ISO/IEC 17024 Standard
Conformity Assessment — General Requirements for Bodies Operating Certification of Persons
The ISO/IEC 17024 standard is the global benchmark that specifies the requirements for the competence, consistent operation, and impartiality of certification bodies certifying individuals. It serves as the framework that ensures professional certifications (e.g., Welders, Project Managers, Cyber Security Experts, NDT Technicians) are awarded based on a fair, valid, and reliable assessment of a person's real-world capabilities.
1. Overview of the Standard
Developed by the ISO Committee on Conformity Assessment (CASCO), ISO/IEC 17024 is designed to harmonize the certification process for individuals worldwide. The core objective is to ensure that the certified individual has met a recognized set of skills and competencies. Unlike education or training degrees, which focus on completed coursework, this standard focuses strictly on ongoing competence. A key rule of the standard is the strict separation of training and certification to prevent conflicts of interest—a body cannot legally teach a specific course and then turn around and certify their own students under the same accredited umbrella without rigorous firewalls.
2. Target Sectors Served by the Standard
ISO/IEC 17024 is utilized across industries where professional competence directly impacts safety, security, and economic risk. Major application areas include:
Engineering and Technical Trades: Certification of non-destructive testing (NDT) personnel, welders, crane operators, and electricians.
Information Technology and Cyber Security: Certifications for ethical hackers, data protection officers, and cloud architects.
Project Management and Business: Frameworks validating project managers, risk analysts, and management consultants.
Healthcare and Safety: Professional credentials for occupational health officers, safety inspectors, and specialized medical technicians.
Financial and Legal Services: Certification of financial auditors, anti-money laundering specialists, and legal compliance officers.
3. Key Clauses of the Standard
The standard is meticulously organized to control the entire life cycle of personnel certification schemes:
Clause 1: Scope: Outlines the requirements for bodies managing a certification scheme for persons.
Clause 2: Normative References: Lists foundational standard documents relevant to the text.
Clause 3: Terms and Definitions: Defines essential jargon such as "certification scheme", "competence", "examination", and "applicant".
Clause 4: General Requirements:
Impartiality: Managing risks to fairness and ensuring no financial or commercial bias compromises the certification process.
Financial and Legal Liability: Ensuring appropriate legal status and adequate financial reserves.
Clause 5: Structural Requirements:
Establishing a clear organization chart and appointing a scheme committee that represents a balanced interest of stakeholders.
Clause 6: Resource Requirements:
Personnel: Competence requirements for internal staff, examiners, and assessors.
Outsourcing: Strictly controlling any external contracts for exam venues or proctoring services.
Clause 7: Records and Information Requirements:
Secure management of applicant records, verifying certificates, and maintaining a publicly accessible directory of certified individuals.
Clause 8: Certification Schemes:
Mandates how a "Certification Scheme" must be built, including definition of job roles, required competencies, prerequisites, and re-certification cycles.
Clause 9: Process Requirements:
Application & Assessment: The registration process and evaluating candidate eligibility.
Examinations: Designing exams that are valid, reliable, and secure (written, practical, or oral).
Decision on Certification: Ensuring the final pass/fail decision is made by individuals separate from those who examined the candidate.
Recertification: Ensuring the individual maintains their skills over time (e.g., every 3 to 5 years).
Clause 10: Management System Requirements:
Specifies how the certification body controls its own internal policies, audits, documents, and corrective actions (similar to ISO 9001).