ISO 27001 · Audit cycle

How does an ISO 27001 surveillance audit work?

An ISO 27001 surveillance audit is a shorter check-in visit by your certification body in years one and two of the three-year certificate. It samples controls rather than testing all of them, and focuses on what changed and what was raised last time.

When does a surveillance audit happen?

Your certificate runs on a three-year cycle: a full initial audit in year zero, a surveillance visit in year one, another in year two, then a recertification audit before the certificate expires. Certification bodies usually schedule surveillance within twelve months of the previous visit, and the date is agreed in advance, not sprung on you.

What does the auditor actually look at?

A sample. The auditor proposes which controls this visit covers and writes it into a sampling plan. Three things are almost always in it: the findings raised last time and what you did about them, any change to scope, people or systems, and the parts of the management system that must operate every year, such as internal audit, management review and risk assessment.

Each sampled control gets a conclusion: compliant, partially compliant, non-compliant, or not yet recorded. The last one is a real state. An unreviewed control and a passing one are different facts.

How is it different from the initial audit?

Scope and depth. The initial audit tests every control in the Statement of Applicability. A surveillance visit tests a slice, so it is shorter, usually one to two days for a small organisation. The certificate stays valid throughout unless a major non-conformity is left unresolved.

What can go wrong?

The visit fails on handover, not on controls. The evidence lives in a shared drive, the auditor works from an emailed spreadsheet, and nobody can show which version they saw last year. The first two days go on reconstructing history instead of reviewing the sample.

Certifyi keeps findings, evidence and scope attached to each engagement, so the surveillance auditor opens with last year’s record intact and reads the prior findings inside the current visit. The remaining work is answering the sample.

How should you prepare?

  • Close or formally track every finding from the last visit, with who verified the fix.
  • Run the internal audit and management review before the visit, and keep the minutes.
  • Refresh evidence that has aged: access reviews, training records, supplier assessments.
  • Confirm readiness with the auditor once preparation is complete, and agree the sampling plan in advance.

Where you stand

Score your own readiness in one sitting

The free self-assessment walks through the controls an auditor samples, gives you a scored report, and takes about fifteen minutes. No account needed.

Related questions

No. Stage 1 and Stage 2 belong to the initial certification. A surveillance visit is a single fieldwork stage against a sampled scope.

Only if a major non-conformity is raised and not corrected within the period the certification body sets. Minor findings are tracked to the next visit.

Certifyi supports ISO 27001 as a framework in the platform. Supporting a framework and being certified against it are different statements; ask us for our own current status on a call.

See it against your own controls.

30 minutes with a compliance lead, not a sales rep.
Scroll to Top