Finnco, a subsidiary of a certification body, provided ISMS consultancy services to an organization. Considering this scenario, when can the certification body certify the organization?
A.
There is no time constraint in such a situation
B.
The certification body can certify the organization immediately after consulting services end
C.
If a minimum period of two years has passed since the last consulting activities
ISO/IEC 17021-1:2015 (Requirements for Certification Bodies) prohibits certification bodies from certifying organizations they have provided consultancy services to, unless a two-year separation period is maintained.
This prevents conflicts of interest and ensures independent certification audits.
A. Incorrect:
There is a strict time constraint to prevent certification bias.
B. Incorrect:
Certification cannot happen immediately after consulting services end, as this would create an independence conflict.
Relevant Standard Reference:
ISO/IEC 17021-1:2015 Clause 5.2.4 (Impartiality in Certification Activities)
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit