Certificates do not fade; they expire on a date. This is the year as it actually runs once you hold a certificate or a recognition — what falls due, how far ahead it has to start, and the three places companies get caught.
For a company holding ISO certification, a BizSAFE level and a PDPA programme — which is most of our clients.
| When | What falls due | How far ahead to start |
|---|---|---|
| Every month | PDPA access and correction requests handled and logged; the data register kept current as staff and vendors change | Same month, before it becomes a backlog |
| Every year | ISO surveillance audit — a shorter check-up, not the full exam | Book the slot four weeks out; prepare two to three weeks out |
| Every year | Internal audit and management review, for the ISO system | Run three to four weeks before the surveillance audit |
| Every year | PDPA: policy review and the retention sweep — deleting what you no longer need | One week, scheduled rather than remembered |
| Year three | ISO recertification — a full audit again | Eight to ten weeks out, as for a first certification |
| Two months before expiry | BizSAFE renewal for Level 3 and above, submitted at least 60 days before the expiry date | Prepare evidence six weeks out; the WSH Council requires the application no later than 60 days before |
| When work changes, or every three years | Risk assessments reviewed — a legal duty under the WSH (Risk Management) Regulations | Whenever processes, equipment or sites change |
| Until roughly April 2029 | The transition window for ISO 14001:2015 certificates to the 2026 edition | At your next scheduled audit, not at the end of the window |
The point: Every date in this table is a consequence of something you already hold. We put the client-specific version of it in one calendar with names against each date, so the first time anyone thinks about it is not the week it expires.
Decide who owns the renewal, check the certificate date against the real expiry, and book the audit or prepare the application.
Evidence gathered: records complete, internal audit run, gaps closed. This is where a calm renewal is won or lost.
Submit. Renewals submitted at the last legal moment leave no room for a query, and a query means a lapse.
Renewal applications for Level 3 and above must be in at least two months before expiry. Miss it and the recognition lapses visibly, at exactly the moment a buyer looks.
The certificate does not lapse immediately, but the body's process does — and popular auditor slots are booked weeks out.
The data register, the legal register, the training matrix. All three are living documents, and an out-of-date one is the easiest finding an auditor can make.
We put your dates in a calendar and remind you ahead of each one as part of the work. What we cannot do is act on your behalf without your say-so — the person who signs the renewal is still you.
For BizSAFE, reinstatement goes through the WSH Council's process and approval is theirs to give. For ISO, a lapsed certificate usually means a fresh initial audit — which is why we treat a late date as an emergency, not a detail.
Partly. The internal audit, management review and PDPA review can be scheduled in the same week if that helps. The surveillance audit date is the body's to give, and the BizSAFE renewal date is fixed by the expiry.
Yes — the renewal deadline, the risk assessment review and the training records all apply, and the two-month rule is the one people miss.
That is what our support engagements are for. We will also tell you honestly when a company is capable of running its own calendar and does not need to pay us.
Checked at the source on 20 September 2026. If a rule changes, this page changes with it.
Give us the expiry dates for everything you hold — ISO, BizSAFE, DPO appointment, licence renewals — and we will build the calendar with the start dates that keep each one calm.