Back to playbooks
    Playbook

    Running the external audit

    A method for hosting the certification body: evidence architecture, the opening meeting, nonconformity handling, and findings tracked to verified closure.

    Compliance5 Sept 202622 min read

    ISO 19011:2018ISO/IEC 17021-1:2015ISO/IEC 27001:2022
    On this page

    Scope: the third-party certification audit, stage 1 to closure · Who: the officer who hosts the certification body · Prerequisites: a management system already operating · First result: one audit

    1. Why this exists (the failure mode it prevents)

    An external audit is a sampling exercise. The auditor asks for a small number of records and reasons from them to the whole management system. What the auditee does before and after either makes that sample easy to draw or makes it look thin.

    The failure mode has four moves, usually together. Evidence is hunted in the fortnight before the auditor comes. Questions are answered from memory, because nobody can find the record. Findings are accepted at the closing meeting without being read. Corrective action is then written as a single word: fixed.

    Each move surfaces predictably. Hunted evidence produces a nonconformity worded around an inability to demonstrate. An unread finding produces a correction aimed at the wrong requirement. A finding closed as fixed returns at the next surveillance audit against the same clause.

    The cost is a date, not a rebuke. Certification is decided by people who read the report, not by the audit team, and the decision carries conditions. Where a major nonconformity is open, those conditions are unmet until the correction and corrective action are reviewed, accepted and verified 1. A system that genuinely works can still lose a certificate date to a badly run audit week.

    This playbook is the audit-week counterpart to Building an ISMS people actually use, sections 3.6 and 3.7. That playbook makes the records exist; this one makes them findable and closable.

    2. Definitions (only the ones that cause disputes)

    Requirement text in both auditing standards is copyright and is paraphrased throughout. Only clause numbers and titles are cited.

    TermWorking definitionSource
    Certification audit, internal auditA certification audit is carried out by an auditing organization independent of the client and of the parties relying on certification. An internal audit is the organisation's own conformity check.ISO/IEC 17021-1:2015 clause 3.4 2; ISO/IEC 27001:2022 clause 9.2 3
    Stage 1 and stage 2The two stages of an initial certification audit. Stage 1 establishes readiness; stage 2 evaluates implementation, including effectiveness, at the client's sites.ISO/IEC 17021-1:2015 clauses 9.3.1.1 and 9.3.1.3 4
    Audit criteria, audit evidenceThe criteria are the requirements evidence is compared against: the normative document plus the organisation's own processes and documentation. Evidence is records, statements of fact or other information relevant to those criteria and verifiable.ISO 19011:2018 clauses 3.7 and 3.9 5; ISO/IEC 17021-1:2015 clause 9.2.1.4 6
    Audit finding, audit conclusionA finding results from evaluating collected evidence against the criteria, and indicates conformity or nonconformity. A conclusion is the outcome once objectives and findings are weighed.ISO 19011:2018 clauses 3.10 and 3.11 7
    Major and minor nonconformityA nonconformity is a requirement that has not been met. It is major where it undercuts the management system's ability to reach its intended results, minor where it does not. Several minors against one requirement can be classified as major.ISO/IEC 17021-1:2015 clauses 3.11 to 3.13 8
    Correction and corrective actionCorrection deals with the detected instance; corrective action removes the cause. The certification body requires both, with the cause analysis, inside a defined time.ISO/IEC 27001:2022 clause 10.2 9; ISO/IEC 17021-1:2015 clause 9.4.9 10
    Certification cycle, surveillance, recertificationThe first three-year cycle begins with the certification decision, later cycles with the recertification decision. Surveillance audits are on-site but not necessarily full system audits. Recertification confirms continued conformity, effectiveness and scope.ISO/IEC 17021-1:2015 clauses 9.1.3.2, 9.6.2.2 and 9.6.3.1.1 11

    3. The method — numbered steps, each with input, activity, output and owner

    Ten steps, in the order the audit imposes.

    3.1 Know which audit you are in

    One audit programme covers the full cycle and every management system requirement. Initial certification is fixed in shape: a two-stage initial audit, surveillance in the first and second years after the certification decision, then recertification in the third year. Surveillance runs at least once a calendar year outside recertification years, the first within twelve months of that decision 12. Each surveillance has a defined minimum: internal audits and management review, actions on earlier nonconformities, complaints, effectiveness, improvement progress, operational control, changes and marks 13. Recertification reads the previous surveillance reports and cycle performance, and can pull in a stage 1 after significant change 14.

    • Input: the audit programme; the certificate cycle dates; open findings.
    • Activity: identify the audit type and its minimum content; calendar the cycle; flag changes that could pull a stage 1 into recertification.
    • Output: audit cycle plan: each audit, its type, its coverage, its deadlines.
    • Owner: the management system owner; top management approves the dates.

    3.2 Build the evidence architecture

    An evidence architecture is one index from every requirement to the record answering it, naming the process producing it, its location, its cadence and the accountable role. Evidence is obtained by appropriate sampling and then verified, through interviews, observation of processes and activities, and review of records 15. The criteria also include the organisation's own processes and documentation 6. Version, approver and distribution make a sampled record defensible 16.

    • Input: the Statement of Applicability; the clause list; the document control register.
    • Activity: one row per clause and per applicable control; walk three rows end to end and fix what cannot be retrieved.
    • Output: evidence index, maintained continuously rather than rebuilt per audit.
    • Owner: the management system owner; each row's accountable role owns its record.

    3.3 Read the audit plan and settle the people

    The body sets the audit objectives and settles scope and criteria after discussion with the client 17. The plan carries the objectives, the criteria, the scope with the processes audited, the dates and sites, the expected duration, and the roles of team members and accompanying persons. Dates are agreed in advance, and the team's names arrive with time enough to object to a member 18. Name the auditee side too: a guide assists the audit team, an observer accompanies without auditing 19. The guidance standard makes planning and guide assignment distinct activities 20.

    • Input: the received audit plan; the evidence index; the roles matrix 21.
    • Activity: map each session to index rows and to the role answering; brief one guide per team member; object to team composition in writing, in time.
    • Output: audit plan acknowledgement: session, attendee, guide, records staged.
    • Owner: the management system owner; process owners confirm their own sessions.

    3.4 Treat stage 1 as an audit, not a formality

    An initial certification audit runs in two stages 22. Stage 1 reviews the documented information, evaluates site conditions with personnel, tests how far the organisation understands the standard, and gathers scope information on sites, processes and levels of control. Its last objective is decisive: whether internal audits and management reviews are planned and performed, and whether implementation substantiates readiness for stage 2 23. The written conclusions identify areas of concern that could become a nonconformity at stage 2, and stage 1 results can postpone or cancel stage 2 24. Stage 2 evaluates implementation and effectiveness on site, covering at least conformity, performance monitoring, statutory and contractual requirements, operational control, internal audit and management review 25.

    • Input: stage 1 documented conclusions; the areas of concern; the evidence index.
    • Activity: turn every area of concern into a dated action with an owner; confirm the audit programme and review record predate stage 2 26.
    • Output: stage 1 response log, closed or dated before stage 2.
    • Owner: the management system owner; process owners hold individual actions.

    3.5 Use the opening meeting

    The on-site process opens and closes with a formal meeting 27. The opening meeting is held with the client's management and those responsible for the processes audited. It confirms the certification scope, the plan and its changes, the communication channels, the resources needed, confidentiality, safety, and the roles of guides and observers. It states the reporting method including any grading of findings, the conditions for early termination, the sampling basis and the language 28. Two items repay attention: ask how findings will be graded before any exists, and confirm the channel by name 29.

    • Input: the audit plan; the acknowledgement from step 3.3; the attendance list.
    • Activity: confirm scope, plan changes and channels; record the grading method; agree how record requests will be logged.
    • Output: opening meeting note: attendance, scope, channel, grading method.
    • Owner: the management system owner.

    3.6 During the audit: supply, escort, communicate

    The team leader reports progress and concerns as the audit runs. Where evidence suggests the objectives are unattainable, or an immediate and significant risk appears, the team leader reports it. The response can extend to changing the plan, the objectives or the scope, or terminating the audit 30. Nothing said in a corridor counts. Give what was asked for, in the version current in the audited period, and say plainly when a record does not exist. Volunteering adjacent documents widens the sample, not the scope 31. Escorting is a control, not hospitality. A guide is appointed by the client to assist the audit team 32. In practice that means retrieving records, finding the right person and logging every request.

    • Input: the audit plan; the evidence index; the staged record set.
    • Activity: log every request with time, record supplied and index row; answer the question asked; escalate a disputed point the same day.
    • Output: evidence request log; daily note of concerns raised and answered.
    • Owner: the guide for each session; the management system owner consolidates.

    3.7 Findings: read the wording, agree the facts

    Findings are identified, classified and recorded so an informed certification decision can be made, and a nonconformity is never logged as an opportunity for improvement 33. The wording rule is worth knowing by heart. A nonconformity is recorded against a specific requirement, states it clearly, and identifies in detail the objective evidence behind it. It is discussed with the client so the evidence is accurate and the nonconformity understood, and the auditor refrains from suggesting the cause or the solution 34. So check that the requirement cited is the one the evidence engages, and that the evidence is described accurately.

    Grading is the certification body's judgement, not a negotiation. A major is one that undercuts the management system's ability to reach its intended results; a minor is not. Several minors against one requirement can be classified as major 35. Argue the facts and the requirement cited. Where disagreement stands, the team leader attempts to resolve it and unresolved points are recorded 36. Before the closing meeting the team reviews findings, classifies nonconformities and agrees conclusions 37. The auditee should copy that separation: facts first, grading second 38.

    • Input: draft finding wording; the cited requirement; the evidence request log.
    • Activity: read each finding against the log; correct the factual description; confirm the requirement cited; record any diverging opinion in writing.
    • Output: findings register rows: the finding as written, the clause cited, the agreed facts.
    • Owner: the management system owner; the named process owner co-signs.

    3.8 The closing meeting and the report

    The closing meeting is formal, attendance is recorded, and it presents the conclusions and the recommendation regarding certification. Nonconformities are presented so they are understood and the response timeframe agreed; the standard's own note is worth carrying into the room, that understood does not mean accepted. The meeting also covers the sampling basis, the reporting method and timeframe including grading, the handling of nonconformities and its consequences, the timeframe for a plan of correction and corrective action, and the appeal process. Unresolved diverging opinions are recorded and referred to the certification body 39. A written report follows for each audit, owned by the body; the team may name opportunities for improvement but not solutions. Prescribed content includes the audit type, criteria, objectives and scope, and the findings with reference to evidence. It also includes unresolved issues, a sampling disclaimer, the recommendation, and verification of earlier corrective actions 40. Read it against the meeting note; changed wording is worth querying 41.

    • Input: the closing agenda; the findings register; the agreed response timeframe.
    • Activity: record attendance and timeframes; confirm each finding's wording against the register; reconcile the issued report against the note.
    • Output: closing pack: meeting note, wording as presented, agreed dates, reconciliation.
    • Owner: the management system owner.

    3.9 From finding to verified closure

    The body requires the client to analyse the cause of each detected nonconformity. It also requires the specific correction and corrective actions, taken or planned, described within a defined time 10. The management system standard asks the same from the other side: react, examine the cause, act on the cause, review effectiveness 9. It then reviews the corrections, causes and corrective actions, verifies effectiveness, and records the evidence of resolution. It tells the client whether an additional full audit, a limited audit, or documented evidence confirmed later will be needed 42. Those routes differ sharply in cost. Five parts make a submission complete: the finding as written, the agreed facts, the cause, the correction, and the corrective action with an owner and a date 43.

    • Input: the findings register; the response timeframe; the process owner per finding.
    • Activity: analyse the cause without renaming the symptom; write correction and corrective action separately; set an effectiveness check date.
    • Output: findings-to-closure tracker (see Findings-to-closure tracker); corrective action records.
    • Owner: the process owner where the finding sits; the management system owner tracks closure.

    3.10 The certification decision and what follows

    The decision is made by competent people who did not carry out the audit, and each decision is recorded 44. Before deciding, the body checks that the audit team's information is sufficient. For any major, the correction and corrective actions are reviewed, accepted and verified. For any minor, the client's plan for correction and corrective action is reviewed and accepted 1. That asymmetry is the most useful fact here. A minor needs an accepted plan; a major needs verified action. Where a major cannot be verified within six months after the last day of stage 2, another stage 2 precedes any recommendation 45.

    Recertification repeats the asymmetry against a harder deadline. Time limits are set for any major, and those actions are implemented and verified before certification expires. An incomplete audit, or a major still unverified at expiry, means recertification is not recommended 46. Two duties run between audits. The certified client reports without delay any matter that may affect the system's capability to keep meeting the standard. Notifiable changes include status or ownership, management, sites, scope, and the system itself 47. And certification is suspended where failures persist, or where audits are refused at the required frequency 48.

    • Input: the closure pack; the body's acceptance or rejection; the change log.
    • Activity: confirm in writing which findings are accepted and which verified; calendar the next surveillance; report notifiable changes as they arise.
    • Output: closure confirmation record; change notifications sent; next-audit plan.
    • Owner: the management system owner; the management review record carries the decisions 49.

    4. Deliverables

    Six artefacts carry the method. Retention periods are organisational choices rather than requirements of any of the three standards; the defaults suit a three-year cycle.

    DeliverableProduced byFormatRetention
    Audit cycle planStep 3.1documentwhole cycle
    Evidence indexStep 3.2registercurrent version, plus the whole cycle
    Audit plan acknowledgementStep 3.3documentper audit, whole cycle
    Findings-to-closure trackerSteps 3.7 and 3.9 · templatespreadsheet or registerwhole cycle, plus one
    Corrective action recordsStep 3.9records with evidencewhole cycle, plus one
    Closing packStep 3.8meeting note plus reconciliationper audit, whole cycle

    5. What the auditor will ask

    Every clause named below is registered with its verified reference in section 7. The phrasing follows how a certification-body auditor opens a line of enquiry: a request for a record, then a request for the decision behind it.

    An audit that stays at document level is going well. One that moves to records, and then to the people who produce them, is where the index earns its cost.

    6. Failure modes and how they surface as findings

    Five patterns account for most avoidable audit-week damage: the pattern, the wording it produces, the fix.

    The root is the same in all five: the audit is treated as a performance, not a sample of something already running.

    7. Mapping to the standards

    Every clause number and title below was read from the publisher's own text on the date shown. Requirement text is paraphrased; only clause numbers and titles are cited.

    ClauseTitleCertification bodyAuditee preparesVerified
    8.5.3Notice of changes by a certified clientRequires changes affecting the system to be reported without delayChange log; a notification route47
    9.1.3Audit programmeBuilds a cycle programme covering every requirementAudit cycle plan with internal deadlines50
    9.2.3Audit planIssues a plan, names the team, agrees datesAcknowledgement mapping sessions to records51
    9.3.1Initial certification auditAudits in two stages, reporting readiness after stage 1Stage 1 response log52
    9.4.2Conducting the opening meetingCovers scope, plan, channels, guides and gradingOpening meeting note28
    9.4.4Obtaining and verifying informationSamples and verifies by interview, observation, record reviewEvidence index; a request log53
    9.4.5Identifying and recording audit findingsRecords each nonconformity against a specific requirementFactual check; disagreement in writing54
    9.4.7Conducting the closing meetingPresents conclusions; agrees the response timeframeClosing pack: attendance, wording, dates55
    9.4.8Audit reportIssues and owns a written report per auditReconciliation against the meeting note56
    9.4.9Cause analysis of nonconformitiesRequires cause analysis, correction and corrective actionTracker rows carrying all three separately10
    9.4.10Effectiveness of corrections and corrective actionsReviews and verifies; states what else is neededEvidence of closure; verification date42
    9.5.2Actions prior to making a decisionChecks majors are verified, minors have an accepted planSubmission split by grade1
    9.6.3RecertificationConfirms conformity, effectiveness and scope before expiryMajors verified before the expiry date57
    What the certification body does, and what the auditee therefore prepares — ISO/IEC 17021-1:2015
    ClauseTitleAuditee-side activityVerified
    4Principles of auditingRead the seven principles before disputing a finding58
    6.3.2Audit planningRead the plan against the evidence index59
    6.4.2Assigning roles and responsibilities of guides and observersName and brief one guide per team member60
    6.4.8Generating audit findingsCheck the description and the requirement cited61
    6.7Conducting audit follow-upRun cause and action to a verified date43
    Guidance clause titles and the auditee-side activity — ISO 19011:2018
    ClauseTitleRecord the audit samplesVerified
    5.3Organizational roles, responsibilities and authoritiesRoles matrix naming who answers for each area21
    7.5.3Control of documented informationVersion, approver, distribution, retention62
    9.2.2Internal audit programmeCycle coverage of clauses 4 to 10 and applicable controls26
    9.3.3Management review resultsMinutes recording decisions with owners and dates49
    10.2Nonconformity and corrective actionTracker with cause, action, verification, closure date9
    Annex AInformation security controls referenceEvery applicable control judged and traceable63
    Management system clauses and the records the audit samples — ISO/IEC 27001:2022

    8. Checklist

    Each item is observable. "Prepared" is not observable; a dated row in a register is.

    References

    Primary sources only. The two auditing standards were read as published documents; clause numbers and titles are cited and requirement text paraphrased. The management system clause titles were read on the ISO Online Browsing Platform, where they are visible without purchase.

    1. ISO/IEC. Conformity assessment — Requirements for bodies providing audit and certification of management systems — Part 1: Requirements. ISO/IEC 17021-1:2015. First edition, 2015-06-15, prepared by the ISO Committee on Conformity Assessment (CASCO). Catalogue entry at https://www.iso.org/standard/61651.html; clause numbers and titles read from a licensed single-user copy 64
    2. ISO. Guidelines for auditing management systems. ISO 19011:2018. Third edition, 2018-07, prepared by Project Committee ISO/PC 302. Catalogue entry at https://www.iso.org/standard/70017.html; contents and clauses 3 to 5.1 read from the publisher's document preview 65
    3. ISO/IEC. Information security, cybersecurity and privacy protection — Information security management systems — Requirements. ISO/IEC 27001:2022. Contents and clause titles read at https://www.iso.org/obp/ui/#iso:std:iso-iec:27001:ed-3:v1:en 66

    Retention periods, calendar habits and internal deadlines above are organisational choices, not requirements of any of the three standards.

    Standards and certification names are the property of their respective owners. GRCIDE is an independent publication and is not affiliated with, authorized, sponsored or endorsed by ISO, IEC, NIST or any other standards body.

    Sources

    1. 1ISO/IEC 17021-1:2015 clause 9.5.2, licensed copy · verified 2026-09-05
    2. 2ISO/IEC 17021-1:2015 clause 3.4, licensed copy · verified 2026-09-05
    3. 3ISO/IEC 27001:2022 clause 9.2, iso.org/obp · verified 2026-09-03
    4. 4ISO/IEC 17021-1:2015 clauses 9.3.1.1 and 9.3.1.3, licensed copy · verified 2026-09-05
    5. 5ISO 19011:2018 clauses 3.7 and 3.9 · verified 2026-09-05
    6. 6ISO/IEC 17021-1:2015 clause 9.2.1.4, licensed copy · verified 2026-09-05
    7. 7ISO 19011:2018 clauses 3.10 and 3.11 · verified 2026-09-05
    8. 8ISO/IEC 17021-1:2015 clauses 3.11 to 3.13, licensed copy · verified 2026-09-05
    9. 9ISO/IEC 27001:2022 clause 10.2, iso.org/obp · verified 2026-09-03
    10. 10ISO/IEC 17021-1:2015 clause 9.4.9, licensed copy · verified 2026-09-05
    11. 11ISO/IEC 17021-1:2015 clauses 9.1.3.2, 9.6.2.2 and 9.6.3.1.1, licensed copy · verified 2026-09-05
    12. 12ISO/IEC 17021-1:2015 clauses 9.1.3.1 to 9.1.3.3, licensed copy · verified 2026-09-05
    13. 13ISO/IEC 17021-1:2015 clause 9.6.2.2, licensed copy · verified 2026-09-05
    14. 14ISO/IEC 17021-1:2015 clauses 9.6.3.1.2 and 9.6.3.1.3, licensed copy · verified 2026-09-05
    15. 15ISO/IEC 17021-1:2015 clauses 9.4.4.1 and 9.4.4.2, licensed copy · verified 2026-09-05
    16. 16ISO/IEC 27001:2022 clauses 7.5 and 7.5.3, iso.org/obp · verified 2026-09-03
    17. 17ISO/IEC 17021-1:2015 clause 9.2.1.1, licensed copy · verified 2026-09-05
    18. 18ISO/IEC 17021-1:2015 clauses 9.2.3.2 to 9.2.3.5, licensed copy · verified 2026-09-05
    19. 19ISO/IEC 17021-1:2015 clauses 3.8 and 3.9, licensed copy · verified 2026-09-05
    20. 20ISO 19011:2018 contents, clauses 6.3.2 and 6.4.2 · verified 2026-09-05
    21. 21ISO/IEC 27001:2022 clause 5.3, iso.org/obp · verified 2026-09-03
    22. 22ISO/IEC 17021-1:2015 clause 9.3.1.1, licensed copy · verified 2026-09-05
    23. 23ISO/IEC 17021-1:2015 clause 9.3.1.2.2, licensed copy · verified 2026-09-05
    24. 24ISO/IEC 17021-1:2015 clauses 9.3.1.2.3 and 9.3.1.2.4, licensed copy · verified 2026-09-05
    25. 25ISO/IEC 17021-1:2015 clause 9.3.1.3, licensed copy · verified 2026-09-05
    26. 26ISO/IEC 27001:2022 clause 9.2.2, iso.org/obp · verified 2026-09-03
    27. 27ISO/IEC 17021-1:2015 clause 9.4.1, licensed copy · verified 2026-09-05
    28. 28ISO/IEC 17021-1:2015 clause 9.4.2, licensed copy · verified 2026-09-05
    29. 29ISO 19011:2018 contents, clause 6.4.3 · verified 2026-09-05
    30. 30ISO/IEC 17021-1:2015 clauses 9.4.3.1 to 9.4.3.3, licensed copy · verified 2026-09-05
    31. 31ISO 19011:2018 contents, clauses 6.4.4 to 6.4.7 · verified 2026-09-05
    32. 32ISO/IEC 17021-1:2015 clause 3.8, licensed copy · verified 2026-09-05
    33. 33ISO/IEC 17021-1:2015 clauses 9.4.5.1 and 9.4.5.2, licensed copy · verified 2026-09-05
    34. 34ISO/IEC 17021-1:2015 clause 9.4.5.3, licensed copy · verified 2026-09-05
    35. 35ISO/IEC 17021-1:2015 clauses 3.12 and 3.13, licensed copy · verified 2026-09-05
    36. 36ISO/IEC 17021-1:2015 clause 9.4.5.4, licensed copy · verified 2026-09-05
    37. 37ISO/IEC 17021-1:2015 clause 9.4.6, licensed copy · verified 2026-09-05
    38. 38ISO 19011:2018 contents, clauses 6.4.8 and 6.4.9 · verified 2026-09-05
    39. 39ISO/IEC 17021-1:2015 clauses 9.4.7.1 to 9.4.7.3, licensed copy · verified 2026-09-05
    40. 40ISO/IEC 17021-1:2015 clauses 9.4.8.1 and 9.4.8.2, licensed copy · verified 2026-09-05
    41. 41ISO 19011:2018 contents, clauses 6.4.10 to 6.5.2 · verified 2026-09-05
    42. 42ISO/IEC 17021-1:2015 clause 9.4.10, licensed copy · verified 2026-09-05
    43. 43ISO 19011:2018 contents, clause 6.7 · verified 2026-09-05
    44. 44ISO/IEC 17021-1:2015 clauses 9.5.1.1 and 9.5.1.4, licensed copy · verified 2026-09-05
    45. 45ISO/IEC 17021-1:2015 clause 9.5.3.2, licensed copy · verified 2026-09-05
    46. 46ISO/IEC 17021-1:2015 clauses 9.6.3.2.2 to 9.6.3.2.5, licensed copy · verified 2026-09-05
    47. 47ISO/IEC 17021-1:2015 clause 8.5.3, licensed copy · verified 2026-09-05
    48. 48ISO/IEC 17021-1:2015 clause 9.6.5.2, licensed copy · verified 2026-09-05
    49. 49ISO/IEC 27001:2022 clause 9.3.3, iso.org/obp · verified 2026-09-03
    50. 50ISO/IEC 17021-1:2015 clause 9.1.3, licensed copy · verified 2026-09-05
    51. 51ISO/IEC 17021-1:2015 clause 9.2.3, licensed copy · verified 2026-09-05
    52. 52ISO/IEC 17021-1:2015 clause 9.3.1, licensed copy · verified 2026-09-05
    53. 53ISO/IEC 17021-1:2015 clause 9.4.4, licensed copy · verified 2026-09-05
    54. 54ISO/IEC 17021-1:2015 clause 9.4.5, licensed copy · verified 2026-09-05
    55. 55ISO/IEC 17021-1:2015 clause 9.4.7, licensed copy · verified 2026-09-05
    56. 56ISO/IEC 17021-1:2015 clause 9.4.8, licensed copy · verified 2026-09-05
    57. 57ISO/IEC 17021-1:2015 clause 9.6.3, licensed copy · verified 2026-09-05
    58. 58ISO 19011:2018 clause 4 · verified 2026-09-05
    59. 59ISO 19011:2018 contents, clause 6.3.2 · verified 2026-09-05
    60. 60ISO 19011:2018 contents, clause 6.4.2 · verified 2026-09-05
    61. 61ISO 19011:2018 contents, clause 6.4.8 · verified 2026-09-05
    62. 62ISO/IEC 27001:2022 clause 7.5.3, iso.org/obp · verified 2026-09-03
    63. 63ISO/IEC 27001:2022 Annex A, iso.org/obp · verified 2026-09-03
    64. 64ISO/IEC 17021-1:2015 contents, licensed copy · verified 2026-09-05
    65. 65ISO 19011:2018 contents · verified 2026-09-05
    66. 66ISO/IEC 27001:2022 contents, iso.org/obp · verified 2026-09-03