The Spreadsheet That Nobody Checked
Meridian Certifications is a small certification body with about 180 active certificates. Their operations planner, Aysel, manages surveillance scheduling in a spreadsheet. Each row contains the client name, the standard, the Stage 2 completion date, and the next surveillance due date. Aysel updates it weekly, highlights upcoming audits in yellow, and flags overdue ones in red.
In March, Aysel goes on medical leave. She emails the spreadsheet to her colleague Emre before she goes. Emre downloads it, opens it once, and gets pulled into a rush of Stage 2 audits that landed in the same month. The spreadsheet sits in his downloads folder.
The Certificate That Slipped
One of Meridian's clients, a packaging manufacturer called Yildiz Ambalaj, had their Stage 2 audit completed on April 15, 2025. Their first surveillance was due within twelve months -- by April 15, 2026. The surveillance window, accounting for the allowed flexibility, required the audit to be completed and the report finalized before that date.
Nobody scheduled it. Nobody noticed. On April 20, Meridian's quality manager realizes the surveillance window has passed. The certificate must be suspended. Yildiz Ambalaj calls, furious. They have a tender submission next week that requires a valid ISO 9001 certificate.
But it gets worse. During Meridian's next accreditation assessment, the assessor asks to see the surveillance tracking records. The suspended certificate is flagged. The assessor asks how it happened. The answer -- "our planner was on leave and the spreadsheet was not checked" -- generates a major nonconformity against Meridian's own management system.
Why Spreadsheets Fail for Surveillance Tracking
Surveillance scheduling is deceptively simple on the surface. Every certificate has a cycle: Stage 2, then surveillance 1 at roughly twelve months, surveillance 2 at roughly twenty-four months, then recertification at thirty-six months. It seems like a calendar task.
But the complexity compounds quickly:
- •Dates are anchored to Stage 2 completion, not to arbitrary calendar dates. If Stage 2 finishes on April 15, every subsequent surveillance is calculated from that anchor.
- •Multi-standard clients may have different cycle dates for different scopes if certifications were not issued simultaneously.
- •Transfer clients bring their own cycle dates from a previous CB, which may not align neatly.
- •Postponements and early audits shift subsequent dates.
- •The sheer volume of 180 certificates means there are surveillance events due almost every week.
A spreadsheet can list all of this. But it cannot alert anyone. It cannot enforce anything. It cannot stop a certificate from silently expiring. It relies entirely on a human being opening the file, scanning the rows, and taking action. When that human is unavailable, the system has no fallback.
How Certiva Prevents This
In Certiva, surveillance dates are not tracked in a separate spreadsheet. They are built into the certificate record itself.
Automatic Date Anchoring. When a Stage 2 audit is completed and a certificate is issued, Certiva automatically calculates the surveillance schedule. Surveillance 1 is anchored to the Stage 2 completion date, tracked at twelve months. Surveillance 2 at twenty-four months. Recertification at thirty-six months. These dates are part of the certificate lifecycle, not a planner's personal tracking system.
Countdown Visibility. Every certificate in the portfolio displays a surveillance countdown. Planners can see at a glance which certificates are approaching their surveillance window, which are within the window, and which are overdue. This is not a static snapshot -- it updates in real time as days pass.
Overdue Flagging. When a surveillance date passes without a completed audit, the system flags it automatically. This is not a gentle reminder -- it is a visible status change on the certificate record that planners, quality managers, and administrators can all see. The certificate's status reflects reality.
No Single Point of Failure. Because surveillance tracking is embedded in the platform rather than in a personal file, it does not depend on any single person. When Aysel goes on leave, the system does not go on leave with her. Emre can open Certiva and see the same surveillance dashboard. The quality manager can see it. Anyone with the appropriate access can see exactly which audits are due and which are overdue.
The Accreditation Consequence
Accreditation bodies expect certification bodies to have robust systems for maintaining certification. ISO/IEC 17021-1:2015 Clause 9.6 specifically addresses the obligation to monitor and maintain certifications through surveillance and recertification.
When an assessor finds a suspended certificate that resulted from a missed surveillance, they are not just looking at one mistake. They are evaluating whether the CB's system is adequate. A spreadsheet that one person maintains and nobody else checks is not an adequate system. It is a workaround.
Certiva provides the system that accreditation bodies expect to see: automated, visible, independent of any single person, and producing a clear audit trail of every surveillance cycle from initial scheduling through completion.
Meridian's problem was not that Aysel went on leave. It was that their surveillance tracking could not survive one person being unavailable for three weeks. That is not a personnel problem. That is a systems problem. And it has a systems solution.