Key takeaways
- 1The most common, and the easiest to check independently.
- 2Distinct from scope, and less visible.
- 3Three clauses, each with a two-year memory.
A certification body that has never declined an application is not being generous. It is not doing application review.
The standard requires the review to reach a decision, and "no" is one of the available answers. Here are the situations where it is the correct one — and what each says about a body that gives it, or does not.
Outside the accredited scope
The most common, and the easiest to check independently.
Accreditation is granted scheme by scheme and, within a scheme, sector by sector. A body accredited for ISO 9001 is not thereby accredited for ISO 22000. A body accredited for ISO 9001 in construction and IT is not accredited for ISO 9001 in pharmaceuticals.
If your scheme or sector sits outside a body's accredited scope, the honest answer is that it cannot issue you an accredited certificate. Some bodies will offer to issue a non-accredited one instead — which is lawful if labelled clearly, and useless if what your customer asked for was accreditation.
You can check this yourself before applying, on the accreditation body's public register.
No competence for the sector
Distinct from scope, and less visible.
A body can hold accreditation for a technical sector and still not have an auditor competent in your particular processes available. ISO/IEC 17021-1 requires the certification body to determine the competences it needs and confirm it has them before undertaking the audit.
The failure mode here is not a refusal. It is an audit conducted by someone learning your industry at your expense, producing findings that miss what matters and raise what does not.
An impartiality bar
Three clauses, each with a two-year memory.
5.2.7 — consultancy from a body related to the certification body: no certification for at least two years after it ends. 5.2.6 — internal audits performed by the certification body: the same. 5.2.10 — individuals who consulted for you: off your audits for two years.
A body that asks about consultancy and then proceeds regardless has told you what its impartiality controls are worth.
Inability to perform
Working language. Access to sites, including those in other countries. Availability of competent auditors where the work has to happen.
These sound administrative and are not. An audit conducted through interpretation by an auditor who cannot read your records is a weaker audit, and the certificate that results carries that weakness invisibly.
The client who will not allow access
Certification requires the organization to make arrangements for the conduct of audits, including examining documentation and access to all processes, areas, records and personnel — and to accommodate observers such as accreditation assessors or trainee auditors where applicable.
An organization that will not commit to this at application review is telling the certification body that the audit cannot be performed as required. That is a legitimate basis to decline.
An unacceptable relationship
Clause 5.2.3 states that where a relationship poses an unacceptable threat to impartiality — the example given is a wholly owned subsidiary of the certification body requesting certification from its parent — certification shall not be provided. Not mitigated. Not provided.
And clause 5.2.4: a certification body shall not certify another certification body for its quality management system.
What this means when choosing a body
You cannot audit a certification body's application review from outside. But you can ask questions whose answers reveal it.
"Is our scheme and sector inside your accredited scope?" — verifiable on the register while they answer.
"What competence do you hold for our sector, and will that auditor be on our audit?"
"What would make you decline our application?" — the most revealing of the three. A body with a real answer has thought about it. A body that says it never declines has told you that the review is a formality.
"How did you arrive at the day-count?" — asked before you have given shift patterns and outsourced processes, this exposes whether a calculation happened at all.
The uncomfortable part
A body that declines your application has cost you time and given you nothing you can use immediately.
A body that accepts an application it should have declined has given you a certificate — and a risk you will not discover until a customer, an accreditation assessor or a market surveillance authority looks closely.
The second feels better and is worse.
This article is generic information about how certification bodies are required to operate, not advice on any particular certification.
CAS — An EGAC accredited MS certification body No. 012418.
Verify any certificate: cas.com.eg/certsearch
Read next