The next thing a newly certified organisation faces is the surveillance audit in year two. Certification is not a one-off award: across the three-year certification cycle, an annual surveillance audit is what keeps it valid.
Year two can be harder to prepare for than year one. The reason is simple — in year one an external partner was alongside, the deadline was explicit, and the whole company was moving toward "get certified." Once the certificate arrives, that momentum evaporates on its own. The surveillance audit asks whether an organisation back in its normal rhythm kept the ISMS turning for twelve months.
The other common misreading is the nature of the audit. A surveillance audit is a reduced version of the initial one, but the depth is not reduced. The scope narrows; within that narrowed scope, whether things are genuinely operated is examined through concrete records.
This article covers how it differs from the initial audit, what twelve months of records must show, how to report changes, and how to build the annual schedule. For the whole picture see What Is an ISMS (ISO/IEC 27001)?; for the initial audit see What Stage 1 Looks At and What Stage 2 Looks At.
Disclaimer: This article is general information. Timing, auditor-days, and the scope examined at surveillance vary by certification body. The authoritative texts are ISO/IEC 27001 (JIS Q 27001) itself and the publications of the accreditation and certification bodies. Confirm your own dates and requirements with your body.
Where It Sits in the Three-Year Cycle
| Year | Audit | Purpose | Effort |
|---|---|---|---|
| 1 | Stage 1 + Stage 2 | Confirm the ISMS is established and meets the requirements | Largest |
| 2 | Surveillance (first) | Confirm continued operation and maintained effectiveness | Less than the initial audit |
| 3 | Surveillance (second) | As above; scope allocated so as not to repeat year two | Similar to year two |
| 4 | Recertification | Re-evaluate the effectiveness of the ISMS as a whole | Larger than surveillance |
The key point is that surveillance is designed as a continuation. Certification bodies plan across the full three-year cycle so that the requirements and the scope are covered in aggregate — so an area examined lightly in year one may be examined closely in year two, and what year two skipped may come up in year three. "They didn't ask last year" is not a forecast.
Failing to undergo surveillance, or failing to close a major nonconformity, can lead to suspension or withdrawal of the certificate. Not deferring the scheduling conversation is the single most effective precaution. Recertification is covered in Preparing for Recertification in Year Three.
How It Differs from the Initial Audit
| Aspect | Initial audit (stages 1 and 2) | Surveillance audit |
|---|---|---|
| Purpose | Confirm the ISMS is established | Confirm it is maintained and still functioning |
| Scope | The full set of requirements and the whole scope | Narrowed — but with items always examined |
| Auditor-days | Largest (for a small organisation, roughly 1–2 days stage 1 plus 2–3 days stage 2) | Typically fewer than the initial audit |
| Main focus | Documentation, risk assessment, SoA, implementation | Twelve months of operating records, closure of previous findings, changes |
| Document review | A distinct stage | Covered as needed within the on-site audit |
| Findings | Bear directly on the certification decision | Bear on whether certification is maintained |
Narrower scope notwithstanding, some items come up every time. Treat the following as certain to be examined:
- Internal audit records, findings, and corrections
- Management review records
- Status of previous nonconformities and observations
- Records of complaints and incidents
- Use of the certification mark and logo on your site and materials
- Any change to scope, organisation, or systems
Anchor your preparation on those six and you will not be far off.
What "Twelve Months of Records" Means
This is the heart of it. Not whether the documents are tidy, but whether you did for twelve months what you said you would — evidenced by records.
| Area | Records expected | Where gaps appear |
|---|---|---|
| Internal audit | Plan, checklist, report, findings and corrections | Not all departments covered in one cycle; auditor independence not assured |
| Management review | Minutes, decisions, resource judgements | Required inputs missing — audit results, progress against objectives, changes in risk, interested-party requirements |
| Training and competence | Attendance records, comprehension checks, coverage of mid-year joiners | In-year joiners and contractors fall outside the target list |
| Risk assessment | Evidence of review, what changed and why | Year one's table untouched — note that "no change" also needs a record |
| Asset register | Additions, disposals, transfers reflected | Leavers' devices, cancelled SaaS, decommissioned servers still listed |
| Access rights | Recertification records, removal on leaving or transfer | The review is logged as "done" with no differences or actions recorded |
| Incidents | Occurrence, response, prevention of recurrence | "None occurred" is never recorded; near-misses not captured |
| Supplier management | Supplier register, evaluation records, contract renewals | Annual evaluation not performed; sub-contracting untracked |
| Objectives and KPIs | Measurement results, action where missed | Targets set but never measured |
| Continuity and exercises | Exercise records, results, improvements | A plan exists; the exercise never happened |
Two failures dominate: "we did it but have no record" and "we decided but kept no basis." Audits verify through records, so work actually done but not recorded is treated as not done. Conversely, "we reviewed it and decided not to change anything" is a perfectly good record — note the conclusion and the date.
The recurring finding patterns are collected in Common Audit Nonconformities.
Answering for Previous Findings
Surveillance always examines the nonconformities and observations from the last audit. A complete answer has three parts:
- What you did — the corrective action
- Why it cannot recur — the root cause, and what in the mechanism changed
- That it is actually working — twelve months of operating records since
Miss the third and the assessment becomes "actioned, effectiveness unverified," which invites the same finding again. Submitting the corrective action report is not the end; the following year's records are the evidence of effectiveness.
The same applies to observations. They are not breaches, so action is optional — but arriving at the next audit having done nothing can convert the point into a nonconformity. If you decide not to act, record why you considered it and chose the status quo.
See Writing a Corrective Action Report and Clause 10: Improvement.
Reporting Change: Organisation, Systems, Scope
Organisations change over a year. Reporting changes to your certification body in good time is part of maintaining certification. Report late and you invite a heavy finding on audit day: the scope statement no longer matches reality.
| Type of change | Examples | How to handle it |
|---|---|---|
| Scope change | Adding or closing a site, adding a business line, changing which departments are in scope | Consult the body in advance. It affects auditor-days and the audit plan, so raise it before it is final |
| Organisational change | A new ISMS manager, change of top management, a large change in headcount | Report promptly. On a handover, prepare the handover record and evidence of the new appointee's competence |
| Significant system change | Replacing a core system, cloud migration, changing data centre, launching a new service | Handle together with a risk assessment update; change management records will be examined |
| A major incident | Data breach, ransomware, extended service outage | Check your contract and procedures for whether the body must be notified; keep the response records regardless |
| Changes in legal or contractual requirements | New security requirements from a customer, responding to a guideline revision | Record as a review of interested-party requirements |
For healthcare companies, revisions to Japan's three-ministry guidelines and changing requirements in hospital contracts fall into this category. A record of how you reviewed your own posture after a guideline revision is strong material at surveillance (The Three-Ministry Guidelines, Demarcating Responsibility).
If headcount grew substantially, recalculated auditor-days can change the fee. See Audit Fees: Ranges and What Moves Them. And if you are unhappy with the fit or with the quality of reports, transferring mid-cycle has its own defined procedure — gather information early if you are considering it (Choosing a Certification Body).
Building the Annual Schedule
Most organisations that stumble do so for one reason: they try to run the internal audit and management review just before the audit and run out of time. Fix an annual plan worked backwards from the audit date.
| Timing (relative to audit) | Work |
|---|---|
| 6 months before | Confirm the annual plan; fix dates for training and the internal audit |
| 4–5 months before | Deliver training; chase completion |
| 3 months before | Review the risk assessment; recertify the asset register and access rights |
| 2–3 months before | Perform the internal audit; raise findings |
| 2 months before | Correct internal audit findings; confirm the audit date with the body |
| 1–2 months before | Hold the management review; report changes to the body |
| 1 month before | Final self-check of records; arrange attendees and location |
| Audit day | Explain closure of previous findings and twelve months of operation |
The order of internal audit and management review cannot be swapped. The review takes audit results as an input, so the audit must come first. Reverse them and you get a finding for incomplete review inputs.
See Running an Internal Audit and Management Review and Its Minutes.
Preparation Checklist
One month out, verify the following.
Always examined
- Internal audit performed, report exists, dated before the audit
- Internal audit findings corrected, with records
- Management review held, minutes exist, required inputs all present
- Previous nonconformities and observations closed, with evidence of effectiveness
- Incident and complaint records exist (including a record that none occurred)
- Certification mark and logo used as the body's rules require
Twelve months of operation
- Training records complete for the full roster, including in-year joiners and contractors
- Risk assessment review recorded (including a decision of no change)
- Asset register matches reality
- Access rights review recorded; no live accounts for leavers or transferees
- Supplier evaluations performed and recorded
- Security objectives measured, with action recorded where targets were missed
Changes reflected
- Organisational, system, and scope changes reported to the certification body
- Risk assessment updated for those changes
- Procedures, organisation chart, and scope statement match reality
Conclusion
- Surveillance audits happen every year in years two and three of the cycle; skipping one, or leaving a major nonconformity open, affects whether certification is maintained
- The difference from the initial audit is purpose — not "is it established" but "is it maintained and functioning," evidenced over twelve months
- Scope narrows, but internal audit, management review, previous findings, incidents, logo use, and changes should be assumed examined every time
- No record means not done. "Reviewed and decided no change" is a valid record
- Answer previous findings in three parts: what you did, why it cannot recur, and that it is working
- Report organisational, system, and scope changes in good time — scope changes especially, before they are final
- Internal audit → management review → audit is a fixed order. Build the year backwards from the audit date
Pottech also supports operation after certification: reviewing roles and scope, updating the risk assessment, performing internal audits, and handling surveillance and recertification audits. ISMS operational support starts at ¥800,000 per year (excluding tax, assuming an organisation of up to around 50 people). Payments to the certification body (audit fees) are not included in this price.
See ISMS Certification Support for detail, or contact us if year two is proving more than your team can carry alone.
References and Sources
- Information Management System Accreditation Center (ISMS-AC)
- ISO/IEC 27001 Information security management systems | ISO
- ISO/IEC 17021-1 Conformity assessment — Requirements for bodies providing audit and certification of management systems | ISO
- Guidelines for the Safe Management of Medical Information Systems | MHLW
Note: surveillance timing, auditor-days, examined scope, and the conditions for suspension or withdrawal vary by certification body. Interpretation of requirements and controls, and the handling of accreditation and certification, are governed by the standard itself and the publications of the accreditation and certification bodies. Guidelines are revised; always check the current edition.