Further to the answer given to question 48.11, what would be acceptable as impartially risk measure?
E.g. a stage 1 audit could be performed more than twice or more or the CAB could decide to “convert” the stage 1 and or 2 audit to a preliminary audit. Is this acceptable or under what conditions can this be accepted?
E.g. the CAB uses the preliminary audit as the internal audit of the client.
E.g. the risk is that the auditor that performed the preliminary audit is following up on his own preliminary audit and does not perform a full audit.
E.g. The auditor that performed the preliminary audit is given informal advice besides the preliminary nonconformities.
Given the answer to question 48.11:
a: Would it be acceptable under ISO/IEC 17021-1 that stage 1 audits can be performed over and over again?
b: Would it be acceptable under ISO/IEC 17021-1 that preliminary audits can be performed over and over again?
c: If not, what could be a proper justification and/or risk mitigation measure?
March 2025
a: It would not be acceptable without proper justification (see 9.3.1.2.4.). To repeat a stage 1 audit is a decision of the CB and not of the client. If any significant changes which would impact the management system occur, the certification body shall consider the need to repeat all or part of stage 1. As a rule of thumb, a second stage 1 audit should be recognized as potentially compromising the impartiality, i.e. additional risk measures should be in place.
b: Preliminary audits are outside of the certification process. The repetition of preliminary audits irremediably is oriented to determine if the problems encountered in the previous preliminary audits have been solved and it should be considered as “participating in the development of the management systems”. So, it would not be acceptable. As a rule of thumb, more than one preliminary audit should be recognized as potentially compromising the impartiality.
c: Considering the answers to a) and b), mitigation measure should be taken in order to fulfil 5.2.3 from ISO/IEC 17021-1:2015.

