How should teams handle Surveillance Audits under ISO/IEC 27001?
Start with the operational decision: define what Surveillance Audits means in your ISO/IEC 27001 scope, who owns it, and what record proves the decision is current.
For ISMS work, keep the traceability chain visible: scope, risk, treatment choice, SoA entry, control owner, evidence sample, exception, corrective action, and management review decision. This keeps the answer useful in audits, customer reviews, incidents, supplier reviews, and management review.
- Name the accountable owner and reviewer for Surveillance Audits.
- Record the scope, assumptions, decision, approval date, evidence location, exception status, and next review trigger.
- Escalate when Surveillance Audits changes risk acceptance, service commitments, customer promises, regulatory duties, or certification evidence.
Use this source as the governing requirements context for ISO/IEC 27001 scope, control governance, and review cadence in ISMS operations.
This source states that certification bodies audit and certify ISMS in accordance with ISO/IEC 27001 and supports the certification-body context for surveillance audits.