Outsourced quality manager

Management system maintenance

A certified management system doesn't sustain itself between audits: it demands tasks that repeat every year and someone to own them. Summum Calidad fills that role as an outsourced or shared quality manager working alongside your internal team, so the system never becomes shelf-ware.

Certification cycle3 years, with annual follow-up (ISO/IEC 17021-1)
Risk if abandonedMajor non-conformity and temporary suspension of the certificate
ModelOutsourced quality manager or shared with the internal team

Maintaining a management system isn't filing the manual away the day after certification. Between one audit and the next there are objectives to review, indicators to update, non-conformities to close and internal audits to schedule and run. When no one keeps that calendar going, the system becomes what the industry calls a shelf-ware system: correct-looking documents that don't reflect what the company actually does, and behind that expression sits a risk with a name in the standard: suspension (subclause 9.6.5.2).

The cycle the certification imposes is specific. Under ISO/IEC 17021-1:2015, subclause 9.1.3.2, the first certification cycle runs for three years from the decision to certify: surveillance audits are planned in the first and second year, and a recertification audit in the third, before the certificate expires. Each surveillance audit reviews a sample of the system, not the full scope, so what hasn't been touched in a year can reach the next visit unscathed, but it can also build up debt no one notices until it's too late.

The real risk has a name and a documented consequence. The very standard that governs certification bodies (subclause 9.6.5.2) obliges them to suspend a certificate when the client fails to meet the certification requirements or doesn't allow surveillance or recertification audits at the agreed frequency. Under suspension, the certification is temporarily invalid (9.6.5.3); if the reason isn't resolved within the usual period of up to six months the standard notes (subclause 9.6.5.4), the suspension turns into withdrawal or a reduction of the certificate's scope. A carelessly maintained system rarely loses its certificate overnight: it arrives at the surveillance audit with accumulated non-conformities that, if not closed in time, become that scenario.

The outsourced or shared quality manager fills exactly the gap that cycle leaves: sustaining the annual calendar, updating the risk matrix and the legal matrix, preparing the management review, following up open corrective actions and coordinating, without necessarily replacing, the internal audit programme. They arrive at the surveillance audit with the evidence ready, instead of rebuilding it the week before.

This service isn't the same as internal audit: internal audit is a scheduled milestone required by clause 9.2 of each standard, with its own calendar and its own report. Maintenance covers everything that happens around that milestone, throughout the twelve months of the year, including coordinating those same internal audits when contracted separately. And if the system being maintained is an integrated system across several standards, the calendar and the dashboard are sustained the same way, with more pieces to coordinate in the same management review.

At Summum Calidad we've supported management systems in Castilla y León and the Canary Islands since 2007; in that time we've added close to 200 certifications accompanied. The outsourced quality manager doesn't replace the certification body, which still decides whether to maintain, suspend or withdraw the certificate; our role is to make sure that moment never catches you with a neglected system.

The twelve-month template calendar

No two companies share exactly the same certification calendar, but most maintenance tasks repeat each year in a similar order. This is the template calendar we apply, later adjusted to each client's real surveillance audit month:

MonthTaskTypical owner
JanuaryReview of last year's objectives and setting new onesQuality manager
FebruaryRisk-and-opportunity matrix updateQuality manager + management
MarchAnnual internal audit schedulingQuality manager
AprilSpring internal audits carried outInternal auditor (in-house or outsourced)
MayClosing open non-conformities and corrective actionsProcess owners
JuneLegal requirements matrix updateQuality manager
JulyFirst-half indicator reviewManagement
AugustFollow-up of pending corrective actionsQuality manager
SeptemberPreparation for the year's surveillance or recertification auditQuality manager + certification body
OctoberSurveillance or recertification audit, depending on the cycle yearCertification body
NovemberClosing non-conformities found in the external auditProcess owners
DecemberAnnual management reviewManagement + quality manager

The month of the surveillance audit changes depending on when the company was certified: what doesn't change is that all twelve tasks have to run through the calendar, whether the audit falls in October or any other month.

In-house, outsourced or shared: which model fits

There's no single best model in the abstract: it depends on the company's size, how many standards it maintains and whether the certification body has already issued a warning.

ModelAdvantagesRisksWhen it fits
In-house (staff member)Deep knowledge of the business, immediate day-to-day availabilityTends to get absorbed by daily operations; complicates independence if they also run internal audits of their own systemCompanies with enough volume for real, not just nominal, dedication
Outsourced (Summum or another provider)Formal independence before the certification body, experience across several standards and sectorsRequires constant information transfer with the company; less daily on-site presenceSMEs without the volume for a full-time role, or that already received a warning for lack of follow-up
Shared (in-house + external support)Combines internal knowledge with a specialist's technical and calendar backingRequires clearly split responsibilities; if not well defined, commitment gets diluted between both sidesCompanies moving towards an in-house system, or managing several standards at once

The shared model is the one that most often ends up in mid-sized companies: an in-house person sustains day-to-day work and Summum Calidad provides the calendar, regulatory expertise and preparation for the external audit.

What happens if the system is left unattended

"Shelf-ware system" isn't an empty figure of speech: it describes a risk documented in the very standard that governs certification bodies. ISO/IEC 17021-1:2015 obliges suspension of certification when the client fails to meet the requirements, or doesn't allow surveillance or recertification audits at the agreed frequency (subclause 9.6.5.2). Under suspension, the certification is temporarily invalid: the company can't use it with clients or in tenders while it lasts (subclause 9.6.5.3).

Suspension isn't indefinite: in most cases it shouldn't exceed six months (subclause 9.6.5.4, note). If the reason isn't resolved within that period, it results in withdrawal of the certificate or a reduction of its scope (subclause 9.6.5.5). It's almost never reached all at once: the usual path starts with repeated minor non-conformities for lack of follow-up, moves to a major one once the pattern is confirmed, and only reaches suspension if that major finding isn't closed in time.

The certification cycle: surveillance and recertification

The cycle's clock starts on the day of the decision to certify, not the day of the stage 2 audit (ISO/IEC 17021-1:2015, subclause 9.1.3.2). From there, the certification body plans surveillance audits at least once every calendar year, except in recertification years (subclause 9.1.3.3): on-site visits that don't necessarily cover the whole system (subclause 9.6.2.2).

The recertification audit, in the third year, carries an intensity comparable to the initial stage 2 audit: it confirms the system remains effective, reviews the history of previous surveillance visits and, if there's a major non-conformity, requires it to be corrected before the certificate expires to renew it without interruption (subclause 9.6.3). Keeping the system alive across all three years, not just before each visit, is what turns that audit into a formality rather than a surprise.

The Management system maintenance process.

The process · four stages
01

Assessment of the real state

We review what has been kept alive in the system since the last audit and what has been left undone: unreviewed objectives, an outdated risk matrix, open non-conformities, pending internal audits.

02

Annual calendar and owners

We set the twelve-month calendar with the tasks for each certified standard, coordinated with your certification body's real surveillance and recertification cycle, not a generic calendar.

03

Month-by-month upkeep

We update objectives, indicators, the legal matrix and the risk matrix according to the agreed calendar, and coordinate the internal audit programme when the client contracts it as a separate service.

04

Support through the external audit

We prepare the evidence ahead of the surveillance or recertification audit, coordinate the visit with the auditor and manage the closure of any non-conformities within the deadline the certification body sets.

What is included

What Management system maintenance includes.

The operational detail: what we deliver as part of the work and what we keep alive afterwards.

  • Annual maintenance calendar

    Twelve months of tasks, milestones and assigned owners, tailored to each standard's real certification cycle.

  • Risk and context matrix update

    Reviewed at least once a year or whenever something relevant changes in the organisation: a new line, a new critical supplier, a new facility.

  • Tracking of objectives and indicators

    A living dashboard, reviewed periodically, not a document signed once a year for the audit.

  • Coordination of the management review

    Convening, documented inputs (audit results, non-conformities, context changes) and recorded outputs in line with subclause 9.3.

  • Link to the internal audit programme

    Coordination of calendar and scope with our internal audit service when the client contracts it as an independent service.

  • Preparation for the surveillance or recertification audit

    Evidence organised and available before the external auditor arrives, with prior non-conformities already closed or with a documented closure plan.

Marco normativo

The regulatory framework

Normas y reglamentos verificados que aplican a este servicio: ISO/IEC 17021-1:2015, subclause 9.1.3.2, ISO/IEC 17021-1:2015, subclauses 9.6.2 and 9.6.3, ISO/IEC 17021-1:2015, subclause 9.6.5….

ISO ISO/IEC 17021-1:2015, subclause 9.1.3.2 Sets the certification cycle at three years from the decision to certify, with surveillance audits in the first and second year and a recertification audit in the third.
ISO ISO/IEC 17021-1:2015, subclauses 9.6.2… Governs the content of surveillance audits (a sample of the system, not the full scope) and of the recertification audit (intensity comparable to the initial stage 2 audit).
ISO ISO/IEC 17021-1:2015, subclause 9.6.5 Obliges the certification body to suspend, withdraw or reduce the scope of certification when the client fails to meet the requirements or doesn't allow surveillance audits at the agreed frequency.
ISO ISO 19011:2026 Guidance for auditing management systems (fourth edition, published in May 2026, replacing the 2018 edition); expands guidance on auditor competence and audit programme planning, including internal audits.
CERTIF Certifiable management standards (e.g.… Require a planned internal audit programme and a periodic management review as part of the system itself, not as an external requirement from the certification body.

Frequently asked questions about Management system maintenance.

What's the difference between this service and internal audit?

Internal audit is a scheduled milestone: a visit with its own scope and calendar required by clause 9.2 of each standard. Maintenance covers what happens around that milestone the rest of the year: objectives, indicators, the risk matrix and the management review. They can be contracted together or separately.

How often is there a surveillance audit from the certification body?

Generally, once a year in the first and second year of the three-year cycle, and a recertification audit in the third year, before the certificate expires (ISO/IEC 17021-1:2015, subclause 9.1.3.2). Each certification body may adjust the calendar according to sector risk or the results of previous audits.

What happens if the surveillance audit arrives and we haven't run the required internal audits?

It's a frequent cause of non-conformity. The standard requires suspending certification when the client fails to meet the required requirements (ISO/IEC 17021-1:2015, subclause 9.6.5.2), and not keeping the internal audit programme up to date is one of them. If it's corrected before the visit, it usually doesn't reach that extreme; the problem appears after several cycles without an audit.

Can an outsourced quality manager sign off the management review?

No. It's the responsibility of the company's top management and cannot be delegated to an external provider. The outsourced quality manager prepares the inputs (audit results, indicators, non-conformities), convenes the meeting and documents management's outputs and decisions.

How long can a certificate stay suspended before it's lost for good?

The standard doesn't set a single deadline, but it notes that in most cases suspension shouldn't exceed six months (ISO/IEC 17021-1:2015, subclause 9.6.5.4, note). If the reason isn't resolved within that period, the certification is withdrawn or its scope reduced.

Does maintenance work the same way for an integrated system covering several standards?

Yes, and it's usually needed even more as the system covers more standards: there are more indicators and more parts of the management review to coordinate in the same meeting. The calendar and the dashboard are built once for the whole system, with more pieces inside.

What happens if we switch certification body halfway through the three-year cycle?

It's an operational decision for the company: the new body will review the history of previous audits and decide how the cycle continues. Keeping the system up to date, with the calendar, indicators and non-conformities closed, makes that handover easier, whichever body is chosen.

What does ISO 27001 maintenance (and ISO 9001 maintenance) involve?

ISO 27001 maintenance reviews, every year, the information asset risk matrix, the Annex A controls affected by technical changes and the security incident log. ISO 9001 maintenance focuses on quality objectives, product or service non-conformities and customer satisfaction. In both cases the calendar, the internal audit and the management review are the same process; what changes is the technical content specific to each standard.