Surveillance audits are conducted during the second and third years of a three-year certification cycle to confirm your management system remains effective.
Scale
Annual surveillance time runs at roughly a third of the initial certification audit time. The auditor samples rather than covering everything, but certain elements appear every time:
- Internal audits and management review since the last visit
- Progress on previous findings
- Complaints and corrective actions
- Changes to the organisation, its processes, or its scope
- Use of the certification mark
They are not a formality
A surveillance audit can raise major nonconformities, and an unresolved major can lead to suspension or withdrawal of the certificate. Suspension is more disruptive than most organisations expect — customers who require certification generally require it continuously.
The predictable failure
System drift. The certificate is achieved, attention moves elsewhere, and by the first surveillance the internal audit programme has slipped, the management review has not happened, or documents no longer reflect how the work is done.
This is why maintenance costs less than recovery. A light annual rhythm — one internal audit cycle, one management review, document updates as operations change — keeps a system healthy for a fraction of what it costs to rebuild before an audit.
Recertification
At the end of year three, a recertification audit runs at roughly two-thirds of initial certification time and starts a new cycle.