Anacruses Associates Ltd
← Back to ISO InsightsGetting Started

Preparing for an ISO Surveillance Audit: A Practical Checklist

2026-09-15

Surveillance audits catch most businesses flat-footed. You get certification, relax, then six to twelve months later the auditor walks back in. This checklist helps you walk in prepared instead of scrambling. Most findings I see at surveillance are preventable — it's about staying focused on what actually matters.

Surveillance audits are not a formality

A lot of people treat surveillance like a tick-box exercise. It isn't. Your auditor has a narrower scope than your initial assessment, but they're looking harder. They want to see that your system is embedded. That it's working, not just documented. In my experience, this is where the gap emerges — businesses tick boxes during certification, then stop doing the work.

The auditor will typically cover a cross-section of your processes. They're checking whether controls you described are actually running. Whether people know what they're supposed to do. Whether you've acted on your own findings. They'll pull records, interview staff at random, and look for evidence of management review and internal audits actually happening.

What auditors focus on at year two and three

In your first surveillance (usually year two), auditors test the system under real operating conditions. They want to see that you didn't just pass an audit and shelve everything. They'll check your management review minutes. Did you actually discuss performance? Did you identify opportunities? Or did you just read slides aloud?

Internal audits matter hugely at surveillance. I've seen businesses schedule them the week before the auditor arrives. That's obvious and gets flagged. You need a pattern of planned, spaced-out internal audits across the year. The auditor will ask staff if they've been audited. If they haven't, that's a finding.

By year three, the auditor is looking at trends. Are the same nonconformities coming back? Are you actually addressing root causes or just papering over cracks? They'll ask about corrective actions from previous audits. If you can't show what you did or the evidence it worked, that's a problem. They also check whether your system has kept pace with changes in your business. New products? New processes? New regulations? The system should reflect reality.

Common findings I see at surveillance

The biggest finding is absence of internal audit evidence. Businesses don't do them consistently, or they do token audits that don't find anything. An auditor will ask a warehouse supervisor, "When were you last audited?" If the answer is "I don't know" or "Never," that's a nonconformity.

Management review is the second big one. Your review minutes should show discussion of data, not just sign-off. I mean actual metrics — complaints, incidents, performance trends, resource needs. Generic minutes that could apply to any business tell the auditor you're not taking this seriously.

Documentation that's out of date is another common issue. You updated your process last year, but the procedure still references the old version. I've seen competence records that haven't been updated, training logs that stop mid-year, and nobody assigned responsibility for keeping records current. Auditors spot this quickly because they ask staff what the current procedure is, then compare it to what's filed.

Non-conformity evidence is weak. You had a finding last year. Your corrective action was vague — "retrain staff" or "tighten controls" — with no real evidence of what changed or whether it worked. An auditor will come back to that point and ask to see the impact.

The practical preparation checklist

Three months before your audit, pull your management review minutes for the past year. Is there substance there, or are they templates? Fix this before the auditor sees it — rewrite them to show real discussion and decisions.

Check your internal audit schedule and records. Make sure audits have happened, are spaced across the year, and cover all the parts of your system. If you've missed months, do one now. It's better to find gaps yourself than have the auditor find them.

Pull all non-conformities and corrective actions from your previous audit or from your own findings. Can you show what you actually changed? Get evidence — updated procedures, training records, photos, output changes, whatever proves the fix happened.

Review your records — training logs, competence assessments, calibration certificates, incident reports, whatever your system requires. If it's overdue or incomplete, sort it. Assign someone the job of keeping it current and make that visible in your system.

Walk through your operation and check that what you've documented is what you're actually doing. If your procedure says you check supplies weekly but you check monthly, update the procedure. Don't let the auditor catch you out there.

What happens next

Book a preparation call with me or another experienced auditor before your surveillance. I can walk through the specifics of your system and flag the areas auditors usually probe. It's a small investment that usually uncovers gaps you can fix before the audit date.

When the auditor arrives, you should feel like you're showing them how your business really works — not performing for them. If you've done the work consistently, the audit is straightforward. If you haven't, no checklist fixes it in the week before.

Ready to talk about your business?

Book a free, no-obligation call. We will tell you exactly what certification would involve for your size, sector, and starting point.