Certification Strategy 12 min read

Multi-Site R2 Certification: How Audits Work

J

Jared Clark

July 21, 2026

The assumption a lot of recyclers make when they expand to a second or third location is that R2 certification just follows. You're already certified at your main facility, so the new sites should be straightforward to add. That's not quite how it works, and misunderstanding the structure is where multi-site programs tend to run into trouble.

Multi-site R2 certification is genuinely different from single-site. Not necessarily harder, but structured differently — and the audit mechanics that govern it are specific enough that they reward preparation.

What Multi-Site R2 Certification Actually Means

Under R2v3, a multi-site certification covers two or more locations operating under a common management system controlled by a central function — typically headquarters or a parent entity. All covered facilities appear on a single certificate and its appendix. Downstream customers, auditors, and trading partners verify one credential that speaks for every location on the list.

The phrase SERI cares about is "common management system." This isn't a holding-company technicality. Your central function has to actively govern the quality, environmental, and data security systems across every site — setting policy, managing corrective actions, running the internal audit program, and ensuring that training actually reaches each location. Certification bodies look for evidence of that reach, not just organizational structure.

The distinction matters because a nominal central function — one that exists on paper but doesn't meaningfully influence operations at each facility — fails the audit. And it should. The whole value of multi-site certification rests on the premise that your sites are actually running the same system.

For a full breakdown of R2v3 standard requirements that apply to both single and multi-site programs, see our R2v3 Certification Overview.

How the Audit Structure Works

When your Approved Certification Body (ACB) conducts a multi-site audit, they're auditing two distinct things: the central function and a sample of individual sites.

The central function audit looks at the management system at the organizational level. Are your policies consistent and applicable across all locations? Does your internal audit program actually reach every site? Are corrective actions tracked and closed centrally? This portion happens every cycle, without exception.

The individual site portion is where sampling comes in — and this is the piece that surprises most companies the first time through.

Sampling Rules: Not Every Site Gets Audited Every Year

R2 multi-site programs follow ISO/IEC 17021-1 sampling methodology, which sets the minimum number of sites to audit per certification cycle at the square root of the total number of enrolled locations, rounded up. If you have nine facilities on your certificate, your ACB audits at least three per cycle. Sixteen facilities means a minimum of four sites. Twenty-five means five.

This formula is one of the more concrete financial arguments for multi-site certification at scale. A company with 16 separate R2 certificates pays for 16 full audits annually. A company with 16 sites on a single multi-site certificate pays for the central function audit plus four site visits per cycle. The per-location cost difference is substantial as the portfolio grows.

The formula sets a floor, not a ceiling. Certification bodies have both discretion and obligation to expand the sample based on risk.

What Drives Site Selection

Every cycle, your ACB uses risk-based criteria when selecting which sites fall into the sample. Factors that commonly push a site into mandatory or expanded selection include:

  • New locations — any site added within the current certification cycle gets audited in that cycle
  • Open major nonconformances from a prior surveillance visit
  • Higher-risk Focus Materials — sites handling CRTs, mercury-containing devices, batteries, or other elevated-risk streams draw more frequent attention
  • Regulatory actions, environmental incidents, or customer complaints since the last audit
  • Time since last audit — sites that haven't been visited in the longest period are prioritized in the rotation

In my experience, the most productive thing you can do before your ACB finalizes the audit plan is have a direct conversation about which sites carry the most operational complexity. That conversation shapes the selection, and auditors generally appreciate a client who already knows where the risk lives in their own portfolio.

The Certificate and What It Covers

A multi-site R2 certificate lists the central organization and every covered facility in a certificate appendix. SERI maintains a public directory where any interested party can verify that a specific location holds current R2 certification. When a downstream customer checks your credential, they're looking at one document that covers every listed address — a single lookup that confirms your entire operation.

That's a meaningful operational advantage. A trading partner in another region doesn't need to track separate certificates for each of your facilities, coordinate separate expiration dates, or repeat the verification process whenever you add a location. One certificate, one renewal cycle, one verification check.

The tradeoff deserves honest acknowledgment. Under R2v3, a major nonconformance at any single site within a multi-site program can carry consequences for the entire shared certificate — making a robust internal audit program that reaches every location a functional requirement, not an aspiration. If a location is suspended from the program, that suspension attaches to the certificate that covers your entire operation. That systemic exposure is the structural cost of the shared structure.

Single-Site vs. Multi-Site: A Direct Comparison

Factor Single-Site Multi-Site
Certificates issued One per facility One for all covered locations
Annual audit scope Full site audit every cycle Central function + sampled sites (√n)
Per-location cost at scale (5+ sites) Higher — each site fully audited Lower — sampling reduces per-site visits
Central oversight requirement None required Required; central function must actively govern
Nonconformance impact Isolated to that certificate Can affect all sites on shared certificate
Customer verification Separate lookup per facility Single certificate covers all locations
Adding a new location Full new certification process Scope extension through your existing ACB
Internal audit burden Site-level program only Must reach all sites; centrally managed

Adding a New Site to an Existing Multi-Site Certificate

When you open a new facility and want to bring it under your existing certificate, the process is called a scope extension — meaningfully different from starting a new certification from scratch, though not trivial.

Your ACB will conduct a scope extension audit for the new location. This covers the site-specific requirements under R2v3: Focus Materials being processed, equipment and processes in use, data security implementation, downstream vendor qualifications, and whether your existing central management system actually applies to how the new site operates. That last piece is worth thinking through before auditors arrive. A new facility that operates differently from your established locations — different Focus Materials, different processes, different downstream vendors — may require meaningful additions to your documented management system before it can be included on the certificate.

Scope extensions typically happen during your next scheduled surveillance, though some ACBs will schedule a separate visit for a complex new site. One thing to verify in advance: your ACB must hold the appropriate SERI authorization to certify at the new location's jurisdiction. If you're expanding to a new state or a different country, confirm your ACB's geographic authorization before building the timeline.

Where Multi-Site Programs Break Down

I've worked with multi-site R2 programs across a range of organizational sizes, and the breakdowns cluster around a consistent set of issues.

Management system reach that exists on paper but not in practice. The central function has documented procedures that nobody at the satellite locations has ever been trained on. Internal audit reports cover headquarters thoroughly and the smaller facilities inconsistently — or not at all. Auditors look for tangible evidence: training records with signatures and dates, internal audit reports from every site, corrective action logs that include entries from locations other than the main campus.

Downstream vendor qualification that doesn't reach each site. R2v3 requires that every facility verify the downstream vendors receiving materials from that location. A multi-site program can't route all downstream verification through headquarters and leave individual sites with empty records. The documentation has to exist at the site where the material actually moves.

Data security variance across locations. R2v3 data security requirements apply at every facility that handles data-bearing devices. Sites that receive and process data-bearing equipment without the rigor of your flagship location create audit exposure for the entire certificate. This is an area where "we handle it the same way everywhere" is a statement auditors will test, not accept.

Focus Material handling differences that aren't documented. If Site A handles CRTs and Site B doesn't, that difference needs to be visible in your management system. Procedures that address CRT handling generically — without site-specific protocols for the site actively processing them — are an open gap. Auditors aren't looking for perfection; they're looking for honesty about scope and verified procedures for what each site actually does.

What Auditors Are Actually Looking For at Each Site

The site-level audit is a vertical slice — auditors are checking whether the central management system is actually operating at ground level, not whether the site can produce paperwork. Expect interviews with site personnel, walkthrough observations, and records review.

Questions that come up consistently at site-level visits:

  • How do you know which downstream vendors are approved for the materials you process here?
  • Walk me through what happens when a customer device arrives with data on it.
  • Who do you contact when you identify a compliance concern? What happens after that report is made?
  • When was the last time someone conducted an internal audit at this location?

If your site employees can't answer those questions fluently, the management system isn't functioning at that location — regardless of what the policy manual says. Document cleanup in the week before an audit doesn't fix that problem.

Timeline Expectations for Multi-Site Certification

For an organization pursuing multi-site R2 certification for the first time, the timeline depends on how many sites are in scope and the maturity of your existing management system. A general framework:

  • Gap assessment and management system development: 3 to 6 months, longer if building from nothing
  • Initial certification audit: Stage 1 document review followed by Stage 2 site audits — SERI expects the initial audit to cover an expanded sample, more comprehensive than subsequent surveillances
  • Certification decision: typically 4 to 8 weeks after Stage 2 completion, depending on the ACB's review process and any corrective action requirements
  • Annual surveillance: central function plus rotating site sample (√n minimum)
  • Three-year recertification: full scope, expanded sample

The initial certification is the most intensive phase. After that, the annual cadence becomes manageable — assuming your internal audit program runs consistently throughout the year and your corrective action process is keeping the certificate clean between visits.

Designing Your Program to Match the Audit Structure

If you're building or redesigning a multi-site R2 program, in my view the audit structure should shape your program design, not the other way around.

Build your internal audit program with the same logic your ACB uses — site rotation, risk-based selection, documented findings at every location. When your internal audits mirror the cadence and depth of external audits, there aren't surprises. The external audit confirms what you already know rather than discovering what you missed.

Invest in a real central function, not a nominal one. The person or team responsible for the management system needs genuine organizational authority and genuine reach into each facility. Auditors can tell the difference — they're looking at whether corrective actions actually get closed, whether training records reflect consistent delivery, whether internal audit findings get tracked and resolved rather than filed.

Document site-specific variances deliberately. Not every location handles the same materials or runs the same processes, and those differences should be visible in your management system. Clarity about scope differences is not a weakness in your program. Obscuring them is.

Our R2 Audit Preparation Guide covers the documentation checklist and process readiness steps for both initial certification and ongoing surveillance.


Frequently Asked Questions

How many sites get audited in a multi-site R2 surveillance visit?

The minimum is the square root of the total number of sites (√n), rounded up. A 9-site program requires at least 3 sites audited per cycle; a 16-site program requires at least 4. Risk-based factors — new sites, open nonconformances, high-risk Focus Materials — can expand the sample above that minimum.

Can a nonconformance at one site affect the entire multi-site certificate?

Yes. Because all facilities share a single certificate, a major nonconformance or suspension at one location can carry consequences for the entire certificate. This is the structural tradeoff of multi-site certification, and it's why internal audit programs that genuinely reach every site matter so much.

How do I add a new facility to an existing multi-site R2 certificate?

Through a scope extension audit conducted by your existing ACB. The audit covers the new site's Focus Materials, processes, data security practices, and downstream vendor qualifications, and verifies that your central management system applies to the new location. The extension typically happens during your next scheduled surveillance, though complex new sites may warrant a separate visit.

Is multi-site R2 certification less expensive than separate certifications for each facility?

At scale — generally five or more locations — yes, significantly. The √n sampling formula means the annual audit burden grows much more slowly than the number of sites. A company with 25 locations on a multi-site certificate audits a minimum of 5 sites per cycle rather than 25 separate full audits.

What does a central function need to demonstrate to qualify for multi-site certification?

Documented authority over the management system, active governance of all covered facilities (including training delivery, internal audit oversight, and corrective action tracking), and verifiable reach — meaning auditors can find evidence at each site that the central system is actually operating there, not just documented at headquarters.


Last updated: 2026-07-21

J

Jared Clark

Principal Consultant, Certify Consulting

Jared Clark is the founder of Certify Consulting, helping organizations achieve and maintain compliance with international standards and regulatory requirements.

Need R2 Certification Help?

Whether you’re starting your R2 certification journey or preparing for your R2v3 upgrade, our team is here to help. Schedule a free consultation to discuss your goals and get a realistic roadmap.