
A surveillance audit is the certification body’s periodic check that your ISMS still works, not a repeat of the original certification review. Auditors sample evidence rather than re-examine everything, and they weight four areas heavily: closed corrective actions with proof they actually fixed the problem, a current risk assessment, a documented management review, and a completed internal audit. Get those four right and the rest of the visit is mostly conversation.
TL;DR:
- Surveillance audits focus on verifying that existing controls are operating effectively in practice, with sample checks of corrective actions, risk assessments, and selected controls.
- Proper preparation involves assigning an audit coordinator, centralizing evidence, conducting a mock audit 4 to 6 weeks in advance, and documenting management reviews thoroughly.
- Common findings often relate to overdue corrective actions, incomplete management records, stale risk registers, and lack of evidence confirming controls are working.
- Meeting the IAF guideline, surveillance audit durations are typically about one-third of the initial certification audit, with sampling formulas reducing scope for multi-site organizations.
- Maintaining ongoing evidence management, updating key documents continuously, and conducting regular internal reviews help organizations stay audit-ready all year, not just before scheduled visits.
Table of Contents
- What Is an ISO 27001 Surveillance Audit and Why Does It Happen?
- How Surveillance Audits Differ From Initial and Recertification Audits
- When Do Surveillance Audits Happen in the Three-Year Cycle?
- What Do Auditors Actually Check in a Surveillance Audit?
- How to Prepare for a Surveillance Audit: A Practical Timeline
- What Are the Most Common Surveillance Audit Findings?
- How Do You Stay Audit-Ready All Year, Not Just Before the Visit?
- What Audit-Time and Sampling Rules Should You Expect?
- Treat Surveillance as Validation, Not a Checkbox
- Get an Evidence-Ready Estimate Before Your Next Audit
- Sources
- FAQ
What Is an ISO 27001 Surveillance Audit and Why Does It Happen?
A surveillance audit is a scheduled check by your certification body confirming that your information security management system (ISMS) is still operating the way it was when you earned certification. It’s not a paperwork review. Auditors want proof that controls are running day to day, not just described in a policy binder that hasn’t been opened since the last visit.
The goal is operational verification. ISO/IEC 27007 frames the auditor’s job as confirming that a management system functions effectively in practice, which is a different exercise from checking that documents exist. A surveillance visit typically samples:
- Progress on corrective actions from the last audit
- Whether the risk assessment and Statement of Applicability (SoA) still reflect reality
- Evidence that internal audits and management review happened on schedule
- A handful of Annex A controls, chosen by the auditor, tested for actual operation
Passing means the auditor finds no major nonconformities and, ideally, few or no minor ones. A major finding, such as a control that clearly isn’t operating or a corrective action that was never verified, can trigger a suspension of certification if it isn’t resolved within the timeframe the certification body sets. That’s the real stake behind a visit that many teams treat as routine.
How Surveillance Audits Differ From Initial and Recertification Audits
Each audit in the three-year cycle asks a different question. The initial certification audit asks, “Does this ISMS exist and function as documented?” A surveillance audit asks, “Is it still working?” Recertification asks, “Has it kept working across the whole cycle?”
| Audit type | Scope | Typical duration | Who’s usually involved |
|---|---|---|---|
| Initial certification | Full document review (Stage 1) plus full implementation review (Stage 2) | Longest of the three, based on IAF time tables | ISMS owner, most process owners, leadership |
| Surveillance (Years 1 and 2) | Sampled controls, corrective actions, management review, internal audit | About one-third of initial audit time per IAF MD5 | ISMS owner, select process owners |
| Recertification (Year 3) | Full ISMS reassessment against the whole cycle’s performance | Comparable to initial certification | Same breadth as initial audit |
Don’t mistake “sampled” for “less serious.” A minor finding in a surveillance audit carries the same weight toward your certification status as one found during recertification. Auditors are simply looking at a smaller slice of the system each time.
When Do Surveillance Audits Happen in the Three-Year Cycle?
Certification runs on a three-year cycle with a predictable rhythm: surveillance audits in Years 1 and 2, then full recertification in Year 3, before the cycle resets. Certification bodies generally schedule surveillance visits within a defined window around the anniversary of your certification date, and there’s usually some tolerance either side, though drifting too far from that date invites scrutiny.
Build your internal calendar around three checkpoints rather than one deadline:
- Nine months out: confirm the audit date with your certification body and assign an internal owner for prep.
- Six months out: review the previous audit’s corrective actions and confirm they’re closed and verified, not just marked complete.
- Four to six weeks out: run a mock review (more on that below) and finalize the evidence package.
Teams that only start preparing in the final week almost always scramble on management review documentation, since that record has to reflect a meeting that actually happened on schedule, not one assembled the night before the auditor arrives.
What Do Auditors Actually Check in a Surveillance Audit?
Auditors work from a short, predictable list, and most of it comes down to proving that things you say happen actually happened. ISO/IEC 27006 sets the certification-body obligations behind this, but the practical checklist looks like this:
Mandatory reviews:
- Internal audit results from the current cycle, including scope, findings, and closure status
- Management review minutes, with attendance, inputs discussed, and decisions recorded
- Corrective action tracker showing root cause, fix, and verification that the fix worked
Risk and control alignment:
- Updated risk assessment reflecting new assets, threats, or business changes since the last audit
- SoA consistency, meaning your justified inclusions and exclusions still match what you’re actually doing
- A sample of Annex A controls the auditor selects on the day, often without much advance warning
- Incident response records, including any incidents logged since the last audit and how they were handled
Operational evidence auditors like to see:
- Access review logs showing periodic recertification of user permissions
- Control test outputs, such as vulnerability scan results or backup restoration tests
- Training attendance and assessment results, not just a slide deck someone presented once
- Supplier performance records showing you’re actually monitoring vendors against your security requirements, not just filing their contracts
The recurring theme across all of this: ISO/IEC 27007 treats control effectiveness as the real test, and auditors consistently look for evidence that a control operates, not evidence that someone wrote a policy about it.
Pro Tip: Keep a single “evidence index” spreadsheet mapping each ISO clause and Annex A control to its supporting file, owner, and last-updated date. When an auditor asks for proof of a control, you want to open one document, not search four shared drives while they wait.

How to Prepare for a Surveillance Audit: A Practical Timeline
Preparation goes smoothly when one person owns it and everyone else knows their piece. Here’s a sequence that works for most mid-sized ISMS programs.
-
Assign an audit coordinator. This person doesn’t do all the work, but they track who owns what evidence, chase overdue items, and act as the single point of contact for the auditor’s requests. Without this role, evidence collection turns into a scavenger hunt in the final week.
-
Centralize evidence and enforce version control. Scattered folders across email, shared drives, and personal laptops are the single biggest reason preparation drags. Put every audit artifact, risk register, corrective action log, and training record, into one system with clear version history, so nobody hands the auditor an outdated SoA by accident.
-
Map evidence to ISO clauses before the audit, not during it. Go clause by clause through your certification scope and confirm you have current, dated evidence for each requirement. Gaps found here cost you weeks. Gaps found by the auditor cost you a finding.
-
Run a 4 to 6 week mock audit. This is where most of the value sits. Interview process owners the same way an external auditor would: ask them to explain the control, show you the evidence, and walk through what happens when it fails. Test a sample of Annex A controls directly, not just check that a policy references them. Verify that prior corrective actions were not only implemented but actually work, meaning you have test results, metrics, or logs showing the underlying problem hasn’t recurred.
-
Prepare the management review packet. This should include security metrics, incident summaries, audit results, risk changes, and resource needs, organized the way your actual meeting covered them. A management review that happened but wasn’t documented properly is treated by most auditors as if it didn’t happen at all.
A documented mock review conducted 4 to 6 weeks ahead of the real audit is one of the most reliable ways to cut down on minor findings, since it surfaces the exact gaps an external auditor would flag while there’s still time to close them, according to Copla’s surveillance audit planning guide.
Pro Tip: During the mock audit, have someone other than the ISMS owner conduct the interviews. Fresh eyes catch the “we just assume everyone knows this” gaps that the person who built the process will walk right past.
What Are the Most Common Surveillance Audit Findings?
The same handful of issues show up across most surveillance audits, and nearly all of them trace back to documentation that fell behind reality rather than a genuine security failure.
- Overdue corrective actions. A fix gets implemented but never formally closed or verified, so it sits open past its target date.
- Missing or thin management review records. The meeting happened, but nobody wrote down what was discussed or decided.
- Stale risk registers. New systems, vendors, or business changes went live without an updated risk assessment to match.
- Evidence-of-operation gaps. A control exists on paper, but nobody can produce logs, test results, or reports proving it ran during the audit period.
The fix for all four is the same discipline: document root cause, not just the fix, and record how you verified the fix actually worked, whether that’s a follow-up test, a metric trend, or a repeat audit of the same area. Governance habits that prevent recurrence include a live corrective action tracker with owners and due dates, SLAs for closing findings, and a quarterly trend dashboard that flags risks or metrics drifting the wrong way before an auditor ever sees them.
How Do You Stay Audit-Ready All Year, Not Just Before the Visit?
Teams that treat readiness as a once-a-year scramble consistently produce weaker evidence than teams that build it into routine operations. Centralized evidence management and automated control monitoring cut the manual scramble dramatically, since queries an auditor asks on the spot, like “show me access reviews from the last two quarters,” get answered from a live system instead of assembled from memory, an approach Scrut’s surveillance audit guide also points to as a major time saver.
Practical habits that pay off:
- Keep the SoA and risk register as living documents, updated when something changes, not just before an audit.
- Log control test results as they happen rather than reconstructing them retroactively.
- Track training completion and supplier reviews on a rolling schedule instead of an annual push.
Maturity assessments and benchmarking tools help here in a specific way: they translate scattered progress into a structure that maps directly onto what a management review needs to cover. A maturity assessment across the four Annex A control themes gives you a defensible snapshot of where controls stand, and a Gantt-style implementation timeline shows an auditor (or your own leadership) exactly what’s planned, what’s done, and what’s overdue. IAF guidance puts annual surveillance audit time at roughly one-third of the initial certification audit’s duration, which means auditors expect a proportionally focused but still rigorous review, not a token check-in.
A free readiness check can act as a quick executive summary before the real audit, giving you a prioritized list of weak spots while there’s still runway to fix them.
What Audit-Time and Sampling Rules Should You Expect?
Certification bodies don’t set audit duration arbitrarily. IAF MD5 ties surveillance audit time to the initial certification audit, with the guidance that annual surveillance time across the cycle should run close to one-third of the initial audit’s duration, and surveillance audits are rarely shorter than a single audit day regardless of how small the organization is.
A few reference points worth knowing before you question a proposed audit plan:
- Multi-site organizations don’t get every location audited every year. Sampling formulas reduce the number of sites visited during surveillance years, though the certification body still expects evidence that a central function governs the ISMS consistently across all of them.
- ISO/IEC 27006 governs what certification bodies themselves must do, including how they plan surveillance frequency and assess auditor competence.
- ISO/IEC 27007 and the broader ISO 19011 standard guide how audits are actually run and how auditors are expected to behave and reason through evidence.
If a proposed audit duration looks unusually short given your organization’s size and scope, these are the documents to point to when you ask the certification body to justify it.
Treat Surveillance as Validation, Not a Checkbox
The organizations that handle surveillance audits well don’t see them as a hurdle. They see them as a forcing function that keeps governance honest between the bigger recertification cycles. A finding in Year 1 is a gift compared to the same gap surfacing during a client security review or, worse, an actual incident.
The habits that consistently produce clean audits aren’t dramatic: a quarterly review of open corrective actions, a risk register someone actually updates when the business changes, a SoA that reflects reality instead of the day it was first written. None of that requires a big program. It requires someone caring enough to keep it current between visits, not just before them.
Frame your prep this way to leadership: every piece of evidence you gather isn’t for the auditor, it’s proof your security program is doing what you told the board it does. That reframing tends to get budget and attention a compliance deadline never does.
— Martin
Get an Evidence-Ready Estimate Before Your Next Audit
You can use specialized tools to get real-time, organization-specific estimates of the effort and cost remaining between your current ISMS and full audit readiness, with assumptions behind every number fully visible and editable. Many such tools require no signup for initial calculations and provide documented methodologies instead of black boxes.

Start with the free 2-minute readiness check to get an instant snapshot of where your ISMS stands against model reference comparisons. From there, the ISO 27001 Readiness Assessment scores you across all four ISO/IEC 27001:2022 control themes and hands you a prioritized list of gaps, exactly the kind of evidence index a surveillance audit rewards. If you’re mapping out remediation timelines or budget for the next cycle, the ISO 27001 Cost Calculator turns that into a plan your finance team can actually approve. Run the free check now and walk into your next audit with a shortlist instead of a scramble.
Sources
- ISO/IEC 27006 — Requirements for bodies providing audit and certification of ISMS
- ISO 27001 surveillance audit: checklist, frequency, planning & reporting explained — Copla
FAQ
What Happens During an ISO Surveillance Audit?
An auditor reviews a sample of your ISMS rather than the whole system: closed corrective actions, management review records, internal audit results, updated risk assessments, and a handful of Annex A controls chosen on the day. The visit typically runs a proportion of your original certification audit’s duration as guided by IAF MD5, and is rarely shorter than a full audit day.
What Is the Difference Between a Recertification Audit and a Surveillance Audit?
A surveillance audit samples specific areas of your ISMS during Years 1 and 2 of the certification cycle, while recertification in Year 3 reassesses the entire system against performance across the whole cycle. Recertification duration is comparable to your original certification audit; surveillance audits are shorter and narrower in scope.
What Is a Surveillance Audit in ISO 27001?
It’s a scheduled check by your certification body confirming that your ISMS is still operating effectively, not just documented on paper. Auditors verify operational effectiveness through sampled evidence, following the guidance in ISO/IEC 27007, rather than repeating the full initial certification review.
Does ISO 27001 Certification Require Ongoing Audits?
Yes. Maintaining certification requires surveillance audits in Years 1 and 2 of each three-year cycle, followed by a full recertification audit in Year 3. Skipping a scheduled surveillance audit, or failing to close major findings within the certification body’s deadline, can result in suspension or withdrawal of certification.
How Can We Reduce Findings in Our Next Surveillance Audit?
Running a documented mock audit 4 to 6 weeks before the real visit is one of the most effective ways to cut minor findings, since it surfaces gaps while there’s still time to fix them. Tools like the ISO 27001 Readiness Assessment can help prioritize which gaps to close first based on your current maturity across ISO domains.