How to Prepare for Your First ISO 27001 Surveillance Audit
Earning ISO 27001 certification feels like crossing a finish line. It isn’t. Certification runs on a three-year cycle: a two-stage initial audit, then surveillance audits in years one and two, then a full recertification audit in year three. Your first surveillance audit typically lands within twelve months of the initial certification decision — and it tests something the initial audit couldn’t: whether your information security management system (ISMS) actually runs, or whether it was a project that ended when the certificate arrived.
What a surveillance audit is (and isn’t)
A surveillance audit is narrower than your Stage 2 audit. The auditor won’t re-examine every Annex A control; they sample a portion of the ISMS each year, with the full scope covered across the three-year cycle. But some things are checked every year, because they demonstrate the management system is alive:
- Management review — has leadership formally reviewed the ISMS as clause 9.3 requires, with documented inputs and decisions?
- Internal audit — did you run your internal audit program per clause 9.2, and act on what it found?
- Nonconformities and corrective actions — what happened to the findings from your certification audit? Auditors open here almost every time.
- Risk assessment and treatment — has the risk register been reviewed and updated, and does the Statement of Applicability still reflect reality?
- Changes — new products, offices, vendors, or org structure that affect ISMS scope.
- Incidents — what occurred, how you responded, and what you learned.
The unifying theme is continual improvement. A frozen ISMS — same risks, same documents, no internal audit, no management review — is the fastest route to a major nonconformity, which can ultimately put the certificate itself at risk.
The evidence that carries the day
Surveillance auditors want records with dates, names, and outcomes. Before the audit, confirm you can produce:
- Minutes and outputs from at least one management review since certification
- An internal audit report, plus corrective action records for its findings
- Closed-out corrective actions from the certification audit, with root-cause analysis
- A risk register showing review activity — new risks added, treatments progressed, dates updated
- Records of recurring control operation: access reviews, awareness training completions, supplier evaluations, backup and restore tests, vulnerability management activity
- An updated Statement of Applicability if anything changed
Notice the pattern: none of this can be created convincingly the week before. Backdated reviews and suspiciously uniform timestamps are exactly what experienced auditors look for.
A 90-day preparation plan
Days 90–60: Audit yourself first
Run (or refresh) your internal audit, prioritizing the areas your certification auditor flagged and any part of the business that changed. Log findings as formal corrective actions — finding your own nonconformities is a feature, not an embarrassment; it proves clause 10 is working.
Days 60–30: Close the loop
Hold a management review with a proper clause 9.3 agenda: audit results, incident trends, risk status, objectives, resourcing. Update the risk register and Statement of Applicability. Chase every open corrective action to closure or a credible, documented plan.
Days 30–0: Rehearse the story
Compile evidence by clause and control so nothing is hunted for live. Brief the people the auditor will interview — control owners should be able to explain what they do and where the records live, not recite policy. Prepare a short “what changed this year” summary; volunteering changes builds credibility and lets you frame them.
Make year two boring
The teams that dread surveillance audits are the ones whose ISMS hibernates between them. The fix is operational, not heroic: put recurring activities — access reviews, risk reviews, training, supplier assessments, internal audits — on a schedule with named owners, and capture evidence as the work happens rather than reconstructing it later.
This is precisely the workload ComplianceDL automates: control tasks run on their defined cadence, evidence is collected and timestamped continuously, and overdue activities surface before they become findings. When the auditor asks for a year of access reviews, the answer is an export, not an archaeology project.
Your first surveillance audit is genuinely lower-stakes than certification — shorter, narrower, and led by an auditor who wants to see progress, not perfection. Show a living system with honest findings and closed loops, and year one becomes what it should be: routine.