What this programme covers
This is the largest of the three programmes. It applies to any body that audits an organisation’s management system and issues a certificate stating that the system conforms to a standard — ISO 9001, ISO 14001, ISO 45001 and the rest.
ISO/IEC 17021-1 governs how such a body must be structured, how it must establish and maintain auditor competence, how much time an audit must take for an organisation of a given size and risk, and how the certification decision must be separated from the people who performed the audit.
| Standard | Subject |
|---|---|
| ISO 9001:2015 | Quality management systems |
| ISO 14001:2015 | Environmental management systems |
| ISO 45001:2018 | Occupational health & safety |
| ISO 22000:2018 | Food safety management systems |
| ISO/IEC 27001:2022 | Information security management |
| ISO 13485:2016 | Medical devices — quality management |
| ISO 50001:2018 | Energy management systems |
Accreditation is granted against the edition in force. OHSAS 18001 was withdrawn in March 2021 and is not available; ISO 45001:2018 replaces it. ISO/IEC 27001:2022 replaces the 2013 edition.
What is assessed
Assessment covers the whole of the standard, but these are the areas where applications most often need work before accreditation can be granted:
- Impartiality — ownership, governance and income analysed for threats; a documented mechanism for safeguarding impartiality with input from outside the body.
- Consultancy separation — no management system consultancy to certification clients, and no internal audit for a client certified by the same body.
- Auditor competence — defined criteria per standard and per sector, with evidence that each auditor actually meets the criteria for what they are assigned to audit.
- Audit time — durations determined against a documented basis, with reductions justified rather than assumed.
- Certification decision — taken by a competent person or panel who did not perform the audit.
- Certificate control — issue, suspension, withdrawal and reduction of scope handled on a documented process, with certificates carrying the information that lets a third party identify what is covered.
- Use of marks — a licence agreement with clients governing how the certification and accreditation marks may be used, and enforcement when they are misused.
Witness assessment
We observe your auditors conducting a real certification audit at a real client, in each major sector for which accreditation is sought. This is not a demonstration. Witness assessments are scheduled against your live audit programme and cannot be substituted with a simulated audit.
What we are looking at is whether the audit actually tests conformity — whether the auditor pursues evidence, samples across the scope, and raises findings where findings exist. An audit that produces no findings across a large organisation invites the question of what was examined.
How the scope is expressed
Your accreditation certificate names the standards, the economic sectors and, where relevant, the technical areas covered. It does not say “accredited certification body” without qualification, because no such thing exists. Certifying outside the accredited scope while presenting the certificate as accredited is a breach of the accreditation agreement.

