A surveillance audit is the periodic check that your certification body conducts between your initial certification and your recertification audit. If you have achieved ISO 9001, ISO 14001, or ISO 45001 certification, you will face a surveillance audit roughly every twelve months for the next two years before your certificate comes up for renewal. Many organisations treat these visits as a formality. That is a mistake. Surveillance audits have ended certifications, triggered major nonconformities, and exposed management systems that looked good on paper but had quietly deteriorated since the last visit. Understanding exactly what a surveillance audit is, how it differs from a certification audit, and what your auditor will actually be looking for is the first step toward staying certified with confidence.
On this page
The Three Year Certification Cycle
To understand surveillance audits, you need to understand the broader certification cycle. When an organisation achieves ISO certification, the certificate is valid for three years. That three year period is not a free pass. It is structured around a programme of ongoing external audits designed to verify that the management system continues to meet the requirements of the standard and that it is being maintained and improved.
The typical cycle looks like this. In year one, you complete your Stage 1 and Stage 2 certification audits. If no major nonconformities are raised, or if any raised are closed satisfactorily, your certificate is issued. In year two, your certification body conducts Surveillance Audit 1. In year three, they conduct Surveillance Audit 2. At the end of year three, you face the recertification audit, which is a more thorough reassessment that renews the certificate for another three year cycle.
Each surveillance audit is typically shorter than the original certification audit. The exact duration depends on the size and complexity of your organisation, your scope of certification, and the number of sites involved. For a small to medium organisation, a surveillance audit might take one day on site. For a larger, more complex operation, it could take two or more days.
Exemplar Global Recognised Training ProviderRTP No. 310970What Makes a Surveillance Audit Different From a Certification Audit
The certification audit is a comprehensive assessment of your entire management system against all clauses of the standard. The auditor reviews your documented information, interviews staff across all levels and functions, observes processes, and samples records to determine whether your system conforms to the requirements of the standard and is effectively implemented.
A surveillance audit is not a full system review. It is a targeted assessment focused on specific areas. Your certification body is required to include certain mandatory elements in every surveillance audit, but they will also choose areas to focus on based on risk, previous findings, and the parts of your system that have not been reviewed recently.
Mandatory Elements in a Surveillance Audit
Under ISO 17021, the standard that governs the operation of certification bodies, surveillance audits must cover at minimum the following areas:
- Internal audits and management review
- Actions taken on nonconformities identified during previous audits
- Handling of complaints
- Effectiveness of the management system in achieving the certified organisation's objectives
- Progress of planned activities aimed at continual improvement
- Continued operational control
- Review of any changes to the management system or the organisation
- Use of marks and any other reference to certification
These are the non negotiable elements. Your auditor will check these at every surveillance visit. Beyond these, the auditor will select additional areas to sample, and those selections will often reflect the risks identified during your certification audit or areas where your system has shown weakness.
What Auditors Actually Focus On
Here is where the practical reality matters. Many organisations prepare for surveillance audits by tidying up their documented information and making sure their procedures are up to date. That is necessary but not sufficient. Experienced auditors are not primarily interested in your documents. They are interested in whether your system is actually working.
Internal Audit and Management Review
These two elements are checked at every surveillance visit, and they are consistently where organisations get caught out. The auditor will want to see that internal audits have been completed on schedule, that they covered a meaningful scope, that findings were properly recorded, and that any nonconformities raised have been addressed with genuine root cause analysis and corrective action.
Management review is equally scrutinised. The auditor will check that management review has occurred, that it covered the mandatory inputs required by the standard, and that decisions and actions were recorded and followed through. A management review that consists of a brief meeting with no substantive discussion, no documented inputs, and no recorded outputs will attract a nonconformity. This is not uncommon.
Corrective Actions From Previous Audits
If your certification audit or previous surveillance audit raised nonconformities, the surveillance auditor will follow up on every one of them. They will want to see the root cause analysis that was conducted, the corrective action that was implemented, and evidence that the action was effective. Closing a nonconformity by updating a procedure without addressing the underlying cause will not satisfy an experienced auditor.
This is an area where organisations frequently underperform. The corrective action looks complete on paper, but when the auditor interviews staff or reviews records, it becomes clear that the change has not been embedded in practice. The result is often a repeat nonconformity, which raises serious questions about the effectiveness of the management system.
Operational Controls and Objectives
The auditor will sample your operational controls to verify that the system is being maintained in practice, not just on paper. For an ISO 9001 system, this might include reviewing customer order processing, checking calibration records, or verifying that nonconforming outputs are being controlled correctly. For ISO 14001, it might include checking that environmental aspects are being managed in line with documented controls. For ISO 45001, it might involve a site walk to observe whether hazard controls are in place and functioning.
Objectives are also reviewed. The auditor will check that your quality, environmental, or OH&S objectives are being monitored, that progress is being tracked, and that where objectives are not being met, there is evidence of action being taken.
Changes to the Organisation or the System
This element is often overlooked by organisations preparing for surveillance. If your organisation has changed significantly since the last audit, your auditor needs to know about it. New processes, new sites, changes in scope, key personnel changes, new significant environmental aspects, or changes to the risk profile of the organisation all need to be reflected in the management system and communicated to the certification body.
Organisations that have expanded, restructured, or changed their activities without updating their management system are vulnerable here. The auditor will be looking for evidence that changes were planned and controlled, not just that they happened.
Common Reasons Organisations Struggle at Surveillance Audits
After hundreds of external certification audits, the patterns are clear. Organisations that struggle at surveillance audits almost always fall into one of a few categories.
The Post Certification Slump
The most common problem is a drop in engagement after the certification audit. The organisation worked hard to achieve certification, the certificate arrived, and then the momentum faded. Internal audits start slipping. Management review gets deferred. Corrective actions are closed without genuine resolution. By the time the surveillance auditor arrives twelve months later, the system has quietly deteriorated.
The fix is straightforward in principle but requires discipline in practice. The management system needs to be maintained as a genuine operational tool, not a compliance exercise that gets dusted off before external audits.
Documented Information That Does Not Reflect Practice
Procedures that describe how things should be done but do not reflect how they are actually done are a consistent source of nonconformities. When the auditor interviews a worker and asks them to describe the process, the answer should broadly align with the documented procedure. When it does not, the auditor has found a gap, and they will pursue it.
Objectives With No Meaningful Progress
Objectives that were set at certification and have not been reviewed or progressed in twelve months are a red flag. The standard requires that objectives be monitored, that progress be evaluated, and that action be taken where objectives are not being achieved. An objective that sits unchanged on a spreadsheet with no evidence of monitoring or action will attract scrutiny.
Corrective Actions That Address the Symptom, Not the Cause
This is discussed above but deserves emphasis. Surface level corrective actions that address the symptom without identifying and eliminating the root cause are one of the most common reasons for repeat nonconformities at surveillance audits. If the same issue recurs, the auditor has strong grounds for a major nonconformity related to the effectiveness of the corrective action process itself.
How to Prepare for a Surveillance Audit
Preparation for a surveillance audit should not begin two weeks before the auditor arrives. It should be continuous. That said, a structured review in the weeks before the audit is valuable.
Review Your Internal Audit Programme
Check that internal audits have been completed as scheduled. If they have fallen behind, reschedule and complete them before the surveillance visit. The auditor will ask to see your internal audit programme and the results. Gaps in the programme will need to be explained, and if the explanation is simply that audits were not prioritised, that is a problem.
If you want to understand what a robust internal audit programme looks like and how to structure one that holds up under external scrutiny, the article on building an internal audit programme from scratch covers the practical steps in detail.
Review Your Management Review Records
Check that management review has occurred and that the records demonstrate a genuine review of the mandatory inputs. If your management review records are thin or formulaic, consider whether they would satisfy an auditor who is looking for evidence of genuine leadership engagement with the management system.
Review All Open Corrective Actions
Every corrective action that was raised at the certification audit or previous surveillance audit should be reviewed. Check that the root cause analysis is documented, that the corrective action taken addresses the root cause, and that there is evidence the action has been effective. If any corrective actions are still open, be prepared to explain why and what progress has been made.
Review Changes to the Organisation
Think about what has changed in your organisation since the last audit. New processes, new equipment, new staff in key roles, changes to your customer base, changes to your supply chain, changes to your physical environment. Any significant change should have been managed through your change management process and reflected in your management system.
Conduct a Pre Audit Review
A brief internal review of the mandatory surveillance audit elements, conducted a few weeks before the visit, will help identify any gaps that can be addressed before the auditor arrives. This is not about manufacturing evidence. It is about making sure that the system is genuinely functioning and that the records reflect what is actually happening.
For a detailed look at what certification body auditors are checking when they arrive on site, the article on what to expect during an ISO certification audit provides useful context, even though it focuses on the initial certification visit.
Exemplar Global Recognised Training ProviderRTP No. 310970What Happens If the Surveillance Audit Goes Badly
If the surveillance auditor raises a major nonconformity, the certification body will place your certificate under review. You will be given a defined timeframe, typically within a few weeks to a few months depending on the certification body's procedures, to implement and provide evidence of corrective action. If the major nonconformity is not closed within that timeframe, the certification body may suspend or withdraw your certificate.
Suspension means the certificate cannot be used while it is suspended. Withdrawal means the certificate is cancelled and you would need to go through the certification process again to regain it. Both outcomes have commercial consequences, particularly if certification is required for tender eligibility or contractual compliance.
Minor nonconformities raised at a surveillance audit must be addressed and closed before the next surveillance visit or recertification audit. The auditor will follow up on them at the next scheduled visit.
Surveillance Audits as a Genuine Improvement Tool
It is worth stepping back from the compliance framing for a moment. Surveillance audits are not just a hurdle to clear. They are an external check on whether your management system is delivering value. An experienced auditor who identifies genuine weaknesses in your system is doing you a service. The findings they raise, if addressed properly, should make your system more effective.
Organisations that treat surveillance audits as an opportunity to get an independent assessment of their system, rather than as an inspection to be passed, tend to get more value from the process. They engage openly with the auditor, they ask questions, and they use the findings to drive genuine improvement.
If you are responsible for maintaining your organisation's certification and want to build the skills to manage the audit process effectively, including preparing for surveillance visits, understanding what auditors look for, and running internal audits that actually add value, Audit Workshop offers practical, accredited training at Internal Auditor and Lead Auditor level across ISO 9001, ISO 14001, and ISO 45001. The courses are built around real audit practice, not theory, and are delivered by a lead auditor with over 500 external certification audits across a range of industries. You can explore the available courses at auditworkshop.com.













