Assessment of the real state
We review what has been kept alive in the system since the last audit and what has been left undone: unreviewed objectives, an outdated risk matrix, open non-conformities, pending internal audits.
A certified management system doesn't sustain itself between audits: it demands tasks that repeat every year and someone to own them. Summum Calidad fills that role as an outsourced or shared quality manager working alongside your internal team, so the system never becomes shelf-ware.
Maintaining a management system isn't filing the manual away the day after certification. Between one audit and the next there are objectives to review, indicators to update, non-conformities to close and internal audits to schedule and run. When no one keeps that calendar going, the system becomes what the industry calls a shelf-ware system: correct-looking documents that don't reflect what the company actually does, and behind that expression sits a risk with a name in the standard: suspension (subclause 9.6.5.2).
The cycle the certification imposes is specific. Under ISO/IEC 17021-1:2015, subclause 9.1.3.2, the first certification cycle runs for three years from the decision to certify: surveillance audits are planned in the first and second year, and a recertification audit in the third, before the certificate expires. Each surveillance audit reviews a sample of the system, not the full scope, so what hasn't been touched in a year can reach the next visit unscathed, but it can also build up debt no one notices until it's too late.
The real risk has a name and a documented consequence. The very standard that governs certification bodies (subclause 9.6.5.2) obliges them to suspend a certificate when the client fails to meet the certification requirements or doesn't allow surveillance or recertification audits at the agreed frequency. Under suspension, the certification is temporarily invalid (9.6.5.3); if the reason isn't resolved within the usual period of up to six months the standard notes (subclause 9.6.5.4), the suspension turns into withdrawal or a reduction of the certificate's scope. A carelessly maintained system rarely loses its certificate overnight: it arrives at the surveillance audit with accumulated non-conformities that, if not closed in time, become that scenario.
The outsourced or shared quality manager fills exactly the gap that cycle leaves: sustaining the annual calendar, updating the risk matrix and the legal matrix, preparing the management review, following up open corrective actions and coordinating, without necessarily replacing, the internal audit programme. They arrive at the surveillance audit with the evidence ready, instead of rebuilding it the week before.
This service isn't the same as internal audit: internal audit is a scheduled milestone required by clause 9.2 of each standard, with its own calendar and its own report. Maintenance covers everything that happens around that milestone, throughout the twelve months of the year, including coordinating those same internal audits when contracted separately. And if the system being maintained is an integrated system across several standards, the calendar and the dashboard are sustained the same way, with more pieces to coordinate in the same management review.
At Summum Calidad we've supported management systems in Castilla y León and the Canary Islands since 2007; in that time we've added close to 200 certifications accompanied. The outsourced quality manager doesn't replace the certification body, which still decides whether to maintain, suspend or withdraw the certificate; our role is to make sure that moment never catches you with a neglected system.
No two companies share exactly the same certification calendar, but most maintenance tasks repeat each year in a similar order. This is the template calendar we apply, later adjusted to each client's real surveillance audit month:
| Month | Task | Typical owner |
|---|---|---|
| January | Review of last year's objectives and setting new ones | Quality manager |
| February | Risk-and-opportunity matrix update | Quality manager + management |
| March | Annual internal audit scheduling | Quality manager |
| April | Spring internal audits carried out | Internal auditor (in-house or outsourced) |
| May | Closing open non-conformities and corrective actions | Process owners |
| June | Legal requirements matrix update | Quality manager |
| July | First-half indicator review | Management |
| August | Follow-up of pending corrective actions | Quality manager |
| September | Preparation for the year's surveillance or recertification audit | Quality manager + certification body |
| October | Surveillance or recertification audit, depending on the cycle year | Certification body |
| November | Closing non-conformities found in the external audit | Process owners |
| December | Annual management review | Management + quality manager |
The month of the surveillance audit changes depending on when the company was certified: what doesn't change is that all twelve tasks have to run through the calendar, whether the audit falls in October or any other month.
There's no single best model in the abstract: it depends on the company's size, how many standards it maintains and whether the certification body has already issued a warning.
| Model | Advantages | Risks | When it fits |
|---|---|---|---|
| In-house (staff member) | Deep knowledge of the business, immediate day-to-day availability | Tends to get absorbed by daily operations; complicates independence if they also run internal audits of their own system | Companies with enough volume for real, not just nominal, dedication |
| Outsourced (Summum or another provider) | Formal independence before the certification body, experience across several standards and sectors | Requires constant information transfer with the company; less daily on-site presence | SMEs without the volume for a full-time role, or that already received a warning for lack of follow-up |
| Shared (in-house + external support) | Combines internal knowledge with a specialist's technical and calendar backing | Requires clearly split responsibilities; if not well defined, commitment gets diluted between both sides | Companies moving towards an in-house system, or managing several standards at once |
The shared model is the one that most often ends up in mid-sized companies: an in-house person sustains day-to-day work and Summum Calidad provides the calendar, regulatory expertise and preparation for the external audit.
"Shelf-ware system" isn't an empty figure of speech: it describes a risk documented in the very standard that governs certification bodies. ISO/IEC 17021-1:2015 obliges suspension of certification when the client fails to meet the requirements, or doesn't allow surveillance or recertification audits at the agreed frequency (subclause 9.6.5.2). Under suspension, the certification is temporarily invalid: the company can't use it with clients or in tenders while it lasts (subclause 9.6.5.3).
Suspension isn't indefinite: in most cases it shouldn't exceed six months (subclause 9.6.5.4, note). If the reason isn't resolved within that period, it results in withdrawal of the certificate or a reduction of its scope (subclause 9.6.5.5). It's almost never reached all at once: the usual path starts with repeated minor non-conformities for lack of follow-up, moves to a major one once the pattern is confirmed, and only reaches suspension if that major finding isn't closed in time.
The cycle's clock starts on the day of the decision to certify, not the day of the stage 2 audit (ISO/IEC 17021-1:2015, subclause 9.1.3.2). From there, the certification body plans surveillance audits at least once every calendar year, except in recertification years (subclause 9.1.3.3): on-site visits that don't necessarily cover the whole system (subclause 9.6.2.2).
The recertification audit, in the third year, carries an intensity comparable to the initial stage 2 audit: it confirms the system remains effective, reviews the history of previous surveillance visits and, if there's a major non-conformity, requires it to be corrected before the certificate expires to renew it without interruption (subclause 9.6.3). Keeping the system alive across all three years, not just before each visit, is what turns that audit into a formality rather than a surprise.
We review what has been kept alive in the system since the last audit and what has been left undone: unreviewed objectives, an outdated risk matrix, open non-conformities, pending internal audits.
We set the twelve-month calendar with the tasks for each certified standard, coordinated with your certification body's real surveillance and recertification cycle, not a generic calendar.
We update objectives, indicators, the legal matrix and the risk matrix according to the agreed calendar, and coordinate the internal audit programme when the client contracts it as a separate service.
We prepare the evidence ahead of the surveillance or recertification audit, coordinate the visit with the auditor and manage the closure of any non-conformities within the deadline the certification body sets.
The operational detail: what we deliver as part of the work and what we keep alive afterwards.
Annual maintenance calendar
Twelve months of tasks, milestones and assigned owners, tailored to each standard's real certification cycle.
Risk and context matrix update
Reviewed at least once a year or whenever something relevant changes in the organisation: a new line, a new critical supplier, a new facility.
Tracking of objectives and indicators
A living dashboard, reviewed periodically, not a document signed once a year for the audit.
Coordination of the management review
Convening, documented inputs (audit results, non-conformities, context changes) and recorded outputs in line with subclause 9.3.
Link to the internal audit programme
Coordination of calendar and scope with our internal audit service when the client contracts it as an independent service.
Preparation for the surveillance or recertification audit
Evidence organised and available before the external auditor arrives, with prior non-conformities already closed or with a documented closure plan.
Normas y reglamentos verificados que aplican a este servicio: ISO/IEC 17021-1:2015, subclause 9.1.3.2, ISO/IEC 17021-1:2015, subclauses 9.6.2 and 9.6.3, ISO/IEC 17021-1:2015, subclause 9.6.5….
Maintenance relies on internal audit to meet clause 9.2 and, when the maintained system covers several standards at once, it's coordinated with integration; when the company also needs a broader compliance officer, that role is covered by Summum Consultoría.
The internal audits required by clause 9.2 of each standard can be contracted as an independent service, coordinated with the maintenance calendar.
View service → calidadAn integrated system spanning several standards needs the same ongoing maintenance, with a unified calendar and dashboard for every standard at once.
View service → consultoríaWhen the company also needs to outsource broader regulatory compliance, beyond the ISO management system, Summum Consultoría covers that role with the same outsourced or shared dedication model.
View service →Internal audit is a scheduled milestone: a visit with its own scope and calendar required by clause 9.2 of each standard. Maintenance covers what happens around that milestone the rest of the year: objectives, indicators, the risk matrix and the management review. They can be contracted together or separately.
Generally, once a year in the first and second year of the three-year cycle, and a recertification audit in the third year, before the certificate expires (ISO/IEC 17021-1:2015, subclause 9.1.3.2). Each certification body may adjust the calendar according to sector risk or the results of previous audits.
It's a frequent cause of non-conformity. The standard requires suspending certification when the client fails to meet the required requirements (ISO/IEC 17021-1:2015, subclause 9.6.5.2), and not keeping the internal audit programme up to date is one of them. If it's corrected before the visit, it usually doesn't reach that extreme; the problem appears after several cycles without an audit.
No. It's the responsibility of the company's top management and cannot be delegated to an external provider. The outsourced quality manager prepares the inputs (audit results, indicators, non-conformities), convenes the meeting and documents management's outputs and decisions.
The standard doesn't set a single deadline, but it notes that in most cases suspension shouldn't exceed six months (ISO/IEC 17021-1:2015, subclause 9.6.5.4, note). If the reason isn't resolved within that period, the certification is withdrawn or its scope reduced.
Yes, and it's usually needed even more as the system covers more standards: there are more indicators and more parts of the management review to coordinate in the same meeting. The calendar and the dashboard are built once for the whole system, with more pieces inside.
It's an operational decision for the company: the new body will review the history of previous audits and decide how the cycle continues. Keeping the system up to date, with the calendar, indicators and non-conformities closed, makes that handover easier, whichever body is chosen.
ISO 27001 maintenance reviews, every year, the information asset risk matrix, the Annex A controls affected by technical changes and the security incident log. ISO 9001 maintenance focuses on quality objectives, product or service non-conformities and customer satisfaction. In both cases the calendar, the internal audit and the management review are the same process; what changes is the technical content specific to each standard.