ISO Surveillance Audit: What to Expect Year After Year
An ISO surveillance audit is a mandatory annual check that your certified management system continues to conform to the standard and operates effectively. It is conducted by your certification body approximately 12 months after the initial certification and again at 24 months, covering years one and two of the three-year certification cycle. The surveillance audit is shorter than the initial Stage 2 audit, typically lasting one to two days, and focuses on high-risk areas, changes to the organisation and the status of any outstanding nonconformities. Passing both surveillance audits is required to maintain your certificate.
Published: July 2026 | Last updated: July 2026 | Author: Bitrixme Compliance Team
What Is a Surveillance Audit?
A surveillance audit is a periodic assessment conducted by the certification body to verify that a certified management system continues to meet the requirements of the standard. Unlike the initial certification audit, which is a comprehensive evaluation of the entire system, surveillance audits are targeted. The auditor samples selected processes, controls and clauses to confirm that the system is being maintained and improved. Surveillance audits are defined in ISO 17021-1, the standard that governs certification body practices, and are mandatory for all accredited ISO certificates.
When Surveillance Audits Happen
The first surveillance audit occurs approximately 12 months after the certification decision date. The second surveillance audit occurs at approximately 24 months. The certification body must conduct at least one surveillance audit per calendar year, and no more than 12 months may pass between surveillance visits. If the organisation misses a surveillance audit, the certificate may be suspended or withdrawn. At the end of the three-year cycle, a full recertification audit replaces the surveillance audit.
What Auditors Check During Surveillance
The auditor reviews a sample of the management system rather than the entire scope. The following areas are prioritised during every surveillance visit.
- Internal audits and management review. Evidence that internal audits have been conducted as scheduled and that management review addresses system performance, nonconformities and improvement opportunities.
- Nonconformity closure. Verification that minor nonconformities from the previous audit have been corrected and that corrective actions are effective.
- Changes to the organisation. New products, services, locations, technologies or regulatory obligations that may affect the management system.
- Complaints and corrective actions. How the organisation handles customer complaints and internal findings, and whether root cause analysis is applied.
- Continual improvement. Evidence that the organisation is improving the management system, not merely maintaining it.
- High-risk areas. Processes and controls that are critical to the standard’s objectives, such as information security risk treatment for ISO 27001 or hazard identification for ISO 45001.
Surveillance Audit vs Recertification Audit
It is important to distinguish the annual surveillance audit from the recertification audit that occurs every third year. They differ in scope, duration and purpose.
| Aspect | Surveillance Audit | Recertification Audit |
|---|---|---|
| Frequency | Annual (years 1 and 2) | Every 3 years |
| Duration | 30 – 50% of initial Stage 2 audit days | 80 – 100% of initial Stage 2 audit days |
| Scope | Sampled processes, high-risk areas, changes, nonconformity follow-up | Full system re-assessment |
| Document review | Limited – focuses on changes | Full documentation review |
| Purpose | Verify ongoing conformity and maintenance | Confirm continued relevance and effectiveness of the full management system |
| Nonconformity impact | Major NC can result in suspension | Major NC prevents recertification |
| Cost | 30 – 40% of initial audit fee | 80 – 100% of initial audit fee |
How to Prepare for a Surveillance Audit
Preparation for a surveillance audit should be ongoing rather than reactive. The following actions ensure readiness.
- Keep the management system live. Update documentation when processes change, not when the auditor is due. A system that is maintained day-to-day requires no special preparation.
- Conduct scheduled internal audits. Ensure internal audits are performed according to the annual programme and that findings are closed before the surveillance visit.
- Hold the management review. Management review must be conducted at planned intervals. Evidence of a recent management review meeting with documented outputs is a surveillance requirement.
- Review nonconformities from the previous audit. Confirm that corrective actions have been implemented and verified as effective. Open nonconformities are a red flag for the auditor.
- Notify the certification body of changes. If the organisation has changed location, added new sites, changed key personnel or undergone significant process changes, inform the certification body in advance.
- Prepare the audit trail. Ensure records are accessible: internal audit reports, management review minutes, corrective action logs, training records and policy updates since the last visit.
Common Nonconformities Found During Surveillance
The most frequently cited surveillance nonconformities relate to the operation and evaluation clauses. Common findings include incomplete internal audit coverage (some processes are never audited), management review that does not address system performance against objectives, inadequate root cause analysis of customer complaints, delayed corrective actions, and lack of evidence that the management system has been reviewed following organisational changes. Most surveillance nonconformities are minor and can be closed with a corrective action plan, but recurrent issues or unresolved major nonconformities can lead to certificate suspension.
| Common Finding | Affected Clause | Typical Severity |
|---|---|---|
| Internal audit programme not fully executed | Clause 9.2 | Minor |
| Management review inputs incomplete | Clause 9.3 | Minor |
| Corrective action root cause analysis shallow | Clause 10.1 | Minor |
| Documentation not updated after process changes | Clause 7.5 | Minor / Observation |
| No evidence of continual improvement | Clause 10.3 | Minor |
| Training records incomplete | Clause 7.2 | Minor / Observation |
Remote vs On-Site Surveillance Audits
Many certification bodies now offer remote or hybrid surveillance audits, particularly for lower-risk processes. A remote audit is conducted via video conference with document review and interviews, without a physical site visit. On-site audits remain mandatory for high-risk industries, critical processes and organisations where physical observation of controls is necessary. The certification body decides the audit method based on risk assessment. If remote auditing is an option, it can reduce travel costs and auditor availability constraints, but the organisation must have the digital infrastructure to support document sharing and virtual interviews.
FAQ
What is an ISO surveillance audit?
An ISO surveillance audit is a mandatory annual check conducted by your certification body to verify that your certified management system continues to conform to the standard. It occurs in years one and two of the three-year certification cycle.
How long does a surveillance audit take?
Typically one to two days, compared to three to ten days for the initial Stage 2 audit. The duration depends on the standard, organisation size, site count and the findings of previous audits.
Can I fail a surveillance audit?
Yes. A major nonconformity found during surveillance can result in certificate suspension until corrective action is implemented and verified. If the nonconformity is not resolved within the timeframe set by the certification body, the certificate may be withdrawn.
What happens if I miss a surveillance audit?
The certification body may suspend the certificate. If the audit is not conducted within the allowable window, the certificate can be withdrawn and the organisation must restart the full certification process.
Is a surveillance audit the same as recertification?
No. Surveillance audits are shorter annual checks. Recertification occurs every three years and is a full re-assessment similar in scope to the initial Stage 2 audit.
Can surveillance audits be done remotely?
Yes, for certain standards and risk levels. The certification body decides based on a risk assessment. Remote audits require reliable internet, document sharing and video conferencing capability.
Need help preparing for your next surveillance audit? Contact our compliance team for a pre-surveillance readiness review, or message us on WhatsApp.