Certification isn’t the finish line — it’s the start of a three-year cycle, and surveillance audits are the part most businesses underestimate until the first one is suddenly a week away.
What a surveillance audit actually is
After your initial certification (Stage 1 and Stage 2), your certification body returns annually — in year one and year two of the three-year cycle — to confirm your management system is still genuinely operating, not just that it existed on the day you got certified. Year three is a full recertification audit, closer in scope to the original.
Surveillance audits are lighter than the original certification audit, but they’re real audits with real consequences: findings can range from minor observations to non-conformances serious enough to put your certificate at risk.
What auditors actually check
- Evidence the system is still running — internal audits completed, management reviews held, corrective actions tracked to closure.
- Whether anything significant has changed — new sites, new systems, restructures, new suppliers — and whether the management system kept pace.
- A sample of records, not everything. Auditors typically pick specific areas or clauses to test in depth rather than re-auditing the entire system each year.
- Follow-up on any findings from the previous audit — unresolved non-conformances from last time are one of the fastest ways to escalate a problem.
- Whether staff can actually explain how the system works — not recite policy, but describe what they genuinely do day to day.
Why organisations get caught out
The most common failure pattern isn’t a dramatic gap — it’s quiet drift. The person who built the original management system changes roles. A new tool replaces the one the risk register assumed. Internal audits get deprioritised when things get busy. None of this looks like a crisis in the moment, but a year or two later, a surveillance auditor finds a system that looks good on paper and doesn’t quite match reality anymore.
How to actually stay ready
- Keep internal audits running on schedule, not just before the surveillance audit is due. They’re what catches drift early, while it’s still cheap to fix.
- Close out findings properly, not just enough to satisfy the auditor at the time. An unresolved issue from last year is the first thing this year’s auditor will ask about.
- Treat management review as a genuine check-in, not a box-ticking meeting — it’s where leadership is meant to actually look at whether the system is working.
- Update the system when the business changes, rather than letting documentation fall behind reality. New site, new supplier, new tool — the management system needs to know about it.
What it costs
Surveillance audit fees are charged by your certification body and are typically lower than the original Stage 1/Stage 2 audit, since the scope is narrower. The variable cost is really on your side: how much time it takes to prepare depends entirely on whether the system has been actively maintained or needs a scramble beforehand.
If your system has drifted
It’s common, not a failure. If you want a health check before your next surveillance audit rather than finding out on the day, book a free consultation — we’ll look at where things stand and what, if anything, needs attention before the auditor arrives.