Understand the Difference Between Certification Audits and Surveillance Audits

Published on: December 3, 2025

Whether you’re an independent ISO professional supporting multiple clients or part of an organisation preparing for or maintaining ISO certification, understanding the different types of audits can be confusing. One of these types, the audits conducted for Certification to ISO Standards, is broken down into initial certification audits and surveillance audits.

Both certification audits and surveillance audits are conducted by independent accredited  Conformity Assessment Bodies (CABs), meaning they are both classified as external audits. These audits provide an objective, third-party assessment of whether your management system meets the requirements of the applicable ISO standard in order to achieve or maintain Certification.

In this article, we’ll explore the differences between the initial certification and the surveillance audits, as well as why internal audits are essential, and show how ICExperts Academy’s Management System Internal Auditor online course equips you with the skills to conduct audits confidently and professionally.

Keep reading as we will cover:

What is a Certification Audit?

A certification audit is the first formal evaluation conducted by an accredited, independent Conformity Assessment Body (CAB), for an organisation wishing to become Certified. Its purpose is to verify that the management system meets the requirements of the relevant ISO standard, and a successful outcome results in the ISO Certification to the relevant standard being issued. Common standards include:

The initial certification audit is typically structured in two stages:

  1. Stage 1 – Documentation Review: The auditor examines the organisation’s policies, procedures, and system design. This stage identifies gaps, evaluates readiness, and determines if the organisation is prepared for a full implementation audit.
  2. Stage 2 – Implementation Review: The auditor assesses the actual operation of the management system. They review evidence, interview staff, and verify that processes are implemented effectively.

Upon successful completion, the organisation is awarded with the desired ISO certification, which is generally valid for three years. Once a year the CAB auditor returns for a surveillance audit. Upon completion of the third year of Certification, a Re-Certification audit is conducted to renew the 3 year Certification cycle. The re-Certification audit is similar to the initial certification audit, but is shorter, and not broken down into Stage 1 and Stage 2.

What is a Surveillance Audit?

After the initial certification, surveillance audits typically occur annually. Surveillance audits are not as extensive as the initial certification audit, but they serve a critical role in maintaining conformance and facilitating continual improvement.

Key points about surveillance audits:

  • They focus on whether the management system continues to operate effectively.
  • They verify corrective actions have been implemented for any issues raised in previous audits.
  • They provide ongoing assurance to management, customers, and regulators.
  • They help identify emerging risks or changes that could affect the system’s effectiveness.

Unlike the certification audit, which is more comprehensive, surveillance audits are more targeted. They may include sampling certain processes, reviewing a subset of documentation, or focusing on areas identified as high risk.

The Limitations of External Audits

The Limitations of External Audits

While certification and surveillance audits are essential to achieve and maintain Certification, relying solely on external audits carries risks:

  • Periodic Insight Only: External audits generally happen at 12-monthly intervals, so nonconformities may go unnoticed between audits.
  • Reactive Corrections: Without internal monitoring, issues are often only addressed once flagged by an external auditor, which can be stressful, costly, and inefficient.
  • Lack of advice and recommendations: Due to conflict of interests, Certification Auditors (from CABs), are only allowed to identify and report on the gaps and non-conformances. However, they can’t go any further than that to provide advice on how to address the issues.
  • Fail or Loss of Certification: Major non-conformances identified during external audits may result in organisations failing the Certification audits, or even losing Certifications already achieved.

This is why organisations and independent professionals must focus on internal auditing capability. Internal audits provide continuous monitoring, enabling proactive detection and correction of issues before they impact external audits.

Why Internal Audits Are Essential – and Required!

Internal audits are a fundamental part of effective management systems, and are a direct requirement of the Management System Standards. They serve multiple purposes:

  1. Early Detection of Nonconformities – Internal audits help identify process weaknesses, incomplete documentation, or misaligned procedures before they escalate into major issues or go to external audits.
  2. Maintaining ISO Readiness – Regular internal audits ensure your organisation is always prepared for external certification or surveillance audits.
  3. Supporting Continual Improvement – Findings from internal audits feed into management reviews and improvement initiatives.
  4. Building a Conformance Culture – Conducting audits internally encourages staff to understand and follow the organisation’s own requirements and ISO requirements consistently, fostering accountability across the organisation.
  5. Reducing External Dependence – Organisations with strong internal audit capabilities rely less on costly consultancy services for audit preparation or remediation.
  6. Meeting ISO Standards requirements – Not conducting Internal Audits may result in a major non-conformance to organisations, jeopardising the Certification.

ICExperts Academy’s Management System Internal Auditor Course

Whether you are an internal staff member or an independent ISO consultant, ICExperts Academy’s Management System Internal Auditor online course provides the practical skills, resources and knowledge required to conduct effective internal audits.

Course Highlights:

  • ISO-Aligned Training – Learn auditing principles aligned with ISO 19011:2018, the Guidelines for auditing management systems, and the main ISO management system standards.
  • Practical Application – Develop real-world audit skills: planning, conducting, reporting, and following up on findings.
  • Templates & Tools – Gain access to audit checklists, reporting templates, and other resources to get you ready, and make audits easier and more professional.
  • Flexible Online Learning – Study at your own pace, fitting training around work commitments.
  • International Recognition – Complete the course and gain a certificate of completion, with international recognition via Exemplar Global.

Who Benefits from the Internal Auditor Course?

  • Independent ISO Professionals: Expand your audit services, improve credibility with an internationally-recognised qualification, and support multiple clients with confidence.
  • In-House Staff: Build internal audit capability to maintain ISO certification, improve internal knowledge of the ISO standards and conformance, and enhance system effectiveness.
  • Organisations Preparing for Certification: Ensure your system is audit-ready and reduce risk during external audits.
  • Organisations Maintaining Certification: Continuously monitor processes, identify areas for improvement, and support surveillance audit success.

How Internal Audits Complement External Audits

Internal audits are not optional, but a mandatory requirement of ISO management system standards such as ISO 9001, ISO 14001, ISO 45001 and ISO 27001. Their purpose goes far beyond simply “checking the system”. Internal audits provide assurance that the management system is functioning as intended, identify areas for improvement, and help maintain readiness for external audits.

The internal audits are essential for maintaining the integrity, accuracy, and improvement of the management system, making them a valuable process in preparation for the external audits. Well-conducted internal audits will minimise the risks at external audits, improve the business, and help organisations be confident for the external audits.

Whether you’re a professional working across multiple organisations or an internal staff member responsible for conformance, the Management System Internal Auditor course from ICExperts Academy equips you with the skills, knowledge, and tools to conduct effective internal audits, maintain ISO readiness, and support continual improvement.

Invest in your skills today and build a strong foundation for long-term ISO conformance and business excellence.

Enrol here in the Management System Internal Auditor Course

Sarah Kammigan

Sarah is a seasoned Business Development Manager at ISO Certification Experts, specialising in providing tailored certification solutions for ISO 9001, ISO 14001, ISO 45001, and ISO 27001 to our clients. In addition to her strong background in quality management systems, Sarah also has a proven track record of driving revenue growth and building strategic partnerships, while her collaborative approach fosters a culture of continuous improvement. Dedicated to delivering exceptional customer service, she helps organisations with the right solutions to their certification needs.

All information on this blog site is for informational purposes only. As this information is based on our professional experience, opinion, and knowledge, we make no representations as to the suitability of this information for your individual business circumstances. Especiality Pty Ltd trading as ICExperts Academy and all related businesses and brands will not be liable for any errors, omissions, legal disputes or any damage arising from its display or use. All information is provided as is, with no warranties and confers no rights.

We will not be responsible for any material that is found at the end of links that we may post on this blog site. The advice, ideas, and strategies should never be used without first assessing your own personal business situation or seeking professional and/or legal advice. Information may also change from time to time to suit industry and business needs, requirements and trends.