About
A certification body built around one idea: the certificate has to mean something
RiskZero was founded in 2017 by auditors who had watched certification become a box-ticking exercise and thought it could be done better. We audit information security management systems against ISO/IEC 27001, and nothing else.
- Founded
- 2017
- Standard
- ISO/IEC 27001:2022
Principles
Four things we will not compromise on
We audit. We do not advise.
A certificate means nothing if the people who issued it also designed the system. SRG advises and attests; we audit and decide. Different companies, different people, different signatures, and nobody crosses from one side to the other on the same package.
The auditor never decides.
Every certification decision is made by a reviewer who was not on the audit team, from the full audit file. It is slower than signing off at the closing meeting. It is also what accreditation requires and what makes the outcome trustworthy.
Findings are explained, not just recorded.
A finding names the clause or control, the evidence examined, and why it matters. If a client cannot explain a finding to their board without calling us, we have not written it well enough.
Everything we issue can be checked.
Anyone can ask us to confirm the scope, status, and expiry date of a certificate we issued, and we answer within one business day. Suspensions and withdrawals are disclosed too. A body that only confirms good news is not worth trusting.
Who does what
Three parties, one package, separate people
Most packages we certify are built and attested by SRG and reach us through riskzero.us. We work with both, we disclose it, and we accept packages from any consultancy or in-house team on the same terms. What keeps the certificate credible is that the people who prepare a package are never the people who audit it or sign the decision.
Consultancy and attestation
SRG
Scopes and builds the ISMS with the client, implements and hardens the controls, performs penetration testing, writes the policies, and attests that the package is ready. The intermediary between the client and RiskZero.
Platform
riskzero.us
Where the package is assembled, attested, and submitted, and where our auditors examine it. Two separate teams, one package, no shared people.
Certifier
RiskZero Certifiers
A separate company whose auditors, reviewers, and signatories perform Stage 1, Stage 2, and the certification decision. Nobody who prepared the package takes part.
Our impartiality statement sets out the rules in full: who may not be assigned to an audit, how the decision is separated from the audit, and how the relationship is overseen.
Auditors
Practitioners first, auditors second
Our auditors have run security programs, built platforms, and handled incidents. That is why they ask the right questions and why their findings are worth acting on.
- Lead auditor qualification for ISO/IEC 27001 with logged audit days
- Five or more years in hands-on security, engineering, or IT operations roles before auditing
- Sector allocation: cloud and software, financial services, health, public sector, professional services
- Annual calibration and witnessed audits by our technical review team
- Continuing professional development, including on ISO 27002:2022 and cloud platforms
Governance
How we are held accountable
ISO/IEC 17021-1 sets the requirements for bodies that audit and certify management systems: impartiality, competence, responsibility, openness, confidentiality, and responsiveness to complaints. ISO/IEC 27006-1 adds requirements specific to certifying information security management systems, including auditor competence and audit time.
Our impartiality is overseen by a committee that includes people from outside RiskZero, representing client, customer, and public interests. It reviews our activities, our relationships with SRG andriskzero.us, and our decisions for anything that could compromise objectivity, and it can escalate concerns beyond management. Our impartiality statement sets out the commitments in full.
Any client can appeal a certification decision or complain about our service. Both are handled by people independent of the original work.
Ready to scope your audit?
Tell us about your organization, your ISMS scope, and your target date. We reply with a fixed-fee quote and available audit dates within two business days.