Our surveillance audit is next month and we haven't done our internal audits. What do we do?
Run a real audit cycle now across your highest-risk processes, raise genuine findings, and start corrective actions. A short honest program beats a backdated full one.
What to do now
You have four weeks. Here is the order that salvages the most.
Do not backdate anything. The dates on audit reports, findings, and corrective actions form a pattern an experienced auditor reads in minutes. A compressed but honest program produces one finding about audit frequency. A fabricated one produces a much worse conversation, and it puts your certificate at genuine risk rather than notional risk.
Audit the processes most likely to be sampled, not all of them. Look at last year's findings, your customer complaints, and your nonconformance records. Those three sources tell you where the problems are. A focused internal audit of four or five processes, done properly, is worth more than a clause-by-clause sweep done superficially.
Raise real findings and start the corrective actions. An internal audit that finds nothing tells the auditor your program is cosmetic. Findings that are open but under active work are normal and defensible. Findings closed the day before the audit, all at once, are not.
Hold the management review, properly. It is a mandatory item at every surveillance audit, the inputs are listed in clause 9.3, and your general manager needs to be in the room. If it has also been skipped, this is a two-hour meeting that prevents a second finding.
Write down what happened and what changes. A short memo acknowledging the program fell behind, with a revised schedule and an owner, is a legitimate corrective action and auditors respond to it far better than to a story.
What it costs
Outsourced internal audits benchmark at roughly $2,000 to $6,000 per audit, with one national provider advertising from $1,440 for an audit sized by the IAF day brackets. For a single site, an annual program works out to roughly $2,500 to $8,000 a year by derivation from those figures.
Against that, consider the cost of the alternative. A nonconformity against clause 9.2 is among the most-cited findings in the standard, and the usual wording is that audits were not performed as scheduled or not conducted at all. A minor costs you a corrective action and management attention. If your program has been absent long enough that the auditor writes it as a systemic failure, you are looking at a major, a closure window of 60 to 90 days, and a follow-up audit billed by your registrar.
The recurring cost of doing it right is the smallest number in this paragraph.
What good looks like
A program that runs across the year rather than in a burst, staffed by people who did not design the processes they audit, finding real things.
Concretely: a schedule that considers the importance of each process and last year's results, completed reports with evidence cited, findings graded and tracked, corrective actions with root cause and an effectiveness check, and a management review that reads the audit results as an input rather than as a formality.
The test an auditor applies is whether your internal findings and your registrar's findings overlap. If your program never finds what the registrar finds, the program is not working, whatever the schedule says.
When to bring in outside help
Two situations, and both are common.
You cannot staff impartial auditors. Clause 9.2 requires objectivity and impartiality, and in a plant of 60 people the number of candidates who did not design the process in question is small. This is the most frequent legitimate reason to outsource, and consultants are permitted to run your internal audits. The prohibition binds your certification body, not a consultancy.
The program has lapsed and the audit is close. Somebody who has run audits before can cover more ground in two days than an untrained internal team covers in two weeks, and knows which processes the registrar is likely to sample this cycle.
If you have trained auditors with available hours, do it yourself. The knowledge stays in the building.
How ARG does it
An independent internal audit, run the way a registrar runs it: on site, evidence first, interviewing the people who do the work. You get findings with clause references, graded, with a remediation plan in the order that matters for your audit date.
For companies that are already certified, this is usually the first engagement and often the only one needed. It is the same activity as a gap assessment, pointed at a different purpose: satisfying clause 9.2 on the record, and finding what your registrar would find while there is still time to close it.
Noah Brown runs those audits. He is a certified ISO 9001 lead auditor who hosts registrar and customer audits from the auditee side inside a working manufacturer, which is the seat you will be sitting in next month.
FAQ
Will we lose our certificate over this?
Almost certainly not for a first lapse. Expect a finding, probably a minor, and a corrective action. Certificates are lost when majors go unclosed inside the registrar's window, not when a program slipped for a year and was honestly repaired.
Can we do all our internal audits in one week?
You can, and the standard requires planned intervals, so a single compressed week is itself a departure from the requirement. It is still far better than not doing them. Document the compression and the corrected schedule.
Can the registrar do our internal audits for us?
No. ISO/IEC 17021-1 clause 5.2.6 bars a certification body from performing internal audits for a client it certifies, with two-year cooling rules attached.
Should we tell the auditor the program lapsed?
Yes. They will find it, and volunteering it with a corrective action already underway is a materially better position than being found out.
How many findings is normal at a surveillance audit?
Around four to six minors across a typical audit, concentrated in clause 8 and clause 9 areas: calibration, competence records, incomplete management review. Zero is unusual.
Sources
- ISO 9001:2015 clauses 9.2 and 9.3; ISO/IEC 17021-1:2015 clause 5.2.6.
- ARG market research 2026, section 4.5 for clause 9.2 as a top-cited finding and the four-to-six minor average, section 7.1 for internal audit benchmarks, section 4.2 for closure windows.
Tell us which audit is on your calendar.
A gap assessment is a flat-fee, on-site project led by a certified ISO 9001 lead auditor. Three founding-client spots are open for the quality practice.
We prepare you for certification. We never issue it. Your registrar's independence is the point.