On 5 November 2015 the Fundão tailings dam at Samarco's mine near Mariana, Brazil, failed, killing 19 people and sending tailings down the Rio Doce to the Atlantic. Samarco had been known as the first mining company in the world to certify every stage of its production to ISO 14001. The dam had been drifting from its design for six years. After an ISO 14001 audit, the step is to decide which operating changes will reopen the significant-aspects register before the next auditor arrives.
An ISO 14001 audit is an independent check by a certification body that an environmental management system conforms to ISO 14001 and is being maintained in practice.
An ISO 14001 audit certifies the system on the days it was sampled
A certification audit does real work. The auditor tests whether the organisation has determined its environmental aspects and rated which are significant, identified its compliance obligations, evaluated compliance against them, set objectives, run internal audits and held management reviews. Those are the core requirements of ISO 14001:2015. Nonconformities are raised, causes written up, corrective actions closed. A clean surveillance visit keeps the certificate alive for another year.
The outputs are specific. A significant-aspects register that ranks emissions, discharges, waste and land disturbance by consequence and likelihood. A compliance obligations register that maps each permit condition and legal requirement to an owner. A dated compliance evaluation. A closed-out list of findings. For many organisations that pack is the most complete description of their environmental footprint they have ever assembled.
It also changes behaviour. Teams that never looked at their own discharge data start trending it. The same discipline shows up after an ISO 9001 audit and after an ISO 45001 audit: the system gets tidier, owners get named, and the paperwork starts to match the plant. The audit confirms that the machinery for managing environmental risk exists and runs.
What the audit cannot do is see forward. Certification bodies return for surveillance about once a year and recertify every three. Between visits, the register describes the operation as it was when someone last rated it. The same limit applies after an internal audit, and it sits inside the wider question of organisational governance: who is watching the conditions the system was built on?
Take the significant aspect your environmental objectives lean on hardest, write down the operating condition its rating assumes, and name who reopens it when that condition moves. Start the Walk →
The aspects register assumes the operation stays as it was rated
Every significance rating is a snapshot, as any risk assessment is. A tailings facility rated as a controlled aspect assumes a particular throughput, a particular water balance and a design that is being followed. A discharge rated low assumes the treatment plant runs within its design load. The compliance evaluation assumes the permits and laws it was checked against have not moved. None of those assumptions carries an expiry date. A DPIA makes the same assumption about the processing it describes.
ISO 14001 does require organisations to take change into account when they determine aspects, including new developments and modified activities. That requirement is easiest to meet for formal change: a new plant, a permit application, a management-of-change form. Gradual drift rarely fills in a form. Operating conditions creep past design limits one month at a time, and the certification cycle is not built to notice.
Research on certified sites points the same way. Boiral (2007) studied nine ISO 14001 certified Canadian organisations and found daily practice often decoupled from what the system prescribed. Aravind and Christmann (2011) found that certified facilities overall performed no better environmentally than uncertified ones; only high-quality implementers did. Certification tells stakeholders a system exists. It does not tell them the system is looking at the right things now.
That is the gap between compliance and governance. Compliance asks whether the register conforms. Governance asks whether the register is still true, and that question needs a trigger, not a calendar.

Samarco's Fundão dam drifted away from its own design
Fundão was designed to keep sand tailings and fine slimes apart. The sand would form the embankment, a 200-metre beach would hold water and slimes back from the crest, and a base drain would keep saturation down. The Fundão Tailings Dam Review Panel, commissioned by Samarco and its shareholders Vale and BHP Billiton, reported in August 2016. It traced the failure to a chain of unplanned changes, not a single event.
In 2009, defects in the base drain forced a revised design with a drainage blanket at a higher elevation, and more widespread saturation was accepted. Through 2011 and 2012 the beach criterion was often not met, with water as close as 60 metres to the crest, so slimes settled where they were never meant to be.
In late 2012 a concrete conduit under the left abutment was found to be structurally deficient. To keep operations running in the interim, the embankment alignment was set back, directly over those slimes. The interim lasted. The setback rose about 18 metres in 2013, seepage appeared on it that year, and on 27 August 2014 extensive cracking ran across the slope. A reinforcement berm was built within two weeks. Each signal was met with an engineering fix.
On 5 November 2015, about 90 minutes after three small seismic shocks, the left abutment failed in a liquefaction flowslide. Araújo, Soares and Abreu (2018), the source for that certification record, count 19 deaths and the destruction of Bento Rodrigues.
The Review Panel's report is a geotechnical document and does not assess Samarco's environmental management system. It does show the kind of change such a system has to be told to look for: each deviation was gradual or meant to be temporary, and together they rewrote the risk. A significance rating set against the original design would have described a dam that no longer existed. Many governance failures share that shape.
Name the change that reopens the aspects register
The step after the certificate is to write down, for each significant aspect, the condition that would make its rating wrong and the observable signal that the condition has moved. The artefacts are the significant-aspects register and the compliance obligations register beside it. Add one column to each: what would have to change for this rating to be false, and who checks. A rating without a reopening condition ages silently.
Set the trigger points concretely. Reopen the register when throughput moves past the range the rating assumed. Reopen it when a design limit goes unmet for a set period, as Fundão's beach width did, or when a temporary arrangement outlives its planned end, as the setback did. Reopen the compliance register when a permit is renewed, a licence condition is varied or new law commences. Reopen both after any incident or near miss involving a significant aspect.
Then give the trigger list an owner who is not the auditor. Surveillance visits will keep checking that the system conforms. The trigger list checks that the ratings are still true between visits, the same gap that opens after a governance audit. The method treats this as monitoring built into a decision before it leaves the desk. Decide what will send the register back to the table before the certificate goes in the drawer.
A renewed ISO 14001 certificate tells you the system conformed on audit day. It doesn't tell you whether the conditions behind each aspect rating still hold.
Work through your decisionNo sign-up. Just pick your decision and start.
Grant Purdy is the co-author, with Roger Estall, of Deciding (2020), and the architect of the Universal Decision-Making Method.