A surveillance audit is a shorter, sampling-based check, usually one day and sometimes two depending on your size and scope, that your certification body runs each year between your three-yearly recertification audits to confirm your management system is still doing what it did the day you were certified. It is not a repeat of your initial certification audit: the auditor does not re-examine the whole system, they sample a rotating slice of it, follow up on any previous findings, and check that nothing material has changed without the certifier knowing. It can still raise nonconformities, and an unresolved one can put your certificate at risk, so shorter does not mean low-stakes.
How is a surveillance audit different from your initial certification audit?
Your initial certification audit (Stage 1 and Stage 2) examines the whole system against every clause of the standard, because the certifier is deciding whether to issue the certificate at all. A surveillance audit starts from a different question: has anything changed, and does the system still work the way it did when we certified it? That narrower question is why it is shorter, why it samples rather than covers everything, and why the auditor spends real time on your previous findings and any changes to scope, sites, people or processes since the last visit.
The recertification audit, which happens every three years, resets the clock: it is closer in depth to the initial audit, because it is renewing the certificate for another three-year cycle rather than checking in on an existing one.
| Audit type | When it happens | Typical duration | What's examined | Purpose |
|---|---|---|---|---|
| Stage 1 (desktop review) | Once, before first certification | Usually 0.5-1 day | Documentation, readiness for Stage 2 | Confirm the system is ready to be audited on site |
| Stage 2 (initial certification) | Once, shortly after Stage 1 | 1-3 days depending on size and sites | Full system, all applicable clauses | Decide whether to certify |
| Surveillance audit | Annually, in years 1 and 2 of the 3-year cycle | Typically 1 day, sometimes 2 | Sampled clauses, previous findings, changes since last visit | Confirm the system is still conforming |
| Recertification audit | Every 3 years | Similar depth to initial certification | Full system re-sampled against current standard | Renew the certificate for the next cycle |
How long does a surveillance audit actually take?
For most contractors in Hillview's client range, one day on site is typical for a single standard at a single location. Multi-site operations, integrated systems (quality, safety and environmental audited together) or businesses with a history of findings tend to run closer to two days, because the auditor has more ground to sample or more prior nonconformities to verify closed. Audit duration is set largely by headcount, site count and the number of standards in scope, calculated by the certification body against accreditation rules - it is not negotiable down to save time, though it can be negotiated up if your scope has grown.
What does the auditor actually sample on the day?
Four things, roughly in this order:
- Follow-up on previous findings. Every nonconformity from your last audit gets checked first, and not just for a signed close-out form - the auditor wants to see the cause was actually fixed, not just the paperwork tidied.
- A rotating sample of clauses. Certifiers plan a multi-year sampling schedule so the whole standard gets covered across the three-year cycle without repeating everything every year. Which clauses come up this year is usually set by the certifier's plan, not random on the day.
- Records and documents. Recent internal audit results, management review minutes, training records, incident and NCR registers - whatever evidence the sampled clauses require.
- Interviews and site observation. Conversations with the people actually doing the work, not just the person who manages the system, plus a look at how the site or job in progress compares with what the documents describe.
What trips people up on surveillance audit day?
The same handful of things, repeatedly:
- Previous findings closed on paper but not in reality. The corrective action form is signed, but the same root cause is still active in how the work is actually done. Auditors check this first for a reason.
- Internal audits or management review that lapsed. If the system requires quarterly internal audits and none happened since the last visit, that gap is its own finding before the auditor even looks at anything else.
- Undisclosed scope changes. A new site, a new service line, a significant change in headcount or subcontracting model - certifiers generally need to be told, and an auditor discovering it on the day rather than being told in advance is its own credibility problem.
- The key contact being unavailable. If the person who holds the system in their head is on leave or has left, and nobody else can speak to it, that is itself evidence of the single-point-of-failure risk auditors are trained to notice.
- Records that exist but do not match what people actually say. A register that looks complete but does not survive five minutes of genuine interview questioning is worse than an obviously incomplete one, because it reads as an attempt to present rather than an honest gap.
None of these are exotic. They are the ordinary consequences of treating the system as an annual event instead of something that runs continuously between visits.
How should you prepare for a surveillance audit?
Preparation for a surveillance audit should look nothing like the scramble before an initial certification audit, because the goal is not to build evidence in a hurry, it is to confirm evidence that should already exist:
- Check previous nonconformities are actually closed, not just marked closed - re-walk the fix, not just the paperwork.
- Confirm your internal audit and management review actually happened since the last visit, with real records, not calendar placeholders.
- Tell your certification body about material changes as they happen through the year, not on the morning of the audit.
- Brief the people likely to be interviewed on how the system works, not on what to say - the goal is genuine familiarity, not a script.
A business running this rhythm experiences surveillance audits as a routine check-in. A business that only opens the system once a year experiences every audit, surveillance or otherwise, as a fire drill.
If you are not confident your own evidence would hold up to that kind of questioning today, the Audit Readiness Check is free and gives a fast, honest read on where you stand before your next visit, not during it.
FAQ
Does a surveillance audit cover every clause of the standard? No. A surveillance audit samples a rotating slice of the standard each year, plus mandatory elements like internal audit results, corrective actions, management review and any changes to the business, so that the full system gets covered across the three-year cycle without repeating the entire audit annually.
Can you fail a surveillance audit? You cannot "fail" in the sense of losing certification on the spot, but a surveillance audit can raise major or minor nonconformities, and an unresolved major nonconformity can suspend or withdraw your certificate if it is not closed out within the certification body's required timeframe.
How much notice do you get before a surveillance audit? Certification bodies typically confirm the date some weeks ahead as part of the standing audit program, though the exact notice period varies by certifier and contract. Unannounced surveillance visits exist in some sectors and schemes but are the exception, not the default.
What happens if a nonconformity is raised at a surveillance audit? You get a defined window, commonly 30 to 90 days depending on severity and the certification body's rules, to investigate the cause and close it out with evidence, not just a promise. Genuinely closing it, not just marking it closed, is what the following year's auditor checks first.
Do surveillance audits get easier over time? They get more predictable, not automatically easier. A business that closes findings properly, keeps its internal audit and management review genuinely current, and tells its certifier about material changes as they happen tends to have calmer, shorter surveillance visits than one that treats each audit as a fresh scramble.
Jemma Kennedy - Lead Auditor, 15+ years in civil, mining and infrastructure.
Founder, Hillview Business Services. 15+ years inside civil construction, mining and infrastructure businesses.