Office 140, 254 Chapman Rd, Suite 101-B, Newark, Delaware 19702, USAinfo@iscbonline.com
Resources

ISO 17021 accreditation requirements

The essential ISO/IEC 17021-1 requirements for management-system certification bodies, organised as an implementation checklist.

ISO/IEC 17021-1:2015 sets principles and requirements for bodies that audit and certify management systems. Its purpose is competent, consistent and impartial certification. It applies across management-system disciplines, but sector-specific standards and mandatory documents can add requirements.

Core principles

The operating model should reflect impartiality, competence, responsibility, openness, confidentiality, responsiveness to complaints and a risk-based approach. These are not slogans: assessors expect evidence that they influence governance and decisions.

General and structural requirements

  • A legally enforceable entity, certification agreements and responsibility for certification decisions.
  • Evaluation and continuing treatment of impartiality risks, including links to consultancy.
  • A structure that documents duties, authority and accountability of management and committees.
  • Suitable arrangements for liability and financial stability.

People and competence

The body must determine competence criteria for every certification function and technical area, then evaluate people against those criteria. Records should show selection, training, monitoring, witnessed performance and authorisation. Outsourced auditors and technical experts remain under the certification body’s control.

Information and confidentiality

Public information must accurately explain certification processes, status, fees where appropriate, complaints and appeals, and use of marks. Client and audit information must be protected while statutory or accreditation disclosures are managed lawfully. A current directory of certified clients and status is normally required.

Certification process

The operational system must cover application review, programme design, audit-time determination, planning, initial two-stage audit, reporting, review, independent decision, surveillance, recertification, special audits and transfer where applicable. It also needs controls for expanding or reducing scope and for suspending, withdrawing or restoring certification.

Management system

The certification body needs controlled documents and records, internal audits, corrective action, management review and continual improvement. The system can be structured using the option permitted by the standard, but it must cover all accreditation requirements in practice.

Common readiness gaps

  • Generic competence criteria that do not distinguish technical sectors.
  • Certification decisions made by people involved in the audit.
  • Weak analysis of consultancy, training or related-company conflicts.
  • Audit duration without a documented, reproducible justification.
  • Incomplete public status information or controls over certification marks.

Use the current edition of the standard, the applicable scheme requirements and any recognised mandatory documents. For information-security certification, for example, ISO/IEC 27006-1 adds requirements to ISO/IEC 17021-1.

Primary references