ISO/IEC 17021-1:2015 sets principles and requirements for bodies that audit and certify management systems. Its purpose is competent, consistent and impartial certification. It applies across management-system disciplines, but sector-specific standards and mandatory documents can add requirements.
Core principles
The operating model should reflect impartiality, competence, responsibility, openness, confidentiality, responsiveness to complaints and a risk-based approach. These are not slogans: assessors expect evidence that they influence governance and decisions.
General and structural requirements
- A legally enforceable entity, certification agreements and responsibility for certification decisions.
- Evaluation and continuing treatment of impartiality risks, including links to consultancy.
- A structure that documents duties, authority and accountability of management and committees.
- Suitable arrangements for liability and financial stability.
People and competence
The body must determine competence criteria for every certification function and technical area, then evaluate people against those criteria. Records should show selection, training, monitoring, witnessed performance and authorisation. Outsourced auditors and technical experts remain under the certification body’s control.
Information and confidentiality
Public information must accurately explain certification processes, status, fees where appropriate, complaints and appeals, and use of marks. Client and audit information must be protected while statutory or accreditation disclosures are managed lawfully. A current directory of certified clients and status is normally required.
Certification process
The operational system must cover application review, programme design, audit-time determination, planning, initial two-stage audit, reporting, review, independent decision, surveillance, recertification, special audits and transfer where applicable. It also needs controls for expanding or reducing scope and for suspending, withdrawing or restoring certification.
Management system
The certification body needs controlled documents and records, internal audits, corrective action, management review and continual improvement. The system can be structured using the option permitted by the standard, but it must cover all accreditation requirements in practice.
Common readiness gaps
- Generic competence criteria that do not distinguish technical sectors.
- Certification decisions made by people involved in the audit.
- Weak analysis of consultancy, training or related-company conflicts.
- Audit duration without a documented, reproducible justification.
- Incomplete public status information or controls over certification marks.
Use the current edition of the standard, the applicable scheme requirements and any recognised mandatory documents. For information-security certification, for example, ISO/IEC 27006-1 adds requirements to ISO/IEC 17021-1.
