Back to ISO 17100

Maintaining ISO 17100 compliance: ongoing best practices for TSPs

Photo: Unsplash

Maintaining ISO 17100 compliance is the long game after the celebration email from your certification body. Certificates typically sit inside a cycle of surveillance and eventual recertification. The TSPs that keep the logo honest are the ones that refresh competence, resist process drift under deadline pressure, and close feedback loops—not the ones with the thickest binder from Stage 2 week.

ISO 17100:2015 remains a translation-services standard: interpreting and raw MT+PE are typically outside its intended model, and mandatory second-person revision stays non-negotiable for in-scope work. Maintenance is about proving the system still operates when volume spikes and freelancers churn.

SecureSlate’s contribution is evidence ownership, policies, confidentiality/security controls, and recurring reviews—not replacing linguistic QA.

This guide covers:

  • How surveillance and certificate cycles usually work
  • Competence updates and vendor churn controls
  • Detecting process drift before auditors do
  • Confidentiality and continuous improvement rhythms that stick

Teamwork that keeps quality systems moving after certification

GIF via GIPHY

Related guides:


Key takeaways

  • Surveillance is inevitable—plan sample packs and CAPA hygiene year-round, not two weeks before the auditor.
  • Competence records age—new freelancers and domain shifts need controlled onboarding and refresh.
  • Process drift usually starts with skipped revision under rush jobs; measure dual-assignment compliance.
  • Confidentiality controls support client trust and frequently appear beside quality sampling.
  • Continuous improvement needs owners—client feedback, internal audits, and management review must close the loop.

Why maintenance matters after the certificate

Initial certification proves a snapshot. Clients, however, assume the system still works next quarter. Failures after certification commonly look like:

  • New vendors onboarded without complete competence files
  • PMs approving same-person “revision” to hit an impossible deadline
  • Complaint trends ignored until a major account escalates
  • Scope creep on the website beyond the certificate

If you are still deciding whether certification was the right bet, revisit Who needs ISO 17100 certification? and What is ISO 17100:2015? Everything you need to know.


Surveillance audits and certificate cycles

Certification bodies commonly schedule surveillance audits during the certificate cycle and a broader recertification later. Exact timing depends on your CB agreement.

Treat surveillance like a lighter Stage 2: competence files, project traces showing translation + revision, agreements, complaints/CAPA, and technical/confidentiality resources still matter. See ISO 17100 audit: what auditors look for.

Budget note: surveillance fees and staff time are part of total cost of ownership—see How much does ISO 17100 certification cost?.


Keep competence records alive

Translator qualification paths commonly remain:

  • Translation degree, or
  • Other degree + about two years’ experience, or
  • About five yearsfull-time professional experience

Maintenance practices that work:

  • Onboarding gate: no project assignment until the competence file is complete
  • Quarterly spot checks: sample active freelancers for expired docs or missing NDAs
  • Domain expansion control: require evidence before enabling new specialized domains
  • Reviser roster hygiene: ensure revisers stay distinct from translators on jobs

Deep dive: ISO 17100 translator and reviser competence requirements.


Stop process drift in production

Process drift is the silent certificate killer. It often starts with exceptions that become norms.

Watch these metrics monthly:

Signal Healthy pattern Drift warning Owner
Dual assignment rate Translator ≠ reviser on in-scope jobs Rising same-person checks Project Mgmt
Brief completeness Requirements captured pre-production Kickoffs from chat only Project Mgmt
Query logging Material questions recorded Silent assumptions Linguist leads
Delivery checklist use Consistent final steps Skipped under rush Ops
Exception log Rare, approved, timed Unlogged shortcuts Quality

If dual-assignment compliance drops, freeze exceptions and retrain PMs before surveillance. Requirements context: ISO 17100 requirements: a complete breakdown.

Technology can help consistency, but do not quietly convert in-scope work into raw MT+PE and expect ISO 17100 sampling to look the same.


Confidentiality and security as ongoing controls

Clients care that their content stays protected while it moves through freelancers and tools. Ongoing practices commonly include:

  • Access reviews for TMS/CAT and shared drives
  • Offboarding that revokes vendor access promptly
  • Incident logging when files land in the wrong place
  • Clear rules for personal email and consumer file-share tools

These controls support confidentiality commitments that sit beside quality processes. They are a natural place for SecureSlate-style evidence ownership without confusing GRC with linguistic revision.

If you also operate a broader QMS, keep roles clear—see ISO 17100 vs ISO 9001: what's the difference?.


Continuous improvement loops that auditors respect

ISO 17100 maintenance is healthier when improvement is routine:

  1. Client feedback and complaints enter a single register
  2. Root causes distinguish one-off human error from systemic gaps
  3. Corrective actions have owners and due dates
  4. Internal audits sample real projects, not only policy text
  5. Management review looks at trends, resources, and risks—and records decisions

Empty improvement logs are a smell. So are endless open CAPAs. Aim for fewer, closed actions that change behavior (for example, TMS validation that blocks same-person revision).

Reuse the ISO 17100 certification checklist as a living register for surveillance readiness.


A practical operating rhythm

Cadence Activity Primary owner
Weekly Spot-check rush jobs for dual assignment Project Mgmt
Monthly Review complaint/CAPA aging Quality
Quarterly Competence file sampling + access review Vendor Mgmt + Security
Semiannual Internal audit of ISO 17100 processes Quality
Annual Management review + surveillance prep pack Leadership + Quality

Adjust frequency to volume and risk. High-churn vendor networks usually need tighter quarterly gates.

When growth or M&A hits the system

Maintenance gets harder when you add offices, acquire another LSP, or suddenly scale a new domain. Before the next surveillance:

  • Revisit the certificate scope with your CB if entities or services changed
  • Re-run competence sampling on newly inherited vendor pools
  • Confirm dual-assignment rules still enforce in every TMS instance
  • Align sales collateral so claims match the live scope statement

Path refresher if the system has eroded: How to get ISO 17100 certified: step-by-step. For a requirements refresh when onboarding acquired teams, use ISO 17100 requirements: a complete breakdown.


Streamline ongoing compliance with SecureSlate

Maintaining ISO 17100 compliance fails when reviews depend on memory. SecureSlate helps TSPs keep the non-linguistic control plane on a calendar—owners, policies, evidence, and follow-ups.

With SecureSlate you can typically:

  • Schedule recurring reviews for competence sampling, access, and management review
  • Centralize confidentiality and vendor policies next to quality procedures
  • Track CAPA owners and due dates so improvement loops close
  • Assemble surveillance evidence packs from linked artifacts
  • Reduce last-minute scramble by making readiness continuous

SecureSlate does not replace revisers or your certification body. It helps you keep the system around them trustworthy between audits.

Get started for free


FAQ: maintaining ISO 17100 compliance

How often are surveillance audits?

Typically on a cycle defined by your certification body agreement—often annually or as otherwise scheduled within the certificate period. Confirm your contract.

What is the biggest maintenance failure mode?

Process drift that drops second-person revision, especially on rush work, combined with incomplete competence files for new freelancers.

Do we need to re-document everything each year?

No. Update when processes change, then prove operation through samples, internal audits, and management review.

How do we handle new machine translation features?

Document carefully. Raw MT+PE remains commonly outside ISO 17100’s human translation-and-revision model. Align scope and CB expectations before marketing claims.

Can we expand certificate scope later?

Often yes, through CB scope extension processes. Budget extra sampling and competence evidence for new domains or sites.

Does maintenance cost as much as initial certification?

Usually less in consulting and initial remediation, but surveillance fees + ongoing staff time still matter. Plan them explicitly.


Disclaimer (legal note)

SecureSlate is not a law firm, and this article does not constitute legal advice, certification advice, or a guarantee of continued certification. Surveillance practices and certificate cycles vary by certification body. Confirm obligations against ISO 17100:2015 and with your auditor or qualified counsel. Guidance here uses careful language because operational details differ by organization and market.

Need compliance without the complexity?

SecureSlate automates ISO 27001, SOC 2, GDPR, HIPAA, and more. Built for growing teams. See it in action.

No credit card required

Filed under:

Author: SecureSlate Team

4.7(241 reviews)

Keep reading

Jul 23, 2026 · ISO 17100

How much does ISO 17100 certification cost? A practical breakdown

Jul 23, 2026 · ISO 17100

How to get ISO 17100 certified: a step-by-step guide for TSPs

Jul 23, 2026 · ISO 17100

ISO 17100 audit: what auditors look for in TSP evidence

View more posts
Jamie
Virtual Agent

Hi! I'm Jamie. Curious about your current compliance challenges and how automation might help your team?