What is Surveillance Audit ?

Surveillance audit in the three-year ISO 27001 certification cycle

A surveillance audit is the shorter annual check that keeps an ISO 27001 certificate valid between full recertification audits.

  • Glossary
  • ISO 27001

The short answer

An ISO 27001 certificate runs for three years. In years one and two the certification body carries out a surveillance audit, a partial review confirming the management system is still operating. In year three there is a full recertification audit. Surveillance audits are shorter than the original Stage 2, but they are not a formality: a major nonconformity can suspend the certificate.

The shift in emphasis matters. The first audit asked whether you built a system. Surveillance asks whether you have been running it since.

The three-year cycle

THE CERTIFICATION CYCLE 0 Certification Stage 1 + Stage 2 1 Surveillance Partial, shorter 2 Surveillance Partial, shorter 3 Recertification Full audit again Surveillance audits are due within twelve months of the previous audit date, not the certificate date.
Swipe to see the full diagram. Miss a surveillance window and the certificate can be suspended, regardless of how good your controls are.

What a surveillance audit covers

Not everything. The certification body works to a plan that guarantees the whole system is covered across the three-year cycle, with certain items examined every single time.

Examined every yearSampled across the cycle
Internal audit programme and its resultsA rotating selection of Annex A controls
Management review recordsSpecific departments, sites or systems
Corrective actions from the last auditSupplier and third-party arrangements
Complaints and security incidentsBusiness continuity testing
Changes to scope, systems or the organisationAwareness and training coverage
Use of the certification mark and logoPhysical and environmental controls

Change is the trigger

New product, new cloud region, new office, an acquisition or a big headcount jump all get scrutiny. Tell the certification body in advance. Discovering an unreported scope change during the audit is worse than declaring it.

What happens if something fails

OutcomeConsequence
Minor nonconformityCorrective action plan submitted, usually verified at the next audit. Certificate unaffected
Major nonconformityMust be resolved within a set window, often 90 days, with evidence. Certificate at risk
Unresolved majorCertificate suspended, and withdrawn if it stays unresolved
Audit not scheduled in timeSuspension on process grounds, independent of how the controls are performing

Staying ready between audits

Run the programme

Internal audits and management reviews on schedule. Their absence is the fastest route to a major.

Keep the register live

A risk register untouched since certification tells the auditor the system stopped operating.

Log evidence as it happens

Access reviews, patching and incidents recorded continuously, the way evidence collection should work.

How Osto keeps evidence continuous

The hard part of surveillance is not the audit day, it is the eleven months before it. Osto runs the controls that generate the evidence, access and MFA, cloud posture, endpoint control, vulnerability testing and monitoring, and records the output as it happens. When drift appears, in a misconfigured cloud account or a device out of policy, it shows up in the dashboard rather than in an auditor’s finding a year later.

Free security assessment

Stay audit-ready for the eleven months in between

Osto catches drift as it happens, in cloud configuration, device state and access, rather than leaving it for next year’s auditor.

Get a free security assessment Book a platform walkthrough

Continuous evidence · Drift caught early · One platform, everything

Frequently asked questions

What is a surveillance audit?

A shorter annual audit carried out by your certification body in years one and two of the three-year ISO 27001 cycle. It confirms the management system is still operating, examining a subset of controls plus the internal audit and management review records.

How often does a surveillance audit happen?

Once a year, in years one and two after certification. Year three is a full recertification audit. Each audit must fall within twelve months of the previous one, measured from the audit date rather than the certificate date.

How long does a surveillance audit take?

Typically about a third of the original Stage 2 duration. For a small organisation with a narrow scope that often means one auditor day, though scope changes or open findings extend it.

Can you lose certification at a surveillance audit?

Yes. A major nonconformity that is not resolved within the agreed window leads to suspension, and continued failure leads to withdrawal. Missing the audit window entirely can also trigger suspension.

What is the difference between a surveillance audit and recertification?

Surveillance is partial and confirms ongoing operation. Recertification in year three re-examines the entire management system, closer in depth to the original Stage 2, and results in a new three-year certificate.