ISO/IEC 17021-1 Standard
Conformity Assessment — Requirements for Bodies Providing Audit and Certification of Management Systems
The ISO/IEC 17021-1 standard is the definitive international benchmark that specifies the requirements for the competence, consistency, and impartiality of certification bodies (often called registrars) that audit and certify organizations' management systems. It is the framework that ensures if a company claims to be certified to standards like ISO 9001, ISO 14001, or ISO 45001, the certificate is credible and globally recognized.
1. Overview of the Standard
Developed by the ISO Committee on Conformity Assessment (CASCO), ISO/IEC 17021-1 ensures that the certification process is conducted in a competent, consistent, and impartial manner. The core purpose of this standard is to inspire user confidence in certificates issued by accredited bodies. It outlines strict rules to prevent conflicts of interest, such as a certification body offering consultancy services to the same company it intends to audit.
2. Target Sectors Served by the Standard
Unlike standards meant for specific products, ISO/IEC 17021-1 governs the bodies that audit management systems across all industries. The core management systems certified under this standard include:
Quality Management Systems (QMS): Auditing organizations against ISO 9001 across manufacturing, technology, and service industries.
Environmental Management Systems (EMS): Auditing organizations against ISO 14001 for heavy industries, chemical plants, and construction sectors.
Occupational Health and Safety (OH&S): Auditing organizations against ISO 45001 in high-risk environments like oil and gas, mining, and logistics.
Information Security Management Systems (ISMS): Auditing organizations against ISO/IEC 27001 for IT firms, data centers, banking, and government agencies.
Food Safety Management Systems (FSMS): Auditing organizations against ISO 22000 along the food supply chain, from farms to packaging plants.
3. Key Clauses of the Standard
The standard is built around a structured framework designed to maintain strict control over the auditing and certification lifecycle:
Clause 1: Scope: Defines the requirements for bodies providing audit and certification of management systems.
Clause 2: Normative References: Lists foundational standards required to implement this document.
Clause 3: Terms and Definitions: Clarifies terms like "certified client", "impartiality", and "audit program".
Clause 4: Principles: Establishes the guiding pillars for certification, including Impartiality, Competence, Responsibility, Openness, Confidentiality, and Responsiveness to complaints.
Clause 5: General Requirements:
Legal and Contractual Matters: Legal status and certification agreements.
Management of Impartiality: Identifying, analyzing, and documenting conflicts of interest.
Liability and Financing: Ensuring adequate financial resources and liability insurance.
Clause 6: Structural Requirements:
Organizational structure, top management duties, and operational control.
Clause 7: Resource Requirements:
Competence of Personnel: Defining competence criteria for auditors, technical reviewers, and administrative staff.
Personnel Involved in Certification Activities: Training, monitoring, and maintaining auditor records.
Use of Individual External Auditors: Rules for outsourcing audit personnel.
Clause 8: Information Requirements:
Maintaining public information regarding certified clients, directory lookups, and the correct use of certification marks/logos.
Clause 9: Process Requirements:
Pre-certification activities: Application review and determining audit time.
Planning audits: Developing an audit program and appointing the audit team.
Conducting audits: Managing Stage 1 (readiness review) and Stage 2 (on-site evaluation) audits.
Certification decisions: Ensuring the decision to grant or renew certification is made by individuals who did not conduct the audit.
Maintaining certification: Surveillance audits, recertification, and handling suspensions or withdrawals.
Clause 10: Management System Requirements for Certification Bodies:
Requirements for the certification body's own internal management system (Control of documents, internal audits, management reviews, and corrective actions).