The steps

  1. 9 months out: schedule renewal planning meeting and confirm scope
  2. 6 months out: engage auditor and update all policies
  3. 3 months out: run a mock audit
  4. 2 months out: fix mock audit findings
  5. 1 month out: submit evidence
  6. Audit days: same playbook as initial audit
  7. Post-audit: close non-conformities within 90 days

Common mistakes to avoid

  • Treating renewal as a tick-box (auditors expect to see learning since last audit)
  • Not updating policies since initial audit
  • Skipping the mock audit