Home / Blog / GRC & Compliance

Preparing for Your First ISO 27001 Surveillance Audit: What Kenyan Enterprises Overlook After Certification

Preparing for Your First ISO 27001 Surveillance Audit: What Kenyan Enterprises Overlook After Certification

Most Kenyan enterprises pop the champagne after receiving their ISO 27001:2022 certificate, then go quiet for eleven months. Around month ten, someone remembers the surveillance audit is coming. Panic sets in. Evidence gets backdated. Risk registers get "refreshed" in a weekend. Auditors from bodies like KEBS, BSI, or Bureau Veritas notice this pattern immediately.

The surveillance audit is not a repeat of your stage 2 certification audit. It is a targeted check for one thing: whether your Information Security Management System (ISMS) is actually alive, or whether it froze the day the certificate was printed. This is where the majority of first-year nonconformities come from, and the gaps are predictable.

What a Surveillance Audit Actually Covers

Under ISO 27001:2022, your certification body must audit you at least once a year during the three-year certification cycle. Surveillance audits are shorter than the initial certification audit, but they are sharper. Auditors focus on:

  • Mandatory clauses 4–10, particularly management review, internal audit, and continual improvement
  • A rotating subset of Annex A controls, prioritised by risk and by findings from your stage 2 audit
  • Any changes to scope, structure, or the threat landscape since certification
  • Evidence of ongoing operation, not just documented policies

The key word is *evidence*. Not policies. Not intentions. Dated, traceable proof that the ISMS ran for twelve months.

Expert tip: If your only ISMS activity in the past year happened in the six weeks before the surveillance audit, expect a major nonconformity on Clause 10 (continual improvement) at minimum.

Four Things Kenyan Enterprises Consistently Overlook

1. Management Review Meetings That Never Happened

Clause 9.3 requires top management to review the ISMS at planned intervals. "Planned intervals" does not mean once, right before the auditor arrives. We see boards and executive committees in Nairobi that met to approve the ISMS pre-certification, then never formally reviewed it again. Auditors will ask for minutes, attendance registers, and evidence that inputs like audit results, risk changes, and KPI performance were actually discussed.

Run management reviews at least twice a year. Document them properly. Track the actions to closure.

2. Internal Audits Treated as a Formality

Clause 9.2 requires an internal audit programme covering the entire ISMS across the certification cycle. Many Kenyan firms outsource one internal audit right before surveillance, cover 30% of controls, and call it done. Auditors will check your internal audit plan against actual execution. If your plan says quarterly and you did one, that is a nonconformity.

3. Risk Register Frozen in Time

Your Statement of Applicability (SoA) and risk register should reflect changes in the business: new cloud workloads, new third-party vendors, the shift to hybrid work, ransomware trends targeting East African financial services. If your risk register still shows the same threats and scores from your certification audit, the auditor knows the risk assessment process is dormant.

4. Weak Evidence for Annex A Controls

ISO 27001:2022 restructured Annex A into 93 controls across four themes. Controls that consistently trip up Kenyan enterprises during surveillance include:

  • A.5.7 Threat intelligence — a new control in the 2022 revision. Most organisations have no documented process.
  • A.5.23 Information security for cloud services — critical for AWS and Azure deployments, often lacking a formal cloud security policy.
  • A.6.3 Awareness, education and training — annual training records, phishing simulation results, role-based training for developers and admins.
  • A.8.16 Monitoring activities — logging is on, but who reviews the logs and how often?

For a deeper look at how these map to your environment, see ISO 27001:2022 Annex A Controls Guide.

How to Prepare in the 90 Days Before the Auditor Arrives

Start three months out, not three weeks.

  • Month 1: Complete an internal gap review against Clauses 4–10 and the Annex A controls flagged in your last audit report. Close open corrective actions from stage 2.
  • Month 2: Run a full internal audit if you have not already. Convene a formal management review with documented inputs and outputs.
  • Month 3: Refresh your risk assessment, update the SoA if scope or controls changed, and package evidence by clause and control. Rehearse control owners on what they will be asked.

Assign a single ISMS coordinator to own the preparation. Fragmented ownership is the fastest way to fail a surveillance audit.

The Kenya Data Protection Act Overlap

Many Kenyan enterprises pursued ISO 27001 partly to strengthen their posture under the Kenya Data Protection Act, 2019. The Office of the Data Protection Commissioner (ODPC) has ramped up enforcement, and auditors increasingly ask how your ISMS supports data protection obligations. Show them: DPIAs, records of processing, breach notification procedures, and how Annex A controls map to KDPA requirements. For context on ODPC enforcement trends, see Kenya Data Protection Act Enforcement Updates.

Surveillance audits are not designed to trip you up. They are designed to confirm the ISMS is a living management system. If it is, you will pass. If it is not, no amount of last-minute documentation will hide that.

SecureZaidi helps East African enterprises achieve and maintain compliance. Get in touch.