Guide · Getting certified

How to prepare for an ISO surveillance audit — without the panic

A surveillance audit is one of two things, and you decide which. If the management system has genuinely been running, it's a checkpoint — the auditor confirms what's already true. If it hasn't, it's a fortnight of heroics: chasing signatures, rebuilding the trail, hoping the management review minutes exist. Here's how to make it the first kind, honestly — including what really looks after itself and what still needs people.

What a surveillance audit actually is

Once you've achieved initial certification, the certification body comes back — usually annually — to confirm your system is still operating and improving. It isn't a full re-examination of everything; it's a check that the system has stayed live since the last visit. (A fuller recertification audit comes round roughly every three years.) So the whole game is being able to show continuous activity, not a burst of preparation.

Why people panic

The panic comes from treating certification as a certificate to renew rather than a system to run. If the system goes quiet between audits, the evidence has to be assembled the fortnight before — and experienced auditors can tell the difference between records created as work happened and records created last Tuesday. The fix isn't working harder in that fortnight; it's not letting the system go quiet in the first place.

What good preparation looks like — all year, not the fortnight

The honest bit — what collects itself, and what doesn't. Some evidence genuinely can look after itself: for ISO 27001, technical signals from your Microsoft 365 tenant — MFA coverage, admin roles, device compliance — can be read continuously instead of screenshotted before a visit. But the internal audits, the management review, incident investigations and corrective actions still need people to do them. Good software keeps those on cycle and keeps the evidence together; it doesn't run the audit or make the decisions for you. Anyone promising that "the evidence collects itself" as a blanket is overselling.

The week before — a short, calm checklist

  1. Confirm the scope and standard being audited, and the agenda with your auditor.
  2. Check last audit's findings are closed — this is the first place many auditors look.
  3. Confirm the audit programme and management review are on record for the period.
  4. Pull the evidence pack — dated records for the controls and processes in scope.
  5. Brief the people the auditor will talk to, so they can speak to what they actually do.

The goal: an export, not a project

When the system has genuinely been live, preparing for surveillance stops being a project. The pack is largely an export of dated evidence and reviews already on record, and the audit becomes a conversation about a system that's plainly working — which is also, not coincidentally, the point of having a management system at all. It's the same discipline that keeps the cost of an incident down and makes running several standards as one system manageable.

Where Kavorly fits

Kavorly is built to keep the system live between audits, so readiness is continuous rather than assembled: evidence kept current as people work, the internal audit programme and management review on cycle, corrective actions tracked to closure, and approved documents watched for drift. For ISO 27001 it reads the technical posture of your own Microsoft 365 tenant daily, so those signals are already there when the assessor asks — while the audits, reviews and investigations stay where they belong, with your people. The result is that a surveillance visit is a checkpoint, not a fire drill.

How ISO 27001 evidence works → · Turning Microsoft 365 into evidence →


This guide is a general introduction to surveillance-audit preparation, not certification advice. For the authoritative requirements, refer to the relevant ISO standard or your certification body.

Questions

If the visit is in the diary.

We still have an open finding from last year. How bad is that?

It's one of the things they look for first. An open action from the last visit says the system isn't closing the loop. Close it before they arrive, with evidence of what you did, and be ready to explain why it took that long. Don't hide it.

We haven't done a management review since we certified. What now?

Book one. A surveillance visit expects to see the system running: internal audits on cycle, a management review with inputs and outputs, actions tracked. A missing review is a gap you can still fill if there's time; leaving it until they ask is how a checkpoint becomes a finding.

Can software replace the internal audit?

No. Software can keep the programme on the calendar, hold the reports and track actions. Someone still has to audit. Same for management review and investigations — people do the work; the system stops it slipping.

What's the difference between this visit and recertification?

Surveillance is the annual check that the system stayed live. Recertification is the fuller audit roughly every three years to renew the certificate. Don't treat surveillance as a mini-certification project; if you do, the three-year one will be worse.

Next step

Surveillance visit on the calendar?

See where you stand against the standard in three minutes — free, no sign-up — or book a walkthrough of running the system so audits stay checkpoints.