Your ISO 9001 certificate is valid for three years. This is the number everyone plans around: the recertification date goes in the calendar, the surveillance audits get scheduled, and the quality function organises its year against it.
Now consider the evidence that certificate rests on. A calibration certificate is good for six or twelve months. A training record is valid until the work instruction it covers gets revised — which might be next Tuesday. A supplier's ISO certificate expires on their cycle, not yours. A process validation holds until someone changes a parameter. A risk assessment reflects a product configuration that shipped four design changes ago.
None of these things announce their own expiry. They simply stop being true, quietly, at different rates, in different systems, owned by different people. And the gap between a three-year certificate and evidence with a fourteen-month average half-life is where most surveillance audit findings actually come from.
This is evidence decay — a term the GRC world has used for years, and one of the most predictable problems in quality management as well as one of the least systematically managed. The reason is worth understanding: every individual piece of it is somebody's job, and the aggregate is nobody's.
Three ways evidence goes stale
Not all decay works the same way, and the differences determine what you can do about it.
Dated expiry is the easy class. The artefact carries an expiry date on its face: calibration due, certificate valid until, licence renewal, competence requalification. It is visible, it is schedulable, and most organisations handle it reasonably well — usually with a spreadsheet and a person who remembers. The failure mode here is capacity, not visibility. You know the date is coming; you just do not get to it.
Silent invalidation is the dangerous class, and it accounts for most of the damage. The record itself did not expire. Something changed underneath it, and the change invalidated it without touching it. A work instruction is revised from rev C to rev D — every training record against rev C is now, strictly, evidence of training on a superseded document. An operator moves to a different line. A supplier relocates a process to a second plant. A gauge is replaced with a different model. A software tool is updated. In each case, a record that was correct on Monday is stale on Tuesday, its file unchanged, its date unchanged, nothing flagged.
Contextual drift is the slowest and the hardest to argue about. The evidence remains technically valid and no longer represents reality. The process map still matches the documented process; the documented process no longer matches what the line actually does, because eighteen small accommodations accumulated over two years and none of them individually justified a change request. Nothing here is expired. Everything here is wrong.
Most quality systems are built to manage the first class, are blind to the second, and discover the third during an audit.
Why the second class is invisible
Silent invalidation is invisible for a structural reason, not a discipline one.
The trigger and the victim live in different systems. The trigger is a document revision, in your document management system. The victim is a training record, in your learning management system or HR platform. The link between them — this training covered that revision — exists in somebody's head, or in a column of a spreadsheet, or nowhere.
Multiply that across the real topology. Calibration data sits in a maintenance or metrology system. Supplier certificates sit in purchasing, or in an email folder. Validation records sit with engineering. Training sits with HR. Audit records sit with quality. CAPA sits in the QMS proper. Each system has its own reminder mechanism for its own dated expiries, and none of them knows anything about events happening in the others.
Your quality management system, as an auditor experiences it, is the union of all of these. Nobody owns the union. The organisation chart has an owner for every box and no owner for the lines between them — which is exactly where silent invalidation lives.
The arithmetic, and why it compounds
It is worth putting rough numbers on this, because the scale surprises people.
Take a mid-sized manufacturer with a mature QMS. Say twelve hundred discrete evidence artefacts in scope: calibration records, training completions, supplier approvals, validation reports, competence assessments, equipment qualifications, risk assessments. If the average validity period is around fourteen months, then roughly eighty-five artefacts require refresh every month just to hold steady.
If your organisation refreshes sixty a month — which is not laziness, that is a real and substantial workload — you accumulate twenty-five stale artefacts a month. After a year, three hundred. After the full certificate cycle, closer to nine hundred, except that the real number is worse because silent invalidation adds artefacts that were never on anyone's expiry list to begin with.
Treat those figures as illustrative of the shape rather than a claim about your own system. The shape is the point: decay is a rate, refresh is a rate, and any gap between them compounds silently across a three-year cycle. Organisations experience this as "our audits keep getting harder" without ever identifying the mechanism, because at no point does anything visibly break.
How it shows up in an audit — and why it escalates
Here is the part that turns an administrative nuisance into a certificate risk.
Evidence decay does not present as one large gap. It presents as scatter. A calibration overdue on one gauge. Two training records against a superseded revision. A supplier certificate that lapsed four months ago. A validation report referencing an obsolete parameter. Individually, every one of these is a minor nonconformity — annoying, correctable, forgettable.
Competent auditors do not stop at the individual findings. They ask a second question: is there a systemic reason these keep occurring? And when the answer is that the organisation has no mechanism for detecting evidence that has silently gone stale, the scatter gets consolidated into a single finding against your control of documented information, or your competence management, or — worst case — the effectiveness of your internal audit programme for failing to detect it first.
That consolidated finding is a different animal. A handful of minors is a correction exercise. A systemic finding against the mechanism is a major, and majors are what put certificates into suspension conversations. The escalation is not driven by the severity of any individual lapse. It is driven by the absence of a system, and the scatter is what proves the absence.
Approximate half-lives worth knowing
Every organisation's numbers differ, but the ordering is fairly stable:
- Calibration and verification records — six to twelve months. Dated, visible, high volume.
- Training and competence records — nominally one to three years, but effectively invalidated by any revision of the underlying document. In a system with active document control, this is often the shortest real half-life you have and the one least tracked.
- Supplier approvals and certificates — one to three years, on the supplier's calendar rather than yours, with no notification when they lapse.
- Process validations and qualifications — event-triggered rather than dated. Valid until a parameter, material, tool or location changes.
- Risk assessments and FMEAs — event-triggered by design change, and among the fastest-drifting artefacts in any organisation shipping product regularly.
- Internal audit coverage — decays continuously against your cycle. Coverage claimed at the start of a three-year programme is a projection, not a fact.
- Management review outputs — annual, and the actions arising decay faster than the review itself.
Notice how many of these are event-triggered rather than dated. Any system built purely on expiry dates is blind to the majority of its own decay.
Building the mechanism
The fix is not more diligence. It is an explicit register plus an explicit trigger map.
1. Build an evidence register. One list of every class of evidence your QMS relies on, with an owner, a source system, a validity rule and a decay type — dated, event-triggered, or drift. Most organisations have never written this down, and the act of writing it produces the first round of surprises. Expect to find categories nobody owns.
2. Separate dated from event-triggered explicitly. These need entirely different mechanisms. Dated decay needs a calendar and capacity. Event-triggered decay needs a dependency map, and no calendar will ever catch it.
3. Map the triggers to their victims. This is the core of the work. When a document is revised, what becomes stale? When an operator changes role, what becomes stale? When a supplier notifies a process change, what becomes stale? When a gauge is replaced, a tool is modified, a plant is added? Each of these is a small, knowable list — and writing them down converts your largest blind spot into an ordinary process.
4. Instrument the triggers you already emit. Your document control system already knows when a revision is released. Your ERP already knows when a supplier record changes. The events exist; they simply are not wired to anything. Wiring the highest-volume trigger — document revision to training validity — usually delivers more than every other improvement on this list combined.
5. Report the rate, not the backlog. The number that predicts your next audit is not how many items are currently overdue. It is whether your refresh rate exceeds your decay rate. A team clearing forty items a month against a decay rate of eighty-five is losing while looking productive.
Where PEDCO AuditPro fits
Silent invalidation is a relationship problem, which is precisely why it survives in document-centric systems. A document management system stores documents and knows their revisions. It does not know that a training record three systems away depended on the revision it just superseded, because it has no representation of that dependency.
PEDCO AuditPro reads a management system as a graph of processes, requirements, documents and evidence rather than as a folder of files. That representation is what makes decay visible. Because the graph holds the connections, it surfaces the classes of staleness that document-level review cannot: procedures citing revisions that no longer exist, requirements whose only supporting evidence predates the last process change, documents that nothing references and nothing updates, references to external standards superseded by a newer edition, and clusters of evidence in a process area that have all aged past the point where they demonstrate anything current.
Every observation traces back to its source document, because "this evidence is stale" is a claim you will have to defend to an auditor, and a claim you cannot trace is a claim you cannot make.
The more consequential shift is one of cadence. In most organisations an audit is an event. It happens, it produces a report, the report gets worked off over the following quarter, and the next comparable data point arrives a year later. That interval is longer than the half-life of most of the evidence underneath it — which is precisely why decay is discovered six weeks before a surveillance audit, during a scramble that consumes the quality function and produces a burst of corrections without leaving any mechanism behind.
Because assessments run automatically rather than by hand, an audit in PEDCO AuditPro stops being an event and becomes a cycle you can repeat as often as it is useful: monthly, quarterly, or triggered by a significant document release. The cost of running one again is close to zero, which changes what an audit is for.
Once you have a series of runs against the same scope, something appears that no single audit can show you — a trend. Comparing each run against the ones before it turns staleness into a visible slope: a process area whose conformity has slipped three assessments running, a requirement that was fully evidenced in March and only partially evidenced in June, a document cluster ageing faster than it is being refreshed, a supplier whose supporting evidence has quietly thinned since onboarding. A snapshot cannot distinguish "this was always weak" from "this is degrading". Only repeated measurement can, and the difference between those two findings is the difference between a correction and a root cause.
This is what turns evidence decay from a discovery into a managed variable. The decay rate and refresh rate described earlier stop being estimates you construct once and become numbers you read off consecutive audit results. Degradation surfaces while it is still four stale records rather than four hundred, corrective actions can be verified by the next cycle instead of asserted, and improvement becomes something you can demonstrate with a curve rather than argue for in a management review.
A rate you watch is a rate you can manage. That is the whole argument for continuous auditing, and evidence decay is the clearest case for it — because it is the one problem in quality management that is guaranteed to be worse the longer you go without looking.
Four metrics worth putting on a dashboard
- Evidence freshness — the percentage of in-scope evidence currently within its validity rule. One number, trended monthly. It will be lower than anyone expects the first time you calculate it.
- Decay rate versus refresh rate — the two numbers that determine whether you are gaining or losing. Report them together or neither means anything.
- Silent invalidation backlog — artefacts invalidated by an event rather than a date, and not yet refreshed. This is the number that predicts systemic findings, because it is the one no calendar catches.
- Mean evidence age at audit — how old, on average, was the evidence you presented? Rising age is the leading indicator of the scatter pattern that gets consolidated into a major.
The reframe
A certificate is a statement about a moment. It says that on the audit date, against a sample, the system conformed. Everything underneath it is perishable, and it perishes at rates that have nothing to do with your three-year cycle.
Audit readiness, understood properly, is not a project you run before an audit. It is the ongoing management of a decay rate — and the organisations that struggle are not the ones with weak processes. They are the ones with good processes whose evidence quietly aged out from under them, in six different systems, while everyone involved was doing their job correctly.

