The statement “Information from external sources, like regulators or complaints, is automatically public and can be disclosed without restriction” is NOT accurate.
Even if information is sourced externally (e.g., from a regulator or complaint), it is not considered public by default and cannot be disclosed freely. Certification bodies and auditors are bound to confidentiality requirements as per ISO/IEC 17021-1 and ISO/IEC 42001 unless legally or contractually obligated to disclose.
[Reference:, ISO/IEC 17021-1:2015, Clause 9.5 – Confidentiality, ISO/IEC 42001:2023, Clause 9.2.2 – Confidentiality and privacy, PECB ISO/IEC 42001 Lead Auditor Study Guide – Section: Confidentiality in Audits, , \===========, ]
Submit