Skip to main content

Why the firm that prepares you cannot be the firm that certifies you

No certification body may prepare you for its own audit, nor may any entity under its organisational control. Where a related body prepares you, it shall not certify you for two years.

8 min read
On this page (7)

No certification body may prepare you for its own audit. Nor may any entity under its organisational control. And where a body it merely has a relationship with does the preparing, the recognised mitigation is that it shall not certify you for two years afterwards.

That is not a courtesy or a market convention. It is six clauses of ISO/IEC 17021-1:2015 — the standard an accreditation body assesses a certification body against — plus a seventh in the ISMS-specific standard that goes further than any of them.

The clauses are short, they are numbered, and they are the most useful thing a buyer can hold up against a proposal. What follows is what each one says.

First, what the standard means by consultancy

ISO/IEC 17021-1:2015 defines the term at clause 3.3. Management system consultancy is "participation in establishing, implementing or maintaining a management system", with two examples given: "Preparing or producing manuals or procedures" and "Giving specific advice, instructions or solutions towards the development and implementation of a management system."

The definition then carves out what is not consultancy, and the carve-out is as load-bearing as the definition. Note 1 permits training, "provided that, where the course relates to management systems or auditing, it is confined to the provision of generic information; i.e. the trainer should not provide client-specific solutions." Note 2 permits "the provision of generic information, but not client specific solutions" — explaining the meaning and intention of certification criteria, identifying improvement opportunities, explaining associated theories and methodologies, and sharing non-confidential information on related best practices.

ISO/IEC 27006-1:2024, which is what an accreditation body assesses an ISMS certification body against, says the same thing in its own words at clause 5.2.2: certification bodies "may add value during certification and surveillance audits (e.g. by identifying opportunities for improvement, as they become evident during the audit, without recommending specific solutions) without it being considered as consultancy or having a potential conflict of interest."

So an auditor telling you a control looks weak is doing their job. An auditor telling you what to put in its place is doing something the standard has a word for. The line falls at the client-specific solution.

The six clauses

5.2.5 — the consultancy bar. "The certification body and any part of the same legal entity and any entity under the organizational control of the certification body [see 9.5.1.2, bullet b)] shall not offer or provide management system consultancy. This also applies to that part of government identified as the certification body."

The bracketed cross-reference matters more than it looks. Clause 9.5.1.2 defines organisational control as whole or majority ownership, majority participation on another entity's board, or documented authority over another entity in a network of legal entities linked by ownership or board control. A separate brand does not clear the bar. A separate subsidiary does not clear the bar.

5.2.6 — the internal-audit bar, with a two-year tail. "The carrying out of internal audits by the certification body and any part of the same legal entity to its certified clients is a significant threat to impartiality. Therefore, the certification body … shall not offer or provide internal audits to its certified clients. A recognized mitigation of this threat is that the certification body shall not certify a management system on which it provided internal audits for a minimum of two years following the completion of the internal audits."

5.2.7 — the related-body bar, with the same tail. "Where a client has received management systems consultancy from a body that has a relationship with a certification body, this is a significant threat to impartiality. A recognized mitigation of this threat is that the certification body shall not certify the management system for a minimum of two years following the end of the consultancy."

Read 5.2.6 and 5.2.7 as a pair and the consequence is concrete: engaging a certification body's affiliate for readiness work does not merely complicate the audit, it puts that certification body out of reach for two years.

5.2.8 — no subcontracting round the problem. "The certification body shall not outsource audits to a management system consultancy organization, as this poses an unacceptable threat to the impartiality of the certification body (see 7.5). This does not apply to individuals contracted as auditors covered in 7.3."

5.2.10 — the same bar, applied to people rather than firms. Personnel who have provided management system consultancy, "including those acting in a managerial capacity, shall not be used by the certification body to take part in an audit or other certification activities if they have been involved in management system consultancy towards the client. A recognized mitigation of this threat is that personnel shall not be used for a minimum of two years following the end of the consultancy."

5.2.9 — and the clause about how it is sold. "The certification body's activities shall not be marketed or offered as linked with the activities of an organization that provides management system consultancy. The certification body shall take action to correct inappropriate links or statements by any consultancy organization stating or implying that certification would be simpler, easier, faster or less expensive if the certification body were used. A certification body shall not state or imply that certification would be simpler, easier, faster or less expensive if a specified consultancy organization were used."

5.2.9 is the one most often overlooked, and it is the one that reaches marketing material. It obliges the certification body to go and correct a consultancy's claims about it — which means a packaged offer naming a certification body is that body's problem whether or not it wrote the page.

The clause written for an ISMS specifically

ISO/IEC 27006-1:2024 clause 5.2.1 applies the whole of ISO/IEC 17021-1:2015 clause 5.2, then adds this at 5.2.2:

"The certification body shall not provide internal information security reviews of the client's ISMS subject to certification. Furthermore, the certification body shall be independent from the body or bodies (including any individuals) which provide the internal ISMS audit."

The second sentence is the strongest in the set. Clause 5.2.6 of 17021-1 stops the certification body doing your internal audit itself. This one requires the certification body to be independent of whoever does. The mandatory internal audit under ISO/IEC 27001:2022 clause 9.2 therefore has to come from a party that is not your certifier and is not connected to your certifier — not as a preference, as a condition of the certification body's own accreditation.

Why the scheme is built this way

Clause 4.2.4 lists the threats the requirements exist to control, and one of them is named with this exact fact pattern:

"Self-review: threats that arise from a person or body reviewing the work done by themselves. Auditing the management systems of a client to whom the certification body provided management systems consultancy would be a self-review threat."

Clause 5.2.3 then requires a documented process to identify, analyse, evaluate, treat and monitor conflict-of-interest risks, with the instruction that "when a relationship poses an unacceptable threat to impartiality … then certification shall not be provided."

A certificate is read by someone who has met none of the parties. It carries information only if the body that issued it had nothing invested in the answer.

Reading a proposal against the clauses

A proposal that carries you from gap analysis to certificate under one signature is one of two things, and the two lead to different questions.

If the seller is not a certification body, the certificate is coming from one you have not been introduced to. Ask which body, ask which accreditation body has accredited it and for which scheme, and ask whether the seller has a relationship with it — 5.2.7 is measured on the relationship, not on the invoice.

If the seller is a certification body, or under one's organisational control, then 5.2.5 governs the readiness half of the offer, 5.2.9 governs how it is described, and 5.2.10 governs which of their people can be near your audit.

Three questions cover both cases. Which certification body issues the certificate? Who performs the clause 9.2 internal audit, and what is their relationship to that body? And which parts of this proposal are the certification body's own work?

The same rule, arrived at differently: SOC 2

A SOC 2 examination is performed under AT-C section 105, Concepts Common to All Attestation Engagements, and AT-C section 205, Assertion-Based Examination Engagements. AT-C 105.26 states the requirement without qualification: "The practitioner must be independent when performing an attestation engagement in accordance with the attestation standards unless the practitioner is required by law or regulation to accept the engagement." Paragraph .27's first precondition is structural in the same way ISO's clauses are — the practitioner must determine "whether the responsible party is a party other than the practitioner and takes responsibility for the underlying subject matter."

The mechanism differs from ISO's, and the difference is worth getting right. The AICPA routes preparatory work for an attest client through ET section 1.295, on nonattest services. Clause 1.295.030 makes "accepting responsibility for designing, implementing, or maintaining internal control" a management responsibility — and "if a member were to assume a management responsibility for an attest client, the management participation threat would be so significant that no safeguards could reduce the threat to an acceptable level and independence would be impaired." Clause 1.295.040 then permits nonattest services only where the client agrees to assume all management responsibilities, to oversee the service through a named individual with suitable skill, knowledge or experience, to evaluate the adequacy and results of the work, and to accept responsibility for those results — with the understanding documented in writing beforehand. ET section 1.297 sets the independence requirements specific to engagements performed under the attestation standards.

Two professions, two mechanisms, one destination: the party that builds the thing and the party that reports on it are held apart, and the separation is a condition of the report meaning anything.

Where we sit

Security Brigade does the readiness half and only the readiness half: scope and boundary definition, risk assessment and treatment, the Statement of Applicability, control implementation, the clause 9.2 internal audit, management review preparation, and the evidence base a certification body reads at Stage 1 and Stage 2. The certificate comes from an accredited certification body, and the clauses above are why that is a different supplier.

If you want the wider picture first — which party produces which document, and what accreditation adds to a certificate — start with who issues an ISO 27001 certificate.

Every clause number and quotation above was checked against published standards text on 27 August 2026.