Guide · Getting certified
How to prepare for an ISO surveillance audit — without the panic
A surveillance audit is one of two things, and you decide which. If the management system has genuinely been running, it's a checkpoint — the auditor confirms what's already true. If it hasn't, it's a fortnight of heroics: chasing signatures, rebuilding the trail, hoping the management review minutes exist. Here's how to make it the first kind, honestly — including what really looks after itself and what still needs people.
What a surveillance audit actually is
Once you've achieved initial certification, the certification body comes back — usually annually — to confirm your system is still operating and improving. It isn't a full re-examination of everything; it's a check that the system has stayed live since the last visit. (A fuller recertification audit comes round roughly every three years.) So the whole game is being able to show continuous activity, not a burst of preparation.
Why people panic
The panic comes from treating certification as a certificate to renew rather than a system to run. If the system goes quiet between audits, the evidence has to be assembled the fortnight before — and experienced auditors can tell the difference between records created as work happened and records created last Tuesday. The fix isn't working harder in that fortnight; it's not letting the system go quiet in the first place.
What good preparation looks like — all year, not the fortnight
- Keep evidence current as you go. Records created when the work happens, not reconstructed. This is the single biggest difference between a checkpoint and a scramble.
- Run the programme on cycle. Internal audits carried out, management review held, objectives tracked. These are the things auditors most reliably check — and the things most often found missing.
- Close your actions. Corrective actions from last time actually closed, with evidence. Open actions carried over from the previous audit are one of the classic findings.
- Watch document drift. The approved version is the one in use, with obsolete copies out of circulation.
The honest bit — what collects itself, and what doesn't. Some evidence genuinely can look after itself: for ISO 27001, technical signals from your Microsoft 365 tenant — MFA coverage, admin roles, device compliance — can be read continuously instead of screenshotted before a visit. But the internal audits, the management review, incident investigations and corrective actions still need people to do them. Good software keeps those on cycle and keeps the evidence together; it doesn't run the audit or make the decisions for you. Anyone promising that "the evidence collects itself" as a blanket is overselling.
The week before — a short, calm checklist
- Confirm the scope and standard being audited, and the agenda with your auditor.
- Check last audit's findings are closed — this is the first place many auditors look.
- Confirm the audit programme and management review are on record for the period.
- Pull the evidence pack — dated records for the controls and processes in scope.
- Brief the people the auditor will talk to, so they can speak to what they actually do.
The goal: an export, not a project
When the system has genuinely been live, preparing for surveillance stops being a project. The pack is largely an export of dated evidence and reviews already on record, and the audit becomes a conversation about a system that's plainly working — which is also, not coincidentally, the point of having a management system at all. It's the same discipline that keeps the cost of an incident down and makes running several standards as one system manageable.
Where Kavorly fits
Kavorly is built to keep the system live between audits, so readiness is continuous rather than assembled: evidence kept current as people work, the internal audit programme and management review on cycle, corrective actions tracked to closure, and approved documents watched for drift. For ISO 27001 it reads the technical posture of your own Microsoft 365 tenant daily, so those signals are already there when the assessor asks — while the audits, reviews and investigations stay where they belong, with your people. The result is that a surveillance visit is a checkpoint, not a fire drill.
How ISO 27001 evidence works → · Turning Microsoft 365 into evidence →
This guide is a general introduction to surveillance-audit preparation, not certification advice. For the authoritative requirements, refer to the relevant ISO standard or your certification body.