Skip to main content

    Certification bodies

    Audit capacity for certification bodies

    Discuss qualified ISO/IEC 27001 and 42001 auditor capacity within your body's procedures. Personnel, competence, conflicts and access are agreed in advance; scheme responsibilities and certification decisions stay with you.

    Before allocation

    Capacity has to fit the scheme.

    An available person is not automatically suitable for an assignment. Agree the technical area, role and required competence before including any proposed auditor in your audit planning.

    • Auditor availability at planning time

      Surveillance, initial and recertification work can overlap. Define the assignment, dates, audit stage and required technical experience so a capacity discussion is tied to an actual plan, not an assumed standing roster.

    • Competence records you can evaluate

      Identify the qualifications, experience and records your body needs for ISO/IEC 27001 or 42001 work. Your competence evaluation and authorisation process determines whether proposed personnel can take the agreed role.

    • Conflicts checked before assignment

      Discuss prior involvement, consultancy relationships and other relevant conflicts before access is granted. Your body evaluates impartiality and independence under its procedures and decides whether an assignment may proceed.

    • Work that follows your procedures

      Agree audit instructions, evidence access, interview arrangements and reporting formats. Technical observations need to reach the designated audit lead through your escalation route, with enough context for review and follow-up.

    Technical and evidence work

    Support for information security and AI management systems.

    ISO/IEC 27001 and 42001 delivery
    Agree auditor capacity, technical input and evidence preparation against the assignment your body approves. For information security, clarify the systems and management-system boundaries; for AI, clarify the AI activities, governance arrangements and management-system evidence in scope.
    ISO certification delivery support
    Specialist technical questions
    An audit may need closer examination of access arrangements, cloud responsibilities or AI oversight records. IT and AI assessment capabilities can inform an agreed technical workstream, without expanding the audit scope or determining a certification outcome.

    Enterprise gap assessments and internal audits are a different service from certification-body delivery support. Any prior implementation or assessment involvement must be considered in the body's conflict checks; it is not a shortcut to an independent certification decision.

    Under the body's direction

    Your procedures. Your certification decision.

    The certification body keeps

    • The client relationship
    • Engagement leadership
    • Methodology and standards
    • Professional judgment
    • Required review and sign-off
    • Scheme and accreditation responsibilities
    • Auditor authorisation and certification decisions

    AuditPartners supplies

    • Agreed professional delivery
    • Specialists when an engagement needs them
    • RiskAssist™, operated by our professionals
    • Human review before anything reaches your reviewer

    AuditPartners is not a CPA firm or a certification body; it does not issue audit opinions, SOC reports or certificates. The responsible firm or body retains engagement responsibility, judgment, review, report issuance and certification decisions. For these assignments, your body also retains its scheme and accreditation obligations.

    Where agreed, our professionals operate RiskAssist™ for evidence intake, control mapping, consistency checks and draft analysis. Any AI-assisted preparation is subject to agreement and human review before it reaches the body's reviewer; it cannot decide conformity or certification.

    Co-delivery, white-label presentation, client protection and confidentiality are offered subject to the applicable agreement for each engagement.

    Agree suitability before sharing evidence.

    1. Define the assignment

      Describe the standard, audit role, technical scope and planned dates. Delivery personnel, qualifications, location and availability are agreed per engagement, with no assumed allocation before your approval.

    2. Evaluate competence and conflicts

      Agree the records to provide, the body's evaluation process and how unresolved concerns will be handled. Confirm procedures, access, approved tools and confidentiality arrangements before client material is shared.

    3. Set the review route

      Name the audit lead and reviewer, agree the working-file format and confirm where observations are escalated. Your body reviews the work and makes the decisions required by its scheme.

    Tell us which assignment needs capacity.

    Start with the standard, audit role and competence requirements. We can discuss a proposed assignment for your body's evaluation.