Certification
Why management systems fail in year two, not year one
Getting certified is a project with a deadline, a budget and everyone paying attention. Staying certified is an operating rhythm with none of those, which is why the first surveillance audit is where you find out what you actually built.
Facts checked — 2026-09-11
What does a surveillance audit test?
Surveillance visits are shorter than the certification audit and sample a subset, but they are real audits and they can raise nonconformities. What they look for is continuity: that internal audits kept happening, that management review met and decided things, that risks were reassessed, that last year’s findings were closed, and that the controls still produce records.
This is exactly where a system built by a departing consultant comes apart. The documents are immaculate, the policies say the right things, and nothing has been operated since the certificate arrived. An auditor sampling for records from eight months ago finds none, and the finding is not a control gap — it is that the management system stopped being a management system.
The organisations that sail through are rarely the ones with the best documentation. They are the ones where the periodic controls have an owner, a calendar entry and somewhere the output lands automatically, so a quiet year still produces a year of evidence.
The bottom line
Before the certificate arrives, decide who owns each recurring activity and where its output goes. Year one is carried by attention; year two is carried by whatever you made routine.
Related services
ISO/IEC 27001 — Information Security Management
Build an information security management system that survives Stage 2 — and the three years of surveillance that follow.
ISO 22301 — Business Continuity Management
Know which activities cannot stop, how long they can be down, and what you will actually do — tested before you need it.
ISO/IEC 27701 — Privacy Information Management
Turn privacy from a policy document into a management system, with the records a regulator or an enterprise buyer will ask to see.
Related insights
Certification
The Statement of Applicability, and why an auditor opens it first
The document that shows whether your management system has reasoning behind it — and the one most organisations build backwards.
Certification
Stage 1 and Stage 2: what each audit tests, and why Stage 1 is not a rehearsal
One checks that you are ready to be audited. The other is the audit. Both feed the certification decision.
Certification
ISO 27001:2013 certificates have expired — including the ones with later dates on them
The window closed on 31 October 2025. A lapsed holder is treated as a new client — which is the part most summaries leave out.