Certification
Nine reasons ISO 27001 surveillance audits go wrong, and how to avoid them
Most ISO 27001 surveillance audit findings have nothing to do with new threats. They come from an ISMS that was parked after certification. The nine findings auditors raise most often, what each one means, and how to keep the system running between audits.
Most organisations put real effort into their first ISO 27001 certification. Then the certificate arrives, the project team disbands, and the information security management system (ISMS) goes quiet until a month before the next audit. Surveillance audits exist to find exactly that.
The findings auditors raise at surveillance audits are rarely about sophisticated threats. They are about a management system that stopped being managed. Here are the nine that come up most often, what the auditor is looking for, and how to avoid each one.
1. The internal audit didn't happen, or only covered part of the ISMS
Clause 9.2 requires a planned programme of internal audits. A common finding is an audit programme that exists on paper but was not carried out, or that has covered only a handful of clauses and controls since certification. Auditors expect the programme to cover the whole ISMS over the certification cycle, with reports and follow-up for each audit done.
Avoid it: split the internal audit programme into quarterly pieces so no single audit is a burden, and use someone independent of the work being audited.
2. There was no management review, or no record of one
Clause 9.3 requires top management to review the ISMS at planned intervals, against a defined list of inputs. Auditors raise findings when the review was not held, when the minutes do not cover the required inputs, or when it produced no decisions or actions.
Avoid it: put the management review in the board or leadership calendar a year ahead, and use an agenda built from the clause 9.3 inputs so nothing is missed.
3. The risk assessment hasn't changed since certification
Clauses 6.1.2 and 8.2 require risk assessments at planned intervals and when significant changes happen. If the risk register is identical to the one presented at certification, while the business has moved to a new cloud platform, hired 50 people or taken on a major client, the auditor will ask why.
Avoid it: reassess risk on a fixed schedule, and add a trigger to your change process so major changes prompt a review.
4. The Statement of Applicability doesn't match reality
The Statement of Applicability (SoA) records which Annex A controls apply, why, and whether they are implemented. Findings arise when the SoA says a control is in place and the auditor finds it is not, or when the SoA has not been updated after new systems or suppliers were introduced.
Avoid it: review the SoA alongside every risk assessment, and treat any change to it as a controlled document update.
5. Last year's corrective actions are still open
Clause 10.2 requires nonconformities to be corrected and their causes addressed. The first thing many auditors check is whether findings from the previous audit were closed, with evidence. A minor nonconformity left open from last year is one of the quickest routes to a major one.
Avoid it: track every finding to closure with an owner and a date, and record the root cause, not just the fix.
6. Policies exist, but there's no evidence they operate
A written access control policy is not evidence that access is controlled. Auditors sample records: completed user access reviews, leavers removed on time, awareness training completed, supplier security reviews carried out, backups tested. The usual finding is a well-written policy with no records behind it.
Avoid it: for each control, decide what record proves it operates and how often it should be produced, then collect it as you go rather than at audit time.
7. The organisation changed but the scope didn't
New offices, acquisitions, new products and major platform migrations can all affect the scope of the ISMS. If the business has changed and the scope statement, asset inventory and risk assessment have not, the auditor will question whether the certificate still describes the organisation. Significant changes may also need telling to your certification body.
Avoid it: review the scope whenever the business changes shape, and talk to your certification body before, not after, a major change.
8. Security objectives aren't measured
Clause 6.2 requires information security objectives, and clause 9.1 requires you to monitor and measure the ISMS. A common finding is objectives that are written but never measured, or metrics collected but never reviewed. Auditors want to see that measurement leads to decisions.
Avoid it: keep a small set of objectives with numbers you already produce, such as patching times or training completion, and report them to the management review.
9. The one person who ran the ISMS has left
When the ISMS lives in one person's head and inbox, a resignation can leave nobody who knows where the evidence is, what is due, or why decisions were made. Auditors pick this up quickly, because nobody can answer their questions with confidence.
Avoid it: document roles and responsibilities, keep evidence in a shared system rather than personal folders, and make sure at least two people understand how the ISMS runs.
What a finding means for your certificate
Auditors raise nonconformities rather than giving a pass or fail. A minor nonconformity needs a corrective action plan, usually checked at the next audit. A major nonconformity must be corrected and evidenced within a period the certification body sets. If it is not, the certificate can be suspended or withdrawn, which many client contracts and tender requirements treat as losing it.
Auditors also record opportunities for improvement. These are not findings, but they are worth acting on, because the same issue can come back as a nonconformity next time.
The common thread
Almost every finding above comes from treating ISO 27001 as an annual project rather than a system that runs all year. The fix is the same in each case: a calendar of recurring activities, an owner for each, and evidence collected as the work happens.
Before your next audit, check yourself against this list:
- Internal audits are on schedule and cover the whole ISMS over the cycle.
- The latest management review is minuted and covers the required inputs.
- The risk assessment and SoA reflect how the business looks today.
- Every finding from the last audit is closed, with evidence.
- Each control has recent records showing it operates.
- The scope still describes the organisation.
- Objectives are measured and reported.
- More than one person can run the ISMS.
Where Threat Protect fits
Our continuous compliance service keeps your ISMS running between audits. Controls and evidence are monitored year-round, and the recurring activities above are scheduled and tracked, so surveillance audits sample work that is already done rather than evidence rebuilt in the weeks before. Certification itself is delivered through UKAS-accredited certification bodies that audit independently, and we prepare you for each audit.
If your next surveillance audit is coming up, book a call and bring your last audit report. You can also check where you stand with the compliance readiness assessment, or read more about ISO 27001 certification and how to choose an ISO 27001 consultant.
Further reading
Frequently asked
Questions readers ask before getting in touch.
- A shorter audit carried out by your certification body in years two and three of the three-year certification cycle. It checks that your information security management system (ISMS) is still operating as certified: internal audits and management reviews are happening, risks are being reassessed, and corrective actions from earlier audits have been dealt with. A full recertification audit follows at the end of the cycle.
- There is no simple pass or fail. The auditor raises nonconformities. Minor ones need a corrective action plan, usually checked at the next audit. A major nonconformity has to be corrected and evidenced within a period the certification body sets, and if it is not, the certificate can be suspended or withdrawn.
- Broadly, a minor nonconformity is an isolated lapse that does not undermine the management system, such as one missed access review. A major nonconformity means a requirement is not being met at all, or the system's ability to achieve its intended results is in doubt, such as no internal audit taking place. Several related minors can be raised together as a major, and a minor left uncorrected from a previous audit is often escalated.
- The best preparation is not needing any. Keep the internal audit programme, management reviews, risk assessment, Statement of Applicability and corrective actions current throughout the year, so the audit samples records that already exist. If you are preparing now, start with the corrective actions from your last audit, then check that every clause has fresh evidence.
Talk to us
Want to talk through how this applies to your company?
A 30-minute call with a senior advisor. No pitch. We will read your situation against what is in this piece and tell you the smallest sensible next step.