15.2 Follow-Up, Action Plans & Surveillance Audits
Key Takeaways
- Follow-up verifies correction and corrective action effectiveness for reported nonconformities—not just that a form was closed
- Action plans should address root cause, correction, corrective action, responsibilities, and due dates appropriate to NC severity
- Surveillance audits maintain confidence between certification and recertification, typically on an annual rhythm within a three-year cycle
- Surveillance focuses on EMS maintenance, significant changes, complaints, objectives/performance, and progress on previous NCs
- Special audits may be triggered by complaints, serious incidents, or major changes outside the routine programme
15.2 Follow-Up, Action Plans & Surveillance Audits
Quick Answer: After the audit report, the organization must correct nonconformities and eliminate causes through corrective action. Auditors / the CB verify effectiveness. Surveillance audits then maintain confidence that the certified EMS continues to conform between initial certification and recertification—usually yearly in a three-year certification cycle under ISO/IEC 17021-1 practice.
Why this section matters
Certification is not a one-day trophy. Domain 6 expects Lead Auditors to connect reporting to follow-up and to the audit programme that keeps certificates meaningful. Exam scenarios often test whether you know the difference between correction and corrective action, how soon major vs. minor NCs must be addressed, what surveillance must cover, and when a special audit is justified.
Follow-up after nonconformities
ISO 19011 addresses audit follow-up: the completeness and effectiveness of actions taken in response to findings should be verified. In certification schemes under ISO/IEC 17021-1, the CB defines rules for:
- Acceptable response timeframes
- Evidence required (correction, root-cause analysis, corrective action, and later effectiveness checks)
- Whether major nonconformities block certification / continued certification until adequately addressed
- Who verifies (on-site, remote document review, or at the next audit)—based on risk and severity
Correction vs. corrective action (exam favorite)
| Term | Meaning | EMS example |
|---|---|---|
| Correction | Action to eliminate a detected nonconformity | Stop an unbundled hazardous-waste stream and move drums to a compliant storage area |
| Corrective action | Action to eliminate the cause of a nonconformity to prevent recurrence | Redesign waste segregation training, update operational control, and add supervisory checks because root cause was unclear labeling + contractor handover gaps |
| Correction without CA | Fixes the instance but leaves the system weak | Drums moved once, but labeling process and contractor controls unchanged |
Lead Auditor answers must not treat “we fixed it today” as sufficient when the scheme requires cause analysis and systemic corrective action—especially for majors.
Action plan quality criteria
A credible client action plan typically includes:
- NC reference matching the report / NCR ID and clause
- Immediate correction and containment (including environmental impact mitigation if needed)
- Root-cause analysis method appropriate to complexity (5-Why, fishbone, fault tree—not a one-line blame statement)
- Corrective actions tied to the identified causes (procedure, competence, resources, monitoring, supplier control, etc.)
- Responsibilities and due dates realistic for severity
- Evidence the CB/auditor will receive (photos, revised documented information, training records, monitoring data)
- Effectiveness verification method and timing (how the organization will know recurrence stopped)
Weak plans say “retrain staff” for every NC. Strong plans explain why the failure occurred (e.g., temporary workers not in competence matrix; emergency drill never tested spill kits at the tank farm) and change the system accordingly.
Verification of effectiveness
Verification asks: Did the actions work? Evidence may include:
- Recurrence checks over a defined period
- Updated monitoring results for the related aspect/impact
- Observation that the new control is implemented, not only written
- Interview confirmation that affected personnel understand the change
- Closure of related compliance obligation gaps where the NC touched legal/other requirements
Closing an NC because a procedure PDF was emailed is not effectiveness verification. For environmental NCs, look for operational evidence: segregation in the yard, calibrated meters in use, drill records with evaluated results, compliance evaluation follow-through.
The certification cycle and surveillance
Accredited CBs typically operate a three-year certification cycle:
- Initial certification — Stage 1 + Stage 2 (and successful NC closure per rules)
- Surveillance audits — usually at least annually to maintain confidence
- Recertification — before cycle end to renew certification
Surveillance is not a miniature Stage 2 of the entire EMS every time, but it is also not a courtesy visit. Its purpose is to confirm the certified management system continues to fulfill requirements.
Typical surveillance focus areas
Programme details vary, but Lead Auditors should expect surveillance to sample and evaluate:
- Internal audits and management review effectiveness
- Progress on continual improvement and environmental objectives / performance information
- Review of actions on nonconformities from previous audits
- Complaint handling and stakeholder/regulatory issues relevant to the EMS
- Effectiveness of operational controls for significant aspects and compliance obligations
- Changes to the organization: processes, sites, outsourcing, legal context, leadership, or scope
- Use of marks / certificate claims (misuse can trigger action)
- Continuing suitability of resources and competence for EMS roles
High-risk or previously weak areas should be re-sampled. If Stage 2 found fragile emergency preparedness, surveillance should not ignore Clause 8.2 simply because “documents looked fine last year.”
Planning surveillance within the audit programme
ISO/IEC 17021-1 expects the CB to manage an audit programme for the full cycle. Practically:
- First surveillance is often scheduled within a defined window after initial certification (commonly around 12 months, per CB rules)
- Subsequent surveillance maintains coverage so that over the cycle, critical processes and sites receive appropriate attention
- Multi-site schemes follow justified sampling plans; surveillance may rotate sites while still addressing central functions
- Audit duration still reflects size, complexity, environmental risk, and prior performance—not a fixed “half-day for everyone”
Special audits and short-notice audits
Outside routine surveillance, CBs may conduct special audits when justified, for example:
- Serious environmental incidents, regulatory enforcement, or credible complaints
- Significant changes (new processes with major aspects, mergers, scope expansion requests)
- Follow-up on major nonconformities requiring on-site verification
- Concerns about misuse of certification status
Short-notice or unannounced elements may be used where programme rules allow and impartiality/safety are managed. Exam tip: special audits respond to risk and change; they are not punishment for asking questions.
Client and auditor responsibilities during follow-up & surveillance
Organization: owns conformity every day; submits timely responses; implements actions; does not wait for the next auditor to discover recurrence; communicates significant changes to the CB as required by the certification agreement.
Audit team: evaluates evidence impartially; does not consult by designing the corrective actions; records residual risk if actions are incomplete; escalates integrity issues (falsified evidence, deliberate concealment).
CB: maintains programme control; reviews team recommendations; decides on continued certification, suspension, or other actions when surveillance or follow-up fails.
Common exam traps
- Equating surveillance with recertification — Surveillance maintains; recertification renews for a new cycle with a broader confirmation of continued conformity and effectiveness.
- Accepting correction as corrective action — Especially wrong for systemic or major NCs.
- Assuming every NC requires an immediate on-site revisit — Verification method depends on severity and CB rules; some minors may be checked at next surveillance if allowed.
- Treating surveillance as optional “check-in” — Failure to conduct required surveillance jeopardizes certification validity.
- Auditor writing the client’s root-cause analysis — That crosses into consulting and threatens impartiality.
Linking follow-up to Total Hours of learning on the job
In practice, strong lead auditors spend disciplined time reviewing action evidence and re-testing controls—not only ticking “closed.” That rigor protects environmental performance and certificate credibility. On the exam, choose the answer that preserves evidence-based verification and CB programme integrity over speed or client convenience.
When follow-up is thorough and surveillance is risk-based, the certificate remains a trustworthy signal between Stage 2 and recertification—not a historical snapshot that quietly expires in practice while still hanging on the wall.
A site moves mislabeled waste drums into compliant storage the same day an NC is raised, but does not change labeling or contractor handover controls. What has primarily occurred?
What is the primary purpose of surveillance audits in an ISO 14001 certification cycle?
Which set of topics is most appropriate for a routine ISO 14001 surveillance audit sample?
When is a special audit most justified?