What surveillance audits are for
A certificate is a statement that your ISMS conforms to ISO/IEC 27001 and continues to do so. Surveillance audits are how we back that statement up in years one and two of the cycle. They are shorter than the initial audit and do not re-examine everything, but they must cover certain things every year.
What is always covered
- Internal audits and management reviews carried out since the last audit
- Progress on any findings from the previous audit
- Handling of complaints and security incidents
- Changes to the organization, its scope, its risks, and its Statement of Applicability
- Use of the certification mark and how you refer to your certification
- The effectiveness of the ISMS in meeting its objectives
What is sampled
Across the two surveillance audits we sample the Annex A controls in your Statement of Applicability so that, together with Stage 2, the full set has been examined at least once over the cycle. We plan the sampling at certification and share it with you, so you know which areas will be looked at in each year.
How we plan them
Surveillance dates are set at the point of certification and confirmed three months in advance. The audit plan goes out at least two weeks before the visit and names the people the auditor needs to speak to. Most surveillance audits for cloud-first organizations are conducted remotely; sites with physical security controls in scope are visited at least once per cycle.
Reporting
You receive a written report within ten business days. Findings are classified as major nonconformities, minor nonconformities, or opportunities for improvement, with the clause or control reference and the evidence behind each one. Minor nonconformities need a corrective action plan; major nonconformities need to be corrected and verified within an agreed period or the certificate may be suspended.