NEW — The ISO 14001:2026, ISO/IEC 17020:2026 and FSSC 22000 V7 documentation kits are now available.
ISO/IEC 17065

Impartiality and the Consultancy Firewall Under ISO/IEC 17065 (Clauses 4.2 and 5.2)

Published on August 20, 2026
15 min read
By Hafsa J.

Last Updated on August 20, 2026 by Hafsa J.

Impartiality and the Consultancy Firewall Under ISO/IEC 17065 (Clauses 4.2 and 5.2)

Impartiality is the clause family where assessors raise the most non-conformities against a product certification body, and most of those findings are preventable. They come from structure, not from bad intentions: a consultancy arm sitting too close to the certification function, a website that hints certification is easier if you hire a named adviser, an impartiality committee that exists on paper but never met. If you build the firewall before the assessment, the impartiality review becomes the easiest part of your visit. If you wait for the assessor to find the gaps, it becomes the hardest.

This is a build guide for the certification body, not a definition piece. We will walk through the structural walls Clause 4.2 demands, the marketing rule in 4.2.10 that quietly catches well-run CBs, the financial-pressure red lines that turn a good client into a threat, a do and don’t firewall table, and a ready-to-adopt impartiality committee charter drawn straight from Clause 5.2. Read it with your org chart, your website, and your client list open. Every clause number below traces to ISO/IEC 17065:2012; nothing here is invented.

The four walls of the firewall: what Clause 4.2 actually prohibits

Clause 4.2 is the heaviest section of the standard, thirteen requirements in all, and it is not a single principle you can satisfy with one signed statement. It is a set of hard structural prohibitions. Think of them as four walls you build around the certification function so that commercial relationships cannot reach in and bend a decision. Build all four and the rest of 4.2 (the live risk register, the signed undertakings, the duty to act) becomes maintenance rather than emergency repair.

Wall 1: you cannot be the thing you certify (4.2.6)

Clause 4.2.6 prohibits the certification body from being the designer, manufacturer, installer, distributor, maintainer or supplier of the product, process or service it certifies. This is the ownership and shared-activity wall. It catches more than the obvious case of a CB certifying its own product line. It catches a parent company or a related body that performs any of those roles, and it catches shared staff: an engineer who designs the product on Monday cannot sit on the evaluation of that same product on Tuesday. Map your legal entity and every parent or affiliate (Clause 4.1.2 already asks you to do this), then check that no entity in that map performs a 4.2.6 role for any product in your certification scope. Where a related body does, the cleanest answer is to remove that product from your scope.

Wall 2: the consultancy ban (4.2.7)

Clause 4.2.7 is the rule the field worries about most. The certification body shall not certify a client where the CB itself, or a related body, has provided consultancy on the certified item before the evaluation under conditions that would compromise impartiality. In plain terms: you cannot sell a client the advice on how to meet the requirement and then sell that same client the certificate that says they met it. The two revenue streams cannot land on the same client for the same scope. This is why a CB that also runs a profitable advisory practice has to draw a register of who has consulted for whom, and treat any overlap as a bar to certifying that client. The accreditation rulebook reinforces this: clauses 4.2.6 and 4.2.7 together prohibit a CB from selling consultancy to its certification clients.

Wall 3: no certifying your own internal-audit work (4.2.8)

Clause 4.2.8 closes a subtler gap. The certification body shall not provide the client’s internal audit, and shall not certify a client whose internal audit it performed. Internal audit is a consultancy-adjacent service: if your people audited the client’s system from the inside, you cannot then judge that same system from the outside without grading your own homework. If your CB also offers internal-audit support as a service, keep a record that lets you screen it against your certification client list, the same way you screen consultancy under 4.2.7.

Wall 4: you cannot outsource the evaluation to a consultancy (4.2.9)

Clause 4.2.9 stops you from doing through a subcontractor what you cannot do yourself. You shall not outsource any part of the evaluation to a body that provides consultancy or design to certified clients. So when you qualify an external evaluator or a subcontracted test house, the conflict-of-interest screen is part of qualifying them, not an afterthought. The certification decision, separately, is never outsourceable at all (Clause 6.2.2.3), but 4.2.9 is the narrower rule that the evaluation work itself cannot be handed to a consultancy.

Those four walls are the structure. The rest of 4.2 keeps them standing: top management commits to impartiality (4.2.1), you publish an impartiality statement (4.2.2), personnel are independent of commercial interests (4.2.3), you run an ongoing risk identification on every relationship (4.2.4) and then eliminate or minimize each identified risk with a documented action (4.2.5), and every person inside and outside the CB signs a written undertaking to act impartially and to declare prior and present conflicts (4.2.12), with a standing duty to tell you about any conflict they learn of (4.2.13). The single most common non-conformity here is treating impartiality as a one-time statement with no live risk register behind it. The assessor will ask to see the register, the dates, and the treatment actions.

The marketing wall: the 4.2.10 website rule that catches good CBs

This is the highest-value, lowest-cost fix in the whole article, and it lives in your marketing copy rather than your org chart. Clause 4.2.10 requires that your marketing must not imply a link with a consultancy, and must not state or imply that certification would be simpler, easier, faster or cheaper if a named consultancy were used. A CB can build all four structural walls perfectly and still pick up a non-conformity because a page on its own website, or a partner page, crosses this line. Assessors do look at the public site, so the practical move is to audit your own pages before they do.

The trap is rarely a blatant statement. It is usually a friendly hyperlink, a “recommended partners” block, or a sentence that sounds like helpful guidance. The test is simple: would a reader come away believing that hiring a specific adviser improves their odds, speed or cost of getting certified by you? If yes, the copy fails 4.2.10. Below is the line drawn in concrete terms.

Non-compliant website copy (rewrite these)

  • “Not ready yet? Our partner Acme Consulting will get you certification-ready faster.” (Implies a named consultancy makes certification faster.)
  • “Clients who prepare with [Consultancy] typically sail through our evaluation.” (Implies easier certification through a named adviser.)
  • A “Recommended Consultants” page or sidebar that hyperlinks to specific advisory firms. (Implies a link with a consultancy.)
  • “Bundle our certification with [Consultancy] coaching and save.” (Implies cheaper certification when a named consultancy is used.)
  • “Need help meeting the requirements? Talk to our advisory team.” (Implies the CB itself sells the consultancy, which also breaches 4.2.7.)

Compliant website copy (use these instead)

  • “Our certification requirements and evaluation procedures are published here so you can prepare against them directly.” (Points to your own public information per Clause 4.6, names no adviser.)
  • “You may choose any consultant or none. Using a consultant has no effect on the outcome, speed or cost of certification with us.” (States the neutrality 4.2.10 wants on the record.)
  • “We do not provide, recommend or partner with consultancy services, to protect the impartiality of our decisions.” (Turns the prohibition into a trust signal.)
  • “Certification is granted on the evidence, not on who helped you prepare.” (Reinforces that the decision rests on conformity alone.)

One enforcement point worth knowing while you are tidying marketing: under IAF Resolution 2018-13, an accredited 17065 CB must not issue unaccredited product certificates within its accredited scopes (full implementation was 2021-10-31, and UKAS enforces it). It is a separate rule from 4.2.10, but it lives in the same place: the claims and certificates you put in front of the public have to match what your accreditation actually covers.

 

Financial pressure: when a paying client becomes an impartiality threat

The standard does not set a revenue percentage that turns a client into a threat, and you should be wary of any source that claims one exists. What the standard does require is that you identify impartiality risks arising from your relationships on an ongoing basis (Clause 4.2.4) and then treat each identified risk with a documented action (Clause 4.2.5). Financial dependence on a single client is exactly the kind of relationship 4.2.4 is written to catch. The work is to set your own red lines, write them down, and let the impartiality mechanism review whether they are working.

To make 4.2.4 and 4.2.5 concrete on the financial side, pick a concentration threshold the CB will treat as a trigger, for example any single client crossing a defined share of annual certification revenue, and record it in the risk register. When a client crosses it, that is not a disqualification; it is a documented risk that demands a documented treatment. The treatments that satisfy an assessor are structural, not promises:

  • Decouple the people from the money. Clause 6.1.4 already forbids tying evaluator or decision-maker pay to the number or outcome of evaluations, so confirm no one in the certification chain has a personal stake in keeping the dominant client happy.
  • Escalate the dominant client’s decisions for extra review and put the concentration risk in front of the impartiality mechanism (the 5.2 committee), with the date and the action recorded.
  • Hold the segregation line regardless of client size. The person who decides must not have evaluated (Clause 7.6.1), and a large account does not buy a shortcut around that rule.
  • Build a deliberate path to dilute the concentration over time and track it, so the register shows movement rather than a risk that sits open year after year.

The red line that genuinely disqualifies is behavioral, not arithmetic: the moment a commercial consideration actually influences, or visibly threatens to influence, a certification outcome. If a client’s volume is used as leverage over a decision, or staff feel pressure to soften a finding to protect revenue, the threat has materialized and you must act on it and be able to demonstrate that you acted (Clause 5.2.5). An assessor is not looking for a CB with no large clients. They are looking for a CB that sees its concentration risks, records them, and can show the treatment.

The firewall do and don’t table

Hand this to anyone in your CB who touches clients, evaluations, marketing or subcontracting. Each row pins a behavior to the clause it serves, so a team member can see not just the rule but why it exists.

Clause Do Don’t
4.2.6 Map every parent and affiliate, and remove from scope any product a related body designs, makes, installs, distributes, maintains or supplies. Certify a product your own group designs, makes or supplies, or let a designer of an item evaluate that same item.
4.2.7 Keep a consultancy register and screen every applicant against it before evaluation. Sell a client consultancy on the item and then certify that same client for the same scope.
4.2.8 Screen any internal-audit service you provide against your certification client list. Perform a client’s internal audit and then certify that same client.
4.2.9 Run a conflict-of-interest screen when qualifying any external evaluator or test house. Outsource any part of the evaluation to a body that provides consultancy or design to certified clients.
4.2.10 State on your site that using any consultant has no effect on the outcome, speed or cost of certification. Link to, recommend or partner with a named consultancy, or imply certification is easier or cheaper with one.
4.2.12 and 4.2.13 Collect a signed impartiality undertaking from every internal and external person, and require them to declare conflicts as they arise. Assume verbal goodwill is enough, or skip the undertaking for subcontractors.
6.1.4 Pay evaluators and decision-makers on a basis unrelated to how many or which way evaluations go. Tie any certification-chain pay to throughput or to favorable outcomes.

A ready-to-adopt impartiality committee charter (Clause 5.2)

Clause 5.2 requires a documented mechanism for safeguarding impartiality, usually a committee or council. The most common non-conformity is a committee that exists on paper: unbalanced membership, or no annual review record. The charter below is built directly from the five requirements of 5.2 so that each clause has a clause in your governing document. Adapt the names and numbers to your CB, but keep every element, because each one answers a question the assessor will ask.

Purpose

The Impartiality Committee is the documented mechanism required by Clause 5.2.1. Its purpose is to safeguard the impartiality of [CB name] in all certification activity by performing the functions in Clause 5.2.2: helping to develop the policy on impartiality of certification activities, countering any tendency of the certification body to let commercial considerations compromise impartiality, advising on matters that affect confidence in certification, and reviewing the impartiality of the body’s evaluation, review, decision and surveillance activities at least once a year.

Composition (Clause 5.2.3)

Membership shall be balanced so that no single interest predominates. The committee documents each member against the interest they represent, for example: the certification body itself, certified clients, users of certified products, and an independent interest such as a regulator, technical expert, consumer or trade representative. The balance is verified at appointment and at each annual review, and the member list with represented interests is kept on file. If any single interest could outweigh the others, the composition is corrected before the committee acts.

Functions and meetings (Clause 5.2.2)

  • Assist in developing the policy on impartiality of the certification body’s activities.
  • Counter any tendency of the certification body to allow commercial or other considerations to prevent the consistent objective provision of certification.
  • Advise on matters affecting confidence in certification, including openness and public perception.
  • Conduct a review of the impartiality of the evaluation, review, decision and surveillance activities at least once a year, recorded with date, attendees and conclusions.

Access to information (Clause 5.2.4)

The committee shall have access to all the information it needs to perform its functions, including the impartiality risk register, the consultancy register, certification decision records and surveillance results. Management shall not withhold information on commercial grounds.

Authority to act (Clause 5.2.5)

Where the committee identifies a threat to impartiality, the certification body shall take action in response and shall be able to demonstrate that it acted. The charter should name the escalation path: how a flagged threat reaches top management, the requirement to record the response, and confirmation that the committee can see the outcome of its own escalation. This is the line that separates a real mechanism from a paper one, because the committee can do more than discuss; it can trigger an action the body has to take and document.

For the outputs an assessor will ask to see, this committee charter pairs with the rest of your certification system: the segregation between evaluation, review and decision (Clause 7.6) and the management-system records that feed your management review. If you want the full evidence-per-clause picture for the assessment, our companion guide on the key requirements of ISO/IEC 17065 lays out what assessors expect against each clause, and the walkthrough on preparing for an ISO/IEC 17065 audit covers how the impartiality review fits the wider assessment.

Self-check: where would an assessor find a gap in your firewall?

Before your next assessment, run your CB through the questions an impartiality assessor actually works from. The check below walks the structural walls, the marketing rule, the financial red lines and the committee charter you have just read, and tells you where the open gaps are likely to sit so you can close them while it is still cheap to do so.

ISO 17065 IMPARTIALITY TOOL
Consultancy Firewall Self-Check
Eight questions that test your certification body against the impartiality requirements assessors raise most
Answer each question for your certification body. The check maps your answers to clause 4.2 (management of impartiality) and 5.2 (mechanism for safeguarding impartiality). It is an educational self-check, not an accreditation assessment.

Disclaimer: This self-check is an educational aid that maps your answers to ISO/IEC 17065 clauses 4.2 and 5.2. It is not an accreditation assessment and does not guarantee a particular accreditation outcome. A flagged item is a prompt to review your arrangements against the standard and your accreditation body's requirements, not a finding.

If the check surfaces gaps you want help closing, the ISO/IEC 17065 documentation kit gives you the impartiality statement, risk register, consultancy register, committee charter and signed-undertaking templates already structured to the clauses above, so you are editing rather than drafting from a blank page.

The mindset that passes the impartiality assessment

The certification bodies that find the impartiality review easy are not the ones with no relationships, no large clients and no commercial pressure. Every CB has those. They are the ones that treated impartiality as a structure to build rather than a value to declare: four prohibition walls mapped against the legal entity, a website that says using a consultant changes nothing, financial red lines written into a live register, and a committee that meets, reviews at least yearly, and can force an action when it sees a threat. Each of those traces to a specific clause, and each leaves a record an assessor can read.

It is worth remembering why accreditation bodies guard this so closely. When the chain that protects impartiality breaks at a certification body, it does not stay contained: a CB that lost its accreditation is a different thing from the certificates it issued, and the gap between the two is where suppliers and the public get hurt. We unpack that distinction in our analysis of the BBA accreditation suspension and what it means for certificate holders. Build the firewall now, keep the records current, and the impartiality assessment stops being the part of the visit you dread. For the full text of the requirements, the standard is available on the ISO Online Browsing Platform.

Share on social media
Take the next step

Prepare your ISO/IEC 17065 certification with the complete kit

The complete documentation package to deploy an ISO/IEC 17065:2012-compliant product certification body: ready-to-use document architecture covering scheme management, evaluation, certification decisions, and surveillance.