 2028. They schedule the first surveillance for "sometime in early 2026" and put it on a general task list.

In February 2026, the planner checks the list and sees the surveillance is due. But the client requests a postponement — they are in the middle of a facility relocation and ask for the audit to be pushed to June. The planner agrees, noting that the certificate does not expire until 2028 so there is plenty of time. The surveillance is rescheduled to June 2026.

The problem: the first surveillance window closes on April 10, 2026 — 12 months after Stage 2. By June, the window has been missed. Under IAF MD 1, the certificate must be suspended. The client is furious, the planner is embarrassed, and the CB now has a process failure that may surface during the next AB assessment.

This scenario plays out more often than most CBs would like to admit. It happens because the critical date — the Stage 2 completion date that anchors the surveillance window — is not systematically tracked and enforced.

Why Spreadsheet Tracking Fails

Many CBs track surveillance dates in spreadsheets. A master spreadsheet lists all active clients with their certification dates, surveillance due dates, and recertification dates. In theory, this works. In practice, it fails for several reasons:

  • No automated alerts. The spreadsheet does not send reminders when a surveillance window is approaching. Someone must remember to check it regularly.
  • Dates get overwritten. When a surveillance is rescheduled, the original due date is often replaced with the new date. The anchor date — the Stage 2 completion date that defines the window boundary — may not even be in the spreadsheet.
  • No enforcement. A spreadsheet cannot prevent a planner from scheduling a surveillance outside the valid window. It is just data in cells.
  • Scaling problems. A CB with 200 active certifications has 200 rows to monitor, each with its own surveillance cadence. As the roster grows, the spreadsheet becomes unwieldy and errors multiply.

How Certiva Tracks Surveillance Cycles

Certiva treats surveillance date tracking as a core system function, not an optional feature:

The Stage 2 completion date is the anchor. When the Stage 2 audit is recorded as complete in Certiva, the system automatically calculates the first surveillance due date based on the 12-month window. This date is locked to the audit completion, not the certificate issuance date.

Annual surveillance windows are calculated and displayed. For each active certification, Certiva shows the current surveillance window — the date range within which the next surveillance must be completed. This is not a manual entry; it is a system calculation based on the anchor date and the applicable rules.

Approaching deadlines trigger alerts. When a surveillance window is approaching — typically at 90 days, 60 days, and 30 days before the window closes — the planner receives alerts. These are not subtle indicators buried in a dashboard; they are active notifications that require acknowledgment.

Overdue surveillance flags the certification. If a surveillance window closes without a completed audit, Certiva flags the certification for suspension action. The system does not automatically suspend — that decision involves the CB's management — but it ensures the situation is visible and cannot be overlooked.

The full cycle is visible. For each client, the planner can see the complete certification timeline: Stage 2 date, each surveillance date (completed or upcoming), and the recertification date. The three-year cycle and the yearly surveillance windows are both tracked, not one at the expense of the other.

The Recertification Dimension

Surveillance tracking is only half the cycle management challenge. Recertification has its own timing requirements. The recertification audit must be completed and the certification decision made before the current certificate expires. If it is not, there is a gap in certification — the old certificate expires and the new one has not been issued.

Certiva tracks recertification deadlines alongside surveillance windows, ensuring that the planner has a complete view of all upcoming audit obligations for every client. The system calculates backward from the certificate expiry date to identify when the recertification audit must be scheduled to allow adequate time for report writing, committee review, and certificate issuance before expiry.

The Operational Discipline

Surveillance tracking is ultimately about operational discipline — ensuring that the CB meets its obligations to every client on every cycle, without exception. A single missed surveillance window does not just affect the client; it affects the CB's credibility with the accreditation body and, if it occurs during an AB assessment period, can result in a nonconformity finding.

The solution is not more vigilance from planners. Planners are busy, they manage dozens or hundreds of clients, and they are human. The solution is a system that calculates the dates, tracks the windows, issues the alerts, and flags the exceptions — so that the planner's job is to act on clear information rather than to generate it from raw data.