A 36-month governance cycle moves through three distinct phases: build, maintain, and renew. In year one, organisations establish the foundational structures, policies, and controls needed to achieve certification. Years two and three shift focus to continuous monitoring, evidence collection, and incremental improvement, culminating in a recertification audit that resets the cycle. This pattern applies across frameworks including ISO 27001, ISO 42001, NIS2, and GDPR, all of which align to roughly three-year certification or review windows. The sections below unpack each phase, the risks in between, and who should be responsible throughout. If you have questions about how this applies to your organisation, feel free to get in touch with us at any point.

Why is 36 months the standard length for governance cycles?

Thirty-six months is the standard governance cycle length because most major certification bodies, including ISO, set their surveillance and recertification schedules on a three-year basis. ISO 27001 and ISO 42001 both require an initial certification audit followed by two annual surveillance audits and a full recertification in year three. This rhythm reflects the practical reality that governance frameworks take time to embed, mature, and demonstrate sustained effectiveness across an organisation.

The 36-month window is not arbitrary. It balances two competing needs: long enough for organisations to demonstrate genuine operational maturity rather than a one-time compliance sprint, and short enough to ensure frameworks stay current as threats, regulations, and business models evolve. A three-year cycle also aligns with typical strategic planning horizons, making it easier to integrate governance investment into budget and resource planning.

Regulatory frameworks like NIS2 and DORA reinforce this rhythm by requiring periodic reviews of security measures and risk assessments. GDPR, while not tied to a fixed audit cycle, expects organisations to maintain demonstrable compliance on an ongoing basis, which in practice means structured annual reviews. When you plan governance as a continuous three-year programme rather than a series of disconnected projects, certification becomes a natural outcome rather than a disruptive event.

What governance activities happen in year one?

Year one focuses on building the governance foundation: scoping the framework, conducting gap analyses, establishing policies and procedures, assigning roles and responsibilities, and completing the initial certification audit. This is the most resource-intensive phase of the cycle because organisations are creating structures that do not yet exist, or formalising practices that have been informal.

Foundation setting in the first six months

The first half of year one is typically consumed by discovery and design. This means defining the scope of the management system, identifying applicable legal and regulatory requirements, conducting a formal risk assessment, and documenting the control framework. For ISO 27001, this includes producing a Statement of Applicability. For AI governance under ISO 42001, it means mapping AI systems and their associated risks. These outputs form the backbone of everything that follows.

Preparation and certification audit in months seven to twelve

The second half of year one shifts to implementation and evidence. Policies need to be communicated and understood. Controls need to be operational and demonstrably so. Internal audits must be completed, and a management review must take place before the certification body conducts its stage one and stage two audits. Organisations that underestimate the evidence-gathering burden in this phase often find themselves scrambling in the final weeks before the audit.

How does governance maintenance work in years two and three?

Governance maintenance in years two and three operates on a rhythm of continuous monitoring, scheduled reviews, and incremental improvement. The certification body conducts annual surveillance audits, which assess whether the management system remains effective and whether nonconformities from the previous cycle have been addressed. Internally, organisations should run quarterly control reviews, annual risk assessments, and regular internal audits to stay audit-ready at all times.

The common mistake organisations make in years two and three is treating maintenance as passive. Once the initial certification is achieved, momentum often drops. Teams return to operational priorities, governance documentation goes unupdated, and evidence collection becomes inconsistent. By the time the recertification audit arrives in year three, organisations find themselves rebuilding rather than renewing.

Effective maintenance means treating governance as an operational function rather than a project. This involves assigning clear owners to each control, scheduling recurring review activities in advance, and tracking exceptions and improvements through a structured process. Continuous governance is not about doing more work than necessary, it is about distributing the work evenly across the full 36 months so that no single period becomes a crisis.

Our governance services are structured precisely around this maintenance challenge, providing the ongoing expert oversight that keeps organisations audit-ready throughout the full cycle rather than only in the weeks before an audit.

What causes governance drift between certification cycles?

Governance drift occurs when the documented management system falls out of alignment with how the organisation actually operates. The most common causes are organisational change, resource attrition, and the absence of structured review cadences. When people leave, processes evolve, or new technologies are adopted without updating the governance framework, the gap between what is documented and what is real grows steadily wider.

Drift is particularly dangerous because it is invisible until it is tested. An organisation can appear compliant on paper while running significant unmanaged risks in practice. Surveillance auditors and regulatory inspectors are specifically trained to identify this gap through interviews, evidence sampling, and process walkthroughs. Organisations that have experienced drift often receive major nonconformities in surveillance audits, which can jeopardise certification status.

The triggers for drift are predictable. A merger or acquisition changes the risk landscape without triggering a governance review. A key compliance officer leaves and their institutional knowledge is not transferred. A new software platform is deployed without a privacy impact assessment. An AI tool is adopted without assessing it against the AI governance framework. Each of these events is a drift event, and without a system that flags and captures them, they accumulate silently across the cycle.

Preventing drift requires two things: a trigger-based review process that activates when significant changes occur, and a baseline monitoring process that checks the health of controls on a regular schedule regardless of whether anything has changed. Both are necessary because drift can result from change and from stagnation equally.

Who should own governance activities across the full cycle?

Governance ownership should be distributed across three levels: management, operational leads, and a dedicated governance function. Management owns the strategic commitment, resource allocation, and formal review outputs. Operational leads own the controls and processes within their domains. The governance function, whether internal or external, owns the system architecture, audit readiness, and continuous oversight across the full 36-month cycle.

A common structural weakness is concentrating governance ownership in a single person, often a compliance manager or CISO, without embedding accountability into the wider organisation. When that individual leaves or is stretched across too many responsibilities, the governance system loses its operational coherence. Role-based accountability, where responsibilities attach to roles rather than individuals, is far more resilient.

Management ownership is particularly important and often underestimated. ISO management system standards explicitly require top management to demonstrate leadership and commitment, not just sign off on a policy document. This means participating in management reviews, acting on audit findings, and making resourcing decisions that reflect genuine prioritisation of governance. Organisations where management treats governance as a delegated administrative task consistently underperform in certification audits compared to those where leadership is actively engaged.

For organisations that do not have the internal capacity to sustain a dedicated governance function across the full cycle, a hybrid model combining in-house ownership with external expert support provides the continuity and expertise that neither a pure internal team nor a periodic consultancy engagement can deliver alone.

What happens across a 36-month governance cycle?

Across a full 36-month governance cycle, an organisation moves from initial framework design and certification in year one, through active maintenance and surveillance in years two and three, to recertification and cycle renewal at month 36. Each phase has distinct activities, risk profiles, and resource demands. The cycle is not linear in effort: year one is the most intensive, but years two and three carry the highest risk of drift if governance is not actively maintained.

The practical shape of the cycle looks like this:

  • Months 1 to 6: Scoping, gap analysis, risk assessment, policy development, and control design
  • Months 7 to 12: Control implementation, internal audit, management review, and initial certification audit
  • Months 13 to 24: Operational monitoring, first surveillance audit, nonconformity management, and improvement activities
  • Months 25 to 36: Continued monitoring, second surveillance audit, recertification preparation, and cycle renewal

What makes this cycle work in practice is not the activities themselves but the consistency with which they are executed. Governance that operates as a living system, with defined owners, structured review cadences, and proactive change management, produces organisations that are genuinely resilient rather than periodically compliant. The 36-month cycle is the container; continuous governance is what fills it with meaning.

If you want to understand how a structured governance cycle could work for your organisation across security, privacy, quality, or AI, get in touch with us and we will help you map out the right approach.

Frequently Asked Questions

How do we handle a mid-cycle framework change, such as moving from ISO 27001:2013 to ISO 27001:2022?

A major framework revision effectively resets portions of your governance cycle, requiring a gap analysis against the new standard, updates to your control set and documentation, and confirmation from your certification body on transition timelines. ISO set a formal transition deadline for the 2022 revision, and organisations that missed it had their certifications withdrawn. The practical advice is to treat any significant standard update as a mini year-one exercise within your current cycle: scope the delta, assign owners, and build the transition work into your existing review cadences rather than treating it as a separate project.

What is the minimum internal resource commitment needed to sustain a governance cycle without external support?

At a minimum, you need one dedicated role with sufficient protected time — typically at least 50% of a full-time equivalent for a mid-sized organisation — supported by named control owners across each operational domain. Without protected time, governance tasks are consistently deprioritised in favour of operational work, which is one of the most reliable predictors of drift. If your organisation cannot commit that level of internal resource, a hybrid model combining a lighter internal ownership structure with external expert oversight is usually more cost-effective than hiring a full-time resource who then becomes a single point of failure.

How should we manage governance across multiple frameworks simultaneously, such as ISO 27001 and GDPR or ISO 42001?

The most efficient approach is an integrated management system that maps shared controls across frameworks rather than running separate compliance programmes in parallel. ISO 27001 and ISO 42001 share a common High Level Structure, meaning their policy, risk, audit, and management review requirements can largely be unified into a single operational rhythm. GDPR obligations, including data protection impact assessments and records of processing activities, can be embedded into the same review cadences. The upfront investment in integration pays back quickly through reduced duplication, fewer audit events, and a more coherent governance narrative for stakeholders.

What are the most common reasons organisations fail their surveillance audits in years two and three?

The three most frequent causes of surveillance audit failures are incomplete or outdated documentation, evidence gaps where controls are operational but not recorded, and unresolved nonconformities from the previous audit cycle. Auditors specifically look for continuity of evidence — they want to see that monitoring has been happening consistently, not that activity was reconstructed in the weeks before their visit. A fourth and increasingly common cause is undocumented organisational change, such as new systems, restructured teams, or expanded scope that was never formally assessed against the management system.

How far in advance should we start preparing for the year three recertification audit?

Recertification preparation should begin no later than month 30, giving you a six-month runway to complete a full internal audit, conduct a management review, close any open nonconformities, and refresh documentation that may have drifted since the initial certification. Organisations that start preparing at month 33 or 34 consistently find themselves in a reactive, high-pressure situation that undermines both audit performance and team confidence. If your governance has been maintained effectively throughout years two and three, month 30 preparation is largely a consolidation exercise rather than a rebuild — which is precisely the outcome a well-run continuous governance programme is designed to produce.

Can we scope down our management system after initial certification if the original scope was too broad?

Yes, scope changes are permissible but must be formally agreed with your certification body and documented with a clear rationale. Narrowing scope after certification is sometimes the right decision — for example, if a business unit was divested or if the original scope was set aspirationally rather than operationally. However, certification bodies will scrutinise scope reductions carefully to ensure they do not represent an attempt to exclude problematic areas from oversight. Any scope change should be accompanied by an updated Statement of Applicability, a revised risk assessment, and a formal management review decision.

How do we keep senior leadership engaged with governance after the initial certification excitement fades?

Sustained leadership engagement requires connecting governance outcomes to business language rather than compliance language. Presenting surveillance audit results, risk register changes, and control effectiveness metrics in terms of operational risk, customer trust, and commercial exposure is far more effective than reporting on clause conformity. Structured management reviews, which ISO standards require at least annually, are the formal mechanism for this — but the most effective organisations use them as genuine strategic conversations rather than sign-off exercises. Tying governance performance to leadership objectives or board reporting cycles also helps ensure that attention does not evaporate once the certification certificate is framed on the wall.

Related Articles

Share