Surveillance Audit
A surveillance audit is a follow-up check that a certification body performs after an organization has already earned certification to a standard, to confirm that it is still meeting the requirements. It is typically lighter and more focused than the original certification audit, often reviewing only a sample of controls rather than everything. Think of it as a periodic 'snapshot' that keeps the certification valid between full audits.
A surveillance audit is a periodic conformity-assessment activity conducted by an accredited certification body during the certification cycle, following the initial certification audit, to verify that a certified organization continues to conform to the applicable standard (for example, an ISO management-system standard such as ISO/IEC 27001). As commonly described, surveillance audits are less intensive than certification or recertification audits, typically examining a sample of controls and emphasizing continual improvement rather than performing a full re-evaluation of the entire scope. They are distinct from recertification audits, which involve a comprehensive reassessment of the management system. Note: the specific frequency, sampling approach, and scope depend on the certification body's program and the standard in question, and the evidence here does not establish a single universal schedule or requirement.
Why it matters
Certification to a management-system standard is not a one-time event. A surveillance audit exists because conformity can erode over time as organizations change their processes, personnel, technology, and scope. It provides ongoing assurance to the certification body, and by extension to customers, regulators, and other stakeholders, that a certified organization continues to meet the standard's requirements between more comprehensive assessments. For contexts where certification (such as to an ISO management-system standard like ISO/IEC 27001) is used as evidence of organizational maturity, the surveillance audit is what keeps that evidence current rather than stale.
For professionals responsible for maintaining certification, the surveillance audit shapes how continual improvement is demonstrated and documented. Because these audits typically examine only a sample of controls and emphasize ongoing conformity rather than a full re-evaluation, an organization cannot assume that passing a surveillance audit means every control has been re-verified. A common error is to treat a successful surveillance audit as equivalent to a comprehensive reassessment; it is not, and residual gaps outside the sampled scope may go undetected until a later recertification audit.
It is important to note that the specific frequency, sampling approach, and scope of surveillance audits depend on the certification body's program and the standard in question. The evidence here does not establish a single universal schedule or requirement, so organizations should confirm the exact expectations with their accredited certification body rather than assuming a fixed cadence applies across all standards or jurisdictions.
Who it's relevant to
Inside Surveillance Audit
Common questions
Answers to the questions practitioners most commonly ask about Surveillance Audit.