Guide

Preparing for an ISO 27001 surveillance audit

A surveillance audit is a sample, not a full reassessment — but it is a sample chosen by someone looking for evidence that the management system has been operating since they last visited.

What a surveillance audit is

After certification, the certification body returns periodically — commonly annually — to confirm that your ISMS is still implemented, still effective and still improving. The visit is shorter than the original Stage 2 audit and samples parts of the system rather than examining everything.

The auditor is not attempting to catch you out. They are gathering evidence that the management system described in your documentation is the one your organisation actually operates.

What is normally covered

  • Mandatory clauses, particularly internal audit, management review and improvement
  • Status of nonconformities and corrective actions from previous audits
  • Changes to the organisation, scope, systems, suppliers or risk profile
  • The risk assessment and risk treatment plan, and evidence they were reviewed
  • The Statement of Applicability and a sample of implemented controls
  • Security objectives and how performance is measured
  • Incidents, complaints and any use of the certification mark
  • Interviews with control owners and staff across the scope

What auditors typically ask for

  • Internal audit programme, reports and findings for the period
  • Management review minutes with the required inputs and outputs evidenced
  • Current risk register with review dates and risk owners
  • Updated Statement of Applicability where controls have changed
  • Policy set with approval and version history
  • Records of joiners, movers and leavers, and access reviews
  • Supplier and third-party assessments for significant providers
  • Incident log and evidence of how incidents were handled and closed
  • Training and awareness records
  • Change records for significant technology or organisational change
  • Backup, restore or continuity test evidence where within scope

A four-week preparation approach

  1. Four weeks out: confirm the audit plan and scope with the certification body, identify who will be interviewed and check their availability. Review previous findings and confirm each is closed with evidence.
  2. Three weeks out: run a readiness review against the mandatory clauses. Identify anything missing — an internal audit not completed, a management review overdue, a risk register not reviewed — and schedule it properly rather than backdating it.
  3. Two weeks out: assemble evidence in one accessible place, organised the way the auditor will ask for it. Check documents are the current approved versions.
  4. One week out: brief the people who will be interviewed. They do not need to memorise policies; they need to be able to describe what they do, where they would find the relevant procedure and who they would tell if something went wrong.

Common findings and how to avoid them

  • Internal audit not completed as planned. Schedule it early in the year, not the month before the external visit.
  • Management review missing required inputs. Use an agenda drawn directly from the clause and record decisions and actions.
  • Risk register untouched since certification. Review it with owners and record dates.
  • Corrective actions closed without root cause. Show what was changed and how effectiveness was checked.
  • Access reviews not evidenced. Keep dated records of who reviewed access and what changed.
  • Supplier changes not assessed. Assess new providers before they go live, not afterwards.

If findings are raised

Nonconformities are not a failure of the organisation; they are how the system is expected to improve. Respond promptly with a proper root-cause analysis, realistic corrective actions and named owners. Major nonconformities need swift attention and can affect certification if left unresolved, so agree timescales with the certification body and evidence closure carefully.

Reduce the effort permanently

Organisations that maintain the ISMS throughout the year spend a fraction of the effort on audit preparation. Our guide on maintaining ISO 27001 certification sets out a practical annual rhythm, and ongoing CISO support exists precisely to keep that rhythm going.

Surveillance audit approaching?

We can carry out a focused readiness review, close the gaps that matter and support you through the audit itself.

Or email info@isosecurity.co.uk