All resources
GuideAug 2026 · 6 min

What ISO/IEC 17021-1 means when you outsource compliance work

You can buy help running a management system. You cannot buy it from the people who certify you. The line matters and it is often blurred.

When an organisation decides to hand compliance work to somebody outside, the first sensible question is whether that is allowed. The answer is yes, with one boundary that is worth understanding properly, because vendors on the wrong side of it are common and the consequence lands on you.

The rule, plainly

ISO/IEC 17021-1 governs bodies that audit and certify management systems. It requires that a certification body and its auditors do not provide management system consultancy to an organisation they certify. The purpose is obvious: an auditor should not be assessing work they were paid to produce.

The rule binds certification bodies. It does not stop you buying help from anyone else, and it does not make outsourced compliance work improper. What it does mean is that the party helping you build and run the system cannot also be the party issuing your certificate.

Where it gets blurred

  • A certification body offering a training or advisory arm that sells into the same client. Ask how the two are separated and who audits you.
  • A consultant who also holds an auditor role with your certification body. This is a question worth asking directly and early.
  • A vendor implying their involvement makes certification more likely. Nobody outside the certification body can offer that, and offering it is a signal.

Internal audit is a different thing

Clause 9.2 in the management system standards requires the organisation to conduct internal audits at planned intervals. This is a management activity that you own, and it can be conducted by a competent party you engage. It is not the certification audit and it does not replace it.

Keeping the two visibly separate is the point. Internal audit is how you find problems before your certification body does. If the same party did both, it would stop being able to do either well.

What stays yours regardless

Outsourcing the running of a management system does not outsource accountability for it. The scope, the risk appetite, the policy and every approval remain decisions of your leadership, and the audit log should carry their names rather than a vendor's.

A service that quietly makes those decisions for you is convenient right up until an auditor asks who approved something and the honest answer is a supplier. Preparing a decision with a recommendation is a service. Making it is a governance problem.

What the first conversation looks like

Bring one finding that has been open too long.

Forty-five minutes on your real scope. We walk that finding back to the control it breaks, the risk it raises and the person who owns it, with nothing prepared in advance.