FAQGlobalISO/IEC 27001

ISO/IEC 27001 FAQ Surveillance Audits

What happens during an ISO/IEC 27001 surveillance audit, and how should the organization prepare?

Keep the certified scope, risk and SoA decisions, control samples, internal audit, management review, changes, and corrective actions current between certification cycles.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Questions
4

Structured answer sets in this page tree.

Primary sources
5

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

A is a 's external audit during an active . It checks continuing conformity and maintenance of the certified ISMS through selected requirements, changes, and evidence. It does not replace the organization's internal audits or management reviews, and it is different from the fuller recertification activity at the end of a cycle.

Search this module

Find a question or answer quickly

4 of 4 questions
Question 1

What is a surveillance audit, and what is it not?

A is performed by the during the to assess continuing conformity and maintenance of the certified ISMS. It is external certification activity, not the internal audit required by Clause 9.2 and not a substitute for management review under Clause 9.3.

The organization must keep operating the whole management system between external audits. Passing the original certification audit does not freeze the scope, risk register, SoA, controls, or evidence. Certification concerns conformity of the scoped management system; it is not a guarantee that every system is secure or that no incident will occur.

  • Keep internal audit, management review, monitoring, corrective action, and risk reassessment on their planned schedules regardless of the surveillance date.
  • Use the 's audit programme and contract for the exact surveillance scope, timing, sampling, and notification rules.
  • Do not describe an internal readiness review as a certification-body .
  • Keep the three activities distinct: internal audit is the organization's own Clause 9.2 evaluation; surveillance maintains external confidence during the active cycle through selected sampling; a supports renewal through a broader end-of-cycle evaluation.
Citations
ISO/IEC 27001:2022 standard page

ISO/IEC 27001:2022 contains the organization's continuing ISMS requirements, including internal audit, management review, risk reassessment, and corrective action.

ISO/IEC 27006-1:2024 standard page

This source states that certification bodies audit and certify ISMS in accordance with ISO/IEC 27001 and supports the certification-body context for surveillance audits.

Question 2

What should be ready for surveillance sampling?

Prepare the current scope, risk assessment and treatment records, SoA, objective and performance results, internal-audit programme and reports, management-review decisions, prior external-audit actions, nonconformities, corrective actions, and operating samples for selected controls.

Follow the 's audit plan for the actual sample and evidence period. Be ready to explain material changes and show both normal operation and how the ISMS responded to incidents, failed controls, missed objectives, supplier changes, or other deviations. The audit may select evidence outside a prepared index when it is relevant to the scope and criteria.

  • Map samples to the and the current SoA rather than presenting unrelated company-wide evidence.
  • Show the cause, action, and effectiveness review for earlier nonconformities instead of only a closed status.
  • Reconcile certificate wording, internal scope, customer claims, and the live products or services before the audit.
  • Example: after adding a new location, cloud platform, or service inside the claimed boundary, update the scope and dependencies, reassess risk, revise the SoA and operating records as needed, and notify the under the agreed process rather than waiting for the auditor to discover the change.
Citations
Question 3

Who does what during surveillance?

The plans and performs the external audit and makes certification decisions under its scheme. ISO/IEC 27006-1 addresses the competence, consistency, and impartiality of bodies that audit and certify ISMSs.

The organization remains responsible for the ISMS: top management, risk owners, control owners, internal auditors, and corrective-action owners must be able to explain and evidence their own decisions. The external auditor does not assume those roles.

  • Name one audit coordinator, but keep evidence explanations with the people who operate and govern each process.
  • Escalate potential scope or certificate impacts to top management and the through the agreed process.
  • Verify certification and accreditation records independently when customers or suppliers rely on the certificate.
Citations
ISO/IEC 27001:2022 standard page

ISO/IEC 27001:2022 assigns ISMS responsibilities within the organization, including top-management review and risk-owner treatment approval and residual-risk acceptance.

Question 4

How often do surveillance audits happen?

ISO/IEC 27001 sets the organization's ISMS requirements but does not itself state the surveillance dates for a particular certificate. The certification process is governed by ISO/IEC 17021-1, supplemented for ISMS certification by ISO/IEC 27006-1. Under ISO/IEC 17021-1, surveillance audits occur at least once in each calendar year except a recertification year, and the first after initial certification must be no more than 12 months after the certification decision. Use the certification agreement and audit programme for the actual dates, scope, duration, and remote or on-site arrangements.

Do not wait for the scheduled audit when a material change could affect or the validity of the claim. Follow the certification arrangement's notification process and update the ISMS records as the change occurs.

  • Record the agreed audit schedule and evidence period from the certification-body plan.
  • Set internal readiness checkpoints early enough to close real corrective actions, not to manufacture records.
  • Track recertification separately from surveillance and preserve the 's terminology.
  • A is normally three years, but the certificate, certification-body programme, and any scheme-specific rules control the organization's actual renewal timetable.
Citations
ISO/IEC 27001:2022 standard page

ISO/IEC 27001:2022 requires the organization's internal audits and management reviews at planned intervals but does not provide a certificate-specific surveillance calendar.

ISO/IEC 27006-1:2024 standard page

ISO/IEC 27006-1:2024 provides the ISMS-specific certification-body requirements; the organization's certification arrangement supplies its actual audit programme.

ISO/IEC 17021-1:2015 standard page

Official ISO source for certification cycles, surveillance activities, recertification, and the general requirements applying to management-system certification bodies.

Primary sources

References and citations

iso.org
Referenced sections
  • Official ISO source for certification cycles, surveillance activities, recertification, and the general requirements applying to management-system certification bodies.
iso.org
Referenced sections
  • ISO/IEC 27001:2022 requires the organization's internal audits and management reviews at planned intervals but does not provide a certificate-specific surveillance calendar.
"Information security management systems - Requirements"
iso.org
Referenced sections
  • ISO/IEC 27002:2022 provides guidance that can help explain the design and operation of sampled information security controls.
"Information security controls"
iso.org
Referenced sections
  • ISO/IEC 27005:2022 provides risk-management guidance relevant to current risk assessment, treatment, monitoring, and change evidence.
"Guidance on managing information security risks"
iso.org
Referenced sections
  • ISO/IEC 27006-1:2024 provides the ISMS-specific certification-body requirements; the organization's certification arrangement supplies its actual audit programme.
"Requirements for bodies providing audit and certification"
Related guides

Explore more topics

ISO/IEC 27001 Annex A Control Evidence Guide
Build useful ISO/IEC 27001:2022 Annex A control evidence: selected controls, SoA rationale, owners, implementation proof, effectiveness checks, audit records, and improvement actions.
ISO/IEC 27001 Annex A Control Ownership FAQ
How to assign practical owners for ISO/IEC 27001 Annex A controls without confusing control ownership with the standard's required risk-owner accountability.
ISO/IEC 27001 Audit Readiness Guide
Prepare ISO/IEC 27001 audit evidence across ISMS scope, risk assessment, risk treatment, Statement of Applicability, Annex A controls, internal audit, management review, and corrective actions.
ISO/IEC 27001 Certification Body Evidence FAQ
What ISO/IEC 27001 certification auditors may sample, how to connect requirements to operating evidence, and what the certification body does not own.
ISO/IEC 27001 Certification Stage Workflow
Plan optional ISO/IEC 27001 certification from scope readiness through Stage 1, Stage 2, findings, certification decision, surveillance, and recertification.
ISO/IEC 27001 Compliance Guide: ISMS Evidence
Build ISO/IEC 27001:2022 conformity evidence for ISMS scope, leadership, risk assessment and treatment, the Statement of Applicability, operations, audits, management review, and corrective action.
ISO/IEC 27001 FAQ: ISMS Scope, Risk and SoA
Practical ISO/IEC 27001 FAQ covering ISMS scope, risk assessment, risk treatment, Statement of Applicability, Annex A controls, certification evidence, audits, management review, and surveillance readiness.
ISO/IEC 27001 Implementation Roadmap Guide
A practical ISO/IEC 27001:2022 roadmap from context and scope through risk treatment, the SoA, control operation, internal audit, management review, corrective action, and optional certification.
ISO/IEC 27001 Internal Audit and Management Review Guide
Keep ISO/IEC 27001 internal audit and management review distinct and connected: independent audit evidence, top-management decisions, corrective actions, resources, and improvement records.
ISO/IEC 27001 Internal Audit FAQ
How should teams run ISO/IEC 27001 internal audits: who should own each step, what evidence is expected, and how findings are resolved.
ISO/IEC 27001 Management Review FAQ
What ISO/IEC 27001 management review must consider, what top management must decide, what evidence to retain, and how to set the cadence.
ISO/IEC 27001 Requirements Guide
Plain-language guide to ISO/IEC 27001:2022 Clauses 4-10: context, leadership, planning, support, operation, performance evaluation, improvement, and Annex A control selection.
ISO/IEC 27001 Risk Acceptance FAQ
How ISO/IEC 27001 risk acceptance works: criteria, risk-owner approval, residual-risk evidence, external obligations, and reassessment triggers.
ISO/IEC 27001 Risk Treatment and Residual Risk Guide
Connect ISO/IEC 27001 risk-treatment choices, necessary controls, the treatment plan, Statement of Applicability, residual-risk acceptance, owners, evidence, and review triggers.
ISO/IEC 27001 Risk Treatment Register Workflow
Build an ISO/IEC 27001 risk-treatment register that links assessed risks to treatment options, controls, SoA entries, actions, owners, residual-risk approval, evidence, and review triggers.
ISO/IEC 27001 SoA Exclusions FAQ
How should teams justify Statement of Applicability exclusions under ISO/IEC 27001? Practical answer with owners, evidence, review triggers, and external source references.
ISO/IEC 27001 SoA: workflow for gathering and documenting control evidence
Operate the ISO/IEC 27001 Statement of Applicability as a live evidence index linking necessary controls, Annex A inclusion and exclusion rationale, implementation status, owners, and proof.
ISO/IEC 27001 Statement of Applicability template: Annex A control selection and justification
Practical ISO/IEC 27001:2022 Statement of Applicability template fields for necessary controls, Annex A applicability, inclusion and exclusion rationale, status, owners, evidence, and review history.
ISO/IEC 27001 vs NIS2 Comparison
Compare voluntary ISO/IEC 27001 ISMS conformity and optional certification with NIS2 legal duties, entity scope, management accountability, incident reporting, supervision, and penalties.
ISO/IEC 27001 vs NIST CSF 2.0 Comparison
Compare ISO/IEC 27001:2022's certifiable ISMS requirements with NIST CSF 2.0's cybersecurity outcomes, Profiles, Tiers, Functions, evidence uses, and adoption choices.
ISO/IEC 27001 vs SOC 2 Comparison
Compare ISO/IEC 27001 certification with SOC 2 examination reports: criteria, scope, assurance period, auditor and certification-body roles, deliverables, evidence reuse, and claim limits.