
Surviving the surveillance audit
The certificate arrives, the project team disbands, and the management system quietly stops operating. Twelve months later a surveillance audit is booked and someone discovers that the last access review was conducted during the certification push.
This is the most common way organisations get into trouble with ISO 27001, and it is entirely avoidable. The surveillance audit is not looking for perfection. It is looking for continuity.
What the surveillance audit actually checks
It is a smaller audit than certification, usually sampling a subset of controls plus a fixed set of management system requirements. The parts that are always examined:
- The internal audit programme. Did it happen, did it cover what it said it would, did it find anything.
- Management review. Did it take place, who attended, what was decided.
- Corrective actions. What was raised last time, and what happened to it.
- Incidents. What occurred, how it was handled, what changed as a result.
- Changes. To scope, to the organisation, to risks.
- Continual improvement. Evidence that the system is being improved rather than merely maintained.
Notice how much of that is about records existing across the year rather than about controls being technically perfect.
The evidence that must exist continuously
These are the records that cannot be reconstructed after the fact, and they are where organisations get caught.
Access reviews. Conducted on the stated frequency, with dates, participants and outcomes. If your policy says quarterly and there are two reviews in the file, that is a nonconformity against your own policy, which is worse than having no policy, because you wrote the standard you failed.
Risk assessment updates. The register should show movement. New risks, closed risks, changed ratings. An untouched register suggests it is not being used.
Supplier assessments. Reviews conducted on the schedule you defined, particularly for anything added during the year.
Training and awareness. Delivered, with attendance records, including for people who joined during the year.
Incident records. Even minor ones. An organisation reporting zero incidents in twelve months is not reporting, and auditors read it that way.
Change records. Showing that significant changes went through the process you described.
Internal audit is the one most often skipped
It is required, it must be independent of the areas audited, and it must be more than a formality.
Two failure modes:
It did not happen. Usually because the person who did it during certification has moved on and nobody owned it afterwards.
It happened and found nothing. An internal audit with zero findings across an entire management system tells the external auditor that the internal audit is not real. Every organisation has gaps. Finding and recording them is evidence the system works, not evidence it is failing.
The most useful internal audit finds three or four genuine issues, records them as corrective actions, and shows them closed by the time the external auditor arrives. That sequence is exactly what continual improvement is supposed to look like.
What changed during the year
Surveillance audits pay particular attention to change, because change is where management systems drift out of alignment with reality.
Be ready to describe:
- New systems or services brought into scope, and how they were assessed.
- Organisational changes: new sites, restructures, significant headcount movement.
- Supplier changes: new providers, particularly any handling data in scope.
- Anything removed from scope, and why.
If your organisation changed materially and the management system documentation did not, that gap is the easiest finding an auditor can write.
Preparing without a scramble
The organisations that find surveillance audits uneventful do a small number of things routinely.
A calendar with owners. Access reviews, supplier assessments, internal audit, management review, risk register review, awareness training, each with a date and a named person. Most of the required evidence is produced by simply doing these when scheduled.
A single evidence location. One place where the records live, organised so that anything can be found in a minute. Assembling evidence from six systems and four people's mailboxes is where audit preparation time actually goes.
A pre-audit walkthrough. Someone internally walks the likely audit path a month ahead, checking that each required record exists and is current. Everything found is fixed on your schedule rather than under scrutiny.
Corrective actions closed properly. Anything raised at the last audit should be closed with evidence, not marked complete. Open items from the previous audit are the first thing checked and the worst thing to fumble.
When something genuinely went wrong
If you had a real incident during the year, do not attempt to minimise it. Auditors respond well to an organisation that detected something, handled it according to its own process, recorded it, and made changes as a result. That is the management system working.
They respond badly to discovering an incident that was not recorded, which raises the question of what else was not.
The framing that helps
The surveillance audit is easier to prepare for if it is understood as a check that the system is alive rather than a re-examination of whether it was well designed. The design was assessed at certification.
What is being tested now is whether the organisation kept doing the things it said it would. That is a question about calendars, ownership and habit far more than about security technology, and it is answered in the months in between rather than in the week before.
Want this looked at in your own environment?
Talk to an expert →Keep reading


