Menu

What Happens During an ISO 27001 Surveillance Audit?

What Happens During an ISO 27001 Surveillance Audit?

An ISO 27001 surveillance audit is a periodic external audit performed during the certification cycle to determine whether an organization's Information Security Management System (ISMS) continues to conform to ISO/IEC 27001 requirements. Unlike the initial certification audit, a surveillance audit does not normally examine every part of the ISMS in the same depth. Instead, the certification body samples relevant areas, reviews changes since the previous audit, examines objective evidence, and evaluates whether the ISMS continues to operate as required.

For organizations in the United States, understanding the ISO 27001 surveillance audit process is important because certification is maintained through an ongoing certification cycle rather than a one-time audit. ISO/IEC 27001:2022 remains the current edition of the standard, with Amendment 1:2024 also applicable.

Build Confidence With ISO/IEC 27001 Certification. Show customers, partners, and stakeholders that your organization follows a recognized information security standard.

What Is an ISO 27001 Surveillance Audit?

An ISO 27001 surveillance audit is an external audit conducted by the certification body during the period between the initial certification audit and recertification. Its purpose is to determine whether the certified ISMS continues to meet the applicable requirements and whether the organization has maintained the system within its certified scope.

ISO/IEC 27001 defines the requirements for an ISMS, while ISO/IEC 17021-1 establishes requirements for bodies that audit and certify management systems. ISO/IEC 27006-1:2024 adds requirements specifically related to bodies that audit and certify information security management systems.

Purpose of an ISO 27001 Surveillance Audit

The main purpose of surveillance is to evaluate continued conformity and the ongoing operation of the certified ISMS. The auditor considers relevant areas such as internal audits, management review, previous audit findings, changes affecting the ISMS, information security objectives, operational controls, and continual improvement.

A surveillance audit therefore looks at what has happened since the previous certification activity. Evidence from actual operations is important because the auditor needs to determine whether the ISMS continues to function as established.

Surveillance Audit vs Initial ISO 27001 Certification Audit

The initial ISO 27001 certification audit is broader and establishes whether the organization meets the requirements for certification. It normally consists of Stage 1 and Stage 2 activities.

A surveillance audit takes place after certification and focuses on continued conformity within the certified scope. It uses sampling rather than repeating the entire initial certification audit. This means an organization should not expect every ISMS process or every applicable control to receive the same level of review during every surveillance audit.

When ISO 27001 Surveillance Audits Take Place

ISO 27001 certification generally operates on a three-year certification cycle. Surveillance audits normally take place during the first and second years following the certification decision, followed by a recertification audit at the end of the cycle.

The exact audit dates and programme are established by the certification body in accordance with applicable certification requirements. Organizations should therefore confirm the surveillance schedule with their certification body rather than relying only on the certificate issue date.

What Happens Before an ISO 27001 Surveillance Audit?

Before the audit begins, the certification body establishes the audit arrangements and the organization provides relevant information concerning its ISMS. The organization should ensure that its records accurately reflect how the ISMS currently operates.

Confirming the ISO 27001 Surveillance Audit Scope

The organization and certification body review the certified ISMS scope, including relevant locations, organizational units, processes, services, technologies, and information assets within the certification boundary.

Changes to the organization can affect the scope. For example, a new business unit, acquisition, significant change in technology, new location, or substantial change in services may require the scope and associated ISMS information to be reviewed.

Reviewing the Audit Plan and Schedule

The certification body provides an audit plan covering the activities, areas, personnel, locations, and timing expected to be considered. The organization should review the plan and ensure that appropriate personnel are available for interviews and evidence review.

The audit schedule can vary according to the organization's size, complexity, locations, scope, and the areas selected for sampling.

Preparing Relevant Information Security Evidence

The organization should have current records available for areas that may be sampled. These can include risk assessment records, the Statement of Applicability, internal audit records, management review records, corrective action records, security incident information, training records, monitoring results, and evidence associated with selected controls.

The objective is not to create a separate set of records specifically for the surveillance audit. Evidence should reflect the normal operation of the ISMS throughout the certification cycle.

Identifying Changes Since the Previous Audit

Changes are an important part of the ISO 27001 surveillance audit process. Auditors may consider changes to organizational structure, information assets, technologies, suppliers, locations, business processes, regulatory obligations, information security risks, and applicable controls.

Organizations should be able to explain how significant changes were evaluated and how the ISMS was adjusted where necessary.

ISO 27001 Surveillance Audit Process

The ISO 27001 surveillance audit process generally follows a structured sequence that allows the auditor to evaluate selected areas of the ISMS and collect objective evidence.

Opening Meeting

The audit normally begins with an opening meeting between the audit team and relevant organizational representatives. The auditor confirms the audit objectives, scope, criteria, schedule, communication arrangements, and other practical matters.

The meeting also provides an opportunity to confirm any changes that could affect the audit programme.

Review of the ISMS

The auditor reviews selected parts of the ISMS against the applicable ISO/IEC 27001 requirements and the organization's established processes. The review may include policies, objectives, risk management activities, management oversight, monitoring, corrective actions, and other relevant areas.

The extent of the review depends on the audit plan and the areas selected for surveillance.

Interviews With Relevant Personnel

Interviews allow auditors to understand how information security processes operate in practice. Personnel responsible for information security, risk management, technology, human resources, supplier management, physical security, or other relevant functions may be interviewed.

The questions generally relate to responsibilities, processes, decisions, controls, records, and changes within the audited areas.

Examination of Information Security Evidence

Auditors examine objective evidence to determine whether activities have been performed as required. Depending on the sampled area, this can include records, reports, system-generated information, meeting records, risk information, training records, incident records, access reviews, monitoring results, and other relevant evidence.

The evidence should be consistent with the organization's policies, procedures, risk decisions, and actual business activities.

Sampling of Processes and Controls

Sampling is a central feature of surveillance audits. The auditor selects representative areas rather than reviewing every activity in the ISMS during every surveillance audit.

The selected sample can be influenced by the organization's scope, previous audit results, changes, risks, system complexity, and the certification body's audit programme.

Audit Findings and Closing Meeting

At the end of the audit, the auditor communicates the audit results and identified findings. The closing meeting normally covers conformity, nonconformities where identified, relevant observations or opportunities for improvement, and the next steps associated with the audit report and certification process.

The certification decision is made through the certification body's established independent process rather than simply being determined by the individual auditor.

What Auditors Check in an ISO 27001 Surveillance Audit

The specific areas reviewed can vary, but an ISO 27001 surveillance audit typically considers whether the ISMS remains suitable, maintained, and effective within its certified scope.

Information Security Policies and Objectives

Auditors may review information security policies and objectives to determine whether they remain relevant to the organization's context and information security needs. Evidence showing monitoring and progress against objectives can also be considered.

Risk Assessment and Risk Treatment

The auditor may examine how information security risks are identified, evaluated, treated, monitored, and reviewed. Changes to business activities, technology, suppliers, locations, and threats can influence the organization's risk profile.

Current risk information should therefore correspond with the organization's actual operating environment.

Statement of Applicability

The Statement of Applicability, commonly called the SoA, identifies the controls the organization has determined to be applicable, their implementation status, and the justification for exclusions where applicable.

During surveillance, auditors may examine whether the SoA remains consistent with the organization's risks, scope, and current information security arrangements.

Information Security Controls

The auditor samples applicable information security controls and examines evidence showing how selected controls operate.

ISO/IEC 27001:2022 includes Annex A as a reference control set, while the organization determines applicable controls based on its information security risk process and other requirements.

Internal Audit and Management Review

Internal audits and management reviews are important parts of the ISMS cycle. Auditors may examine whether planned internal audits were completed, whether relevant findings were addressed, and whether management reviewed the ISMS as required.

The auditor may also consider whether management review outputs resulted in appropriate decisions and actions.

Corrective Actions From Previous Audits

Previous nonconformities remain relevant during surveillance. The auditor may examine the organization's response, the cause identified, actions taken, and evidence demonstrating that the issue was addressed effectively.

Simply marking an action as closed does not necessarily demonstrate that the underlying issue was adequately addressed.

Changes Affecting the ISMS

Changes in business activities, personnel, technologies, locations, suppliers, legal requirements, and information security risks can affect the ISMS.

The auditor may examine how these changes were identified, evaluated, and reflected in relevant ISMS processes.

Performance and Effectiveness of the ISMS

Auditors may examine information security objectives, monitoring and measurement results, incidents, audit results, management review outputs, corrective actions, and improvement activities to understand how the ISMS is performing.

The emphasis is on objective evidence rather than simply confirming that policies exist.

ISO 27001 Surveillance Audit Requirements

An organization holding ISO 27001 certification needs to maintain its ISMS throughout the certification cycle. Surveillance is therefore connected to the organization's ongoing operation of the management system.

Maintaining the ISO 27001 Management System

The ISMS should continue to operate within the defined scope and according to the organization's established processes. Policies, risk information, objectives, controls, records, and responsibilities should remain current where changes occur.

Monitoring and Measuring Information Security Performance

Organizations should monitor relevant information security performance and maintain appropriate results. Depending on the ISMS, this can include security incidents, objectives, control performance, audit results, risk indicators, supplier performance, or other measurements selected by the organization.

Addressing Changes and Information Security Risks

Changes to the business or technology environment can create new or modified information security risks. Organizations should evaluate relevant changes through their established risk management processes and update the ISMS where necessary.

Maintaining Relevant Audit Evidence

Records should demonstrate that the ISMS has operated throughout the period between audits. Evidence should be traceable, accurate, current, and relevant to the activities being reviewed.

Addressing Previous Audit Findings

Previous nonconformities should be addressed through appropriate corrective action. During surveillance, auditors can review evidence associated with previous findings and determine whether the actions taken are appropriate and effective.

ISO 27001 Surveillance Audit Evidence

The evidence required for a surveillance audit depends on the audit scope, organization, previous findings, changes, and areas selected for sampling. Common evidence includes the following.

Risk Assessment and Risk Treatment Records

These records demonstrate how information security risks have been evaluated and treated. The auditor may compare the records with current business activities and significant changes.

Internal Audit Records

Internal audit programmes, audit reports, findings, and associated corrective action records can demonstrate that the organization has evaluated its ISMS according to its planned arrangements.

Management Review Records

Management review records provide evidence that relevant management personnel have reviewed the ISMS and considered appropriate inputs, performance information, changes, risks, and improvement opportunities.

Security Incident Records

Where relevant, security incident records can show how incidents were identified, evaluated, recorded, responded to, and reviewed.

Training and Awareness Records

Training and awareness records may demonstrate that personnel received information security training or awareness activities relevant to their responsibilities.

Monitoring and Measurement Results

Monitoring results can include information security objectives, performance indicators, control measurements, audit results, incident trends, or other measures established by the organization.

Corrective Action Records

Corrective action records should show the issue identified, relevant cause analysis, action taken, responsible parties, completion status, and evidence used to determine whether the action was effective.

Evidence Related to Applicable Security Controls

Evidence can vary significantly by control. Depending on the selected sample, auditors may review access review records, security monitoring information, supplier records, backup evidence, asset information, training records, incident records, physical security records, or technical records.

ISO 27001 Surveillance Audit Checklist

A practical ISO 27001 surveillance audit checklist can include the following areas:

ISMS Scope and Context

Confirm that the certified scope remains accurate and reflects the organization's current business activities, locations, technologies, and relevant interested parties.

Information Security Risk Management

Review current risk assessment and risk treatment information and verify that significant changes have been considered.

Statement of Applicability

Confirm that the SoA remains current and consistent with the organization's information security risk decisions and applicable controls.

Information Security Controls

Maintain appropriate evidence for applicable controls and ensure that sampled controls can be traced to actual operating activities.

Internal Audits

Confirm that internal audits have been planned and performed as required, with relevant results and actions recorded.

Management Reviews

Confirm that management reviews have taken place at appropriate intervals and that relevant outputs and decisions have been recorded.

Corrective Actions

Review previous findings and confirm that corrective actions have been completed and evaluated for effectiveness where applicable.

Continual Improvement

Review changes, performance results, corrective actions, lessons learned, and other activities demonstrating ongoing improvement of the ISMS.

What Are the Possible Findings During an ISO 27001 Surveillance Audit?

A surveillance audit can result in different types of audit conclusions depending on the evidence examined and the certification body's applicable procedures.

Conformity and Areas of Effective Implementation

Auditors may identify areas where the organization demonstrates conformity with applicable requirements. Positive observations can also be recorded where the audit methodology permits.

Nonconformities

A nonconformity indicates that a requirement has not been fulfilled. The significance of the finding depends on the requirement involved, the circumstances, and the certification body's applicable criteria.

Minor and Major Nonconformities

Certification schemes distinguish between minor and major nonconformities according to the applicable certification rules. The classification can consider factors such as the extent and impact of the issue and whether the management system's ability to achieve intended results is affected.

The certification body determines the classification according to the applicable audit and certification requirements.

Opportunities for Improvement and Audit Observations

An auditor may identify an observation or opportunity for improvement where the applicable audit methodology allows it. Such comments are different from formal nonconformities and should not automatically be interpreted as evidence that the organization failed to meet an ISO/IEC 27001 requirement.

Corrective Action and Follow-Up

Where nonconformities are identified, the organization is expected to address them according to the certification body's applicable process. Follow-up activities can include reviewing submitted evidence or performing additional audit activity, depending on the nature of the finding.

How ISO 27001 Surveillance Audit Findings Are Addressed

A finding should be addressed according to the requirements and procedures established by the certification body.

Understanding the Audit Finding

The organization should first understand the requirement involved, the evidence reviewed by the auditor, and the specific condition recorded in the audit report.

Identifying the Cause of the Nonconformity

For a nonconformity, the organization should determine why the issue occurred and evaluate whether related areas may also be affected.

Taking Corrective Action

Corrective action should address the identified cause and the condition that resulted in the nonconformity. The nature of the action depends on the specific finding.

Providing Objective Evidence

The organization provides relevant evidence showing the actions taken and, where applicable, evidence demonstrating their effectiveness.

Follow-Up and Closure of Findings

The certification body reviews the response and evidence according to its established procedures. Depending on the finding, additional verification may be required before the nonconformity can be closed.

ISO 27001 Surveillance Audit Scope

The surveillance audit scope is connected to the certified ISMS scope and the audit programme established by the certification body.

Reviewing the Certified ISMS Scope

The organization should verify that the scope statement accurately represents the activities, locations, services, information, and organizational boundaries covered by certification.

Changes to Organizational Scope

A new service, business unit, acquisition, location, or significant organizational change may affect the certified scope. Such changes should be communicated to the certification body when required.

Changes to Locations, Processes, and Technologies

Technology changes are particularly relevant for information security management. New cloud services, applications, infrastructure, remote working arrangements, data environments, or business processes can introduce changes that need to be considered within the ISMS.

Changes to Applicable Information Security Controls

Changes in risks or business circumstances can affect the controls considered applicable. The organization should ensure that its risk information, Statement of Applicability, and control arrangements remain consistent.

How Long Does an ISO 27001 Surveillance Audit Take?

There is no single fixed duration for every ISO 27001 surveillance audit. Audit time depends on factors such as the size and complexity of the organization, the ISMS scope, number of locations, number of employees, operational complexity, and changes since the previous audit.

ISO/IEC 27006-1:2024 establishes specific requirements for certification bodies performing ISMS certification activities, while audit planning also takes account of the characteristics of the organization and the management system.

Factors Affecting Surveillance Audit Duration

The certification body determines the audit programme and duration based on applicable requirements and the characteristics of the certified organization. A larger or more complex ISMS generally requires more audit time than a smaller and less complex scope.

Organization Size and ISMS Scope

The number of employees, business activities, information systems, processes, and the breadth of the certified scope can influence audit duration.

Number of Locations and Employees

Organizations with multiple offices, data centers, operational sites, or geographically distributed teams may require additional audit planning and sampling.

Complexity of Information Security Processes

Complex technology environments, significant third-party relationships, critical information assets, cloud services, regulated activities, and extensive operational processes can influence the amount of audit time required.

For US organizations with distributed operations, the audit programme may also take account of remote locations and the nature of the activities included within the certified ISMS scope.

Take The Next Step Toward ISO/IEC 27001 Certification. Demonstrate a structured approach to information security and strengthen trust across your business ecosystem. Connect With INTERCERT Today.

What Happens After an ISO 27001 Surveillance Audit?

The process does not necessarily end when the auditor leaves. The certification body completes its reporting and certification activities according to the applicable certification process.

Audit Report

The audit report records the audit activities, areas examined, evidence considered, and findings identified during the audit.

Review of Audit Findings

The organization reviews the findings and determines the required actions where nonconformities have been identified.

Corrective Action for Nonconformities

Where corrective action is required, the organization submits the relevant response and objective evidence according to the certification body's procedures and timelines.

Certification Status

The certification body determines the certification status based on the audit results and applicable certification requirements. A surveillance audit can result in continued certification when the applicable requirements for maintaining certification are met. Significant unresolved issues can affect certification status according to the applicable certification rules.

Preparation for the Next Surveillance Audit

After the audit, the organization should continue operating and maintaining its ISMS rather than treating surveillance as an isolated annual event. Information security risks, objectives, internal audits, management reviews, incidents, corrective actions, changes, and control activities continue throughout the certification cycle.

Why Choose INTERCERT for ISO/IEC 27001 Certification

INTERCERT provides independent ISO/IEC 27001 certification services through a third-party certification approach. Its certification activities are designed to evaluate conformity with the applicable ISO/IEC 27001 requirements within the agreed certification scope.

For organizations in the United States, independent certification can provide a recognized way to demonstrate that an information security management system has been evaluated against an internationally recognized standard. INTERCERT provides certification and audit services for organizations seeking ISO/IEC 27001 certification across different industries and business environments.

Read More:
How to Prepare for Your ISO 27001 Surveillance and Renewal Audit
ISO 27001:2022 Information Security Management System Guide

  1.  

Frequently Asked Questions

How Can We Help You?

We are here to answer all your questions.


©2026 Intercert. All Rights Reserved