ISO 45001 Surveillance Audits: Maintaining Your Certification Year-on-Year
Your ISO 45001 certificate is valid for three years. But that doesn’t mean you’re left alone for three years. Your certification body will visit annually to verify you’re maintaining standards. These surveillance audits keep you accountable and ensure continuous improvement.
Surveillance audits are lighter than Stage 2, but they’re not perfunctory. They can identify nonconformities that must be closed. Understanding what to expect and how to prepare helps you pass smoothly.
What Is a Surveillance Audit?
A surveillance audit is an annual on-site audit conducted by your certification body between your Stage 2 certification audit and your triennial recertification audit. It’s your certification body’s way of verifying you’re maintaining your system and continuing to improve.
Think of it as a “health check”. You certified. Are you keeping your system healthy? Or has it degraded?
Surveillance Audit vs. Recertification Audit
It’s important to distinguish between surveillance and recertification:
Surveillance Audits (Annual, Years 1 & 2): Check that you’re maintaining your system. Typically 1-2 days on-site. Focus on different areas each year. Not a complete system reassessment.
Recertification Audit (Year 3): Full reassessment of your entire system. Similar in scope to Stage 2. Determines whether your three-year certificate will be renewed or revoked.
You’ll have two surveillance audits (usually in years 1 and 2), then a recertification audit in year 3. Together, they ensure you’ve remained compliant throughout the three-year cycle.
What Auditors Focus On During Surveillance
Surveillance audits don’t assess everything. They sample. Each year typically focuses on different areas so that over three years, you’ve been comprehensively audited.
Year 1 Surveillance Audit
Year 1 surveillance typically focuses on:
- Follow-up on any minor nonconformities from Stage 2 (have you closed them?)
- Hazard identification and risk assessment (have you identified new hazards since certification?)
- Control effectiveness (are controls working as intended?)
- Leadership commitment (evidence of continued investment in health and safety)
- Sample of operational areas
Year 2 Surveillance Audit
Year 2 surveillance typically focuses on:
- Competence and training (have new staff been trained and assessed?)
- Internal audit programme (are internal audits happening? Are findings acted upon?)
- Management review (are reviews happening and driving decisions?)
- Incident investigation and corrective action (if incidents have occurred, were they properly investigated?)
- Worker consultation and participation (are workers involved?)
The Sampling Approach
Your certification body develops a three-year surveillance plan. They’ll audit different operational areas each year—not the same area twice. By year 3, they’ll have audited the entire system across all three years. This approach is more efficient than full system audits every year, while still providing comprehensive coverage.
If your organisation has multiple sites, surveillance audits sample across sites rather than auditing all sites every year. Your certification body’s plan will specify which sites are audited in which year.
How to Prepare for a Surveillance Audit
Surveillance audits require less preparation than Stage 2, but they’re not trivial. Here’s what you should do:
Pre-Audit Preparation (Weeks Before Audit)
- Confirm Scope: Ask your certification body what areas they’ll focus on in this year’s surveillance. Ensure you understand the expected timing and which staff will be needed.
- Review Your System: Revisit your documented procedures. Have they changed? Are they still accurate? Update if necessary.
- Gather Evidence: Compile evidence of maintenance activities: training records (any new staff trained?), internal audit reports, management review minutes, incident investigation files (if any), corrective action records, consultation records.
- Close Outstanding Items: If you had any outstanding nonconformities from surveillance audits or internal audits, close them before the auditor arrives.
- Verify Controls: Walk your facilities. Verify controls are still in place and functioning. If equipment maintenance is due, schedule it before the audit.
- Brief Management: Ensure management understands the audit is happening and what their role is.
During the Audit
- Provide Access: Make sure the auditor can access people, documents, and operational areas without hindrance.
- Answer Honestly: Don’t hide issues. If your system has weaknesses, acknowledge them. Honesty builds trust and credibility.
- Demonstrate Commitment: If the auditor sees evidence of continued investment in health and safety (training records, control improvements, management involvement), that’s positive.
Post-Audit
- Receive the Report: Your certification body will send a surveillance audit report, typically within 2-4 weeks.
- Address Findings: If there are minor nonconformities, address them according to the timeline specified (usually 6-12 months).
- Plan Next Surveillance: Coordinate with your certification body on scheduling the following year’s surveillance.
Typical Surveillance Audit Findings
Most surveillance audits reveal some findings. This is normal. Typical findings include:
- Hazard register hasn’t been updated for new work processes
- A group of new staff hasn’t been trained or assessed for competence
- Internal audit programme lagged (audits weren’t conducted as scheduled)
- Management review wasn’t conducted in the period covered
- An incident wasn’t properly investigated
- Control effectiveness hasn’t been verified (you assume controls work but haven’t verified)
- One area’s procedures diverge from the documented system
Minor findings are expected and address through corrective action. Major findings are rare in surveillance audits (they’re more typical of Stage 2 or recertification) and would trigger urgent action.
What Triggers an Unscheduled Audit
Sometimes, your certification body will conduct an unscheduled (extraordinary) audit. Triggers include:
Significant Incident
If your organisation has a serious workplace incident or fatality, the certification body may conduct an unscheduled audit to verify your incident investigation and corrective actions. This isn’t punitive—it’s ensuring you’ve investigated thoroughly.
Non-Closure of Major Nonconformity
If you fail to close a major nonconformity within the specified timeline, the certification body will conduct an unscheduled audit to verify closure or may suspend your certification.
Complaint or Regulatory Issue
If a regulatory authority reports concerns about your safety management or if workers lodge formal complaints about your system, the certification body may conduct an audit.
Credibility Concerns
If the certification body suspects your internal audit programme isn’t rigorous or that your system has degraded significantly, they may conduct an unscheduled audit.
Unscheduled audits are rare but possible. Maintaining a robust internal audit programme and promptly closing findings minimises this risk.
Managing Multiple-Site Surveillance Audits
If you’re certified across multiple sites, your certification body will develop a multi-site surveillance plan. This typically involves:
- Targeted Sampling: Auditing different sites in different years, rather than all sites every year
- Risk-Based Selection: Prioritising higher-risk sites and those with previous nonconformities
- Consistency Verification: Ensuring the same procedures are followed across all sites
- Comparison Across Sites: Looking for best practices in one site that should be shared with others
Your certification body will share their planned surveillance schedule. Know which sites will be audited when so you can prepare accordingly.
What Happens If You Fail a Surveillance Audit?
“Failure” is a strong word. More accurately: what happens if surveillance audit findings are serious?
If You Have Minor Nonconformities
You address them according to the specified timeline (usually 6-12 months). Your certification remains valid. You provide evidence of closure to the certification body. Normal process.
If You Have Major Nonconformities at Surveillance
This is serious but rare. You’ll typically have 3 months to close the major nonconformity. You must provide evidence of closure to the certification body. Until closure is verified, your certification may be suspended (depending on the severity).
If You Don’t Address Findings
If you ignore findings or fail to close nonconformities within the specified timeline, your certification body can suspend or withdraw your certificate. At this point, you’re no longer certified, and you’d need to undergo recertification to restore certification.
If You Don’t Schedule Surveillance Audits
If you avoid scheduling surveillance audits or decline to cooperate, your certification body will eventually withdraw your certificate. Surveillance audits are mandatory conditions of certification.
The message is clear: surveillance audits must be taken seriously. Don’t ignore findings. Close them within the specified timeline. Don’t avoid audits.
Keeping Your System Alive Between Audits
Surveillance audits are annual, but you can’t rely on them to keep your system healthy. You must actively maintain it between audits.
Continuous Maintenance Activities
- Internal Audits: Conduct them as planned. Don’t delay or skip.
- Management Review: Conduct quarterly or at least biannually. Review audit findings, incidents, performance data, and make decisions.
- Hazard Identification: When work changes, update your HIRA. Don’t wait for an audit.
- Competence Assessment: When new staff join, assess their competence. Don’t assume they know your system.
- Incident Investigation: Investigate any incidents or near-misses thoroughly. Don’t skip minor ones.
- Control Verification: Periodically verify controls are still working. Equipment maintenance, PPE condition, procedures relevance.
- Worker Consultation: Maintain ongoing channels for workers to raise concerns. Respond to them.
An organisation that actively maintains its system between audits will pass surveillance audits easily. An organisation that ignores its system between audits will face findings and credibility questions.
Common Surveillance Audit Mistakes
After observing thousands of surveillance audits, certain mistakes appear regularly:
Mistake 1: Neglecting Internal Audits
You certified with an internal audit programme. Then, in year 1 or 2, internal audits trail off. When the auditor reviews internal audit records, they find gaps. This signals the system isn’t being maintained.
Solution: Stick to your internal audit schedule. Even if you’re busy, audits must continue.
Mistake 2: Not Updating HIRA for New Work
You’ve brought in new equipment or processes, but you haven’t updated your hazard register. The auditor discovers undocumented hazards. This is a finding.
Solution: When work changes, update HIRA immediately. Don’t wait for an audit to discover gaps.
Mistake 3: No Evidence of Management Review
You certified with a management review procedure. But in years 1-2, no management reviews were conducted. The auditor finds no minutes or evidence of review.
Solution: Conduct management reviews as planned. Document them with minutes and decisions.
Mistake 4: Outstanding Findings Not Closed
You had a minor nonconformity from a previous audit, but you haven’t closed it. The auditor asks about it and finds no evidence of corrective action. This damages credibility.
Solution: Track all outstanding findings. Close them before the next audit arrives.
Mistake 5: System Drift
Your procedures say one thing, but your people are doing something else. You’ve drifted from your documented system. The auditor notices the gap.
Solution: Periodically review whether your people are actually following documented procedures. Update procedures if your practice has legitimately changed, or reinforce procedures if people have drifted.
Surveillance Audits as Continuous Improvement Opportunities
Don’t see surveillance audits as compliance hassles. See them as opportunities to improve. Each auditor brings fresh perspective. They see your system as outsiders. Use their input to strengthen what’s working and fix what isn’t.
Good organisations use surveillance audits as coaching opportunities. They take feedback seriously and implement improvements between audits. This continuous improvement is exactly what ISO 45001 is designed to drive.
An organisation that improves year-on-year will sail through recertification. An organisation that ignores findings will struggle.
Key Takeaways
Surveillance audits are annual health checks. They verify you’re maintaining your system and continuing to improve. They’re lighter than Stage 2 but not trivial. Prepare well, address findings promptly, and use the feedback to strengthen your system.
Surveillance audits over three years provide comprehensive coverage. By recertification, your auditor will have audited your entire system across all surveillance visits. Maintaining a robust system between audits ensures you’ll pass with minimal findings.
Frequently Asked Questions
Typically 1-2 days on-site, depending on organisation size. They’re shorter than Stage 2 because the auditor isn’t comprehensively reassessing everything, just sampling key areas.
Yes, you might have a different auditor. However, there’s usually continuity—if possible, the same auditor from Stage 2 conducts at least some surveillance audits to maintain familiarity. But ask your certification body about their approach.
Typically 2-4 weeks notice. This allows you to schedule the auditor and prepare evidence. In rare cases, audits are unscheduled (e.g., after a serious incident), but routine surveillance audits are scheduled.
Report it to your certification body immediately. They may conduct an unscheduled audit to review your incident investigation. This isn’t punitive—it’s standard practice to ensure you’ve investigated properly.
Yes. If you’re certified for ISO 9001, ISO 14001, and ISO 45001, your certification body can conduct a combined audit assessing all three standards in one visit. This is efficient and reduces audit fatigue.
Negotiate a different date. However, surveillance audits must occur at planned intervals. If you persistently avoid or delay audits, your certification can be suspended.
Ask your certification body in advance what areas they’ll focus on. They may not give complete detail, but asking shows proactivity. Then prepare evidence in those areas.
Conclusion: Surveillance as System Maintenance
ISO 45001 certification is a three-year journey, not a three-year rest. Surveillance audits ensure you’re actively maintaining and improving your system throughout. They’re not obstacles—they’re essential checkpoints that keep your organisation accountable.
Prepare well. Address findings promptly. Use auditor feedback to improve. By the time you reach recertification in year three, you’ll have built a genuinely mature system, not just a certified one.
Need Help Preparing for Your Surveillance Audit?
We provide pre-audit readiness reviews and help you organise evidence. Contact us to ensure you’re fully prepared for your annual surveillance visit.
Recent Comments