Skip to main content
RiskZeroCertifiers

Trust

Impartiality statement

Impartiality is the basis of confidence in certification. This statement sets out who we work with, what we do and do not do, and how RiskZero keeps the audit and the decision independent of the people who prepared the package.

Our commitment

The management of RiskZero Certifiers understands the importance of impartiality in carrying out management system certification activities. We are committed to managing conflicts of interest and to ensuring the objectivity of our certification audits and decisions. This commitment applies to everyone acting on our behalf, including employed and contracted auditors, technical reviewers, and members of committees.

Who we work with

Most of the packages we certify reach us through a defined route, and we disclose it. We accept packages prepared by any consultancy, or built in-house, on the same terms.

  • SRG is a consultancy. It helps an organization scope and build its ISMS, implement and harden controls, perform penetration testing, and write policies. When the package is complete, SRG attests that it is ready and submits it. SRG is the intermediary between the client and RiskZero.
  • riskzero.us is the platform on which packages are prepared, attested, and submitted, and through which our auditors examine them. It is how two separate teams work on one package without sharing people.

RiskZero Certifiers is a separate company with its own auditors, technical reviewers, and signatories. No member of RiskZero's audit or decision-making staff works for SRG, and noSRG consultant takes part in a RiskZero audit, review, or certification decision.SRG's attestation is an input to Stage 1, never a substitute for it: our auditors form their own view of every package, and the findings do not depend on who prepared it.

What we do not do

To protect impartiality, RiskZero does not:

  • Provide management system consultancy, including designing, implementing, or maintaining an ISMS.
  • Perform internal audits for organizations we certify or are considering certifying.
  • Provide training that could be considered consultancy for a specific client's ISMS.
  • Assign anyone to an audit, technical review, or certification decision who took part in preparing, attesting, or submitting the package, at SRG or anywhere else, within the previous two years.
  • Certify an organization that is a related body of RiskZero, or that RiskZero has audited internally in the previous two years.
  • Offer or accept inducements that could influence the outcome of an audit or certification decision.
  • State or imply that certification will be simpler, faster, or cheaper because a particular consultancy was used. The audit is the same for every package.

How conflicts are managed

Before accepting any engagement we identify, analyze, and document potential conflicts of interest arising from relationships between RiskZero, its personnel, and the applicant organization, including any roleSRG played in preparing the package. Auditors declare any relationship with a client, including prior employment, consultancy, financial interest, or personal relationships, and are not assigned where a conflict exists.

Personnel are not permitted to audit and make the certification decision for the same client. Certification decisions are made by competent persons who were not part of the audit team and had no part in preparing the package.

Oversight

An impartiality committee, comprising members drawn from outside RiskZero who represent the interests of clients, their customers, and the wider public, reviews our policies, processes, and activities at least annually, including our working relationship with SRG and riskzero.us. The committee has access to all information necessary to fulfill its function and may escalate concerns outside RiskZero if management fails to act on its advice.

Financial independence

Certification fees are set according to the audit time required and are not linked to the outcome of an audit or to who prepared the package. No member of staff is paid in a way that depends on the number of certificates issued or on the results of specific audits.

Raising a concern

Anyone who believes that RiskZero's impartiality has been or may be compromised is encouraged to tell us. Concerns can be raised through our complaints process or directly with the impartiality committee through the contact form, marked for the attention of the committee.

This statement is reviewed annually and was last reviewed in September 2026.