kis.group

Keeping Your ISO Compliance System Current

Keeping Your ISO Compliance System Current

The surveillance auditor who visits twelve months after certification is focused on one thing: whether your system has been maintained, updated and actually used since you were first certified. Most WHSEQ systems that fall over between audits do not fail because the original build was poor. They fail because nobody owned the ongoing work clearly enough.

Why ISO Systems Drift After the Initial Certification Audit

The gap between certification and first surveillance is typically twelve months, which is long enough for real drift to accumulate. Legislation changes, new contractors come on site, a process gets modified without a document revision, and the risk register that was current in the certification year quietly goes stale. Auditors are experienced at spotting this pattern: current looking documents with version dates that stop at certification.

Common causes of drift include staff turnover in the person who owned the system, no scheduled review cycle built into the calendar, and documentation controls that rely on individual memory rather than a formal version control process. Each of those is fixable with the right structure in place before drift starts. KIS Group has spent more than 10 years building ISO compliant WHSEQ systems across Australia, New Zealand, Singapore, South Africa and Ireland, specifically to be maintainable after go live, and that experience consistently surfaces the same failure points when ongoing structure is absent.

What Does an Ongoing Maintenance Schedule Actually Look Like?

A working maintenance schedule has three layers: continuous, periodic and triggered.

Building all three layers into a Donesafe based system means the reminders, workflows and evidence capture happen inside the platform rather than relying on a spreadsheet someone may or may not check.

How Often Should You Review Policies and Procedures?

ISO 45001, ISO 9001 and ISO 14001 do not specify a universal review frequency. What they require is that documents are controlled and remain appropriate to the organisation. In practice that means you need a documented review schedule, evidence that reviews actually happened, and a record of what changed and why. A review with no changes still needs to be recorded, or it looks like the review never happened. That last point catches organisations out regularly.

The right review frequency for any individual procedure depends on how stable the underlying activity is and the level of risk it involves. High risk procedures and those tied to activities that change frequently warrant more regular attention than stable, lower risk ones. Your review schedule should reflect that risk based thinking rather than applying a single timeframe across all documents.

Version control built into your documentation system, rather than managed through file naming conventions on a shared drive, is the difference between a clean audit trail and a confusing one.

What Happens If You Miss a Surveillance Audit Requirement?

Missing a surveillance audit, or arriving at one with a system that cannot demonstrate ongoing maintenance, puts your certificate at risk. The typical sequence is a major non-conformance finding, a corrective action period and then a follow up assessment at your cost. If non-conformances are serious enough, or corrective actions are not addressed within the agreed timeframe, the certificate can be suspended or withdrawn. Returning to recertification from a withdrawn certificate means repeating the full initial certification process, which is a significantly larger investment of time and money than keeping the existing certificate current through steady maintenance.

Beyond the certificate itself, a lapsed system creates real liability exposure. ISO 45001 in particular is often referenced in contracts, insurance policies and tenders. Losing it mid-contract or at renewal can carry commercial consequences well beyond the audit fee.

Legislation Changes: The Maintenance Task Most Teams Underestimate

Across the five markets KIS serves, work health and safety legislation evolves continuously. Requirements in Australia, New Zealand, Singapore, South Africa and Ireland are each subject to new guidance, updated codes of practice and enforcement decisions that can affect your documented procedures and risk assessments without any change to the core standard you are certified against. An ISO 45001 or ISO 14001 system that does not reflect current legal requirements in the jurisdictions where you operate carries a gap that an external auditor will find.

The practical approach is to nominate someone to monitor legislative updates for each jurisdiction your operations touch, connect those updates to a formal change management process in your system, and document the assessment of whether a change affects your procedures or risk assessments. That process should be visible in your system as evidence, not sitting in someone's email inbox. To discuss how this is structured inside a live system, you can reach KIS directly on AU 1800 544 690.

Should You Use a Consultant for Ongoing Maintenance or Build Internal Capacity?

Both approaches work, and the right answer depends on your team's bandwidth and expertise. Many organisations find a hybrid model most practical: internal staff own the day to day system use and basic document updates, while a specialist partner handles legislative monitoring, management review facilitation, internal audit programs and any structural changes when the business changes significantly.

The risk with a fully internal model is that the person who built the system leaves, and the institutional knowledge about why things were structured the way they were goes with them. The risk with a fully outsourced model is that the system becomes opaque to internal staff, which shows up in audits when the auditor asks a team member to explain a procedure and they cannot.

KIS Group's approach to ISO compliant WHSEQ systems is built around this principle: the system is designed for internal ownership from the outset, with documentation controls, audit schedules and review workflows that your team can actually run, supported by specialist input when you need it.

Keeping Donesafe Based Systems Current

For organisations running Donesafe as the operational backbone of their WHSEQ system, platform maintenance adds another layer to the calendar. As your operational needs change over time, module configurations may need adjustment. Scheduled inspection and audit templates need reviewing when the underlying procedure changes. Workflow logic needs testing when staff roles or approval structures change.

A Donesafe implementation that is not maintained tends to accumulate workarounds: staff bypass steps they find confusing, custom fields get repurposed for things they were not designed for, and the data that comes out of the system becomes unreliable. Reliable data is the whole point, particularly for management reviews and the kind of trend analysis that demonstrates a functioning safety management system to an auditor. The homepage of KIS Group notes that organisations running a properly built and maintained system see 62% less admin time on reporting. That figure reflects how much a well structured Donesafe configuration can reduce the manual effort that otherwise consumes compliance teams in the lead up to each audit cycle.

Building a Practical Review Calendar Before Your Next Audit Cycle

The most useful thing you can do immediately after certification is build a twelve month review calendar and put it in your system rather than in someone's notebook. That calendar should include at minimum: the date your next surveillance audit falls, the management review meeting date scheduled well before the audit, the internal audit schedule covering all processes within scope, and the document review dates for your highest risk procedures.

Map the legislative monitoring tasks against that calendar as well, assigning a named person and a review date. If your Donesafe configuration includes automated reminders for audit schedules and corrective action due dates, make sure those are tested and that the right people receive the notifications. The combination of a clear calendar, automated reminders and a named owner for each maintenance task is what separates organisations that find surveillance audits straightforward from those that find them stressful.

Frequently Asked Questions

Can my ISO certificate be suspended without warning?

Suspension without prior notice is uncommon. The typical process involves a finding of major non-conformances at a surveillance or recertification audit, followed by a defined corrective action period. If corrective actions are not closed out within the agreed timeframe, the certification body can suspend and ultimately withdraw the certificate. The practical warning is the audit outcome itself. Keeping your maintenance schedule current is what prevents that outcome.

How much does a surveillance audit cost?

Surveillance audit fees vary by certification body, the number of standards you hold, your organisation's size and the number of sites in scope. KIS Group does not set those fees, as they are charged directly by your chosen certification body. What KIS can affect is your preparation cost and the risk of a costly follow up assessment by ensuring your system is audit ready throughout the certification cycle, not just in the weeks before the auditor arrives.

What is the difference between a surveillance audit and a recertification audit?

A surveillance audit is a periodic check, typically annual, that your certified system continues to meet the standard. It covers a portion of your system rather than the full scope. A recertification audit occurs at the end of the three year certification cycle and covers the full scope again, effectively renewing the certificate. Both require evidence of ongoing maintenance, but recertification is more comprehensive and typically takes longer.

Do we need a consultant if we already have Donesafe configured?

Having Donesafe in place is a strong foundation, but the platform itself does not maintain your compliance system. Procedures still need reviewing, legislative changes still need assessing, internal audits still need conducting and management reviews still need facilitating. A consultant adds value when your internal team lacks the time or specialist knowledge to do those things consistently, or when your business changes in ways that affect your system's scope or structure.

What does KIS Group's ongoing support actually cover, and how do I find out what it would cost for our organisation?

KIS Group offers ongoing build and support services for WHSEQ systems and Donesafe implementations, covering tasks such as document reviews, legislative monitoring, internal audit facilitation, management review support and platform configuration updates. The scope and cost of a support engagement depends on your organisation's size, the standards you hold, the number of jurisdictions you operate in and how much of the ongoing work your internal team handles. The most direct way to understand what a support arrangement would look like for your situation is to book a free consultation or call AU 1800 544 690.

All articles

kis.group