Skip to main content

Quality Statement

Risk3sixty ISO Certifications is in the process of gaining accreditation to issue ISO 27001 certifications. ISO 27001 is an international standard that provides a framework for establishing, implementing, maintaining, and continuously improving an Information Security Management System (ISMS).

All information on this page is important information about our operations which support public confidence and trust in the certification system. Please note that risk3sixty is unable to offer advisory services to ISO certification clients.

Risk3sixty ISO Certifications is committed to conducting all certification activities with the highest standards of impartiality, integrity, and objectivity. We understand the importance of impartiality in carrying out our certification responsibilities, and we manage all potential conflicts of interest to ensure that our decisions are based solely on objective evidence of conformity.

Impartiality may be compromised through commercial or financial pressures, self-review, familiarity, or intimidation. Our commitment to impartiality is overseen by our Impartiality Committee, which monitors our activities to ensure that no undue influence affects the outcome of any certification decision.

Potential threats to impartiality are evaluated for each engagement and mitigating measures are put in place prior to beginning the audit. In addition, risk3sixty ISO Certifications is unable to certify clients who are currently receiving advisory services from risk3sixty.

To safeguard impartiality, we:

  • Identify, analyze, and document potential conflicts of interest, taking appropriate measures to eliminate or minimize them.

  • Review impartiality at the commencement of each engagement.

  • Review risks to impartiality annually and ensure that appropriate mitigating measures are in place.

  • Require all personnel to review and acknowledge our Impartiality policy annually and disclose any known conflicts of interest.

  • Ensure that all personnel, including external assessors, act with fairness, neutrality, and transparency.

risk3sixty ISO Certifications applies the procedures detailed within ISO/IEC 17021-1, as well as other normative references governing the audit activities within the scope of certification. An organization’s obligations at the time of application are communicated in the form of a certificate agreement within our master services agreement.

Supplemental details that support certificate decisions concerning granting, refusing, maintaining, renewing, suspending, restoring, or withdrawing certification, in addition to the expansion or reduction of certificate scopes, are also described within this agreement.

Certificate decisions are facilitated by a centralized team of subject matter experts who review each audit file for conformity to the internal quality system maintained by the certification body and normative references made applicable via the management system’s certification body accreditation.

A summary of the procedures performed and the objective evidence inspected as part of our examination is communicated in an audit report at each assessment’s conclusion. The report is accompanied by a recommendation from the appointed lead auditor who performed certification activities under the oversight of the accredited certification body.

End users or readers who are in receipt of certificate awards issued by risk3sixty ISO Certification can determine the validity of the artifact and status of certification by accessing the public certificate directory.

Risk3sixty ISO Certifications retains the authority to suspend certificates at any time due to various reasons, such as a breach of contract with the certification body, negligence, concealment of evidence, nonconformities related to audit criteria, investigations, misrepresentation of scope or associated marks, complaints, and unpaid or severely overdue fees. During suspension, certification for the affected scope becomes temporarily invalid and is not eligible for transfer. In such cases, any public information related to the affected scope of certification will be updated to indicate a suspended status, which will be reversed once the underlying issue is resolved, as determined by an appointed representative of risk3sixty ISO Certifications.

Suspended scopes of certification are not eligible for transfer to another certification body during the suspension period. Generally, suspension periods do not exceed 30 days; however, exceptions allowing extensions up to six months may be approved through written authorization from an appointed representative at risk3sixty ISO Certifications. Exceptions may be considered in situations when the issue is being reliably addressed and communication is ongoing, but more time is required.

If the suspension period expires, risk3sixty ISO Certifications will withdraw the subject scope of certification from its directory and will expect the client to cease any further internal or public references indicating certification of the scope by risk3sixty ISO Certifications. Scopes that have been withdrawn by risk3sixty ISO Certifications will need to enter into a new contract and then undergo an Initial Certification Audit, including both a Stage 1 Certification Audit and Stage 2 Certification Audit.

All suspensions are clearly labeled within the affected certificate entry available in the public certificate directory.

Risk3sixty ISO Certifications clients may use risk3sixty’s certification mark in its intended form as long as they are certified. In addition, all references to certification must be accurate, including with respect to sites and activities in scope, and not in any way imply that a product, service, or process is certified. For further detail, please reference the ISO Certification Terms and Conditions.

If misuse of the risk3sixty ISO Certifications certification mark is identified, or any reference to certification is misleading, we will take immediate action to address it. You may also e-mail us at isocertifications@risk3sixty.com if you have identified any improper use of the certification mark.