Office 140, 254 Chapman Rd, Suite 101-B, Newark, Delaware 19702, USAinfo@iscbonline.com
ISCB-RQ-17021 · Issue 1 - September 2026

Management System Certification Body Accreditation Requirements

Applies to bodies seeking accreditation to audit and certify organisations against specified management system standards and sector schemes.

Document status and use

This ISCB applicant guide sets out the evidence and operating controls normally expected for this accreditation programme. It does not reproduce or replace the applicable ISO or ISO/IEC standard. Applicants must hold an authorised current copy and comply with all applicable requirements, legislation, scheme rules and formally issued ISCB criteria.

No recognition claim: references to IAF or ILAC publications identify technical criteria that may be relevant; they do not by themselves state or imply that ISCB is an IAF or ILAC arrangement signatory.

01

Applicable framework

The assessment hierarchy begins with the primary standard and includes applicable normative, regulatory, scheme-owner and ISCB documents. When requirements conflict, ISCB will identify the controlling criterion before assessment.

  • ISO/IEC 17021-1:2015 is the primary certification-body standard.
  • ISO/IEC 17011:2017 governs ISCB's accreditation process and decisions.
  • Current IAF Mandatory Documents and scheme-specific normative documents apply according to the requested accreditation scope.
02

Core organisational requirements

Legal status and responsibility

The applicant must be a legally identifiable entity, or a defined part of one, that can be held responsible for its conformity-assessment activities, contractual obligations and decisions.

Impartiality and independence

Identify, analyse, evaluate, treat, monitor and record risks to impartiality. Commercial, financial, ownership, relationship, consultancy and self-review threats must be controlled continuously.

Confidentiality and information security

Protect confidential information, personal data, intellectual property, examination or scheme security and electronic records. Disclosures must be legally authorised and appropriately communicated.

Organisation and governance

Define authority, responsibilities, reporting lines, committees and safeguards. Technical work, review and decisions must be assigned to competent and appropriately independent functions.

Competence and resources

Set competence criteria for every role affecting accredited activities; evaluate, authorise, monitor and periodically re-evaluate personnel. Control facilities, equipment, software and externally provided resources.

Controlled operations

Accept work only after confirming capability and scope. Use controlled methods and records, handle deviations, review outputs and ensure decisions are traceable to adequate objective evidence.

Management system

Maintain document and record control, risk and opportunity processes, complaints, appeals, nonconforming work, corrective action, internal audit, management review and continual improvement.

Accreditation claims

Claims, certificates, symbols and references to accreditation must be accurate, limited to the granted scope and changed immediately when accreditation is suspended, reduced, withdrawn or expires.

03

Service-specific technical requirements

  1. Define each certification scope using the applicable management-system standard, technical sector classification, geography and certification activity.
  2. Operate a documented impartiality process with top-management commitment, threat analysis, stakeholder input and effective safeguards.
  3. Establish competence criteria and evaluation processes for application reviewers, auditors, technical experts, reviewers and certification decision-makers by scheme and technical area.
  4. Control application review, audit time, multi-site sampling, audit planning, stage 1, stage 2, surveillance, recertification, special audits, transfer and restoration.
  5. Ensure independent review and certification decisions, certificate content, public status information and controls over marks and claims.
  6. Maintain witnessed-audit readiness and reliable certification data required by applicable schemes and IAF documents.
04

Minimum application and readiness evidence

Submit current, approved documents and representative implementation records. Templates without operational evidence are not sufficient.

01Legal identity, liability and impartiality committee or equivalent mechanism
02Scope matrix and scheme approvals sought
03Competence criteria, technical codes, auditor files and witnessed evaluations
04Application reviews, audit-time calculations and multi-site rationale
05Complete initial, surveillance, recertification and transfer files
06Independent review and decision records
07Certificate register, mark controls and public-status process
08Internal audit, management review, complaints, appeals and corrective actions
05

Assessment, decision and continued accreditation

Application and scope review

ISCB reviews legal identity, requested scope, locations, resources, readiness and applicable criteria before quotation and assessment planning. Acceptance of an application is not a promise of accreditation.

Assessment

Assessment may include document review, office or remote assessment, on-site technical assessment, witnessing, interviews, vertical and horizontal record tracing, and evaluation of representative activities. The mix depends on scope and risk.

Nonconformities and decision

The applicant must determine causes, correct the specific issue, implement proportionate corrective action and provide evidence of effectiveness within the notified period. Accreditation decisions are made independently from assessment and only for demonstrated competence.

Maintenance

Accredited bodies must remain competent, comply with surveillance and reassessment, notify significant changes without delay, cooperate with witnessing and record access, address complaints and nonconformities, and control all accreditation claims.

06

Principal references

  • ISO/IEC 17021-1:2015
  • Applicable ISO/IEC 17021 series competence documents
  • IAF MD 1, MD 2, MD 4:2025, MD 5, MD 11, MD 15, MD 17 and MD 28
  • Scheme-specific IAF MDs and normative documents, where applicable

Document editions and external publications can change. The edition stated in the accreditation agreement, transition notice or other formal ISCB communication controls the assessment. Applicants should verify current editions before use.

Next step

Use the guide to prepare objective evidence