Surveillance is part of ongoing assessment within a management-system certification programme. It is concerned with continued conformity and relevant changes, rather than simply issuing another copy of a certificate. The programme determines the precise activities and timing.
Keep the system operating between visits
An organization should be able to explain how it has worked since the previous assessment. Records, performance information, internal reviews and responses to problems should arise from ordinary operations, not be created only because a surveillance date is approaching.
If a control is described in a procedure but is no longer used, explain what has changed and why. A mismatch between written arrangements and practice is more useful to address directly than to hide behind a document revision made immediately before the audit.
Make changes visible
New sites, services, equipment, personnel arrangements or outsourced activities may affect the system. Tell the certification body about relevant changes according to the programme and agreement. Do not assume that the existing certificate wording automatically expands when the business grows.
For example, a service organization adding a new delivery location should clarify whether the location is within the current scope and whether additional assessment is needed. A company website announcing the new location does not itself update the certification record.
Review actions from earlier findings
Be prepared to explain what was done, what evidence supports the response and how the organization evaluated the result. A closed action in a spreadsheet may need context: what changed in the process, who was affected and whether the issue has recurred.
If an action has not worked as intended, the useful next step is to understand the problem and address it. Treating an ineffective action as permanently complete can obscure an issue that needs attention.
Organize information for the agreed plan
Use the audit plan to arrange access to relevant people and activities. Prepare a clear account of system changes and the information requested. Avoid overwhelming the review with unrelated files; relevance and traceability are more useful than volume.
Ask in advance about confidentiality and access arrangements where information belongs to customers or third parties. Redaction or supervised access may need to be planned rather than improvised.
Does surveillance replace recertification?
No. They have different places in a programme. Confirm the applicable surveillance and recertification arrangements with the certification body instead of assuming that one successful visit extends the certificate indefinitely.
What should happen after the visit?
Review the outcome, assign responsibilities for required responses and check whether any matter affects the certificate scope or status. Keep the next programme activities visible in your planning. Public claims should continue to match the current record.
Read the certification process and certificate validity guide, or contact EQRM about the arrangements relevant to your enquiry.
Keep a change log between assessments
A concise log can list the change, date, affected activity or location, internal owner and any communication with the certification body. Link it to existing records rather than creating duplicate evidence. Before surveillance, review the log against the scope and audit plan so the assessment reflects current operations instead of last year’s organization chart.
Quick answers
Is surveillance simply a certificate renewal?
No. It is ongoing assessment under the applicable certification programme. The work and timing should be confirmed with the issuing body.
What changes should be discussed before surveillance?
Raise changes to activities, sites, personnel, organizational structure or other matters affecting the agreed scope and programme.