Certification bodies
ISO audit support. Your certification decisions.
Technical, evidence and capacity support for ISO/IEC 27001 and 42001 audits, plus gap assessments and internal audits.
For certification organisations seeking defined technical, evidence or personnel support under their own procedures. The body's scheme, accreditation obligations and decision-making responsibilities are not transferred.
Work defined by the certification organisation
Support the audit, not the decision
Start with the scheme, audit scope and the body's assessment of the support it can accept. An assignment may involve technical input, preparation of evidence records or agreed audit capacity. Each has a defined role, competence requirement and review path.
- Technical and evidence work
- Support can include organising the supplied management-system documentation, linking records to the clauses and controls in scope, preparing questions and documenting the agreed procedures performed. Technical specialists can help interpret system configurations or AI operating records where agreed. Preparation is checked by a professional before it is handed to the body's designated reviewer; a mapped record is not itself a finding of conformity.
- Agreed personnel capacity
- Discuss qualified auditor or specialist capacity for an identified assignment. The certification organisation evaluates proposed personnel and the work they may perform under its procedures. Qualifications, competence evidence, location and availability are agreed per engagement rather than inferred from a general service description. Any change of personnel or assignment needs the body's agreed approval process.
AuditPartners is not a CPA firm or a certification body and does not issue audit opinions, SOC reports or certificates. The responsible organisation retains engagement responsibility, judgment, review and report issuance. The certification organisation keeps its scheme and accreditation responsibilities and every certification decision.
Before any client evidence is shared
Agree the conditions with the body
Capacity is only useful when it fits the body's operating requirements. Discuss the following matters before accepting an assignment, including whether the proposed role is permitted and how the body will supervise and review it.
- Personnel and competence. Agree the roles, relevant technical knowledge, competence records and evaluation required for the particular scheme and assignment. The body determines what evidence it needs and whether the proposed personnel meet its requirements.
- Conflicts and impartiality. Identify prior or current work with the organisation being assessed, other relationships and any implementation involvement. The body evaluates conflicts under its procedures and decides whether a role can proceed or must be restricted.
- Procedures and review. Agree audit instructions, templates, reporting lines, supervision, escalation and the handling of findings. Separate the delivery of an assigned procedure from the body's review, report authorisation and certification decision.
- Access and handling. Agree authorised evidence access, tools and providers, data location, retention and confidentiality before records are shared. AI-assisted preparation is only used where agreed; it is not an assumed feature of every assignment.
Co-delivery, white-label presentation, client protection and confidentiality are offered subject to the applicable agreement for each engagement.
Discuss engagement safeguardsHuman OversightTwo management-system contexts
ISO/IEC 27001 and ISO/IEC 42001
Information security management
For ISO/IEC 27001 assignments, agree the management-system boundary and technical areas requiring support. Evidence work may cover risk assessment and treatment records, the statement of applicability, control operation, internal audit and management review records, according to the body's instructions.
Technical questions can involve identity and access, change control, cloud services or incident handling. Support stays within the approved assignment; the body evaluates the evidence and determines findings under its own process.
Related IT audit workAI management systems
For ISO/IEC 42001 assignments, clarify the AI systems, organisational roles and lifecycle activities within scope. Agreed evidence support may address inventories, risk and impact assessment records, third-party responsibilities, oversight arrangements and records of management-system review.
Technical input should connect descriptions of AI use to observable records, including permissions, changes and human intervention where relevant. It does not substitute for the body's determination of conformity or authorise a certification outcome.
Related AI assurance workSeparate enterprise engagements
Need a gap assessment or internal audit?
Organisations preparing their own management systems can discuss gap assessments or internal audits separately from certification-body delivery support. Agree the criteria, scope, independence and intended use of the work. Management owns remediation; readiness work does not provide a certificate or guarantee a certification decision.
A specific assignment first
Discuss the capacity you need
Bring the scheme, scope, proposed dates, role requirements and procedures the assignment must follow. Discuss competence evaluation, conflicts and evidence access before settling the work plan. Availability is agreed for that engagement, not promised across an unspecified audit programme.
Where approved, RiskAssist™ supports evidence intake, control mapping, consistency checks and draft analysis. Our professionals operate it and review the preparation before it reaches the body's reviewer. Agree permitted tools and any AI assistance with the body rather than assuming they fit its scheme.
After the assignment, review the documentation, escalations and practical fit with your procedures. Decide whether another engagement is appropriate while keeping certification decision-making separate from delivery capacity.
Start with your body's requirements
Discuss an identified audit assignment and the personnel, competence, procedures and access that would need to be agreed.