What is a surveillance audit?
A surveillance audit is the registrar's shorter annual check in years one and two of the three-year certification cycle, sized at roughly a third of the initial audit time.
If yours is close and the internal audits are not done, start with Our surveillance audit is next month and we haven't done our internal audits. What do we do?
What it is
Certification runs on a three-year cycle. Year zero is the initial audit in two stages. Years one and two bring a surveillance audit each. Year three is recertification, and then the cycle repeats.
A surveillance audit is shorter than the initial audit, sized at roughly a third of the initial audit time under the IAF day tables. It is not a lighter audit in kind, only in coverage: the auditor samples part of the system rather than all of it, and certain items are mandatory in every visit.
Those mandatory items are the ones companies most often fail. Internal audits, management review, corrective actions from the last visit, complaints, and use of the certification mark get looked at every single time.
When you will hear it
On your audit calendar, usually about twelve months after the last visit, with some flexibility either side that the registrar controls rather than you.
In a quote as a recurring annual line, separate from the initial audit and from recertification.
In a panic, roughly four weeks out, when someone realizes the internal audit schedule stalled in March.
What the auditor expects to see
A year of the system running.
Specifically: internal audits completed against the plan, with findings raised and closed; a management review held with the required inputs and real decisions recorded; corrective actions from last year's findings verified as effective rather than just closed; and the processes selected for sampling this cycle operating with their records intact.
The word effective carries weight. Closing a corrective action by retraining the operator, and then producing the same nonconformity a year later, is evidence the action was not effective, and auditors escalate on repeat findings.
Common mistakes
Doing a year of internal audits in the four weeks before the visit. The dates give it away, and an audit program compressed into a month is itself a finding against clause 9.2.
Holding a management review that reviews nothing. Minutes that record attendance and the word "satisfactory" do not satisfy clause 9.3. The standard lists the inputs and the auditor has the list.
Assuming the same clauses will be sampled. Registrars rotate coverage across the cycle precisely so the whole scope is seen by recertification.
Ignoring the mark. Misusing the certification mark on marketing material, product, or test reports is an easy finding and an avoidable one.
FAQ
How much does a surveillance audit cost?
At a single site of about 100 people, derived figures put the registrar's fee near $3,100 to $3,700 a year plus travel. Yours will vary by body and by headcount.
Can a surveillance audit suspend our certificate?
Yes, indirectly. A major nonconformity that does not close within the registrar's window, typically 60 to 90 days, leads to suspension and then withdrawal.
Can we delay it?
Within limits set by the body, and asking is better than missing it. Certification requires the cycle to be maintained, and a missed surveillance audit puts the certificate at risk.
Is recertification different?
Yes. Recertification in year three is longer, roughly two thirds of the initial audit time, and covers the whole system rather than a sample.
Tell us which audit is on your calendar.
A gap assessment is a flat-fee, on-site project led by a certified ISO 9001 lead auditor. Three founding-client spots are open for the quality practice.
We prepare you for certification. We never issue it. Your registrar's independence is the point.