An ISO 27001 surveillance audit checks continued conformity during the certification cycle. Recertification assesses renewal for the next cycle. Your certificate’s expiry date is therefore not the only date to plan around: keep the external audit schedule, internal audit programme and corrective actions visible throughout the year. NQA certification process.
| Checkpoint | Purpose | Planning implication |
|---|---|---|
| Initial certification | Stage 1 and Stage 2 assess readiness and the implemented management system before the certification decision. | Build and operate the ISMS, not just its documents. |
| Surveillance | Check continued conformity during the active cycle, using the certification body’s audit programme. | Maintain operating evidence and follow up findings between visits. |
| Recertification | Assess continued conformity and effectiveness for renewal. | Allow time for the audit, necessary corrective actions and the certification decision before expiry. |
| Internal audit | Evaluate the ISMS against applicable requirements through the organisation’s own audit programme. | Use planned intervals and coverage appropriate to the system; leave time to act on findings. |
Atoro is an Irish AI governance and cyber compliance consultancy, and the first in Europe to be certified against ISO 42001. We support software companies from implementation and internal audit to ongoing managed compliance with TrustOps, with outsourced DPO and virtual CISO support where needed.
What happens after initial certification?
The ISMS must continue operating after the certificate is issued. Initial certification is the start of an ongoing cycle, not the end of the work.
Management-system certification commonly follows a three-year cycle, with annual surveillance and recertification before renewal. The certification body sets the audit programme and confirms the dates. NQA’s published registration rules describe the first surveillance as normally no more than twelve months after the initial certification decision. Do not substitute that limit for the earlier date agreed with your own certification body. NQA, NQA registration regulations.
Keep responsibilities clear for risk reviews, control operation, internal audits, management reviews and corrective actions. Evidence should show what happened across the relevant period, not only what was prepared shortly before the external audit.
What does surveillance examine?
Surveillance checks that the certified management system continues to function. It is a formal external audit, even where its scope and duration are narrower than recertification.
Prepare to discuss changes, performance and follow-up. Useful evidence includes current scope and risk records, internal audit results, management-review decisions, corrective actions and records showing that controls operated. Confirm the specific coverage with the certification body instead of assuming every surveillance visit examines the same areas.
A shorter visit does not mean a lower obligation to operate the ISMS. Nor should you assume a green platform dashboard answers every audit question. Be able to explain what a record demonstrates, the period it covers and who reviewed it.
What changes at recertification?
Recertification supports the decision to renew certification. Booking an audit before expiry is not, by itself, the same as completing the renewal process.
Review the business and system changes made over the cycle: products, services, locations, suppliers, risks and responsibilities. Make sure the proposed scope reflects the current organisation. Ask the certification body to confirm the audit arrangements, deadlines for resolving findings and the decision timetable. NQA audit guidance.
Do not assume recertification always requires repeating the original two-stage process unchanged. Equally, do not assume renewal is automatic because earlier surveillance visits went well. The certification body determines the necessary activities under its applicable rules.
Where does the internal audit fit?
ISO 27001 internal audit requires audits at planned intervals. It does not turn every external visit into a universal deadline for a fresh, complete internal audit of the entire system. BSI ISO 27001:2022 self-assessment.
Plan an audit programme that covers the requirements, reflects the importance of the processes and considers previous results. Work completed through that programme should give management useful information before an external assessment. In practice, leaving enough time to address findings is better than finishing an internal audit immediately before surveillance.
Protect objectivity and impartiality when assigning auditors. A person auditing the controls they operate can create a self-review problem. The appropriate arrangement depends on competence, responsibilities and safeguards, not simply whether the auditor is an employee or an external consultant.
A practical readiness sequence
Work backwards from the next external audit and the applicable certification deadlines, not only the printed certificate expiry date.
- Confirm whether the visit is surveillance or recertification.
- Confirm dates, scope and requested evidence with the certification body.
- Check whether the ISMS scope and risk treatment reflect current operations.
- Review the internal audit programme and complete due work with time for follow-up.
- Record findings, corrective actions, owners and due dates.
- Ensure management review considers the relevant audit results and system performance.
- Prepare evidence of actions taken and identify what remains open.
This is a planning recommendation, not a replacement for the organisation’s audit programme or the certification body’s requirements. Do not backdate records to make the sequence appear complete.
What if findings are still open?
Show their actual status and follow the applicable deadlines. An action plan is not the same as completed corrective action.
Record the issue, its cause where relevant, the planned response and evidence of implementation and effectiveness. Where the certification body requires correction or corrective-action verification before a decision, an internal target date does not override that requirement. Ask promptly if you are uncertain about a finding’s classification or deadline.
FAQs
1. How often are surveillance audits held?
They are commonly annual during the certification cycle. Confirm the programme with your certification body, including the first surveillance deadline and any scheme-specific requirements.
2. Is surveillance the same as recertification?
No. Surveillance checks continued conformity during the cycle; recertification supports renewal for the next cycle.
3. Does the expiry date tell us when the next audit is due?
Not necessarily. Surveillance is normally due before expiry, so use the confirmed audit programme as well as the certificate dates.
4. Must we complete a new full internal audit before every visit?
Not as a universal rule. Internal audits must follow a suitable programme at planned intervals, and the resulting evidence should demonstrate coverage and follow-up.
5. Can someone audit their own controls?
That can undermine objectivity and impartiality. Assign competent auditors and arrangements that avoid self-review conflicts.
6. Must every finding be closed before surveillance?
It depends on the finding and applicable deadlines. Report the true status and follow the certification body’s requirements; do not imply closure where only a plan exists.
7. Is booking recertification before expiry enough?
No. Leave time for the necessary assessment, resolution of findings and certification decision, and confirm the timetable with the certification body.
8. Can our compliance platform replace internal audit?
No, a platform can organise evidence but does not itself demonstrate that a suitable audit was performed. Competent, objective evaluation and documented results are still needed.
If the next external visit is approaching, book a scoping conversation with Atoro about an independent internal audit. Bring your audit programme, previous findings and confirmed certification-body dates.
Sources
- NQA, Certification FAQs: https://www.nqa.com/en-us/faqs
- NQA, Registration regulations: https://www.nqa.com/getmedia/ffafafe7-bc9d-42a7-9325-6baffcf2d90f/2023wk6-NQA_Registration_Regulations_A4v2.pdf
- NQA, Audit stages and cycle: https://www.nqa.com/en-ca/resources/knowledge-hub/audits-the-what-when-how
- BSI, ISO 27001:2022 self-assessment questionnaire: https://www.bsigroup.com/globalassets/localfiles/en-us/brochures/Information%20Security/bsi-iso-27001-self-assesment-questionnaire-us.pdf
- ISO/IEC 27001: https://www.iso.org/standard/27001