Home / Insights / The 8 things every surveillance audit must cover
Quality & IMSChecklist
The 8 things every surveillance audit must cover
Surveillance is not a lighter version of the certification audit. Its minimum content is fixed by the standard certification bodies are accredited against, so preparation can work from a known list.
Published 4 August 2026Reviewed 4 August 20266 minute read
Certification is a cycle; surveillance keeps it alive between initial audit and recertification.
- Surveillance happens at least once per calendar year, except in recertification years.1
- The first surveillance audit takes place no later than 12 months after the initial certification decision.1
- The cycle runs to three years: initial audit, surveillance in years one and two, recertification in year three, unless an industry-specific scheme sets a different cycle.1, 4
- Within those limits, the schedule is not fixed: date, duration and scope depend on the certification programme, the contract, and your certified scope, sites and risk.
The eight items below are the minimum content the surveillance audit programme must include under ISO/IEC 17021-1, clause 9.6.2.2.2 The auditor selects a sample within them; the list does not vary between certification bodies.
Each item states what to have ready. Where we describe how organisations typically fail, that is practice observation rather than rule.
This checklist is about keeping a certificate. For appointing a consultant in the first place, see the 9 checks before you appoint an ISO consultant.
The mandatory review areas
Internal audits and management review
The first item on the mandatory list, and the one that most often fails. An internal audit programme delayed, shortened or conducted superficially gives the auditor no basis to confirm the system operates as intended. Management review fails in a different way: the meeting happened, but not every required input was covered.
Have readyThe internal audit schedule with evidence it was followed, the findings and what was done about them, and management review records showing each required input was addressed with documented outcomes.
Action taken on previous nonconformities
Not that corrective action was logged. That it worked. A closed action with no evidence of effectiveness is one of the most common findings: organisations record the intervention and stop there.
Have readyFor each previous finding: the cause analysis, the action taken, and separate evidence that the cause no longer produces the problem. “Training was delivered” is the action; the subsequent audit finding nothing is the evidence.
Treatment of complaints
Complaints are a mandatory review area whether or not you consider them significant. The auditor tests whether they enter the system at all, and whether the response reaches the cause rather than only the complainant.
Have readyThe complaints record for the period: how each was handled, what it revealed, and any resulting change. An empty log invites the question whether complaints are captured at all.
Effectiveness against your own objectives
The standard requires the surveillance audit to examine whether the management system is achieving the certified organisation’s objectives. Objectives set once and never revisited are hard to evidence.
Have readyCurrent objectives with named owners, the measures behind them, and the performance data showing where each stands.
Progress on continual improvement
Planned improvement activity, and what happened to it. Intent is not progress: the auditor looks for activities planned, pursued, and either completed or consciously changed.
Have readyThe improvement plan, its current status, and what has changed since the last audit.
Continuing operational control
Whether the controls described in the system are the controls being operated. Drift is usually gradual and invisible from the top: a process changes for good practical reasons and the documentation does not follow.
Have readyAccess to the operations themselves and the people running them, not only the procedures describing them.
What you must declare
Any changes since the last audit
A new service line, a new site, a significant change in operations or in key personnel. Unreported change is a finding in its own right, and it can trigger a scope review that adds audit time.
Have readyA short written summary of what has changed, sent to the certification body before the audit rather than raised during it.
Use of certification marks and claims
How the certificate is referred to on your website, proposals, invoices, vehicles and signage. Misuse is easy to find and easy to avoid, and it is examined at surveillance.
Have readyA review of where the mark and any certification claim appear, checked against the certification body’s rules and your certified scope.
If a finding is raised
When a nonconformity is raised, the certification body sets the response deadline and decides how closure will be verified.3 That may mean reviewing documented evidence, checking implementation at the next audit, or an additional audit.
Fixed 90-day or six-month periods should not be assumed unless they appear in your certification body’s rules or the applicable scheme. Deadline, verification method and whether a further audit is needed depend on the certification body, the scheme and the significance of the finding, not on a universal figure.
We prepare organisations for surveillance and help close findings. We are not part of the audit and we take no part in the certification decision. That decision belongs to the accredited certification body alone, and no preparation, ours or anyone else’s, can guarantee its outcome. Who decides what in ISO certification sets out the separation.
Sources and references
All accessed 4 August 2026. ISO/IEC 17021-1:2015 is copyright protected, so clause text is not reproduced in full here.
- ISO/IEC 17021-1:2015, clauses 9.1.3.2 and 9.1.3.3: the certification cycle, annual surveillance except in recertification years, and the requirement that the first surveillance audit take place no later than 12 months after the initial certification decision. Clause 9.1.3.2 NOTE permits a different cycle where an industry-specific scheme requires it.
- ISO/IEC 17021-1:2015, clause 9.6.2.2: the minimum content of the surveillance audit programme, the eight areas above. Clause 9.6.2.1.2 requires surveillance to include on-site auditing.
- ISO/IEC 17021-1:2015, clause 9.4.10: the certification body requires the client to analyse cause and describe correction and corrective action within a time the certification body defines, and determines how closure is verified. Corroborated in principle by UKAS guidance on improvement action closure, which confirms that closure deadlines are set by the responsible conformity assessment body rather than by a universal period.
- Corroboration on cycle frequency. UKAS CIS 9 states that "normal surveillance audits would take place at least yearly and recertification after three years". This is sector-specific guidance and is cited as corroboration of the pattern only; the governing requirement is ISO/IEC 17021-1 itself.
Last reviewed 8 August 2026.
Read next
If a surveillance date is approaching and you are not sure the evidence is there, a readiness review finds the gaps in time to close them.
Discuss a readiness review