What is a surveillance audit, and what is it not?
A is performed by the during the to assess continuing conformity and maintenance of the certified ISMS. It is external certification activity, not the internal audit required by Clause 9.2 and not a substitute for management review under Clause 9.3.
The organization must keep operating the whole management system between external audits. Passing the original certification audit does not freeze the scope, risk register, SoA, controls, or evidence. Certification concerns conformity of the scoped management system; it is not a guarantee that every system is secure or that no incident will occur.
- Keep internal audit, management review, monitoring, corrective action, and risk reassessment on their planned schedules regardless of the surveillance date.
- Use the 's audit programme and contract for the exact surveillance scope, timing, sampling, and notification rules.
- Do not describe an internal readiness review as a certification-body .
- Keep the three activities distinct: internal audit is the organization's own Clause 9.2 evaluation; surveillance maintains external confidence during the active cycle through selected sampling; a supports renewal through a broader end-of-cycle evaluation.
ISO/IEC 27001:2022 contains the organization's continuing ISMS requirements, including internal audit, management review, risk reassessment, and corrective action.
This source states that certification bodies audit and certify ISMS in accordance with ISO/IEC 27001 and supports the certification-body context for surveillance audits.