When a food safety management system receives certification, consumers, regulators, and business partners trust that the organization truly meets the required standards. But who ensures that the certification bodies themselves are competent, impartial, and consistent? That’s where ISO/IEC 17021:2006 comes in. This international standard sets rigorous requirements for bodies that audit and certify management systems, establishing a foundation of trust in the entire certification process.
Table of Contents
- What is ISO/IEC 17021:2006?
- Core principles that build trust
- Impartiality
- Competence
- Responsibility
- Openness
- Confidentiality
- Responsiveness to complaints
- Structural and organizational requirements
- Legal and contractual matters
- Management of impartiality
- Non-discriminatory conditions
- Resource requirements: competent personnel
- Outsourcing considerations
- Process requirements: the certification journey
- Initial certification
- Certification decisions
- Maintaining certification
- Management system requirements for certification bodies
- The impact on trust and international trade
- Accreditation to ISO/IEC 17021:2006
What is ISO/IEC 17021:2006?
ISO/IEC 17021:2006 is an international standard that specifies requirements for the competence, consistency, and impartiality of bodies providing audit and certification services for management systems. Whether it’s a quality management system under ISO 9001, an environmental management system under ISO 14001, or a food safety management system under ISO 22000, certification bodies must comply with this standard to ensure their certifications are credible and reliable.
The standard applies specifically to third-party conformity assessment bodies-organizations that provide independent certification services. These certification bodies do not need to offer all types of management system certification, but whatever certifications they do provide must meet the requirements outlined in ISO/IEC 17021:2006.
Core principles that build trust
ISO/IEC 17021:2006 is built on six fundamental principles that ensure certification bodies operate with integrity and inspire confidence in their work.
Impartiality
Certification bodies must remain independent and objective, avoiding any conflicts of interest that could influence their certification decisions. The standard recognizes that certification bodies receive revenue from clients seeking certification, which creates a potential threat to impartiality. To address this, certification bodies must identify and manage all risks to impartiality through documented procedures and organizational structures. They cannot provide both certification and consulting services to the same client for the same management system.
Competence
Certification bodies must employ auditors and personnel with appropriate education, work experience, audit training, and expertise for the management systems they certify. This ensures that when an auditor evaluates a food safety management system in a processing facility, they understand both the requirements of the standard and the specific operational context of food production. The standard requires systems for assessing, monitoring, and continuously improving personnel competence.
Responsibility
Certification bodies bear full responsibility for their certification decisions and audit results. They must clearly define the responsibilities and authority of all personnel involved in the certification process, from auditors conducting on-site evaluations to decision-makers granting certificates.
Openness
Transparency is essential for building confidence. Certification bodies must be open about their policies, procedures, and certification processes. Information about how certification works should be publicly accessible, helping organizations understand what to expect when seeking certification.
Confidentiality
While openness is important, certification bodies must also protect sensitive business information obtained during audits. Strict confidentiality procedures ensure that proprietary information, audit findings, and organizational data remain secure and are only accessed by authorized personnel.
Responsiveness to complaints
Effective complaint handling protects both the certification body and its clients. Certification bodies must have documented procedures for addressing complaints and appeals, ensuring that concerns are investigated fairly and resolved transparently. This provides an important safeguard against errors or unreasonable behavior.
Structural and organizational requirements
ISO/IEC 17021:2006 establishes specific requirements for how certification bodies must be structured and operated.
Legal and contractual matters
Certification bodies must be legally identifiable entities with clear contractual agreements that specify the responsibilities of all parties involved. They must have adequate liability coverage and financial resources to operate effectively and cover potential liabilities.
Management of impartiality
One of the most critical structural requirements is the establishment of an impartiality committee. This committee safeguards the objectivity of certification decisions by providing oversight and including balanced representation from various stakeholder groups-such as clients, customers of certified organizations, regulatory bodies, and industry associations. The committee reviews potential conflicts of interest and ensures that commercial or financial pressures do not compromise certification integrity.
Non-discriminatory conditions
Certification bodies must offer their services fairly to all applicants without discrimination. Access to certification should not depend on the size of the organization or its affiliations.
Resource requirements: competent personnel
The quality of certification depends heavily on the people conducting audits and making certification decisions. ISO/IEC 17021:2006 mandates that certification bodies have rigorous processes for selecting, training, and evaluating personnel.
Auditors must possess specific qualifications including relevant education, work experience in the field they’re auditing, formal audit training, and documented audit experience. For specialized areas like food safety, auditors need both technical knowledge of food production processes and understanding of applicable standards.
Certification bodies must maintain records of personnel competence and provide ongoing training to keep auditors current with evolving standards and industry practices. They must also monitor auditor performance through techniques such as witnessing audits and reviewing audit reports.
Outsourcing considerations
If certification bodies outsource any audit or certification activities, they remain fully responsible for those activities. They must ensure that outsourced personnel meet the same competence, impartiality, and confidentiality requirements as their own staff.
Process requirements: the certification journey
ISO/IEC 17021:2006 outlines specific requirements for the certification process itself, from initial application through ongoing surveillance.
Initial certification
The certification process typically begins with an application review where the certification body evaluates whether it has the competence to audit the organization’s management system. Initial certification involves a two-stage audit process.
Stage 1 focuses on reviewing the organization’s documentation and readiness for certification. Auditors assess whether the management system documentation meets standard requirements, review internal audit and management review processes, and plan the Stage 2 audit based on their findings.
Stage 2 is the comprehensive on-site audit where auditors evaluate whether the management system is effectively implemented and achieving its intended objectives. They examine processes, interview personnel, review records, and verify that practices align with documented procedures.
Certification decisions
After completing the audit, only designated personnel who were not involved in conducting the audit make certification decisions. This separation ensures objectivity. If nonconformities are identified, the organization must implement corrections and corrective actions before certification can be granted.
Maintaining certification
Certification is not a one-time achievement. Organizations must undergo surveillance audits throughout the certification cycle to ensure ongoing compliance. These audits assess whether the management system continues to meet requirements and verify that previous nonconformities have been effectively addressed. Certification bodies must also have procedures for suspending, withdrawing, or reducing the scope of certification when organizations fail to maintain compliance.
Management system requirements for certification bodies
In a requirement that exemplifies “practice what you preach,” ISO/IEC 17021:2006 requires certification bodies to implement their own management systems. These systems must include documented policies, procedures, and processes that support the consistent delivery of certification services.
The certification body’s management system should address document control, record keeping, management review, internal audits, corrective actions, and continual improvement. This ensures that certification bodies maintain the same level of systematic management they evaluate in their clients.
The impact on trust and international trade
ISO/IEC 17021:2006 has significant implications for global commerce and public confidence. By establishing internationally harmonized requirements, the standard facilitates recognition of certification bodies across borders. When a food manufacturer in one country receives certification from an accredited certification body, trading partners and regulators in other countries can trust that the certification meets consistent, rigorous standards.
The standard replaced earlier ISO/IEC Guides 62 and 66, distilling international consensus on best practices and incorporating guidance from the International Accreditation Forum. This harmonization helps increase awareness of and confidence in certification bodies, supporting international trade and reducing the need for multiple certifications in different markets.
Accreditation to ISO/IEC 17021:2006
Many certification bodies seek accreditation to demonstrate their compliance with ISO/IEC 17021:2006. Accreditation bodies assess certification bodies against the standard’s requirements through comprehensive evaluations including documentation review, office assessments, and witnessing of actual audits. This third-party verification provides an additional layer of assurance that certification bodies operate competently and impartially.
What do you think? How important is it to verify that your certification body is accredited to ISO/IEC 17021:2006? Does understanding the rigor behind certification processes change how you view management system certifications in your organization?
Leave a Reply