All posts

Why Your Consultant Cannot Certify You

Independence rules decide who is allowed to sign your certificate. Understanding them before you buy saves an engagement.

Published 3 min readBy the Auditly teamDiesen Beitrag auf Deutsch lesenLire cet article en français

A firm helps you build your management system. They know your environment, they wrote half your policies, and they are the obvious people to certify the result. Then you discover they cannot, and the certification has to start again with somebody who has never seen your organisation.

This is one of the more expensive surprises in compliance work, and it is entirely avoidable if you know the rule before you sign.

The rule

ISO/IEC 17021-1 is the standard that certification bodies themselves are accredited against. It sets out how they must be structured, how they must manage impartiality, and what they may not do.

Clause 5.2.6 is the relevant one: a certification body may not certify a management system on which it has provided consultancy within the previous two years. That covers the body, and it covers a body under the same organisational control.

The reasoning is not bureaucratic. A certification audit is an independent opinion on whether your system meets the standard. If the auditor designed the system, they are reviewing their own work, and the certificate stops being evidence of anything a third party can rely on. The value of the certificate to your customers rests entirely on the auditor not having been involved in building what they are assessing.

What counts as consultancy

More than people assume. The standard treats it as participation in designing, implementing or maintaining the management system. In practice:

  • Writing your policies or procedures for you
  • Designing your controls
  • Building your risk assessment methodology
  • Acting in an internal audit capacity for the system being certified
  • Providing specific advice or solutions toward implementation

What is not consultancy: training on the standard itself, provided it is generic and not organisation-specific; and the audit activity, including the findings. An auditor telling you that a control is missing is doing their job. An auditor telling you how to design the replacement is not.

That line matters during the engagement. Auditors who tell you exactly what to write are creating a problem for the certificate they are about to issue, and a good one will decline to.

How this shapes your buying

Plan for two suppliers.

The readiness side. A consultant, an advisory firm or an internal hire builds the system: gap analysis, policies, controls, evidence collection, internal audit. This is the larger part of the work.

The certification side. A separate, accredited certification body performs the stage 1 and stage 2 audits and issues the certificate. Their scope is to assess, not to help.

Firms offering both usually maintain a legal and operational separation between the arms, and the separation must satisfy the accreditation body. That can be legitimate. It is also worth asking directly: if your consultancy arm works with us, can your certification arm still certify us within two years? A straight answer either way tells you something about the firm.

SOC 2 is a different regime with a similar effect

SOC 2 is an attestation under AICPA standards, not an ISO certification, so 17021-1 does not apply. The AICPA Code of Professional Conduct does, and it reaches the same place by another route: independence rules prohibit a CPA firm from auditing work it performed. A firm that designed and implemented your controls has an independence problem with attesting to them.

The practical answer is the same. Separate who builds from who signs.

What to ask before you sign

Four questions, in the order they matter:

  1. Are you accredited, and by whom? For ISO 27001 you want a certification body accredited by a national accreditation body that signs the IAF multilateral agreement. Ask for the accreditation number and check it on the accreditation body's register yourself.

  2. Have you provided any consultancy to us in the last two years? Including through a related entity. If your consultancy engagement was with a sister company under the same parent, ask explicitly.

  3. If we use your advisory arm, does that bar your certification arm? Ask before, not after.

  4. Who is the audit team, and what are their qualifications for this framework and sector? Independence is a property of the body; competence is a property of the people. Both need to hold.

Declaring what you already know

If there is prior work, prior employment or a financial relationship between your organisation and a prospective auditor, say so at the start. A declared relationship is something a certification body can assess and manage, and often accept. An undeclared one, discovered later, can invalidate the certificate you paid for - and the certificate is the only thing you were buying.

ShareLinkedInXEmail
Keep reading