ISO 27001 Surveillance Audit: Everything You Need to Know

Prepare for Your ISO 27001 Audit

  1. Technically Speaking: Your ISO 27001 Checklist
  2. Understanding Technical Controls for ISO 27001 and Enhancing Data Security
  3. 6 Key Benefits of ISO 27001 Certification
  4. ISO 27001:2022 Update: What’s New and Why It Matters
  5. How to Execute an ISO 27001 Audit Plan for Enhanced Security
  6. ISO 27001 Surveillance Audit: Everything You Need to Know

ISO 27001 > Prepare for Your ISO 27001 Audit > ISO 27001 Surveillance Audit: Everything You Need to Know

TL;DR: ISO 27001 surveillance audit

  • An ISO 27001 surveillance audit checks whether an ISMS continues to operate effectively between certification and recertification audits.
  • Certification bodies typically schedule surveillance audits once every 12 months during the three-year certification cycle.
  • Auditors usually start by reviewing how the organization closed prior nonconformities and maintained corrective actions.
  • A practical ISO 27001 surveillance audit checklist helps teams organize evidence, owners, and timelines before the audit window opens.
  • Scytale’s AI GRC platform keeps evidence and remediation work audit-ready year-round, reducing manual audit preparation.

ISO 27001 certification does not end when the certificate arrives. Certification bodies expect organizations to show throughout the certification cycle that controls remain effective, risks stay current, and the information security management system keeps pace with change. The ISO 27001 surveillance audit is how they verify this.

Surveillance audits carry real weight for compliance leads, security teams, and executives because they test whether the program continues to work in practice, not simply whether it passed once. Preparing for a surveillance audit also looks different from preparing for initial certification, and organizations that treat it the same way can lose time gathering evidence that should already be current. In this article, we cover what surveillance auditors check, what to expect from the audit process, and how to prepare and stay ISO 27001 compliant year-round.

What is an ISO 27001 surveillance audit?

An ISO 27001 surveillance audit is a post-certification audit, typically conducted annually, to confirm that an organization’s ISMS and controls continue to meet ISO 27001 requirements.

The audit forms part of the three-year ISO 27001 certification cycle and is conducted between the initial certification audit and recertification. Unlike the initial certification review, a surveillance audit samples selected controls, records, and management activities rather than reviewing every area at full depth. The auditor looks for evidence that the organization has maintained its ISMS, addressed previous findings, and kept security practices aligned with business changes.

Gaps in ongoing ISMS management can put an organization’s ISO 27001 certification at risk. Missed risk reviews, incomplete internal audits, or unresolved corrective actions may indicate that security processes and controls are not being maintained effectively. Addressing these areas consistently helps organizations maintain certification and demonstrate ongoing security oversight

Surveillance audit vs. certification audit vs. recertification audit

Certification, surveillance, and recertification are the main audit ISO 27001 stages within the three-year certification cycle. The initial certification audit determines whether the ISMS meets ISO 27001 requirements, while surveillance audits take place during the certification period to confirm that the system continues to operate effectively and identified issues are being addressed.

At the end of the cycle, a recertification audit provides a broader review to determine whether the organization’s certification should be renewed for another three years. It typically examines overall ISMS effectiveness, significant changes, and how well the organization has maintained and improved its security practices over time. Here’s how the three ISO 27001 audit types compare:

Audit typeWhen it happensPrimary focusScope and depthTypical outcome
Certification auditAt initial certificationInitial conformity with ISO 27001Broad review of ISMS requirements, controls, records, and implementation evidenceInitial certification decision
Surveillance auditUsually annually during years one and twoContinued conformity and ISMS effectivenessSample-based review of selected requirements, controls, previous findings, and changesCertification remains valid, with follow-up if required
Recertification auditAt the end of the three-year cycleContinued certificationBroader and deeper review than surveillance, focused on sustained ISMS effectivenessCertification renewal decision for the next cycle
ISO 27001 audit types across the certification cycle

ISO 27001 surveillance audit timeline and frequency

ISO 27001 surveillance audits follow a regular schedule after certification, although timing and duration can vary based on the organization’s size, scope, and complexity. Understanding the timeline helps teams plan ahead and maintain audit readiness throughout the certification cycle. Here are the key factors that shape the ISO 27001 surveillance audit frequency and timeline:

Annual cadence

Surveillance audits are typically conducted once every 12 months during the three-year certification cycle, with the first around one year after certification and the second approximately one year later. The certification body determines the exact schedule based on the organization and its certification program. Using compliance audit software can help teams keep evidence, controls, and corrective actions organized throughout the year. 

Duration and exceptions

The length of a surveillance audit depends on factors such as company size, ISMS scope, number of locations, and operational complexity. Many audits take between one and several audit days, while larger or more complex organizations may require additional time. Additional audits may also be required after significant changes, such as a major scope expansion, merger, serious control failure, or other material changes to the ISMS.

Planning backward from the audit window

An ISO 27001 audit plan should be built around the expected audit window and allow sufficient time for preparation. Teams should schedule internal reviews, update evidence, check corrective actions, and complete management approvals in advance so that documentation and controls are ready when the surveillance audit begins.

What does an ISO 27001 surveillance auditor check?

An ISO 27001 surveillance auditor checks whether an organization’s ISMS continues to operate effectively and meet the requirements of the standard. Rather than reviewing every area in full, the auditor samples key records, controls, and activities to confirm that compliance has been maintained since the previous audit. Here are the main areas an ISO 27001 surveillance auditor will typically check:

Closure of prior nonconformities

Auditors review findings from previous audits to confirm that identified issues have been properly addressed. This includes checking the root cause, corrective actions taken, evidence of completion, and whether the changes have been effective in preventing the same issues from happening again.

Internal audit and management review records

An ISO 27001 internal audit program helps demonstrate that the ISMS is regularly reviewed between external audits. Auditors may examine internal audit schedules, findings, management review records, decisions, and follow-up actions to confirm that issues are being addressed and leadership remains involved.

Risk assessment and risk treatment updates

Auditors check whether the organization’s risk register remains current as its systems, vendors, operations, and threat environment change. They may review recent risk assessments, treatment plans, assigned owners, and related controls to confirm that identified risks are being managed appropriately.

Control operation and evidence quality

The auditor samples controls across the ISMS scope to confirm they continue to operate as intended. This can include access reviews, vulnerability management, incident response, backups, supplier oversight, and policy acknowledgments, with a focus on whether supporting evidence is current, complete, and clearly linked to each control.

Changes to scope, assets, people, and suppliers

Surveillance audits also assess whether the Information Security Management System (ISMS) has kept pace with changes across the organization. New products, cloud services, offices, critical vendors, or changes in team structure may require updates to asset inventories, risk assessments, the Statement of Applicability, controls, and assigned responsibilities. 

How to prepare for an ISO 27001 surveillance audit

Preparing for a surveillance audit means confirming that the ISMS remains effective and that controls, evidence, and corrective actions are up to date. ISO 27001 compliance software can help teams stay organized, maintain current evidence, and identify gaps before the audit. Here are the key steps to prepare for an ISO 27001 surveillance audit: 

Steps to prepare for an ISO 27001 surveillance audit

Step 1: Confirm the audit window and align owners

Confirm the audit dates, scope, locations, and key contacts with the certification body. Assign internal owners early and set clear deadlines so each team knows what evidence and information it needs to provide.

Step 2: Review prior findings and corrective actions

Start by reviewing previous audit findings, corrective actions, and evidence of closure. Confirm that each issue has been properly addressed and that there is clear evidence showing the corrective action was effective.

Step 3: Update the risk register and treatment plan

Review the risk register, risk treatment plan, and Statement of Applicability to ensure they reflect the current environment. Include relevant business changes, new vendors, system migrations, emerging risks, and updates to controls.

Step 4: Review internal audit and management review records

Check that internal audit and management review records are complete and current. Meeting notes, decisions, action items, and follow-ups should demonstrate that the ISMS has been actively reviewed and maintained throughout the year.

Step 5: Validate control evidence across key areas

Review evidence for key controls, including access control, incident management, vendor reviews, backup testing, and vulnerability management. Make sure records are current, clearly dated, and linked to the relevant controls and owners.

Step 6: Work from an ISO 27001 checklist

Use an ISO 27001 checklist to verify that required documents, records, logs, and approvals are ready before the audit. A checklist can help teams identify missing evidence and keep preparation organized.

For example, 21 Analytics centralized its ISO 27001 policies, evidence, and documentation in Scytale, creating a single source of truth that keeps documentation organized and ready for audits.

Step 7: Run a pre-audit review

Conduct a final review of the organization’s certification scope, controls, and supporting records against ISO 27001. Check that the evidence demonstrates how controls have operated over time rather than relying only on policies or recent snapshots.

Step 8: Prepare process owners

Make sure process owners are prepared to explain how their controls work in practice. They should understand the relevant workflow, supporting evidence, responsibilities, and escalation process so they can answer auditor questions clearly.

Step 9: Organize evidence in a central repository

Keep audit evidence in a centralized repository with clear naming, dates, and version control. This makes it easier to locate requested records quickly and maintain a clear audit trail throughout the review.

Step 10: Address unresolved gaps before the audit

Identify any remaining gaps and address them before the audit where possible. If an issue cannot be fully resolved in time, document the risk, responsible owner, remediation actions, and expected completion date so there is a clear plan in place.

Surveillance audit costs and common nonconformities

ISO 27001 surveillance audit costs vary depending on factors such as ISMS scope, company size, number of locations, certification body, and audit duration. Organizations should consider these costs as part of their broader ISO 27001 certification cost across the three-year cycle. Beyond the audit fee itself, internal preparation, evidence updates, remediation, and external support can also add to the overall cost.

Common nonconformities are often linked to gaps in maintaining the ISMS rather than major control failures. Auditors may identify outdated risk assessments or asset inventories, incomplete internal audit follow-up, missing access review evidence, weak management review records, or corrective actions without clear proof of effectiveness. Minor findings typically require remediation within a set timeframe, while major nonconformities can put continued certification at risk.

Simplify ISO 27001 surveillance audits with Scytale

Scytale helps teams keep evidence, controls, and corrective actions organized and audit-ready between surveillance audits. Its AI GRC platform continuously tracks evidence, control status, open findings, and remediation activities across the ISMS, reducing manual preparation and helping teams identify gaps before the next audit.

For organizations managing ISO 27001 alongside other frameworks, Scytale centralizes evidence and maps shared controls across multiple requirements to reduce duplicate work. Dedicated GRC experts also provide ongoing guidance, helping teams address gaps and prepare for each review. This makes ISO 27001 surveillance audits more predictable and easier to manage year after year.

FAQs about ISO 27001 surveillance audits

  1. How often is an ISO 27001 surveillance audit conducted?

    An ISO 27001 surveillance audit is usually conducted once every 12 months during the three-year certification cycle. The certification body sets the exact timing and may schedule an additional audit if there are significant changes to the organization’s scope, structure, or control environment.

  2. How long does an ISO 27001 surveillance audit take?

    An ISO 27001 surveillance audit often takes one to a few audit days, depending on scope, company size, number of locations, and operational complexity. Smaller organizations may require less audit time, while larger or more complex environments typically require additional sampling and coordination with process owners.

  3. What happens if you fail an ISO 27001 surveillance audit?

    If a surveillance audit identifies nonconformities, the certification body will typically require corrective action within a defined timeframe. Minor nonconformities may require follow-up evidence, while unresolved major nonconformities can put the organization’s ISO 27001 certification at risk.

  4. How much does an ISO 27001 surveillance audit cost?

    ISO 27001 surveillance audit costs vary based on the certification body, scope, company size, and audit duration. Internal preparation, remediation, and evidence collection can also add to the overall cost. Scytale’s AI GRC platform can help reduce manual work and support ongoing audit readiness.

  5. How does a surveillance audit differ from a recertification audit?

    A surveillance audit confirms that your ISMS continues to operate effectively during the three-year certification cycle. A recertification audit takes place at the end of the cycle and is typically broader and more in-depth, determining whether certification should be renewed. Leading ISO 27001 compliance platforms like Scytale help teams stay prepared for both by supporting ongoing compliance and audit readiness throughout the certification cycle.