Key takeaways
- 1Clause 5.2.1 states the principle: conformity assessment activities shall be undertaken impartially, and the certification body shall not allow commercial, financial or other pressures to compromise impartiality.
- 2Some relationships are not risks to be managed.
- 3The two-year rule for people. Clause 5.2.10: personnel who have provided management system consultancy to a client, including in a managerial capacity, shall not take part in the audit or other certification activities for that client; the recognized mitigation is a minimum of two years since the consultancy ended.
A certification body is paid by the organizations it certifies. That sentence describes every accredited certification body in the world, and it is the reason impartiality is not left to good intentions. ISO/IEC 17021-1 turns it into a set of requirements, and an accreditation body checks that they are met. This is what that looks like from the inside.
The principle, and the requirement that makes it real
Clause 5.2.1 states the principle: conformity assessment activities shall be undertaken impartially, and the certification body shall not allow commercial, financial or other pressures to compromise impartiality.
Clause 5.2.3 is where it becomes work. The certification body shall have a process to identify, analyse, evaluate, treat, monitor and document the risks related to conflicts of interest arising from providing certification — on an ongoing basis. Where there is a threat, the body shall document how it eliminates or minimizes it, and document any residual risk. Top management shall review that residual risk and decide whether it is acceptable.
Note 1 to that clause lists where threats come from: ownership, governance, management, personnel, shared resources, finances, contracts, training, marketing, and the payment of a sales commission or other inducement for the referral of new clients. It is a longer list than most people expect, and it is the list a certification body is assessed against.
What is prohibited outright
Some relationships are not risks to be managed. They are closed off.
Consultancy. Clause 5.2.5: the certification body, any part of the same legal entity and any entity under its organizational control shall not offer or provide management system consultancy. The note clarifies that explaining a finding or clarifying a requirement is not consultancy. Designing the client's system is.
Internal audits for certified clients. Clause 5.2.6 names this a significant threat and prohibits it, with a two-year separation before certifying a system on which internal audits were provided.
Certifying another certification body's quality management system. Clause 5.2.4, in one line.
Outsourcing audits to a consultancy organization. Clause 5.2.8 calls this an unacceptable threat. Individual contracted auditors, under the competence requirements of clause 7.3, are a different matter.
Marketing that links certification to a consultancy. Clause 5.2.9: the body's activities shall not be marketed as linked with a consultancy, and the body shall correct any consultancy's claim that certification would be simpler, easier, faster or less expensive if that body were used — and shall not make the mirror claim itself.
What is managed rather than prohibited
The two-year rule for people. Clause 5.2.10: personnel who have provided management system consultancy to a client, including in a managerial capacity, shall not take part in the audit or other certification activities for that client; the recognized mitigation is a minimum of two years since the consultancy ended. The same two-year separation applies under 5.2.7 where the client's consultant has a relationship with the certification body.
Declared conflicts. Clause 5.2.13: every person, internal or external, shall reveal any situation known to them that could present a conflict of interest, the body shall record and use that information, and shall not use the person unless it can demonstrate there is no conflict. At CAS every auditor and every member of the decision function signs a declaration for each assignment, and a prior relationship with the client — employment, consultancy, a family connection — removes them from it.
Pressure from outside. Clause 5.2.11: the body shall act on threats to impartiality arising from other persons, bodies or organizations. That covers a client who asks for a particular auditor, and a reseller who implies a result.
Where the outside view comes in
Clause 5.2.3 requires the risk process to include identification of, and consultation with, interested parties on matters affecting impartiality — balanced, with no single interest predominating. Note 3 says one way to do this is a committee of those parties.
That committee cannot see the auditors' declarations one by one; it sees the process, the register of threats, the residual risks and the decisions taken. Its job is to say, from outside, whether the safeguards are adequate — and its minutes are among the records the accreditation body reads.
How this reaches a certificate
Three mechanisms, and a certificate depends on all of them.
The auditor who visits has declared no conflict for that assignment, and is not the person who takes the decision. The decision is taken by a person or group who did not audit — ISO/IEC 17021-1 separates the two functions deliberately. The whole arrangement is reviewed by an impartiality committee, and assessed by EGAC when it assesses CAS.
None of this is visible on the certificate. It is visible in the accreditation, which is why an accredited certificate is worth checking and a non-accredited one is harder to place.
What this means for you
If you are choosing a certification body: ask how impartiality is managed, and ask who takes the decision. A body that can answer both in one breath has done the work.
If you are using a consultant: expect the certification body to ask about that relationship, and expect the two-year rule to be applied if the consultant is connected to the body. That is the requirement working, not an obstacle.
If you are certified: your auditor cannot advise you on how to close a finding. That is not unhelpfulness. It is clause 5.2.5.
CAS — An EGAC accredited MS certification body No. 012418. Accredited scope: ISO 9001, ISO 14001, ISO 45001, ISO 22000, ISO 50001 and ISO 22301. Certificates accredited for ISO 9001, 14001, 45001, 22000 and 50001 fall within EGAC's IAF MLA scope; ISO 22301 is accredited by EGAC and sits outside that scope.
Verify any certificate: cas.com.eg/certsearch
Read next