Skip to content
SecuriFii

Certification

Why management systems fail in year two, not year one

Getting certified is a project with a deadline, a budget and everyone paying attention. Staying certified is an operating rhythm with none of those, which is why the first surveillance audit is where you find out what you actually built.

Facts checked2026-09-11

What does a surveillance audit test?

Surveillance visits are shorter than the certification audit and sample a subset, but they are real audits and they can raise nonconformities. What they look for is continuity: that internal audits kept happening, that management review met and decided things, that risks were reassessed, that last year’s findings were closed, and that the controls still produce records.

This is exactly where a system built by a departing consultant comes apart. The documents are immaculate, the policies say the right things, and nothing has been operated since the certificate arrived. An auditor sampling for records from eight months ago finds none, and the finding is not a control gap — it is that the management system stopped being a management system.

The organisations that sail through are rarely the ones with the best documentation. They are the ones where the periodic controls have an owner, a calendar entry and somewhere the output lands automatically, so a quiet year still produces a year of evidence.

The bottom line

Before the certificate arrives, decide who owns each recurring activity and where its output goes. Year one is carried by attention; year two is carried by whatever you made routine.

Related insights