Surveillance Audits
In ISO/IEC 27001 certification, a surveillance audit is a periodic, partial audit carried out by the certification body between the initial certification (or recertification) audit and the next recertification audit. Its purpose is to confirm that the certified Information Security Management Syste… In ISO/IEC 27001 certification, a surveillance audit is a periodic, partial audit carried out by the certification body between the initial certification (or recertification) audit and the next recertification audit. Its purpose is to confirm that the certified Information Security Management System (ISMS) continues to meet ISO/IEC 27001 requirements and is effectively implemented and maintained. Under ISO/IEC 17021-1 and ISO/IEC 27006, certification follows a three-year cycle, and surveillance audits must be conducted at least once each calendar year. The first surveillance audit must take place within 12 months of the certification decision date. Surveillance audits are not full system audits. They are typically shorter, often about one-third of the initial audit duration, and examine a planned sample of clauses and Annex A controls. The audit programme must be designed so that all ISMS requirements and relevant controls in the Statement of Applicability are covered across the cycle. Certain elements must be reviewed at every surveillance: internal audits and management review; corrective actions on nonconformities from previous audits; complaint handling; changes to scope, context, risks, or the organization; progress on information security objectives and continual improvement; the risk assessment and treatment process; and correct use of certification marks. For a Lead Auditor managing the audit programme, surveillance planning should be risk-based, as described in ISO 19011. Planning should take into account previous findings, significant changes, security incidents, new technologies, outsourcing, and areas of higher risk. The Lead Auditor defines the objectives, scope, criteria, team competence, and sampling approach, and then reports findings as major or minor nonconformities, opportunities for improvement, or positive practices. Outcomes affect certification status. If the ISMS remains effective, certification is maintained. If major nonconformities are not corrected in time, the certification may be suspended or withdrawn. Surveillance audits therefore support ongoing assurance, accountability, and continual improvement, so the ISMS does not become a one-time compliance exercise.
Surveillance Audits in an ISO/IEC 27001 Audit Programme: A Complete Guide for Lead Auditors
Introduction
Surveillance audits are a core part of the ISO/IEC 27001 certification cycle. Exam questions on this topic test whether you understand how a certification body keeps confidence in a client's Information Security Management System (ISMS) between initial certification and recertification. This guide explains what surveillance audits are, why they matter, how they work, and how to answer exam questions about them.
1. What Is a Surveillance Audit?
A surveillance audit is a periodic, partial audit of a certified ISMS. A certification body carries it out during the three-year certification cycle, after the initial certification audit (Stage 1 and Stage 2) and before the recertification audit.
Its purpose is to confirm that the certified ISMS:
• continues to conform to ISO/IEC 27001 requirements,
• is effectively implemented and maintained, and
• keeps achieving its intended outcomes.
Key reference documents:
• ISO/IEC 17021-1: requirements for bodies that audit and certify management systems.
• ISO/IEC 27006: additional requirements specific to ISMS certification bodies.
• ISO 19011: guidelines for auditing management systems, including managing audit programmes.
2. Why Are Surveillance Audits Important?
• They maintain confidence in the certificate. A certificate is only meaningful if the ISMS keeps working after the initial audit. Surveillance shows interested parties (customers, regulators, partners) that conformity is ongoing.
• They check continual improvement. ISO/IEC 27001 Clause 10 requires continual improvement. Surveillance looks for evidence that the ISMS is evolving, not stagnating.
• They catch drift early. Organisations change through new technology, mergers, outsourcing, new threats and staff turnover. Surveillance detects whether controls have degraded or the risk assessment is out of date.
• They follow up on nonconformities. Surveillance verifies that corrective actions from earlier audits were implemented and effective.
• They protect the integrity of the certification body. Accreditation rules require surveillance. Without it, the certification body would be issuing certificates it cannot stand behind.
• They are the basis for certificate decisions. Results feed into decisions to maintain, suspend, reduce the scope of, or withdraw the certificate.
3. How Surveillance Audits Work
3.1 Position in the Certification Cycle
The typical three-year cycle runs as follows:
• Year 0: Initial certification audit (Stage 1 + Stage 2). Certificate issued.
• Year 1: First surveillance audit.
• Year 2: Second surveillance audit.
• Year 3: Recertification audit, completed before the certificate expires.
3.2 Frequency and Timing
• ISO/IEC 17021-1 requires surveillance at least once each calendar year, except in recertification years.
• The first surveillance audit must take place no later than 12 months from the date of the certification decision. This is a classic exam point: the date is counted from the certification decision, not from the last day of the Stage 2 audit.
• More frequent surveillance (for example, every six months) may be scheduled based on risk, complexity or past performance.
3.3 Scope and Content
A surveillance audit does not have to cover the whole ISMS each time. Over the cycle, however, the audit programme must make sure all clauses, relevant Annex A controls, and all sites and processes in scope are covered.
Each surveillance audit must always include:
• Internal audits and management review (Clauses 9.2 and 9.3).
• Review of actions taken on nonconformities identified in the previous audit.
• Treatment of complaints.
• Effectiveness of the ISMS in achieving the certified client's objectives and intended results.
• Progress of planned activities aimed at continual improvement.
• Continuing operational control.
• Review of any changes to the organisation, its context, scope or ISMS.
• Use of marks and any other reference to certification (for example, misuse of the certificate or logo).
ISO/IEC 27006 adds ISMS-specific expectations, such as:
• risk assessment and risk treatment updates,
• the Statement of Applicability (SoA),
• changes to the threat landscape, and
• effectiveness of controls.
3.4 Audit Duration
Surveillance audit time is usually about one third of the combined initial certification audit time (Stage 1 + Stage 2). Duration is calculated using IAF MD 5 and ISO/IEC 27006, then adjusted for factors such as complexity, number of sites and changes.
3.5 Multi-Site Organisations
Where sampling is allowed (IAF MD 1), surveillance covers the central function every year plus a sample of sites. The programme must ensure all sites are visited over time.
3.6 The Surveillance Audit Process
1. Planning: review the audit programme, previous reports, open nonconformities and any client changes. Prepare an audit plan and send it to the client in advance.
2. Opening meeting: confirm scope, objectives, criteria, schedule and confidentiality.
3. Collecting evidence: interviews, observation, document and record review, sampling.
4. Generating findings: classify findings as conformities, major nonconformities, minor nonconformities or opportunities for improvement.
5. Closing meeting: present findings and agree timeframes for corrections and corrective actions.
6. Reporting: issue a report with a recommendation on continuing certification.
7. Follow-up: verify corrective actions, either remotely or on-site.
3.7 Possible Outcomes
• Certification maintained: there are no major nonconformities, or nonconformities were resolved satisfactorily.
• Suspension: the client fails to address major nonconformities in time, refuses surveillance, misuses the certificate, or has seriously failed its ISMS.
• Scope reduction: some parts of the scope persistently fail to conform.
• Withdrawal: issues are not resolved within the suspension period (often up to six months).
A major nonconformity found during surveillance must be corrected, and the corrective action verified, within the timeframe set by the certification body. Otherwise suspension may follow.
3.8 Special Audits and Short-Notice Audits
These are different from routine surveillance. Special audits may be held to:
• investigate complaints,
• respond to significant changes,
• follow up on suspended clients, or
• extend scope.
Questions sometimes test whether you can tell special audits apart from regular surveillance.
3.9 Remote Audits
Surveillance may use remote auditing techniques (IAF MD 4) when it is risk-appropriate and effective. Information security and confidentiality must be protected during remote sessions.
4. Comparing Audit Types
• Initial certification audit: two stages covering the full system. Stage 1 assesses readiness. Stage 2 assesses implementation and effectiveness.
• Surveillance audit: partial, annual, and focused on continued conformity, changes, mandatory elements and improvement.
• Recertification audit: full system review covering performance over the whole cycle. It must be completed before the certificate expires.
• Internal audit: a first-party audit carried out by the organisation itself (Clause 9.2). It is not performed by the certification body, but it is reviewed during surveillance.
5. Role of the Lead Auditor in Surveillance
The lead auditor:
• plans the audit using a risk-based approach,
• makes sure the audit programme rotates coverage across clauses, controls and sites,
• leads the team and maintains impartiality,
• evaluates corrective actions from earlier audits,
• identifies changes that might affect the certification scope, and
• writes the report and makes the recommendation.
The lead auditor recommends. The certification body's independent decision-maker makes the final certification decision.
Exam Tips: Answering Questions on Surveillance Audits
Tip 1: Memorise the timing rules. The first surveillance audit must occur within 12 months of the certification decision date. After that, surveillance happens at least annually, except in the recertification year. When a question offers dates, pick the option tied to the certification decision.
Tip 2: Know the mandatory elements. Internal audit, management review, follow-up of previous nonconformities, complaints, changes, continual improvement, operational control and use of certification marks must be checked at every surveillance audit. If an option leaves out internal audit or management review, it is probably wrong.
Tip 3: Partial does not mean incomplete. One surveillance audit need not cover everything, but the programme must cover the full scope over the cycle. Watch for distractors that say surveillance covers the whole standard every year, or that some controls never need to be audited.
Tip 4: Separate the roles. The audit team recommends. The certification body decides. The auditee implements corrective actions. Auditors must never provide consultancy, such as designing solutions, because it threatens impartiality.
Tip 5: Know the consequences. Unresolved major nonconformities can lead to suspension. If issues persist, the result is withdrawal or scope reduction. Refusing a surveillance audit within the required time is grounds for suspension.
Tip 6: Answer scenarios with a risk-based approach. In case questions such as "The client acquired a new data centre since the last audit. What should the lead auditor do?", choose answers that:
• assess the impact of the change on scope, risk assessment and SoA,
• adjust the audit plan or duration, and
• consider whether a special audit or scope extension is needed.
Tip 7: Link to ISO/IEC 27001 clauses. Cite relevant clauses to strengthen your answers:
• 4.3 (scope)
• 6.1.2 and 6.1.3 (risk assessment and treatment)
• 8.2 and 8.3 (operational risk activities)
• 9.1 (monitoring)
• 9.2 (internal audit)
• 9.3 (management review)
• 10.1 and 10.2 (continual improvement, nonconformity and corrective action)
Tip 8: Verify corrective action effectiveness. Checking that a corrective action exists is not enough. You must verify that it removed the root cause and that the problem has not come back. An answer that just accepts the client's statement is usually wrong. Look for options involving objective evidence.
Tip 9: Use the right terminology. Use terms such as audit programme, audit plan, audit criteria, objective evidence, nonconformity, correction versus corrective action, certification decision, and impartiality. Precise language earns marks in essay and scenario questions.
Tip 10: Structure essay answers clearly. For long-form answers, use this order:
• Definition
• Purpose and importance
• Requirements (frequency, mandatory content, standards)
• Process
• Outcomes
• Practical example
Tip 11: Watch for trap words. Be wary of absolute words such as "always" and "never", and of claims such as "every control must be audited at every surveillance" or "surveillance can be skipped if no changes occurred." These are usually false.
Tip 12: Remember certificate misuse. Checking how the client uses the certification mark and certificate is a surveillance requirement. It is easy to overlook, so it is often tested.
6. Sample Exam Question and Model Answer
Question: During the second surveillance audit, you find that the client has not held a management review since the certification audit. What should you do?
Model answer:
• Management review (Clause 9.3) must be conducted at planned intervals and is a mandatory surveillance element.
• Missing it for a long period suggests a systemic failure of top management's commitment (Clause 5.1).
• This would normally be raised as a major nonconformity, because it means a requirement is entirely absent.
• The lead auditor should gather objective evidence, such as records and interviews with top management.
• The finding should be presented at the closing meeting, with a requirement for correction and corrective action within the certification body's timeframe.
• The lead auditor should recommend that certification is maintained only if effective corrective action is verified. Otherwise suspension may be considered.
• The auditor must not tell the client how to run the review, since that would be consultancy.
7. Summary
Surveillance audits are periodic, partial, risk-based audits conducted at least annually during the three-year certification cycle. They confirm that a certified ISMS remains conforming, effective and improving. Every surveillance must cover internal audits, management review, previous nonconformities, complaints, changes, continual improvement and use of certification marks. Over the whole cycle, coverage of the full scope must be ensured. In exams, focus on timing rules, mandatory elements, the separation of roles, consequences of nonconformities and risk-based reasoning, and always back your answers with objective evidence and correct terminology.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!