Back to Columns
ISMS & Certification12 min read

Preparing for the Surveillance Audit

September 14, 2026

Preparing for the Surveillance Audit
Share this article

The next thing a newly certified organisation faces is the surveillance audit in year two. Certification is not a one-off award: across the three-year certification cycle, an annual surveillance audit is what keeps it valid.

Year two can be harder to prepare for than year one. The reason is simple — in year one an external partner was alongside, the deadline was explicit, and the whole company was moving toward "get certified." Once the certificate arrives, that momentum evaporates on its own. The surveillance audit asks whether an organisation back in its normal rhythm kept the ISMS turning for twelve months.

The other common misreading is the nature of the audit. A surveillance audit is a reduced version of the initial one, but the depth is not reduced. The scope narrows; within that narrowed scope, whether things are genuinely operated is examined through concrete records.

This article covers how it differs from the initial audit, what twelve months of records must show, how to report changes, and how to build the annual schedule. For the whole picture see What Is an ISMS (ISO/IEC 27001)?; for the initial audit see What Stage 1 Looks At and What Stage 2 Looks At.

Disclaimer: This article is general information. Timing, auditor-days, and the scope examined at surveillance vary by certification body. The authoritative texts are ISO/IEC 27001 (JIS Q 27001) itself and the publications of the accreditation and certification bodies. Confirm your own dates and requirements with your body.

Where It Sits in the Three-Year Cycle

YearAuditPurposeEffort
1Stage 1 + Stage 2Confirm the ISMS is established and meets the requirementsLargest
2Surveillance (first)Confirm continued operation and maintained effectivenessLess than the initial audit
3Surveillance (second)As above; scope allocated so as not to repeat year twoSimilar to year two
4RecertificationRe-evaluate the effectiveness of the ISMS as a wholeLarger than surveillance

The key point is that surveillance is designed as a continuation. Certification bodies plan across the full three-year cycle so that the requirements and the scope are covered in aggregate — so an area examined lightly in year one may be examined closely in year two, and what year two skipped may come up in year three. "They didn't ask last year" is not a forecast.

Failing to undergo surveillance, or failing to close a major nonconformity, can lead to suspension or withdrawal of the certificate. Not deferring the scheduling conversation is the single most effective precaution. Recertification is covered in Preparing for Recertification in Year Three.

How It Differs from the Initial Audit

AspectInitial audit (stages 1 and 2)Surveillance audit
PurposeConfirm the ISMS is establishedConfirm it is maintained and still functioning
ScopeThe full set of requirements and the whole scopeNarrowed — but with items always examined
Auditor-daysLargest (for a small organisation, roughly 1–2 days stage 1 plus 2–3 days stage 2)Typically fewer than the initial audit
Main focusDocumentation, risk assessment, SoA, implementationTwelve months of operating records, closure of previous findings, changes
Document reviewA distinct stageCovered as needed within the on-site audit
FindingsBear directly on the certification decisionBear on whether certification is maintained

Narrower scope notwithstanding, some items come up every time. Treat the following as certain to be examined:

  • Internal audit records, findings, and corrections
  • Management review records
  • Status of previous nonconformities and observations
  • Records of complaints and incidents
  • Use of the certification mark and logo on your site and materials
  • Any change to scope, organisation, or systems

Anchor your preparation on those six and you will not be far off.

What "Twelve Months of Records" Means

This is the heart of it. Not whether the documents are tidy, but whether you did for twelve months what you said you would — evidenced by records.

AreaRecords expectedWhere gaps appear
Internal auditPlan, checklist, report, findings and correctionsNot all departments covered in one cycle; auditor independence not assured
Management reviewMinutes, decisions, resource judgementsRequired inputs missing — audit results, progress against objectives, changes in risk, interested-party requirements
Training and competenceAttendance records, comprehension checks, coverage of mid-year joinersIn-year joiners and contractors fall outside the target list
Risk assessmentEvidence of review, what changed and whyYear one's table untouched — note that "no change" also needs a record
Asset registerAdditions, disposals, transfers reflectedLeavers' devices, cancelled SaaS, decommissioned servers still listed
Access rightsRecertification records, removal on leaving or transferThe review is logged as "done" with no differences or actions recorded
IncidentsOccurrence, response, prevention of recurrence"None occurred" is never recorded; near-misses not captured
Supplier managementSupplier register, evaluation records, contract renewalsAnnual evaluation not performed; sub-contracting untracked
Objectives and KPIsMeasurement results, action where missedTargets set but never measured
Continuity and exercisesExercise records, results, improvementsA plan exists; the exercise never happened

Two failures dominate: "we did it but have no record" and "we decided but kept no basis." Audits verify through records, so work actually done but not recorded is treated as not done. Conversely, "we reviewed it and decided not to change anything" is a perfectly good record — note the conclusion and the date.

The recurring finding patterns are collected in Common Audit Nonconformities.

Answering for Previous Findings

Surveillance always examines the nonconformities and observations from the last audit. A complete answer has three parts:

  1. What you did — the corrective action
  2. Why it cannot recur — the root cause, and what in the mechanism changed
  3. That it is actually working — twelve months of operating records since

Miss the third and the assessment becomes "actioned, effectiveness unverified," which invites the same finding again. Submitting the corrective action report is not the end; the following year's records are the evidence of effectiveness.

The same applies to observations. They are not breaches, so action is optional — but arriving at the next audit having done nothing can convert the point into a nonconformity. If you decide not to act, record why you considered it and chose the status quo.

See Writing a Corrective Action Report and Clause 10: Improvement.

Reporting Change: Organisation, Systems, Scope

Organisations change over a year. Reporting changes to your certification body in good time is part of maintaining certification. Report late and you invite a heavy finding on audit day: the scope statement no longer matches reality.

Type of changeExamplesHow to handle it
Scope changeAdding or closing a site, adding a business line, changing which departments are in scopeConsult the body in advance. It affects auditor-days and the audit plan, so raise it before it is final
Organisational changeA new ISMS manager, change of top management, a large change in headcountReport promptly. On a handover, prepare the handover record and evidence of the new appointee's competence
Significant system changeReplacing a core system, cloud migration, changing data centre, launching a new serviceHandle together with a risk assessment update; change management records will be examined
A major incidentData breach, ransomware, extended service outageCheck your contract and procedures for whether the body must be notified; keep the response records regardless
Changes in legal or contractual requirementsNew security requirements from a customer, responding to a guideline revisionRecord as a review of interested-party requirements

For healthcare companies, revisions to Japan's three-ministry guidelines and changing requirements in hospital contracts fall into this category. A record of how you reviewed your own posture after a guideline revision is strong material at surveillance (The Three-Ministry Guidelines, Demarcating Responsibility).

If headcount grew substantially, recalculated auditor-days can change the fee. See Audit Fees: Ranges and What Moves Them. And if you are unhappy with the fit or with the quality of reports, transferring mid-cycle has its own defined procedure — gather information early if you are considering it (Choosing a Certification Body).

Building the Annual Schedule

Most organisations that stumble do so for one reason: they try to run the internal audit and management review just before the audit and run out of time. Fix an annual plan worked backwards from the audit date.

Timing (relative to audit)Work
6 months beforeConfirm the annual plan; fix dates for training and the internal audit
4–5 months beforeDeliver training; chase completion
3 months beforeReview the risk assessment; recertify the asset register and access rights
2–3 months beforePerform the internal audit; raise findings
2 months beforeCorrect internal audit findings; confirm the audit date with the body
1–2 months beforeHold the management review; report changes to the body
1 month beforeFinal self-check of records; arrange attendees and location
Audit dayExplain closure of previous findings and twelve months of operation

The order of internal audit and management review cannot be swapped. The review takes audit results as an input, so the audit must come first. Reverse them and you get a finding for incomplete review inputs.

See Running an Internal Audit and Management Review and Its Minutes.

Preparation Checklist

One month out, verify the following.

Always examined

  • Internal audit performed, report exists, dated before the audit
  • Internal audit findings corrected, with records
  • Management review held, minutes exist, required inputs all present
  • Previous nonconformities and observations closed, with evidence of effectiveness
  • Incident and complaint records exist (including a record that none occurred)
  • Certification mark and logo used as the body's rules require

Twelve months of operation

  • Training records complete for the full roster, including in-year joiners and contractors
  • Risk assessment review recorded (including a decision of no change)
  • Asset register matches reality
  • Access rights review recorded; no live accounts for leavers or transferees
  • Supplier evaluations performed and recorded
  • Security objectives measured, with action recorded where targets were missed

Changes reflected

  • Organisational, system, and scope changes reported to the certification body
  • Risk assessment updated for those changes
  • Procedures, organisation chart, and scope statement match reality

Conclusion

  1. Surveillance audits happen every year in years two and three of the cycle; skipping one, or leaving a major nonconformity open, affects whether certification is maintained
  2. The difference from the initial audit is purpose — not "is it established" but "is it maintained and functioning," evidenced over twelve months
  3. Scope narrows, but internal audit, management review, previous findings, incidents, logo use, and changes should be assumed examined every time
  4. No record means not done. "Reviewed and decided no change" is a valid record
  5. Answer previous findings in three parts: what you did, why it cannot recur, and that it is working
  6. Report organisational, system, and scope changes in good time — scope changes especially, before they are final
  7. Internal audit → management review → audit is a fixed order. Build the year backwards from the audit date

Pottech also supports operation after certification: reviewing roles and scope, updating the risk assessment, performing internal audits, and handling surveillance and recertification audits. ISMS operational support starts at ¥800,000 per year (excluding tax, assuming an organisation of up to around 50 people). Payments to the certification body (audit fees) are not included in this price.

See ISMS Certification Support for detail, or contact us if year two is proving more than your team can carry alone.

References and Sources

Note: surveillance timing, auditor-days, examined scope, and the conditions for suspension or withdrawal vary by certification body. Interpretation of requirements and controls, and the handling of accreditation and certification, are governed by the standard itself and the publications of the accreditation and certification bodies. Guidelines are revised; always check the current edition.

Share this article

Related Articles

ISMS & Certification

Reading the 37 Organizational Controls

The 37 organizational controls of Annex A.5, grouped into eight clusters rather than translated one by one: policy and governance, assets and classification, access policy, suppliers and cloud, threat intelligence, incident management, continuity, and compliance. What each cluster is asking for, and what you end up producing.

September 14, 2026
ISMS & Certification

Annex A 2022: 93 Controls Across Four Themes

A map of the 93 Annex A controls in ISO/IEC 27001:2022 across four themes — 37 organizational, 8 people, 14 physical, 34 technological. Why there is no duty to implement all 93, how inclusion and exclusion are justified in the Statement of Applicability, what the attributes are for, and the order a healthcare company should work in.

September 14, 2026
ISMS & Certification

Reading the 8 People Controls

The 8 people controls of Annex A.6, grouped into entry, employment, exit, where people work, and reporting culture. How they connect to existing employment rules, how to handle segregation of duties when the team is too small for it, and how far to go on remote working — written for healthcare companies.

September 14, 2026
ISMS & Certification

Reading the 14 Physical Controls

The 14 physical controls of Annex A.7 in five clusters, with a concrete treatment of what a fully remote, cloud-only organisation can exclude and what must be reassigned to home-working rules and supplier management — data centres, media and disposal, and equipment off premises.

September 14, 2026
AI Karte

Explore AI Karte

An AI-native EHR connecting reception, documentation, accounting, claims, and analytics into one cycle.

View the product page

ISMS Certification Support as an Option

From scope design and documentation to training, internal audit, and dealing with the certification body. Pottech supports healthcare companies through ISO/IEC 27001 certification end to end.