ISO/IEC 17021-1 – Part 1: what the standard governs, and what it changes for the audited company
ISO/IEC 17021-1 governs certification bodies, not certified companies. What the standard requires on impartiality, competence and the separation between audit and decision, and what that changes in practice for the audited company.
Behind every ISO certification stands a body that audited, assessed, and ultimately granted the certificate. Yet few QHSE managers question the rules that apply to that body. ISO/IEC 17021-1 defines those rules precisely. Understanding what it requires makes it possible to approach audits differently, and to work with your certification body on a more informed basis.
What the standard covers, and what it does not
ISO/IEC 17021-1 does not set the requirements of management system standards such as ISO 45001 or ISO 9001. It governs the bodies that assess conformity with those standards. It is a standard about certifiers, not about the certified.
In practical terms, it defines how a certification body must organise itself, select its auditors, manage its audits, and reach its decisions. The aim is to ensure that two companies certified to ISO 45001 by two different bodies have undergone assessments of comparable quality.
Without this framework, each certifier could set its own level of rigour, which would weaken the value of certification for every party involved.
The five principles, read from the audited company's side
The standard rests on five fundamental principles. Each has direct implications for the company undergoing the audit.
Impartiality. A certification body cannot have supported a company in setting up its management system and then come to audit it. These two activities are incompatible. If a consultancy guided you towards ISO 45001, it cannot be the body that certifies you.
Competence. An audit only has value if the auditor genuinely understands the activity being assessed. The standard requires sector knowledge, not merely technical command of the reference standards. For an industrial company, an auditor with no concrete experience of the sector concerned is a legitimate warning sign.
Responsibility. The final certification decision does not rest with the auditor alone. It must be subject to an independent review, separate from the audit itself. This principle introduces a second layer of scrutiny that strengthens the reliability of the process.
Transparency. The audited company must understand the criteria used, how the audit is conducted, and the basis on which the decision is made. A certifier unable to explain its decision-making process clearly does not meet this requirement.
Confidentiality. Information collected during audits is protected. This matters particularly in sectors where operational data is sensitive.

The separation between audit and certification decision
A point often overlooked: the auditor who carries out the on-site assessment does not make the certification decision. These are two distinct functions within the certification body. The standard explicitly requires this separation in order to avoid bias.
For the audited company, this means the audit report and the final decision can diverge. The auditor observes and documents. Validation belongs to a separate committee, which reviews the report independently before ruling.

The audit cycle: the three types to know
The standard governs three types of audit to which a certified company is exposed.
Initial audit: carried out in two stages. The first reviews the company's documentation and context. The second is an on-site audit, meeting the teams and checking actual practice against the system as described.
Surveillance audits: carried out annually or twice a year depending on the body and the standard. They verify that the system remains effective and maintained over time. They are not formalities.
Recertification audit: every three years, it reassesses the management system as a whole. It is more comprehensive than surveillance audits and is the occasion to check that the system has evolved along with the organisation.
Knowing this cycle makes it possible to prepare continuously rather than treating each audit as an isolated event.
