Applicable framework
The assessment hierarchy begins with the primary standard and includes applicable normative, regulatory, scheme-owner and ISCB documents. When requirements conflict, ISCB will identify the controlling criterion before assessment.
- ISO/IEC 17024:2026 is the current primary certification-body standard and replaces the 2012 edition.
- ISO/IEC 17011:2017 governs ISCB's accreditation process and decisions.
- Scheme-owner rules, regulatory requirements and applicable IAF or regional documents form part of the criteria when relevant.
Core organisational requirements
Legal status and responsibility
The applicant must be a legally identifiable entity, or a defined part of one, that can be held responsible for its conformity-assessment activities, contractual obligations and decisions.
Impartiality and independence
Identify, analyse, evaluate, treat, monitor and record risks to impartiality. Commercial, financial, ownership, relationship, consultancy and self-review threats must be controlled continuously.
Confidentiality and information security
Protect confidential information, personal data, intellectual property, examination or scheme security and electronic records. Disclosures must be legally authorised and appropriately communicated.
Organisation and governance
Define authority, responsibilities, reporting lines, committees and safeguards. Technical work, review and decisions must be assigned to competent and appropriately independent functions.
Competence and resources
Set competence criteria for every role affecting accredited activities; evaluate, authorise, monitor and periodically re-evaluate personnel. Control facilities, equipment, software and externally provided resources.
Controlled operations
Accept work only after confirming capability and scope. Use controlled methods and records, handle deviations, review outputs and ensure decisions are traceable to adequate objective evidence.
Management system
Maintain document and record control, risk and opportunity processes, complaints, appeals, nonconforming work, corrective action, internal audit, management review and continual improvement.
Accreditation claims
Claims, certificates, symbols and references to accreditation must be accurate, limited to the granted scope and changed immediately when accreditation is suspended, reduced, withdrawn or expires.
Service-specific technical requirements
- Maintain a valid certification scheme with defined scope, competence requirements, prerequisites, assessment methods, certification criteria, surveillance where used and recertification arrangements.
- Use appropriate subject-matter experts and balanced stakeholder input to develop, review and validate the scheme.
- Separate training interests from certification decisions and manage threats created by related education, examination or commercial activities.
- Develop valid, reliable, fair and secure examinations with controlled item banks, administration, scoring, pass marks, accommodations, appeals and breach response.
- Establish competence and authorization for examiners, invigilators, assessors, reviewers and decision-makers.
- Where artificial intelligence is used, validate outcomes, maintain human oversight, control bias and security, and retain accountable decisions.
Minimum application and readiness evidence
Submit current, approved documents and representative implementation records. Templates without operational evidence are not sufficient.
Assessment, decision and continued accreditation
Application and scope review
ISCB reviews legal identity, requested scope, locations, resources, readiness and applicable criteria before quotation and assessment planning. Acceptance of an application is not a promise of accreditation.
Assessment
Assessment may include document review, office or remote assessment, on-site technical assessment, witnessing, interviews, vertical and horizontal record tracing, and evaluation of representative activities. The mix depends on scope and risk.
Nonconformities and decision
The applicant must determine causes, correct the specific issue, implement proportionate corrective action and provide evidence of effectiveness within the notified period. Accreditation decisions are made independently from assessment and only for demonstrated competence.
Maintenance
Accredited bodies must remain competent, comply with surveillance and reassessment, notify significant changes without delay, cooperate with witnessing and record access, address complaints and nonconformities, and control all accreditation claims.
Principal references
- ISO/IEC 17024:2026
- ISO/IEC 17011:2017
- Applicable scheme-owner or regulatory requirements
- Relevant IAF mandatory or informative documents where formally applicable
Document editions and external publications can change. The edition stated in the accreditation agreement, transition notice or other formal ISCB communication controls the assessment. Applicants should verify current editions before use.
