How Certification Expiry Actually Gets Tracked, and Where It Breaks
Four methods dominate: a colour-coded spreadsheet, calendar reminders, the QA manager's memory, and a certification register inside the business system. The first three fail the same way — they warn a person, not the dispatch decision. A defensible tracker blocks assignment when a certification, a written-practice interval, or an annual vision exam has lapsed, and keeps the evidence.
Certification expiry is not one clock. SNT-TC-1A recommends recertification at intervals not exceeding five years, but the employer's written practice is what actually binds, and it carries an annual near-vision examination — Jaeger No. 1 or equivalent — plus periodic colour-perception testing. ISO 9712 runs a separate five-year validity with a twelve-month renewal window, after which a full examination is required. A technician can hold a current method certification and still be ineligible because a vision exam slipped by three weeks. That is the gap every tracking method misses. Spreadsheets colour a cell nobody opens on a Friday. Calendar reminders fire at the person who is on a plane. Memory works until the QA manager takes leave. None of them sit between the scheduler and the job assignment, which is the only place a lapse can be stopped before it becomes a nonconformance.
Source: Verified against ASNT SNT-TC-1A (recommended recertification at intervals not exceeding five years, applied through the employer's written practice; annual near-vision examination to Jaeger No. 1 or equivalent; periodic colour-perception testing); ISO 9712:2021 (five-year maximum validity, renewal window, complete examination required beyond twelve months past expiry); ISO/IEC 17025:2017 clause 7.10, nonconforming work; 29 CFR 1910.119(j)(4)(iv), OSHA process safety management inspection and test records.
| Method | How it warns you | Failure mode | Where it breaks first |
|---|---|---|---|
| Spreadsheet with conditional formatting | A cell turns amber, then red | Warns a file, not the dispatch decision | Multi-site firms where the scheduler is not the QA manager |
| Outlook or Google calendar reminders | Pop-up on a set date | Dismissed while travelling; leaves no evidence it fired | Any renewal needing an exam seat or Level III review |
| The QA manager's memory | Verbal challenge at assignment | Single point of failure; collapses on leave or turnover | The week the QA manager is on holiday |
| Shared-drive folder of certificate PDFs | Nothing warns you at all | Storage, not tracking; expiry invisible until opened | The first audit sample |
| Certification register in the business system | Status flag on the technician record | Only as good as the data entered; stale if nobody updates it | Vision exams and written-practice intervals |
| Assignment-blocking check at dispatch | Refuses to release the job | Requires every rule to be configured and kept current | Nothing, once the rule set is complete |
The four systems actually in use
Walk into any inspection firm with fewer than a hundred technicians and you will find one of four arrangements. A spreadsheet with conditional formatting that turns rows amber at 60 days and red at expiry. A set of calendar reminders in the QA manager's Outlook. A folder of scanned certificates on the shared drive with no dates extracted from them. Or a certification register inside the business system, which works if somebody keeps it current.
Most firms run two or three of these at once and believe they run one. The spreadsheet is the official record, the calendar is the actual alarm, the folder holds the evidence, and none of the three agree. The discrepancy is not discovered during normal operations, because normal operations never ask all three the same question on the same day. An audit does exactly that, on a date you did not choose, about a job you did not expect.
Before changing anything, run the reconciliation. Take ten technicians, pull their certification status from every system you hold, and compare. The number of mismatches in that sample of ten predicts what an auditor will find, and it is the only diagnostic that costs nothing. Do it with the QA manager out of the room, using only what is written down, because his memory is the variable you are trying to measure. Firms that expect zero mismatches routinely find three.
What is actually expiring, and on which clock
Certification expiry is treated as one date. It is at least four. Under SNT-TC-1A, the employer's written practice governs qualification and certification, and the recommended practice puts recertification at intervals not exceeding five years for Levels I, II and III. Separately, near-vision acuity is examined annually — Jaeger No. 1 or equivalent — with colour-perception testing at a longer interval. Both sit under the same certificate and expire independently.
Where a certification body is involved, the clock changes shape. ISO 9712 sets a maximum validity of five years, with renewal available inside a defined window; past twelve months beyond expiry a complete examination is required rather than a renewal. Aerospace work adds NAS 410 personnel qualification and Nadcap audit criteria on top. Nuclear and client-specific qualifications add their own dates, each with its own evidence requirement and its own renewal path.
The practical consequence is that a technician's eligibility is a compound state, not a date. He is eligible for UT on this client's site today if his method certification is current, his vision exam is within twelve months, his written-practice requirements are satisfied, and any site qualification is live. A single-date tracker cannot represent that, which is why it silently gets it wrong and keeps showing green.
Failure mode one: the spreadsheet
The spreadsheet is the most common arrangement and the most defensible-looking. The formula is correct. Rows go amber at 60 days, red at zero, a column holds the certificate number, and the file gets a review at the monthly QA meeting. On paper it is a control with a defined trigger and a defined owner. It fails for reasons that have nothing to do with the maths, which is why firms defend it so hard — the part they built is the part that works.
It fails on access. One person owns the file, and the scheduler who assigns crews is a different person working from a different tool. It fails on freshness — a certificate renewed in the field gets emailed to the QA manager and typed in a week later, if at all. It fails on completeness, because the vision exam column was never added. And it fails silently: a row deleted by accident produces no error, just a technician who stops being tracked.
It also fails at audit for a reason firms rarely anticipate. Asked to show the certification status of a technician as it stood on the date of a job eighteen months ago, the spreadsheet holds only today's values. There is no history, so you cannot evidence that the check passed then. Moving that history into a certification tracking register is the single change that closes it.
Failure mode two: calendar reminders
Calendar reminders feel like a control because they interrupt somebody. They interrupt the wrong person at the wrong moment. A 9 a.m. pop-up on a day the QA manager is mobilising a crew gets dismissed in half a second, and dismissal is indistinguishable from action. Nothing is logged, so the reminder that fired and the reminder that never existed look identical in retrospect.
The deeper flaw is lead time. Reminders are set for the expiry date or thirty days out, which is too late for anything requiring an examination seat, a refresher course, or a Level III review. By the time the alert arrives, the only options are pulling the technician off work or letting him work while the paperwork catches up. Firms choose the second more often than they admit, and that is the exact decision an audit is designed to catch.
Reminders have one legitimate use: a redundant second layer over a system that already blocks assignment. Used that way they add nothing and cost nothing, which is fine. Used as the primary control, they place a company's compliance position inside one person's notification settings, on one device, with no record that the control ever operated. No auditor accepts that, and no QA manager should want the liability.
Failure mode three: the QA manager's memory
Memory is the most effective method right up to the moment it is not. A good QA manager genuinely knows that Rodriguez is due in March and that the new hire's MT ticket came from a firm using different level definitions. That knowledge is faster and more accurate than any spreadsheet, and it is why firms keep relying on it long after they have outgrown it.
It fails in three predictable ways. It fails during leave, when assignments are made by someone without the knowledge. It fails on turnover, when it leaves the building in a single afternoon. And it fails at scale — the practical limit is around twenty-five technicians across two methods, beyond which recall degrades without anyone noticing that it has.
It also cannot be audited. An auditor asking how you ensure certification currency will not accept experience as the answer, because there is nothing to sample and nothing to test. He will ask to see the control operating, and a person saying 'I know' produces no artefact. This is the distinction that frustrates good QA managers most: the objection is not to their competence, it is to the absence of anything that would survive their absence.
One day past expiry: what it actually invalidates
The stakes get understated because nothing visibly breaks. The technician performs the inspection competently, the weld is sound, and the report reads normally. The defect is in the record, not the metal, and it surfaces months later when someone samples the job. Nobody is harmed on the day, which is precisely why firms tolerate the risk — the feedback loop between the lapse and the consequence is measured in quarters, not hours.
What happens then is procedural and expensive. Under ISO/IEC 17025 clause 7.10, nonconforming work triggers an evaluation of significance, correction, and where required notification of the customer and recall of results. OSHA's process safety rule requires each inspection record to name the person who performed it, so on covered equipment the record itself carries the evidence of who was working and when. There is no version of the story where the lapse stays hidden once the sample is drawn.
The commercial consequence lands harder than the compliance one. The client re-shoots the affected scope, questions every other job on that contract, and the finding attaches to your name in their vendor system. One day of lapsed paperwork produces months of reduced trust, which is why the control belongs at dispatch rather than at review.
What a defensible tracker has to do
The requirement is narrow. Hold every clock per technician per method — certification, vision, colour perception, client qualification. Evaluate all of them at the moment a job is assigned, not on a monthly review cycle. Refuse the assignment when any clock has run out. And write a dated record that the check ran, so the control can be evidenced later rather than asserted.
Two supporting behaviours make it stick. Escalating alerts starting 120 days out, addressed to a role rather than a person, so leave and turnover do not create gaps. And a point-in-time query — what was this technician's status on the day of job 4471 — because that is the exact question an auditor asks and the one no spreadsheet can answer. Everything else is presentation.
The same logic applies to instruments, which is why calibration due dates belong in the same blocking check. A current technician using an out-of-calibration instrument produces exactly the same nonconformance, and firms that fix one and not the other simply move where the finding lands.
A thirty-day fix that works with whatever you have now
Days one to five, reconcile. Build one list of every technician, every method, and all four expiry dates from every source you hold. Expect contradictions; record them rather than resolving them silently, because the contradictions are the audit exposure. Days six to ten, close the gaps — chase missing vision exams first, since they are cheap to obtain and they expire fastest.
Days eleven to twenty, move the check to dispatch. Even without new software this is achievable: the scheduler cannot release a job without a signed eligibility confirmation for each assigned technician, and that confirmation gets filed with the job. It is manual, it is slightly annoying, and it converts an invisible risk into a visible one that somebody owns.
Days twenty-one to thirty, decide what carries it permanently. If the reconciliation produced more than a handful of contradictions, the answer is a system that blocks rather than warns. A gap assessment will tell you which findings a client auditor would raise first, and an ASNT Level III on call can own the written practice the whole thing has to enforce. If you want the thirty-day list mapped against your own roster, start there.
What actually expires on an NDT technician's file?
Four separate clocks. The method certification itself, which SNT-TC-1A recommends renewing at intervals not exceeding five years. The annual near-vision examination, Jaeger No. 1 or equivalent. Periodic colour-perception testing. And any client-specific or site-specific qualification layered on top. A technician can be current on the first and ineligible on the second, which is the lapse most spreadsheets miss entirely.
What happens if a technician works one day past expiry?
The inspection becomes indefensible. Under ISO/IEC 17025 clause 7.10 the laboratory must evaluate the significance of nonconforming work, act on it, and where required notify the customer and recall results. In practice the client re-shoots the job at your cost, the certificate that relied on it is at risk, and the finding follows you into the next audit.
Why does conditional formatting fail even when the formula is correct?
Because the formula colours a cell and a cell cannot stop a dispatch. The maths is right; the delivery is wrong. The spreadsheet sits on a shared drive, the scheduler assigns crews from a whiteboard or a phone call, and the amber row is seen on Monday by someone who is not making Tuesday's assignment. Correct data in the wrong place is not a control.
How much lead time does a renewal actually need?
Set the first alert at 120 days, not 30. Recertification by examination needs a seat booked, structured credit needs evidence assembled, and a Level III review needs the Level III to be available. ISO 9712 allows renewal up to twelve months after expiry, after which a complete examination is required — so a missed window converts a paperwork task into a re-qualification project.
Do calendar reminders count as a documented control at audit?
No. An auditor asks for evidence that the control operated, and a dismissed Outlook pop-up leaves nothing behind. There is no record of who saw it, whether action followed, or what happened when nobody acted. Calendar reminders are a personal convenience layered on top of a real system. They are not the system, and stating otherwise in a procedure creates a finding.
What is the minimum a defensible expiry tracker has to do?
Three things. Hold every clock per technician per method, including vision and any client qualification. Refuse a job assignment when any clock has run out, rather than warning about it. And keep a dated record showing the check happened, so the control can be evidenced months later. Everything else — dashboards, colour coding, email digests — is convenience on top of those three.