Year 2 ISMS drift: the six things surveillance auditors look for
Most ISMS drift happens quietly in the twelve months after certification. Here are the six evidence gaps surveillance auditors consistently find in year two, and how to close them.
By Kellwick Team · September 17, 2026 · 6 min read
Certification audits are intense, focused events. Everyone is prepared, evidence folders are organised, and the ISMS looks credible. Surveillance audits, which typically happen at months twelve and twenty-four of a three-year certification cycle, arrive in a very different climate. The sprint energy is gone, competing priorities have accumulated, and the parts of the ISMS that required ongoing discipline have often slipped.
Surveillance auditors are experienced at spotting drift. They are not re-auditing the entire ISMS - they are sampling for evidence that the system has been maintained and is still operating as it was certified. The six areas below are where the evidence most commonly runs out.
1. A stale risk register
The risk register should be a living document, updated when the threat landscape changes, when new assets enter scope, when incidents occur, or at least on the agreed periodic review schedule. In practice, many organisations update their risk register once before certification and do not touch it again until the surveillance audit is approaching.
An auditor will check the date of the last review and will ask who reviewed it and what changed. If the last modification date is within two weeks of the surveillance audit, that is itself a finding - it suggests the review was reactive rather than planned. If nothing has changed in twelve months, they will ask whether that is plausible: did no new suppliers come into scope? No new systems? No incidents? No changes to the regulatory environment?
The most defensible position is a register with dated entries, named reviewers, and a clear log of what was considered at each review - even if the conclusion was that no material changes were needed.
2. A lapsed internal audit programme
Clause 9.2 requires a programme of internal audits at planned intervals. The certification audit will have sampled whether the programme existed and whether at least one internal audit had been completed. The surveillance audit will check whether the programme has continued.
The most common failure pattern: the internal audit that was conducted just before certification is the only one on record. The year-two surveillance auditor asks for the audit schedule and the results of audits conducted since certification, and finds nothing.
This is a significant finding because it is systemic - it suggests the ISMS is not being managed as a continuous programme. Auditors will also check whether findings from the previous internal audit have been addressed, whether corrective actions were raised, and whether those actions were closed within the agreed timescales.
A practical safeguard is to schedule the next internal audit cycle at the point you receive your certification certificate, not at the point you start preparing for surveillance.
3. Lapsed access reviews
A.8.2 (Privileged access rights) and A.8.3 (Information access restriction) both require that access is reviewed and adjusted in line with role changes and at defined intervals. Access review records are one of the most commonly sampled pieces of evidence in surveillance audits, and they are among the most commonly absent.
The typical gap: access reviews were completed as part of certification preparation but have not been repeated since. An auditor will ask for evidence of access reviews conducted in the past twelve months, for both privileged accounts and general user accounts. They will also cross-reference joiners, movers, and leavers records to test whether access was modified or revoked promptly when people changed roles or left the organisation.
If a leavers record shows someone left four months ago and their account still appears in the user list, that is a direct control failure rather than a documentation gap. Both types of finding matter; the control failure carries more weight.
4. Scattered or missing evidence
During the certification audit, evidence was gathered, organised, and presented. In the twelve months since, evidence of ongoing control operation - security awareness training completions, patch management records, backup test results, supplier review records - has been created by operational teams who may not be tracking it against the ISMS.
Surveillance auditors will ask for evidence that specific controls have been operating continuously, not just at the point of certification. If backup test results exist but are in an IT team spreadsheet that nobody has connected to the ISMS, the auditor will note that the evidence management process is not working. If training completion records exist in an HR system but cannot be extracted by department for the in-scope population, the auditor will note that too.
The practical answer is to define, at the point of certification, which records need to be retained as ISMS evidence, where they will be stored, who is responsible for keeping them current, and how they will be accessible for audit. A simple evidence register or ISMS document index, maintained and updated through the year, saves significant time at surveillance and reduces the risk of gaps.
5. A missing or thin management review
Clause 9.3 requires management reviews at planned intervals. The review must cover specific inputs - including audit results, risk assessment updates, performance metrics, and the status of previous action items - and must produce outputs including decisions and actions.
Many organisations conduct a management review for certification and then either skip the next one or hold an informal conversation that is not documented. An auditor will ask for the management review record from the past twelve months, including the inputs considered, the attendees, and the decisions made. A one-paragraph summary note does not meet the standard's requirements for documented information.
The management review is also where the risk register review decisions, the internal audit findings, and the corrective action status should be formally considered. If those documents have drifted (as described in points 1 and 2 above), the management review is the point where that drift should have been caught and corrected. A missing management review means there has been no formal oversight - which is exactly what surveillance auditors are looking for evidence of.
6. Stopped supplier assurance
A.5.19 through A.5.22 cover information security in supplier relationships. Certification requires you to demonstrate that you assess and monitor suppliers who handle in-scope information. Surveillance audits check whether that monitoring has continued.
The common pattern: supplier questionnaires were sent before certification, a few responses were collected, and nothing has happened since. New suppliers have been onboarded without security assessments. Annual review dates on existing suppliers have passed without follow-up. Contracts have been renewed without reviewing the information security clauses.
An auditor will ask how many suppliers are on the register, whether the register reflects current supplier relationships, when each was last reviewed, and whether any new in-scope suppliers have been onboarded since certification. If a significant cloud provider or data processor was added in the past year and has no assessment record, that is a finding.
Supplier assurance is one of the areas where the 2022 revision added explicit new controls - A.5.23 (Information security for use of cloud services) specifically. If your cloud infrastructure has changed since certification and the supplier assurance record has not been updated to reflect it, this is likely to be raised.
Closing the gaps before surveillance
The common thread across all six areas is that they require ongoing action rather than one-time preparation. The organisations that sail through year-two surveillance audits are almost always those that treated the ISMS as an operational programme from the day they received certification - not as a project to revisit when the next audit appears on the calendar.
Where Kellwick fits
If you are approaching a year-two surveillance audit and are uncertain whether your ISMS has kept pace with operations, Kellwick offers a structured pre-surveillance review that checks exactly these six areas. Visit /surveillance-audit-readiness to see how we work with teams to close evidence gaps before the auditor arrives.
Where this fits
ISO 27001
Pass the audit. We find what blocks Stage 1 before the certification body does.
Read the ISO 27001 hubNeed a second pair of eyes before the auditor does?
A readiness review shows exactly where your ISMS stands - and what to fix first - while there is still time to act on it.
Stay audit-ready
Occasional, practical notes on ISO 27001 readiness and ISMS maintenance. No noise.