The initial certification audit gets all the attention. The surveillance audit is where certificates are actually kept or lost. Organisations that worked hard for Stage 2 often let the system drift in the following year, and the first surveillance audit finds it. This article explains what a surveillance audit covers, what auditors look for, and gives you a practical checklist for preparing for your surveillance audit in the weeks before it is due.
What a surveillance audit is for
Under ISO/IEC 17021-1, certification bodies must carry out surveillance audits at least once each calendar year, except in recertification years, and the first surveillance audit after initial certification must take place no later than twelve months from the date of the certification decision. The purpose is to confirm that the certified management system continues to meet the standard and continues to be effective between recertification audits.
A surveillance audit is shorter than the initial audit — typically around a third of the initial audit time — and does not need to cover every requirement every time. Over the cycle, however, the certification body must plan surveillance so that all parts of the scope are covered, and certain elements are examined at every visit.
What every surveillance audit examines
- Internal audits and management review since the last audit
- Actions taken on nonconformities identified at the previous audit, and whether they were effective
- Treatment of complaints
- Effectiveness of the management system in achieving the organisation’s objectives
- Progress of planned activities aimed at continual improvement
- Continuing operational control
- Review of any changes — to scope, sites, headcount, processes, key personnel or legal requirements
- Use of the certification body’s marks and any reference to certification in your publicity
Why certificates get suspended
Certificates are suspended when surveillance cannot be conducted within the required timeframe, when the system has persistently or seriously failed to meet requirements, or when the organisation does not close major nonconformities in time. Suspension is not a formality: during suspension the certification is temporarily invalid, and customers who check the register will see it. If the underlying problem is not resolved, the certificate is withdrawn, and recovering it means starting again.
Surveillance audit preparation checklist
Eight to six weeks before
- Confirm the audit date and share any changes to headcount, sites, shifts, scope or key processes with the certification body
- Check that the internal audit programme has covered the areas planned for the year, and schedule any audits still outstanding
- Review the status of every nonconformity raised at the last external audit — correction done, corrective action implemented, effectiveness verified
- Confirm the management review has been held within the planned interval, with all required inputs and documented outputs
Four to two weeks before
- Update performance data against objectives, including the reasons for any targets missed and the actions taken
- Review the complaint log, customer feedback and returns to confirm each was investigated and closed
- Check the legal and other requirements register for new or amended obligations and evidence of evaluation of compliance where the standard requires it
- Review risk and opportunity actions, aspects or hazard registers, and Statements of Applicability for changes that should have been made
- Confirm calibration, maintenance and training records are current for the areas likely to be sampled
- Check that documents in use at the point of work are the current approved versions
The week of the audit
- Review the audit plan sent by the certification body and make sure the people named, including top management, are available
- Brief process owners on the audit timing — not on what to say. Auditors can tell rehearsed answers from real ones
- Prepare access to records, systems and sites, including remote access if any part of the audit is being conducted remotely
- Check how the certification mark and certificate are being used on your website, letterheads and product literature
The mistakes that produce findings at surveillance
- Internal audits skipped or compressed into the month before the external audit
- Management review minutes that record a presentation but no decisions, actions or resource needs
- Corrective actions from the last audit closed on paper without any evidence that they worked
- Changes — a new site, a new product line, a new outsourced process — not notified to the certification body
- Objectives unchanged from the previous year with no analysis of whether they were achieved
- Certification marks used on products or packaging in a way the certification body’s rules do not permit
Using surveillance well
Surveillance is also an opportunity. An auditor who visits every year sees trends that an internal team, close to the work, can miss. Organisations that treat the surveillance audit as an independent annual health check — rather than as an inspection to be survived — tend to get considerably more value from their certification.
It also helps to think one step ahead. The second surveillance audit leads into recertification before the certificate expires in year three, and the recertification audit reviews the performance of the system over the whole cycle. Findings that recur from one surveillance audit to the next are exactly what a recertification audit will focus on, so closing them properly now makes the next cycle easier.
If you are certified with GMSCPL and want to confirm your surveillance date or notify a change to scope or sites, contact our team. If you are planning a transfer of an existing certificate, request a quote and we will explain the transfer review process.