Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
What is an ISO 27001 surveillance audit?
Last verifiedA surveillance audit is the usual year-1 and year-2 sample that keeps an ISO/IEC 27001 certificate valid inside a typical three-year cycle. It is partial, not a full recertification. This page is not legal advice, does not determine YOUR obligations, does not start a clock, and does not file.
Explainer, last verified 10 September 2026. ISO 27001 is a voluntary standard, not a law. ISO/IEC 17021-1 and ISO/IEC 27006 govern how accredited bodies perform surveillance. Clauses 4–10 must keep operating; Annex A controls marked implemented still need records.
What this page is, and what it is not
Audience: an ISMS owner who has the certificate and needs to keep it.
This page is not legal advice. It does not determine YOUR obligations, does not start a clock, and does not file. Last verified 10 September 2026.
Only the issuing IAF-MLA accredited certification body (or a successor it agrees) performs recognised surveillance.
What is sampled in each year of the cycle
Cadence below is the typical accredited pattern. Your contract may state exact windows. Last verified 10 September 2026. Not legal advice.
| Year in the cycle | What is sampled | What stays continuous | Kind of text |
|---|---|---|---|
| Year 0 — initial Stage 1 and Stage 2 | Documentation/readiness, then implementation/effectiveness of the ISMS. | The ISMS itself — Clauses 4–10 do not pause after the certificate. | Certification process (see that page). Not surveillance. |
| Year 1 — first surveillance (typical) | A partial sample: some processes, some sites, some Annex A controls marked implemented, progress on prior findings. | Internal audit, management review, corrective actions, risk and SoA currency. | ISO/IEC 17021-1 surveillance practice. |
| Year 2 — second surveillance (typical) | Another partial sample, usually covering areas not seen in year 1 so the cycle as a whole is representative. | The same continuous machinery. Scope changes should already have been notified. | ISO/IEC 17021-1 surveillance practice. |
| Year 3 — recertification (not surveillance) | Full reassessment before expiry. | Still the ongoing ISMS; recertification is a milestone, not a substitute for years 1–2. | Recertification — see that page. |
| After a major change (new site, merger, new processing) | Possible special audit or expanded sample, depending on the body. | Revised scope, risk assessment, and SoA. | Accreditation practice — ask your body; this page does not decide. |
| Lapsed or suspended certificate | Surveillance does not restart a dead certificate by itself. | Nothing on this page restores recognition. | Accreditation outcome. Not a law. |
Legal requirement, regulatory guidance, best practice, or our recommendation
Keeping the certificate is a contractual relationship with the body, not a statute. Last verified 10 September 2026. Not legal advice.
| Statement | Which kind of authority | What it does not mean |
|---|---|---|
| Accredited certificates are typically maintained through surveillance. | ISO/IEC 17021-1 / ISO/IEC 27006. | Does not make ISO 27001 a law. |
| IAF MD 5 still influences how many days the sample takes. | IAF mandatory document. | Does not set your internal calendar. |
| Keep internal audit and management review on their planned intervals all year. | Certification standard (Clauses 9–10) plus industry best practice for “always on.” | Does not replace the surveillance visit. |
| Notify the body of significant scope changes when they happen, not at the door. | Industry best practice / typical contract term. | Does not determine YOUR contractual notice duties — read the agreement. |
| Keep evidence collection running so surveillance is a sample, not a rebuild. | ShipReady Metrics recommendation. | Does not produce an auditor's opinion. |
What to keep continuously
Surveillance goes badly when the ISMS was rebuilt for Stage 2 and then left idle. Keep: a current SoA, risk assessment that reflects new systems, internal-audit results, management review, corrective-action status, and operating records for implemented Annex A controls. Last verified 10 September 2026. Not legal advice.
Checklist
This is the checklist artifact for staying ready. Last verified 10 September 2026. Not legal advice.
- Do we know the contracted surveillance window for year 1 and year 2?
- Have internal audit and management review run since Stage 2?
- Is the SoA still true after the last product or vendor change?
- Are prior nonconformities closed with records?
- Have we told the body about scope changes?
- Do we treat this as partial sampling, not as “the easy year”?
What to do now
These steps do not file and do not start a statutory clock.
- Put surveillance dates on the same calendar as recertification expiry.
- Read the recertification and certification-process pages.
- Refresh the auditor-evidence index before the visit.
- Confirm the body is still IAF-MLA accredited in CertSearch.
- Re-verify sources; last verified 10 September 2026.
Where this shows up in ShipReady Metrics
Only shipped behaviour is described here. ShipReady Metrics does not issue certificates, does not produce an auditor's opinion, and is not a downloadable evidence binder.
If you already have a session: signed-in app → Compliance evidence collection and evidence review keep rows current between visits. The obligation map, policies library, and cyber risk register support continuous operation. Annex A crosswalk density is coverage, not a pass.
Surveillance remains the accredited body’s sample.
Primary sources (last verified 10 September 2026)
ISO/IEC 17021-1 surveillance requirements; ISO/IEC 27006; IAF. ISO/IEC 27001:2022 still describes the ISMS you must keep running. Not legal advice.