Last Updated on August 20, 2026 by Hafsa J.
ISO/IEC 17065 Requirements: Clause-by-Clause and the Evidence Auditors Actually Ask For
If you run, or are standing up, a body that certifies products, processes or services, ISO/IEC 17065:2012 is the standard your accreditation body will hold you to. It groups its requirements into five working clauses: Clause 4 (general), Clause 5 (structural), Clause 6 (resource), Clause 7 (process) and Clause 8 (management system). Knowing what each clause says is the easy half. The half that decides whether you pass an accreditation assessment is knowing the specific record an assessor will ask to see for that clause, and the single mistake that most often turns into a written non-conformity.
This page walks every clause in that order and, for each, names two things competitors leave out: the evidence the assessor wants in front of them, and the common non-conformity. It works the product, process and service triad into real cases, covers Annex A (the principles) and Annex B (process and service certification), and is explicit about the one document that drives everything else: the certification scheme. ISO/IEC 17065 is the current and only edition, published September 2012, still in force in 2026 with no revision and no live transition.
Read this as the requirements hub. Three areas have their own deep-dive pages, linked at the relevant point: impartiality and the consultancy firewall, the Option A versus Option B management-system choice, and the evaluation to review to decision chain. This page gives you the whole map and the evidence list; those pages give you the build detail.
What this guide covers
- The certification scheme: the document that drives every requirement
- Clause 4 – General requirements (legal, impartiality, confidentiality)
- Clause 5 – Structural requirements
- Clause 6 – Resource requirements
- Clause 7 – Process requirements (including surveillance, complaints and appeals)
- Clause 8 – Management system requirements (Option A vs Option B)
- Annex A and Annex B: principles, and process or service certification
- Product, process or service: the triad in practice
- Evidence and common non-conformity, clause by clause
- Frequently asked questions
The certification scheme: the document that drives every requirement
Before any clause makes sense, fix one idea in place: ISO/IEC 17065 does not, by itself, tell you what makes a product conforming. The standard sets the rules for how a competent, impartial body operates. What that body checks a product, process or service against comes from the certification scheme, which clause 7.1.2 requires to contain the product and process requirements. The scheme is the driving document, and almost every Clause 7 activity points back to it.
A scheme can be one your body owns and operates, or one owned by a third party that you operate under licence. Clause 7.1.3 is direct about the second case: when you run someone else’s scheme, you meet the scheme owner’s requirements on top of the standard’s. An electrical-safety mark, an organic-food label, a sustainable-forestry certification: each is a scheme with its own product or process requirements, its own evaluation methods, and often its own surveillance frequency. The standard governs your conduct as a body; the scheme governs the verdict. Carry that into every section below. When Clause 7.4 asks for an evaluation, it means evaluation against the scheme; when 7.7 lists what the certificate must show, it requires the scheme and the version used. A body that cannot point to the scheme that defines conformity has missed the architecture of the whole thing.
Clause 4 – General requirements
Clause 4 sets the conditions a body must satisfy to be trusted at all: that it is a real legal entity carrying real liability, that it manages impartiality actively, that it keeps client information confidential, and that it offers its service on non-discriminatory terms and publishes the basics. Of its six subclauses, impartiality (4.2) is by far the heaviest, with thirteen requirements, and it is the area assessors raise the most findings on. The impartiality requirements have a dedicated page; here is the general clause in working order.
4.1 Legal and contractual matters
You must be a legal entity, or a defined part of one, that can be held legally responsible for all of its certification activities (4.1.1), and you must identify that entity and its links to any parent or affiliate organisations (4.1.2). Every client relationship runs on a legally enforceable agreement (4.1.3). And the body retains responsibility for, and authority over, all of its certification decisions: granting, maintaining, renewing, extending, reducing, suspending and withdrawing certification (4.1.4). That last point matters later, because it is why the certification decision can never be handed off to anyone outside the body.
4.2 Management of impartiality
This is the section that decides whether anyone can trust your certificate. Top management must commit to impartiality (4.2.1) and the body must publish a statement to that effect (4.2.2). Personnel must be independent of commercial interests (4.2.3), and the body must continually identify the impartiality risks that arise from its relationships (4.2.4), then eliminate or minimise them and document the action taken (4.2.5). Several hard prohibitions follow. The body shall not be the designer, manufacturer, installer, distributor, maintainer or supplier of the item it certifies (4.2.6). It shall not certify where it, or a related body, provided consultancy before the evaluation under conditions that compromise impartiality (4.2.7, the consultancy ban). It shall not provide a client’s internal audit, nor certify a client whose internal audit it performed (4.2.8), and shall not outsource evaluation to a body that gives consultancy or design to certified clients (4.2.9).
One subclause catches bodies out repeatedly: 4.2.10. Your marketing must not imply a link with a consultancy, or that certification is simpler, easier or cheaper if the client uses a particular consultancy. In practice this is the rule that governs your website, including any link to a consulting firm. The remaining requirements close the loop: act on impartiality threats raised by others (4.2.11), have all personnel, internal and external, sign a written undertaking to act impartially and declare any prior or present conflict (4.2.12), and require personnel to inform you of any conflict they become aware of (4.2.13). The two findings assessors raise most here are impartiality treated as a one-time statement with no live risk register behind it, and a website that links to or recommends a consultancy. For the full firewall build, the ownership rules, the financial-pressure red lines and the literal website wording that passes 4.2.10, see our guide to impartiality and the consultancy firewall.
4.3 to 4.6 Liability, access, confidentiality and public information
The rest of Clause 4 is shorter but still assessed. Assess the risks and liabilities of issuing certification (4.3.1) and hold adequate finance or insurance to cover them (4.3.2), typically a professional liability policy sized to your scope. Keep your policies non-discriminatory (4.4.1), make the service available to all applicants within scope (4.4.2), and avoid undue financial or other barriers (4.4.3), evidenced by a published fee schedule and an access procedure.
Confidentiality (4.5) carries a legally enforceable responsibility for the information you obtain (4.5.1). Tell the client in advance what you will make public (4.5.2) and treat everything else as confidential (4.5.3). When law or the agreement requires disclosure to a third party, the client is told in advance what will be disclosed, unless the law forbids it (4.5.4), and information about a client from any other source, a complainant or a regulator, is also confidential (4.5.5). Finally, 4.6 requires you to publish the schemes you operate and your certification requirements (4.6.1), financing and fees (4.6.2), the rights and duties of clients including mark use (4.6.3), and your complaints and appeals procedures (4.6.4), which must be findable by a member of the public.
Clause 5 – Structural requirements
Clause 5 is about how the body is built: who does what, who answers to whom, and how the body protects its impartiality through its structure rather than through good intentions.
5.1 Organizational structure and top management
Document the structure, duties, responsibilities and authorities of the body, including top management and any governing board (5.1.1). Identify the relationships between the different certification activities, evaluation, review, decision and surveillance, so that no role bleeds improperly into another (5.1.2). And define the competence requirements for every category of certification personnel (5.1.3), not just evaluators but reviewers and decision-makers too, which is where the gap usually shows.
5.2 Mechanism for safeguarding impartiality
This is the structural backbone of impartiality, and the requirement many small bodies underbuild. Establish a documented mechanism, in practice a committee or council (5.2.1), and give it real work (5.2.2): helping to develop the impartiality policy, countering any tendency in the body to let commercial considerations compromise impartiality, advising on matters that affect confidence in certification, and reviewing the impartiality of the body’s evaluations, decisions and activities at least once a year. The mechanism must have a balanced composition, with no single interest predominating (5.2.3), have access to all the information it needs (5.2.4), and, when it identifies a threat, trigger action that the body can then demonstrate it took (5.2.5). The classic finding is a committee that exists on paper only, with unbalanced membership or no record that the annual review happened.
Clause 6 – Resource requirements
Clause 6 covers the people and the means: competent personnel paid in a way that does not bias their judgement, and controlled resources for evaluation, including the rules for outsourcing.
6.1 Personnel
Have sufficient competent personnel (6.1.1). Document the competence requirements for each function, identify training needs and train, and monitor performance (6.1.2). Personnel sign an undertaking covering confidentiality and independence (6.1.3). One requirement is a frequent trip-wire: remuneration must not be linked to the number of evaluations carried out or to their outcomes (6.1.4), so evaluator pay tied to throughput is a direct breach. Maintain a procedure for the selection, training, qualification and monitoring of personnel (6.1.5), and keep qualification records for each person (6.1.6).
6.2 Resources for evaluation
Have or have access to the resources and equipment needed for evaluation (6.2.1.1), and control, calibrate and maintain those evaluation means, with records (6.2.1.2). When you outsource part of an evaluation, you need a legally binding contract that includes confidentiality and an absence of conflict of interest (6.2.2.1), and you must evaluate, qualify and monitor the bodies you outsource to (6.2.2.2). The line that matters most: the body keeps final responsibility, and the certification decision is never outsourced (6.2.2.3).
Clause 7 – Process requirements
Clause 7 is the operational core, with forty-nine requirements covering everything from the first application to ongoing surveillance and complaints. This is where a client file either holds together under assessment or does not, and every step runs against the scheme.
7.1 to 7.3 General, application and application review
Document the whole certification process (7.1.1); the scheme must contain product and process requirements (7.1.2); and when you operate a scheme owned by others, meet the owner’s requirements (7.1.3). At application, obtain the required information from the applicant (7.2.1) and their commitment to comply and cooperate (7.2.2). At application review, confirm the information is sufficient and understood, resolve any differences, confirm the body has the competence and capability, and define the scope, sites and time (7.3.1); if a request cannot be handled, give reasons and keep a record (7.3.2).
7.4 Evaluation
Produce an evaluation plan (7.4.1); assign competent and independent evaluation personnel (7.4.2); carry out the evaluation according to the scheme, whether that means tests, inspections, audits or document review (7.4.3); and write an evaluation report that records conformities and non-conformities (7.4.4). Communicate non-conformities to the client and give them the chance to correct before the decision (7.4.5), then evaluate the corrective actions taken (7.4.6). Maintain traceability between requirements, methods and results (7.4.7), trace any outsourced contributions (7.4.8), and require evaluators to keep confidentiality, especially regarding other clients (7.4.9).
7.5 and 7.6 Review and the certification decision (the segregation rule)
The evaluation results are reviewed by one or more people who did not carry out the evaluation (7.5.1), producing a documented recommendation: grant, maintain, extend, suspend or withdraw (7.5.2). The certification decision itself is then made by one or more people employed by, or under a legally enforceable arrangement with, the body, who did not take part in the evaluation (7.6.1) and have the competence to evaluate the certification processes and requirements (7.6.2). If certification is refused, the applicant is told the reasons and the route to appeal (7.6.3). This is the segregation rule, the single most-tested control in the standard: the person who evaluates is not the person who decides. The finding, especially in a small body, is the same person doing both, or a decision-maker whose independence and competence are not documented. How to run this cleanly with limited staff is the subject of our deep dive on the evaluation, review and decision chain.
7.7 and 7.8 The certificate and the public directory
The certification documentation must show the name and address of the holder and the date the certification was granted, which is not earlier than the decision date; an unambiguous identification of the certified product, process or service; the scheme and version of requirements used; the identity of the body, with the accreditation mark where applicable; and the validity or duration plus any conditions or limitations (7.7.1). It is signed by an authorised person (7.7.2). You also maintain a directory of certified products, available on request as a minimum (7.8.1), giving the identification of the certified item, the scheme, the holder and the validity (7.8.2).
7.9 Surveillance
Certification is not a one-time event. Maintain a surveillance programme (7.9.1) using documented methods, which can include tests, inspections, audits, market surveillance and document review, with a frequency defined and justified by the scheme, the risk and the client’s performance (7.9.2). After each cycle, record a documented decision on whether certification continues (7.9.3). The finding to avoid is surveillance run on a fixed calendar with no risk-based justification, or no recorded decision closing the cycle.
7.10 to 7.12 Changes, sanctions and records
When the scheme changes, notify clients (7.10.1), verify they implement the change and re-evaluate where needed (7.10.2), and contractually require clients to notify you of changes affecting conformity (7.10.3). Hold a documented procedure for terminating, reducing, suspending or withdrawing certification (7.11.1), enforce the consequences including stopping mark use (7.11.2), and keep the public directory updated to reflect suspensions and withdrawals (7.11.3). Keep records demonstrating every process requirement was met for each client (7.12.1), stored securely, confidentially and accessibly (7.12.2).
7.13 Complaints and appeals
Hold a documented procedure for receiving, evaluating and deciding on complaints and appeals (7.13.1); acknowledge receipt and report progress and outcome (7.13.2); and ensure the people deciding a complaint or appeal are different from those who carried out the evaluation or decision being contested (7.13.3). Communicate the formal decision with its reasons (7.13.4) and keep records (7.13.5). The recurring finding is an appeal handled by the same person whose decision is being challenged, defeating the independence the clause exists to protect.
Clause 8 – Management system requirements
Clause 8 asks you to run a management system that supports consistent achievement of everything above, and it gives you two ways to do it. Establish, document, implement and maintain a management system, by either Option A or Option B (8.1.1), with a policy and objectives consistent with your certification activity (8.1.2).
Option A is the body’s own management system meeting subclauses 8.2 to 8.8: management system documentation (8.2), control of documents (8.3), control of records (8.4), management review (8.5), internal audits (8.6), corrective actions (8.7) and preventive actions (8.8). Two of these draw the most scrutiny. The management review (8.5) must run at planned intervals at least once a year, fed by audit results, feedback from interested parties including complaints and appeals, the output of the impartiality mechanism, the status of corrective and preventive actions and the achievement of objectives. The internal audit programme (8.6) verifies the system meets the standard and is effectively implemented, and its auditors do not audit their own work.
Option B is a management system established and maintained in accordance with ISO 9001 that is also capable of supporting and demonstrating consistent fulfilment of ISO/IEC 17065. The trap is to read Option B as a shortcut. It is not. An ISO 9001 system on its own does not satisfy the technical, competence and impartiality clauses of 17065. Choosing Option B does not excuse any obligation under Clause 4 (impartiality), 5.2 (the impartiality mechanism), Clause 6 (resources and competence) or Clause 7 (the certification process, including the 7.6 decision independence). Whichever option you pick, those clauses still apply in full.
The Option B body that points to its ISO 9001 certificate and cannot show how the system addresses the technical and impartiality requirements 9001 never mentions is the classic finding here. For the full decision, including an “are you already ISO 9001 certified” test and a clause-level comparison, see our guide to Option A versus Option B.
Annex A and Annex B: principles, and process or service certification
The clauses tell you what to do. The annexes tell you why, and how the rules stretch beyond physical products. Competitor pages skip them; an assessor does not.
Annex A sets out the principles behind the requirements: impartiality, competence, responsibility, openness, confidentiality and responsiveness to complaints. It is informative rather than a checklist of new requirements, but it is where the reasoning lives. When you are deciding how far a control needs to go, Annex A tells you what outcome the standard is trying to protect, and an assessor who pushes on the intent behind a clause is in effect testing whether you have read it.
Annex B is where the word product stops being limiting. Throughout the standard, product is shorthand that also reads as process or service, and Annex B addresses how the requirements apply when the thing certified is a process or a service rather than a tangible product. The clause framework is the same, but the scheme, the evaluation methods and the surveillance look different from a body testing physical goods, as the next section shows.
Product, process or service: the triad in practice
The triad is easy to state and easy to underestimate. The same clauses land differently across the three. For a product, say an electrical appliance against a safety mark, the 7.4 evaluation is heavy on tests and inspections of physical samples, the 7.7 certificate identifies the model, and 7.9 surveillance may pull product from the market to retest. For a process, say a farm against an organic-production scheme, there is no single object to test: the evaluation is an audit of how the process is run over a season, and surveillance leans on periodic audits and document review. For a service against a service scheme, the evaluation looks at how the service is designed and delivered, through a mix of audit, observation and review of outcomes.
The clause numbers are identical in all three cases; what changes is what counts as evidence of conformity. The framework does not change, but the scheme, the evaluation methods and the surveillance design do. When an assessor reviews a service or process file using a product-shaped mindset, the body that has thought through Annex B and built scheme-specific methods is the one that passes cleanly.
Evidence and common non-conformity, clause by clause
One table, the whole map. For each clause, the record an assessor will ask to see, and the mistake that most often becomes a written finding. Use it as a self-check before an assessment.
| Clause | Evidence the assessor asks for | Most common non-conformity |
|---|---|---|
| 4.1 Legal and contractual | Incorporation documents, legal-structure map, client contract template, certification-decision procedure | Client agreement omits required clauses such as obligations on suspension and rules on mark use |
| 4.2 Impartiality | Signed impartiality declarations, live risk register with treatment, consultancy register, website and marketing copy | Impartiality treated as a one-time statement with no live risk register, or a website that links to a consultancy |
| 4.3 Liability and financing | Risk and liability assessment, professional liability insurance policy | No liability insurance, or a policy not sized to the body’s scope |
| 4.5 Confidentiality | Confidentiality clauses in personnel undertakings and the client contract, disclosure procedure | Staff or subcontractors with no signed confidentiality commitment, or disclosure without advance notice |
| 5.2 Impartiality mechanism | Committee charter, member list with represented interests, annual impartiality review record, escalation procedure | A committee on paper only, unbalanced membership, or no record of the annual review |
| 6.1 Personnel | Competence criteria per function, training records, signed undertakings, pay structure, individual qualification files | Evaluator pay tied to throughput (breaches 6.1.4), or thin competence records |
| 6.2 Resources and outsourcing | Equipment and calibration records, outsourcing contracts with conflict-of-interest clause, qualification of outsourced bodies | Outsourced evaluation without a conflict-of-interest contract, or an attempt to delegate the certification decision |
| 7.4 Evaluation | Evaluation plan, evaluator assignment showing independence, evaluation report, corrective-action trail | Report that does not trace findings to the specific scheme requirement, or corrective actions accepted without evaluation |
| 7.5 and 7.6 Review and decision | Review records naming a non-evaluator reviewer, decision records naming the decision-maker, their link to the body and their competence | The same person evaluates and decides, or the decision-maker’s independence and competence are not documented |
| 7.7 Certificate | Issued certificates showing holder, certified item, scheme and version, body identity, validity and conditions | Certificate that does not name the scheme version, or a grant date earlier than the decision date |
| 7.9 Surveillance | Surveillance programme, justification for the frequency, documented decision per cycle | Surveillance on a fixed calendar with no risk-based justification, or no recorded decision closing the cycle |
| 7.13 Complaints and appeals | Procedure, complaints and appeals log, case records showing deciders were independent of the contested work | The appeal handled by the same person whose decision is being challenged |
| 8 Management system | Option A: 8.2 to 8.8 records, especially management review and internal audit; Option B: ISO 9001 certificate plus the bridge to 17065 | Option B body that cannot show how its ISO 9001 system addresses the technical and impartiality requirements |
Knowing the requirements is one job; building the documents and structure that satisfy them is another. For the clause-by-clause build plan, which document or procedure satisfies which clause and who owns it, see our step-by-step implementation guide. If you would rather start from a ready-made set, the ISO/IEC 17065 documentation kit maps to these clauses out of the box. You can confirm the standard’s scope and current status on the official ISO catalogue page for ISO/IEC 17065:2012.
Frequently asked questions
From requirements to a body that passes
Read the standard once and the five clauses look like a long compliance list. Read it as an assessor does and a pattern appears: almost every requirement asks for a record that proves you did the right thing, in the right order, by the right person, traceable to the scheme. The bodies that struggle are not the ones that misunderstand a clause; they are the ones that never built the evidence behind it, or let the wall between evaluating and deciding quietly come down under staffing pressure.
Use the table above as your standing self-check, treat the scheme as the document that drives the rest, and protect impartiality and the segregation of evaluation from decision as the two controls you can least afford to lose. When you are ready to turn these requirements into a working body, the implementation guide and the impartiality firewall guide are the next two pages to read.