IgeraIndustria Quality Team · Updated 2026-09-18 · 10 min read
Part of the Programme 1: Audits content pillar · ties together the clause-by-clause ISO 9001, 14001, 45001, 50001 and 27001 series
Audit process · Certification maintenance
Surveillance Audit: The 6 Things That Get You a Major Non-Conformity
A surveillance audit is the annual check-in your certification body runs between certification and recertification cycles, under ISO/IEC 17021-1, to confirm your management system is still being followed, not just still on file. Most surveillance visits pass without drama. The ones that produce a major non-conformity almost always fail for one of six recurring reasons — and every one of them is about evidence, not intent. This guide walks through each trigger, what it looks like on the audit floor, and what happens to your certificate once it's raised.
A major non-conformity does not fail your certification on the spot
It does put your certificate on notice: you get a defined window — typically 90 days, set by the certification body — to submit and, often, demonstrate corrective action, or the certificate can be suspended. Two majors in the same audit, or an unresolved major carried from the previous cycle, meaningfully raises that risk.
What a surveillance audit actually checks
Under ISO/IEC 17021-1, a three-year certification cycle includes an initial certification audit (Stage 1 and Stage 2), then surveillance audits in year one and year two, then a recertification audit before the cycle renews. Surveillance audits are shorter than the initial audit — usually one day for a single-site SME — and they don't re-cover every clause of the standard. Instead, the auditor samples: internal audit results, management review, corrective actions from the last visit, and a rotating slice of the system, chosen so that by recertification the full scope has been sampled at least once.
Because the sample is smaller, the bar for what counts as "systemic" is lower than you'd expect. An auditor who finds one gap has to ask whether it's isolated or whether it points at a control that has quietly stopped working since the last visit. That judgment call is where most majors get decided.
The 6 triggers that turn into a major
1. Systemic failure to follow documented procedures
This is the classic: the procedure says one thing, the floor does another, and it isn't a single operator having a bad day — it's the whole shift, or every site, doing it the same "wrong" way. Auditors distinguish a minor (one person, one instance) from a major (a pattern across people, shifts, or locations) by sampling more than one record and more than one person's account. If the second and third samples confirm the first, that's systemic, and systemic against a documented requirement is a major almost by definition.
2. Uncontrolled or expired documents in active use
Finding a superseded work instruction taped to a machine, a drawing revision that doesn't match the version in the document register, or a procedure being followed from a printed copy nobody updated after the last change — these all point to a document control process that exists on paper but isn't actually controlling anything. One outdated printout is a minor. A pattern of them across departments, or evidence that revised documents routinely take weeks to reach the floor, escalates fast.
3. A missed internal audit or management review
Internal audits and management review are the mechanisms the standard relies on for you to catch your own problems before a third party does. If the internal audit programme wasn't completed as planned, or the management review didn't happen, or happened without the mandatory inputs (performance data, prior audit results, corrective action status), the auditor isn't just noting a missed meeting — they're noting that your self-correction mechanism didn't run for a year. That's treated as a major because everything else the system relies on to stay accurate depends on it.
Every surveillance audit opens by checking whether corrective actions from the last visit were actually closed — not just marked closed, but verified as effective. An action that was closed on paper but never implemented, or implemented but never checked for recurrence, is a strong signal to the auditor that corrective action in general isn't being taken seriously. A previous minor that resurfaces unresolved is frequently upgraded to a major on the second occurrence, precisely because it shows the system didn't correct itself when given the chance.
5. Competence or training gaps in key roles
Auditors routinely ask operators and process owners to explain what they do and why, not just to demonstrate the record exists. A training record on file for someone who can't describe the procedure they're supposedly trained on is a red flag — it suggests the training was administrative rather than real. This becomes a major when the gap sits in a role with direct control over product quality, environmental impact, or worker safety, since the consequence of the gap isn't theoretical.
6. Loss of process control evidence — records not kept
A system can be operating correctly and still fail an audit if it can't prove it. Missing calibration records, gaps in inspection logs, incident reports that were never filed, or monitoring data that simply wasn't captured for a stretch of weeks all fall into this category. Auditors can't certify what they can't verify, so a gap in records is functionally treated the same as a gap in the process itself — even when the team insists nothing actually went wrong during that window.
| Trigger |
What the auditor is really testing |
Fastest fix before the visit |
| Procedures not followed |
Is the gap isolated or systemic across people/shifts? |
Spot-check three teams against the written procedure, not one |
| Expired documents in use |
Does document control actually reach the floor? |
Walk the floor and compare posted versions to the register |
| Missed internal audit / review |
Does the system self-correct on its own schedule? |
Confirm the annual programme was completed with minutes on file |
| Unresolved prior NCs |
Was the last corrective action verified as effective? |
Re-check every action closed since the last audit for recurrence |
| Competence gaps |
Can the person explain the procedure, not just sign for it? |
Interview key-role staff the way an auditor would, before they do |
| Records not kept |
Can the process be proven, not just described? |
Audit your own logs for date gaps before the auditor finds them |
What actually happens once a major is raised
A major non-conformity does not automatically revoke your certificate, but it starts a clock. The certification body will require a root-cause analysis and a corrective action plan, usually within a fixed window they set — commonly around 90 days, though this varies by body and scheme. Depending on the severity and the certification body's own procedures, you may need to submit documented evidence of correction, or in some cases host a short follow-up visit to verify the action was implemented and is working. Until that's accepted, your certificate can be suspended, which typically means you can't use the certification mark and may need to notify customers who require it as a condition of doing business with you.
This is exactly why the six triggers above are worth auditing yourself against before the certification body does it for you: none of them require new investment to fix, they require the evidence you were already supposed to be generating to actually exist and actually be current.
Why "we know the process" isn't the same as "we can prove the process"
Most of the six triggers above share a root cause: the organisation genuinely was doing the right thing, but the record of it either wasn't kept, wasn't current, or wasn't retrievable when asked. Auditors aren't looking to catch you out — they're looking for evidence, because evidence is the only thing a certification scheme can actually verify at a point in time.
Common mistakes ahead of a surveillance visit
- Treating surveillance as "the easy audit." It's shorter, not lighter — a smaller sample size actually makes a single bad find look more systemic, not less.
- Fixing the symptom, not the record. Correcting the immediate problem without updating logs, training records or the procedure itself leaves the paper trail broken even after the practice is fixed.
- Closing corrective actions without checking they held. A corrective action closed the same week it was raised, with no follow-up check, is one of the first things a returning auditor re-tests.
- Assuming last year's clean audit means this year is safe. Systems drift. A control that worked at last year's surveillance can quietly stop working months later if nobody's watching it in between visits.
- Scrambling for evidence the week before the audit. Evidence assembled retroactively is easy for an experienced auditor to spot, and it doesn't answer the real question: was the process actually followed on the day, not just documented after the fact.
Where this fits in the wider audit picture
Surveillance audits are one stage in a longer cycle, and the standards themselves are where each of these evidence requirements originates. IgeraSolutions publishes clause-by-clause breakdowns for ISO 9001, ISO 14001, ISO 45001, ISO 50001 and ISO 27001, walking through exactly what documented information, records and controls each clause expects — the same requirements a surveillance auditor is sampling against. If you're building or tightening a management system ahead of your next visit, working from the clause text rather than generic checklists tends to close gaps the six triggers above actually test for.
IgeraSolutions at surveillance prep: evidence you can actually retrieve
// IgeraSolutions demo — preparing for a surveillance visit
Quality Manager: Show me any corrective actions closed in the last 12 months that were never verified as effective.
IgeraSolutions: 3 corrective actions closed without a documented effectiveness check: CA-014 (calibration drift, closed 2026-02-11), CA-021 (supplier delivery non-conformity, closed 2026-04-03), CA-029 (training gap, welding cell, closed 2026-05-22). Source: Corrective Action Log, rows 14, 21, 29. Recommend scheduling verification before the surveillance visit — this is the pattern most commonly flagged as trigger #4 (unresolved prior NCs) in surveillance audits.
This is the practical gap IgeraSolutions closes: instead of a management system where evidence lives scattered across shared drives, binders and someone's memory, Igera answers questions about your own procedures, records and audit history by citing the exact source document and clause — so when a surveillance auditor asks "show me," the answer is retrievable in seconds, not reconstructed under pressure the week before the visit.
Frequently asked questions about surveillance audits
How often are surveillance audits carried out?
Under a standard three-year ISO certification cycle, surveillance audits typically happen once in year one and once in year two, between the initial certification audit and the recertification audit in year three. Some certification bodies or higher-risk schemes may set a different cadence — always confirm the specific schedule with your certification body, since it can vary by scheme and by risk classification.
Not immediately. A major non-conformity triggers a required corrective action process with a deadline set by the certification body — commonly around 90 days. If the corrective action is submitted, accepted and, where required, verified within that window, the certificate is typically confirmed as maintained. If the deadline passes without resolution, suspension or withdrawal becomes a real risk, so timeliness matters as much as the fix itself.
A minor non-conformity is generally an isolated lapse that doesn't indicate the management system itself has broken down — a single missed record, one overlooked signature. A major non-conformity indicates a systemic failure, the complete absence of a required element of the system, or a situation that puts product conformity, safety, or environmental compliance at real risk. The distinction is ultimately the auditor's professional judgment, informed by how many samples confirm the pattern.
Yes, in many certification body procedures, multiple minor non-conformities against the same clause or requirement — especially if they show a repeating pattern rather than isolated incidents — can be combined and reclassified as a single major. This is one reason auditors sample across departments and shifts rather than accepting the first clean example they're shown.
Do I get advance notice of what a surveillance audit will cover?
Yes. Certification bodies issue an audit plan ahead of the visit that outlines the scope, the processes or clauses being sampled, the schedule, and the audit team. It won't reveal every specific record the auditor will ask for, but it does tell you which parts of the system are in scope for that particular visit, which is enough to prepare targeted evidence rather than everything at once.
Who decides whether a finding is a major or a minor?
The lead auditor makes the classification during the audit, guided by the certification body's documented grading criteria and the accreditation rules that certification body operates under. It's a professional judgment call based on the evidence sampled, not a fixed formula — which is also why the same underlying issue can be graded differently by different auditors or different bodies.
Start root-cause analysis before the auditor has even left the site if possible — the closer the analysis is to the actual event, the more accurate it tends to be. Confirm the exact deadline and submission format your certification body requires, assign clear ownership of the corrective action, and make sure the fix addresses the root cause rather than just the specific instance the auditor happened to find, since a recurrence of the same issue is treated more severely at the next visit.
Could you retrieve every piece of evidence a surveillance auditor might ask for, right now?
IgeraSolutions answers questions about your own procedures, records and corrective actions by citing the exact source document — so surveillance prep stops being a scramble through shared drives.
See how Igera helps with audit readiness
Related in the Audits content pillar
- ISO 9001, 14001, 27001, 45001 and 50001 each have a clause-by-clause guide covering the specific documented information and records auditors sample during surveillance
- Stage 1 vs Stage 2: what happens at initial certification, before surveillance audits begin
- Writing a non-conformity that closes the first time: how to respond once a major or minor has been raised
This article is informational and does not constitute legal, professional or certification advice. Non-conformity grading criteria, corrective action deadlines and suspension procedures vary by certification body and accreditation scheme — always confirm the specifics that apply to your certificate with your own certification body. Reviewed by IgeraIndustria Quality Team, updated 2026-09-18. General reference: ISO/IEC 17021-1 (conformity assessment — requirements for bodies providing audit and certification of management systems).