Certification means opening your organisation to an auditor. This is our commitment to protecting what we see — and a clear line around the little that is, by design, public.
Confidentiality is a requirement of ISO/IEC 17021-1 and a condition of trust. Information we obtain about your organisation in the course of certification — through applications, audits, and ongoing management of your certificate — is treated as confidential and used only for the purposes of certification.
Everyone acting on our behalf is bound by confidentiality — our personnel, committee members, auditors and sub-contractors — through their engagement with us. This obligation continues after the engagement ends.
We disclose confidential information beyond Skyeblanc Certification only in defined circumstances:
Where we are required by law or authorised by contract to release information to a third party, we notify you of the information provided, unless prohibited.
A certificate exists to be relied upon, so a limited set of information is public by design: the existence and status of a certificate (valid, suspended, withdrawn, expired), the certified standard and scope, and the certified organisation’s name and location. For accredited certificates, these details are also made available through the certificate-verification and accreditation databases required by the applicable accreditation framework, where applicable. Anyone can check them through our verification tool.
We apply appropriate measures to protect confidential information — including audit records and personal data — against loss, misuse and unauthorised access. How we handle personal information specifically is set out in our Privacy Notice.
If you believe confidential information has been mishandled, you can raise a complaint — it will be investigated by someone not involved in the matter.