TQC Accreditation
HomeSchemesISO/IEC 17021-1

Management system certification bodies

Accreditation for bodies that audit and certify management systems, assessed against ISO/IEC 17021-1.

ISO/IEC 17021-1

What this programme covers

This is the largest of the three programmes. It applies to any body that audits an organisation’s management system and issues a certificate stating that the system conforms to a standard — ISO 9001, ISO 14001, ISO 45001 and the rest.

ISO/IEC 17021-1 governs how such a body must be structured, how it must establish and maintain auditor competence, how much time an audit must take for an organisation of a given size and risk, and how the certification decision must be separated from the people who performed the audit.

Standards available within this programme
StandardSubject
ISO 9001:2015Quality management systems
ISO 14001:2015Environmental management systems
ISO 45001:2018Occupational health & safety
ISO 22000:2018Food safety management systems
ISO/IEC 27001:2022Information security management
ISO 13485:2016Medical devices — quality management
ISO 50001:2018Energy management systems

Accreditation is granted against the edition in force. OHSAS 18001 was withdrawn in March 2021 and is not available; ISO 45001:2018 replaces it. ISO/IEC 27001:2022 replaces the 2013 edition.

What is assessed

Assessment covers the whole of the standard, but these are the areas where applications most often need work before accreditation can be granted:

  • Impartiality — ownership, governance and income analysed for threats; a documented mechanism for safeguarding impartiality with input from outside the body.
  • Consultancy separation — no management system consultancy to certification clients, and no internal audit for a client certified by the same body.
  • Auditor competence — defined criteria per standard and per sector, with evidence that each auditor actually meets the criteria for what they are assigned to audit.
  • Audit time — durations determined against a documented basis, with reductions justified rather than assumed.
  • Certification decision — taken by a competent person or panel who did not perform the audit.
  • Certificate control — issue, suspension, withdrawal and reduction of scope handled on a documented process, with certificates carrying the information that lets a third party identify what is covered.
  • Use of marks — a licence agreement with clients governing how the certification and accreditation marks may be used, and enforcement when they are misused.

Witness assessment

We observe your auditors conducting a real certification audit at a real client, in each major sector for which accreditation is sought. This is not a demonstration. Witness assessments are scheduled against your live audit programme and cannot be substituted with a simulated audit.

What we are looking at is whether the audit actually tests conformity — whether the auditor pursues evidence, samples across the scope, and raises findings where findings exist. An audit that produces no findings across a large organisation invites the question of what was examined.

How the scope is expressed

Your accreditation certificate names the standards, the economic sectors and, where relevant, the technical areas covered. It does not say “accredited certification body” without qualification, because no such thing exists. Certifying outside the accredited scope while presenting the certificate as accredited is a breach of the accreditation agreement.