Compliance

What Happens at a Surveillance Audit — and How to Never Scramble Before One

Surveillance audit year two. You passed certification eighteen months ago. The QMS is built, the policies are signed, and you have been quietly confident that things are roughly on track. The night before the auditor arrives, your operations manager files three expired competency records, updates a procedure that has not been touched since certification day, and realises the nonconformance raised in March was never formally closed.

This is not a fringe story. It is what happens when a business mistakes having a QMS for maintaining one. The certification audit proves the system was built. The surveillance audit proves whether anyone has been living in it.

What a surveillance audit actually is

A surveillance audit is not a shorter version of the certification audit. It is a different kind of assessment, run by your certification body once a year to confirm your QMS is still functioning between the formal three-year recertification cycles.

Where the Stage 2 certification audit asked “does this system exist?”, the surveillance audit asks “has this system been operated?” The auditor is not re-checking whether you have a quality policy or a documented procedure for customer complaints. They already know you do. They are checking whether those procedures have been followed, reviewed, and kept current across the past twelve months, by real people doing real work.

The scope of a surveillance visit is narrower than a full certification audit, typically covering half to two-thirds of the applicable clauses, with the remaining clauses picked up in year two. But the standard of evidence is identical. A record that exists without being current is no record at all.

The three-year certification cycle

ISO 9001 certification is valid for three years from the date the certificate is issued. Inside that three-year window, two surveillance audits keep the certificate alive.

Missing a surveillance audit, or receiving a major nonconformance without completing a corrective action, suspends the certificate. Suspension that is not resolved leads to withdrawal. The certification body sets specific timelines, but the consequence of doing nothing is losing the certification entirely.

What surveillance auditors look for that certification auditors don't

The certification auditor asked whether your QMS was built correctly. The surveillance auditor asks whether it has been operated continuously since then.

The practical difference is the direction of evidence. At Stage 2, the auditor was looking for evidence that processes existed. At surveillance, they are sampling evidence that those processes have been used, across the twelve months since the last visit. A procedure written for the certification audit and not touched since will be visible immediately — not because it says the wrong things, but because there are no records showing it was ever followed.

Surveillance auditors pay particular attention to four areas that the certification audit largely took on trust:

  1. Internal audit completion. The standard (Clause 9.2) requires an internal audit programme covering all applicable clauses over the certification cycle. An audit that happened once, at the certification stage, and has not been repeated is a finding. The auditor wants to see a schedule, conducted audits with documented findings, and evidence that any issues raised were actioned.
  2. Management review records. Under Clause 9.3, senior leadership must conduct a formal review of QMS performance at planned intervals. “We discuss quality in our monthly leadership meeting” is not a management review. The standard requires specific inputs to be considered (customer feedback, audit results, process performance, risks and opportunities) and the outputs to be documented. If the minutes do not reflect those inputs, it is a gap.
  3. Nonconformance closure. Any finding raised during the previous audit — certification or surveillance — must have been addressed through a documented corrective action: root cause identified, action taken, effectiveness verified, and the record closed. An open corrective action from twelve months ago is not just a process issue. It signals to the auditor that the improvement loop the QMS relies on is not functioning.
  4. Competency records for new or changed roles. People join. Roles change. When they do, the competency matrix under Clause 7.2 must be updated to reflect the new hire's training and verification of competence. An auditor who speaks to an employee who joined eight months ago and finds no training record for them has a nonconformance in front of them, regardless of how thorough the records were at certification.

The four most common surveillance audit failures

None of these findings are exotic. They surface across industries, across certification bodies, across businesses that genuinely tried to maintain their systems. What they share is that they are nearly impossible to fix on twelve hours' notice.

  1. Documented information not reviewed or updated. The certification produced a library of procedures. Eighteen months later, those procedures describe a process the business no longer operates quite that way. A version-controlled document with a review date that has passed, and no record of the review being conducted, is expired information. Auditors check review dates. Documents that should have been revisited and weren't are the single most common surveillance finding.
  2. Competency records missing for post-certification hires. The skills matrix that impressed the Stage 2 auditor mapped everyone who was employed at the time. The two people hired since have no records attached to them: no induction evidence, no training sign-off, no verification that they meet the competency requirements for their role. The auditor speaks to one of them. The gap is immediate.
  3. No internal audit conducted in the past year. This one cannot be remediated retrospectively. The internal audit either happened, with a documented schedule and findings, or it did not. Businesses that run the internal audit as a pre-certification exercise and then stop treating it as an ongoing requirement arrive at the surveillance visit with a twelve-month evidence gap that nothing can close. The corrective action, if this surfaces, typically includes a commitment to a scheduled programme, but the finding is unavoidable.
  4. Nonconformances from the last audit with no closed corrective action. The last auditor raised findings. They were acknowledged. They were probably fixed in practice. But the corrective action record was never completed: no root cause documented, no effectiveness verification recorded, no formal closure. A corrective action that exists only as a note from the closing meeting is an open loop. Surveillance auditors follow up on every finding from the previous visit, and an open loop is a new finding.

What year-round tracking looks like in practice

The businesses that walk into a surveillance audit without scrambling are not the ones with the most diligent quality managers. They are the ones with a system that surfaces issues before they become findings.

Four disciplines, maintained continuously, cover the main exposure areas.

Document expiry tracking. Every controlled document should carry a review date, and the system should flag approaching expiry 30 to 60 days out — not the morning the auditor calls to confirm arrival time. A procedure reviewed two months before the audit, with sign-off on file, is clean evidence. The same procedure updated in a panic the day before is a different kind of signal entirely.

Competency records on hire or role change. The competency matrix is a living register, not a snapshot from certification day. Someone joins: their record gets created. Someone changes role: their requirements update. The mechanism does not need to be sophisticated — a register that captures who trained them, when, and who signed off is enough. What fails is any system that depends on someone remembering to do it.

Nonconformance closure. Every nonconformance — from an audit, a complaint, an internal quality issue — should be tracked from the moment it is raised to the moment it is formally closed: root cause documented, action taken, effectiveness confirmed. An open log where half the entries have no closure date is not a corrective action system. It is an unresolved list, and the auditor will read it as one.

Internal audit scheduling and management review. These are the two activities the auditor will always check and that cannot be reconstructed after the fact. An internal audit schedule set at the start of the year, with completed audits and filed findings, is audit-ready by definition. A management review conducted at a regular cadence, with documented outputs however brief, is one less conversation to have in the closing meeting.

Kaiso tracks all four continuously — document aging, competency records, nonconformance status, audit scheduling — surfacing issues weeks before they become findings rather than the week before the auditor arrives.

What to do in the 90 days before your surveillance audit

Ninety days is enough time to close most gaps without panic. Twelve hours is not enough time to close any of them properly.

  1. Pull the findings from the last audit. Every nonconformance and opportunity for improvement from the previous visit should be on a list in front of you. For each one: has a corrective action been raised? Is it closed, with root cause and effectiveness evidence documented? If not, this is your first priority. The auditor will check these items before they check anything else.
  2. Check document review dates across the full library. Every controlled document has a scheduled review date. Work through them systematically. Any document due for review before the audit date gets reviewed now, with evidence of the review — sign-off, version update, distribution record — filed. Do not update documents for the sake of it; only update what has genuinely changed.
  3. Reconcile the competency matrix against your current headcount. Compare the matrix against your actual employee list. Anyone who joined or changed roles since the last audit should have a record in the matrix. If records are missing, build them now: document what training occurred, when, and who verified competence. Retrospective records are acceptable; missing records are not.
  4. Confirm internal audit completion and management review occurrence. At least one internal audit covering applicable clauses must have occurred since the last audit visit, with findings documented and any corrective actions raised. At least one management review must have occurred, with outputs recorded against the required inputs. If either has not happened, schedule it now. An internal audit conducted six weeks before the surveillance visit is legitimate evidence. An internal audit conducted the week before is better than nothing, but the auditor will note the timing.
  5. Walk the audit trail yourself. Pick a recent customer order and trace it through your system the way the auditor will: contract review, production records, delivery, complaint or feedback records if any. At each step, confirm the evidence exists, is current, and reflects what actually happened. The gaps in that walkthrough are the gaps the auditor will find. Better to find them yourself.

Surveillance prep is a review, not a rescue

The businesses that struggle before surveillance audits are not, in most cases, genuinely non-compliant. Their QMS works. Their processes are followed. What they never built was the habit of capturing evidence continuously — so when the audit approaches, prep means reconstructing twelve months of operation from memory and email threads, under time pressure, with the certificate on the line.

It does not have to work that way. When document expiry is tracked automatically, when competency records are updated as people join, when nonconformances are closed in the system rather than in someone's inbox, the surveillance audit is a confirmation, not a test. The evidence already exists. The review is just checking that it does.

If you want to understand the structural reasons why certified companies end up scrambling, the implementation gap post covers the root cause in detail. For what the auditor is doing on day one of a certification visit — before any of this maintenance work matters — the Stage 2 audit post walks through how auditors sample evidence and what they are building toward.

Kaiso tracks document expiry, competency records, and open nonconformances automatically, year-round. If you want to see what continuous audit-readiness looks like in practice, the features page covers the specifics.

Frequently asked questions

How often do surveillance audits happen after ISO 9001 certification?

Surveillance audits are typically conducted once per year, at approximately twelve-month intervals following the certification audit. Most certification bodies schedule the first surveillance visit within twelve months of the Stage 2 audit, with a second visit twelve months after that. The three-year cycle concludes with a full recertification audit, which resets the clock.

Can a business lose its ISO 9001 certification at a surveillance audit?

Yes. A major nonconformance at a surveillance visit results in certificate suspension. The business has a defined period — set by the certification body, typically 30 to 90 days — to submit a corrective action plan and evidence of resolution. If that is not completed, the certificate is withdrawn. Minor nonconformances do not trigger suspension; they require a documented corrective action within the agreed timeframe, after which the certificate remains valid.

What is the difference between a surveillance audit and a recertification audit?

A surveillance audit is a partial assessment, covering a subset of the applicable clauses, conducted annually to confirm the QMS is being maintained. A recertification audit is a full reassessment, equivalent in scope to the original Stage 2, conducted at the end of the three-year certification cycle. Recertification resets the three-year clock; a successful surveillance audit simply keeps it running.

Do surveillance auditors re-check everything from the certification audit?

Not everything, but they do follow up on every finding from the previous visit. If a nonconformance was raised at the certification audit or the previous surveillance visit, the auditor will check that a documented corrective action was completed: root cause identified, action taken, and effectiveness confirmed. Beyond those follow-ups, the auditor samples a subset of clauses — often half to two-thirds — with the remaining clauses covered in the following year's visit.

What happens if an internal audit has not been conducted before a surveillance visit?

It will be raised as a nonconformance. Clause 9.2 requires internal audits to be conducted at planned intervals, covering all applicable clauses across the certification cycle. An internal audit that has not occurred since the last formal audit visit is a systemic gap, not a minor omission. The corrective action will typically require a completed internal audit cycle and evidence of a maintained audit schedule going forward. This is one of the few findings that cannot be closed retrospectively — the audit either happened or it did not.

That's everything.
Kobi's ready when you are.