
ISO 27001 Surveillance Audit: What Happens in Year 2
An ISO 27001 surveillance audit is a shorter, on site audit your certification body runs in year 1 and year 2 after certification, to confirm your information security management system is still working. It is not a full reassessment. It checks a sample: your internal audit and management review, the corrective actions from last time, complaints, changes to your scope, and how you use the certification mark. In year 3 you sit a full recertification audit instead.

Most teams put everything into getting certified and then discover that certification was the start of a three year cycle rather than the end of a project. The good news is that a surveillance audit is smaller than Stage 2. The bad news is that it arrives about twelve months after your certification decision, whether or not anyone has run an internal audit since.
What is an ISO 27001 surveillance audit?
An ISO 27001 surveillance audit is an on site audit conducted by your certification body to confirm that your certified management system continues to meet the requirements of the standard. It is defined in ISO/IEC 17021-1, the standard that certification bodies themselves must follow, which states that surveillance audits are on site audits but are not necessarily full system audits.
That single sentence explains the whole experience. The auditor is not going to re-examine every Annex A control you selected. They will sample. They will look hard at the areas the standard requires them to cover, and they will follow whatever thread looks loose on the day.
How often does an ISO 27001 surveillance audit happen?
ISO 27001 surveillance audits happen once in each of the first two years after your certification decision, with the first taking place within twelve months of that decision. ISO/IEC 17021-1 sets the audit programme for an initial certification as a two stage initial audit, surveillance audits in the first and second years following the certification decision, and a recertification audit in the third year before the certificate expires.
The three year cycle starts at the certification decision, not at the date of your Stage 2 audit or the date printed on your certificate. Those are usually close together, but if your certification decision was delayed by a nonconformity, the clock starts when the decision was made. Subsequent cycles begin at the recertification decision.

What does an ISO 27001 surveillance audit review?
An ISO 27001 surveillance audit must review eight things, and they are listed in ISO/IEC 17021-1 clause 9.6.2.2. Every certification body works from the same list, so you can prepare for a surveillance audit with real confidence about what will be asked. The eight areas are internal audits and management review, actions taken on previous nonconformities, complaints handling, effectiveness of the management system against your objectives, progress on planned improvement, continuing operational control, review of changes, and use of certification marks.
| What the auditor must cover | What they will ask you for | The usual failure |
|---|---|---|
| Internal audit and management review | The internal audit report and management review minutes since the last audit | Neither has been done, or both were done last week |
| Actions on previous nonconformities | Evidence the corrective action worked, not just that it was raised | The action was closed with no evidence attached |
| Complaints handling | Your complaints log and how each one was handled | Nobody can find a log, because nobody complained |
| Effectiveness against objectives | Measured results against the security objectives you set | Objectives were written once and never measured |
| Continual improvement | Movement in the improvement register | Same five items, same status, twelve months on |
| Continuing operational control | Access reviews, patching records, supplier monitoring | Controls run, but nothing is written down |
| Review of changes | Updated scope, risk assessment and Statement of Applicability | A new product launched and the scope never moved |
| Use of certification marks | Where the logo and certification claims appear | The website claims certification for services outside scope |

How is a surveillance audit different from recertification?
A surveillance audit samples parts of your management system in years 1 and 2. A recertification audit reassesses the whole management system in year 3 and results in a new certificate. Recertification also reviews the performance of the management system over the entire certification period, including the previous surveillance audit reports, so a weak year 1 is still visible in year 3.
| Stage 2 certification audit | Surveillance audit | Recertification audit | |
|---|---|---|---|
| When | Before your first certificate | Years 1 and 2 | Year 3, before expiry |
| Coverage | The full management system | A defined sample | The full management system again |
| Length | The longest audit | The shortest audit | Close to Stage 2 |
| Outcome | Certificate issued | Certificate maintained | New certificate issued |
| Looks back at | Your implementation | Since the last audit | The whole three year cycle |
If you have not yet been through the first two, our guide to what to expect at Stage 1 and Stage 2 covers the initial audits, and our ISO 27001 certification cost guide explains what drives audit fees across the cycle.
What happens if you fail or skip a surveillance audit?
Failing a surveillance audit does not usually cost you the certificate immediately. Major nonconformities have to be closed within a time limit set by the certification body, commonly around 90 days, and if they are not closed the body can suspend the certificate. Suspension means you are still certified on paper but cannot use the mark or claim certification until the suspension is lifted. Continued failure leads to withdrawal.
Skipping a surveillance audit is a different problem and a more common one. If the audit is not held within the required interval, the certification body has no basis to maintain certification, and suspension follows. Rescheduling because a key person is on leave is normal and expected. Letting the date pass without contact is not.
The practical risk for an Australian business is commercial rather than regulatory. A suspended certificate turns up in a customer’s annual vendor review, and explaining a suspension to a procurement team is a worse conversation than the audit would have been.
How do you prepare for an ISO 27001 surveillance audit?
Preparing for an ISO 27001 surveillance audit takes about two weeks of part time work if your management system has been running, and considerably longer if it has not. The preparation is the same each year, which means it can be scheduled rather than improvised.
- Run the internal audit properly, and early. Not the week before. An internal audit run three months out gives you time to close what it finds, which is the point of having one. Our guide to running an internal audit that adds value covers the method.
- Hold the management review and minute it. The minutes are the evidence. A meeting that happened but was not minuted did not happen as far as the auditor is concerned.
- Close last year’s nonconformities with evidence. Attach the proof to each one: the changed configuration, the signed policy, the training record.
- Update the risk assessment and Statement of Applicability for anything that changed. New product, new office, new cloud provider, new major supplier. Our guide to the Statement of Applicability covers what a current one looks like.
- Check your scope still matches the business. If you have launched something new, review the ISMS boundary before the auditor does.
- Audit your own website. Search your site for certification claims and check each one sits inside your certified scope.
Common questions
What is an ISO 27001 surveillance audit?
An ISO 27001 surveillance audit is a shorter on site audit run by your certification body in years 1 and 2 of the three year certification cycle. It confirms your information security management system is still operating and still conforms to the standard. Unlike the Stage 2 audit, it samples rather than reassessing everything, and it results in your certificate being maintained rather than reissued.
How often is an ISO 27001 surveillance audit required?
An ISO 27001 surveillance audit is required once in each of the first two years following your certification decision, with the first held within twelve months of that decision. Year 3 is a recertification audit instead. Some certification bodies offer six monthly surveillance for larger or higher risk organisations, but annual surveillance is the standard arrangement for Australian small and medium businesses.
How much does an ISO 27001 surveillance audit cost?
An ISO 27001 surveillance audit costs less than your Stage 2 audit because it takes fewer auditor days, and certification bodies price largely on audit days plus travel. The number of days depends on your headcount, the number of sites in scope and the complexity of your operations. Ask your certification body for the audit day allocation across the full three year cycle when you first engage them, so there are no surprises in year 2.
What are the ISO 27001 surveillance audit requirements?
The requirements come from ISO/IEC 17021-1 clause 9.6.2.2, which obliges the auditor to review internal audits and management review, actions taken on nonconformities from the previous audit, complaints handling, effectiveness of the management system against your objectives, progress on continual improvement, continuing operational control, any changes, and your use of certification marks. Prepare evidence for each of those eight areas.
Can your ISO 27001 certificate be suspended if you miss a surveillance audit?
Yes. If a surveillance audit is not held within the required interval, or major nonconformities are not closed within the time your certification body allows, the body can suspend your certificate. During suspension you cannot use the certification mark or claim to be certified. If the issues are still unresolved after the suspension period, the certificate is withdrawn and you would need to start the certification process again.
How long does an ISO 27001 surveillance audit take?
For a typical Australian business of 20 to 100 staff with a single site in scope, a surveillance audit usually runs one to two days on site, against three or more days for the Stage 2 audit. Larger scopes, multiple sites or higher risk operations increase the allocation. Your certification body sets the audit days from a published formula based on headcount and complexity.
Where to start
If your surveillance audit is more than three months away, book your internal audit now and put the management review in the calendar behind it. That single act of scheduling is what separates a quiet surveillance audit from a stressful one.
Siege Cyber helps Australian businesses run internal audits, close nonconformities and keep an ISMS working between certification audits. You can see what that involves on our ISO 27001 service page, or get in touch if your audit date is approaching and the evidence is not where it should be. If you are still choosing who certifies you, our guide to choosing an ISO 27001 certification body in Australia is the place to begin, and Standards Australia is where the standard itself can be purchased.