Standards Development and Conformity Assessment
Standards development is the structured, consensus-based process through which international standards such as ISO/IEC 27001 are created and maintained. ISO (International Organization for Standardization) and IEC (International Electrotechnical Commission) cooperate through Joint Technical Committ… Standards development is the structured, consensus-based process through which international standards such as ISO/IEC 27001 are created and maintained. ISO (International Organization for Standardization) and IEC (International Electrotechnical Commission) cooperate through Joint Technical Committee JTC 1, Subcommittee SC 27, which is responsible for information security, cybersecurity and privacy protection. Experts nominated by national standards bodies draft standards through defined stages: proposal, preparatory (working draft), committee (CD), enquiry (DIS), approval (FDIS) and publication. Each stage involves review, comments and voting, ensuring that the standard reflects global consensus, is technology-neutral and is applicable to organizations of any size or sector. Published standards are reviewed at least every five years and may be confirmed, revised or withdrawn; ISO/IEC 27001:2022 is an example of such a revision. Management system standards follow the Harmonized Structure (formerly Annex SL), giving common clauses, terms and definitions that make integration with ISO 9001, ISO 14001 and others easier. Conformity assessment is the demonstration that specified requirements relating to a product, process, system, person or body are fulfilled, as defined in ISO/IEC 17000. It can be first-party (self-assessment or internal audit), second-party (by customers or interested parties) or third-party (by an independent certification body). ISO's Committee on Conformity Assessment (CASCO) develops the related standards. Certification bodies auditing ISMSs must comply with ISO/IEC 17021-1 and ISO/IEC 27006, which specify competence, impartiality and audit process requirements. Accreditation bodies, operating under ISO/IEC 17011 and often members of the IAF, evaluate and accredit certification bodies, creating a chain of trust and international recognition through multilateral agreements. ISO 19011 provides guidance on auditing management systems. A typical certification cycle lasts three years, comprising a Stage 1 and Stage 2 initial audit, annual surveillance audits and a recertification audit. For a Lead Auditor, understanding this framework ensures audits are conducted consistently, objectively and credibly, giving stakeholders confidence in certified ISMSs.
Standards Development and Conformity Assessment: A Complete Guide for the ISO/IEC 27001 Lead Auditor Exam
Introduction
Every ISO/IEC 27001 Lead Auditor works inside a larger system. Standards are written by international bodies through a structured, consensus-based process. Organizations then implement those standards. Independent bodies assess and certify that implementation, and accreditation bodies oversee those certification bodies.
This topic, Standards Development and Conformity Assessment, sits within ISMS Fundamental Principles and Concepts. It explains where ISO/IEC 27001 comes from, why it has authority, and how certification is made credible. Exam questions on this domain are often treated as easy marks, yet many candidates lose points by confusing terms such as certification and accreditation, or first-party and third-party audits.
1. Why This Topic Is Important
It defines your role. A lead auditor normally works for, or on behalf of, a certification body (a conformity assessment body). You need to know what rules that body follows and who supervises it.
It underpins trust. A certificate is only valuable if the market trusts it. That trust rests on:
- a consensus-based standards process;
- impartial, competent certification bodies;
- accreditation bodies that oversee those certification bodies;
- international mutual recognition of accreditation.
It keeps you current. Standards are revised over time, for example ISO/IEC 27001:2013 to ISO/IEC 27001:2022, followed by Amendment 1:2024 on climate action. Auditors must know how revisions and transition periods work.
It is examinable. Exams routinely test definitions, roles of organizations, the stages of standard development, and the hierarchy of conformity assessment standards.
2. What Standards Development Is
2.1 What is a standard?
A standard is a document, established by consensus and approved by a recognized body. It provides rules, guidelines or characteristics for activities or their results, for common and repeated use, aimed at achieving the optimum degree of order in a given context (ISO/IEC Guide 2).
Key features of a standard:
- Voluntary. It only becomes mandatory if a law, regulation or contract requires it.
- Based on consensus. General agreement and the absence of sustained opposition, which is not the same as unanimity.
- Reviewed periodically. Every standard has a review cycle.
- ISO (International Organization for Standardization). Founded in 1947 and based in Geneva. It is an independent, non-governmental federation of national standards bodies, with roughly 170 members.
- IEC (International Electrotechnical Commission). Founded in 1906. It develops standards for electrical, electronic and related technologies.
- ISO/IEC JTC 1. A Joint Technical Committee set up in 1987 to cover information technology.
- JTC 1/SC 27. The subcommittee for Information security, cybersecurity and privacy protection. It is responsible for the ISO/IEC 27000 family, including ISO/IEC 27000, 27001, 27002, 27005 and 27006.
- National Standards Bodies (NSBs). Examples include BSI (UK), ANSI (USA), DIN (Germany), AFNOR (France) and SCC (Canada). NSBs participate as P-members (participating, with voting obligations) or O-members (observing).
- ISO CASCO. The ISO Committee on Conformity Assessment. It develops the ISO/IEC 17000 series.
- Standards respond to a market need.
- Standards are based on global expert opinion.
- Standards are developed through a multi-stakeholder process.
- Standards are based on consensus.
The ISO/IEC Directives describe a staged process. Each stage has a code number, which is useful to know for the exam.
- Preliminary stage (00). Work items are considered for the future.
- Proposal stage (10). A New Work Item Proposal (NWIP) is submitted and balloted. It needs a simple majority of P-members, plus a minimum number of experts committed to the work.
- Preparatory stage (20). A working group of experts prepares Working Drafts (WD).
- Committee stage (30). A Committee Draft (CD) is circulated to committee members for comment and consensus.
- Enquiry stage (40). A Draft International Standard (DIS) is balloted by all national bodies, typically over 12 weeks.
It is approved if two-thirds of the P-members voting are in favour and not more than one quarter of the total votes cast are negative. - Approval stage (50). A Final Draft International Standard (FDIS) goes to a final yes/no vote, typically over 8 weeks. Only editorial changes are allowed at this stage.
- Publication stage (60). The International Standard (IS) is published.
- Review stage (90). A systematic review takes place at least every five years. The outcome is to confirm, revise or withdraw the standard.
- Withdrawal stage (95). The standard is withdrawn.
2.5 Other ISO deliverables
- Technical Specification (TS)
- Technical Report (TR)
- Publicly Available Specification (PAS)
- International Workshop Agreement (IWA)
- Amendments (Amd), such as ISO/IEC 27001:2022/Amd 1:2024
- Technical Corrigenda (Cor)
2.6 Types of standards in the 27000 family
Requirements standards (normative, certifiable). These use shall.
- ISO/IEC 27001 (ISMS requirements)
- ISO/IEC 27006-1 (requirements for bodies certifying ISMS)
- ISO/IEC 27701 (privacy information management)
- ISO/IEC 27002 (information security controls)
- ISO/IEC 27003 (ISMS guidance)
- ISO/IEC 27004 (monitoring and measurement)
- ISO/IEC 27005 (information security risk management)
- ISO/IEC 27007 (guidance for ISMS auditing)
Verbal forms used in ISO standards:
- shall = requirement
- should = recommendation
- may = permission
- can = possibility or capability
ISO management system standards now follow the Harmonized Structure, formerly called Annex SL or the High Level Structure. It is defined in the ISO/IEC Directives, Part 1, Consolidated ISO Supplement. It provides identical core text, common terms and the same clause numbering.
Clauses 1 to 3 are scope, normative references, and terms and definitions. The common requirement clauses are:
- 4 Context of the organization
- 5 Leadership
- 6 Planning
- 7 Support
- 8 Operation
- 9 Performance evaluation
- 10 Improvement
3.1 Definition
ISO/IEC 17000:2020 defines conformity assessment as the demonstration that specified requirements are fulfilled. Specified requirements may relate to a product, process, system, person or body.
Conformity assessment activities include:
- testing
- inspection
- validation and verification
- audit
- certification
- accreditation
- First-party. Performed by the organization itself, for example internal audits under ISO/IEC 27001 clause 9.2, or a supplier's self-declaration.
- Second-party. Performed by a party with a user interest in the object, for example a customer auditing its supplier.
- Third-party. Performed by a body independent of both the provider and the user, for example a certification body conducting an ISO/IEC 27001 certification audit.
Certification
- Third-party attestation related to products, processes, systems or persons.
- Performed by a certification body (CB), which is a type of conformity assessment body (CAB).
- Example: the CB certifies that Company X's ISMS conforms to ISO/IEC 27001.
- Third-party attestation related to a conformity assessment body. It formally demonstrates the body's competence, impartiality and consistent operation in performing specific conformity assessment tasks.
- Performed by an accreditation body (AB), often one per country. Examples include UKAS (UK), ANAB (USA), DAkkS (Germany), COFRAC (France) and JAS-ANZ (Australia/New Zealand).
3.4 The conformity assessment hierarchy
- International level. The IAF (International Accreditation Forum) and ILAC (International Laboratory Accreditation Cooperation) operate mutual recognition arrangements. The IAF MLA lets a certificate issued under one signatory AB be recognized by other signatories, supporting the principle of certified once, accepted everywhere.
- Regional level. Bodies such as EA (European co-operation for Accreditation) and APAC.
- Accreditation bodies. These operate according to ISO/IEC 17011.
- Certification bodies. These operate according to ISO/IEC 17021-1 (requirements for bodies auditing and certifying management systems), plus ISO/IEC 27006-1 for ISMS-specific requirements.
- Certified organizations. These implement ISO/IEC 27001.
- ISO/IEC 17000. Conformity assessment vocabulary and general principles.
- ISO/IEC 17011. Requirements for accreditation bodies.
- ISO/IEC 17021-1. Requirements for bodies providing audit and certification of management systems.
- ISO/IEC 17024. Requirements for bodies certifying persons, for example lead auditor personnel certification.
- ISO/IEC 17065. Requirements for bodies certifying products, processes and services.
- ISO/IEC 17025. Competence of testing and calibration laboratories.
- ISO/IEC 17020. Requirements for inspection bodies.
- ISO 19011. Guidelines for auditing management systems. It is guidance, not a requirement, and applies to first-, second- and third-party audits.
- ISO/IEC 27006-1. Requirements for bodies providing ISMS audit and certification.
- ISO/IEC 27007. Guidelines for ISMS auditing, complementing ISO 19011.
4.1 From standard to certificate
- SC 27 develops and publishes ISO/IEC 27001 through the consensus stages.
- An organization implements an ISMS conforming to ISO/IEC 27001.
- The organization performs first-party activities: internal audit and management review.
- The organization selects an accredited certification body.
- The CB conducts the initial certification audit:
- Stage 1. Reviews documentation, scope and readiness, and plans Stage 2.
- Stage 2. Evaluates implementation and effectiveness.
- The CB makes an independent certification decision. The people making this decision must not have conducted the audit.
- A certificate is issued for a three-year cycle, with surveillance audits at least annually and a recertification audit before expiry.
- The AB periodically assesses the CB, for example through office assessments and witness audits, to maintain its accreditation.
- Through the IAF MLA, the certificate is recognized internationally.
- Impartiality
- Competence
- Responsibility
- Openness
- Confidentiality
- Responsiveness to complaints
- A risk-based approach
4.3 Principles of auditing (ISO 19011:2018)
- Integrity
- Fair presentation
- Due professional care
- Confidentiality
- Independence
- Evidence-based approach
- Risk-based approach
When a standard is revised, IAF typically sets a transition period. For ISO/IEC 27001:2022, IAF MD 26 set a three-year transition ending 31 October 2025. After that, certificates to the 2013 version are no longer valid. Auditors must audit against the version stated in the certification scope.
5. Exam Tips: Answering Questions on Standards Development and Conformity Assessment
Tip 1: Know who does what. Many questions are role-identification questions. Remember these chains:
- ISO/IEC develop standards.
- CBs certify organizations.
- ABs accredit CBs.
- IAF harmonizes accreditation.
Tip 2: Separate certification from accreditation. Ask yourself whether the object being attested is an organization's management system (certification) or the competence of a certification body (accreditation).
Tip 3: Match the audit party to the scenario.
- Internal audit = first-party.
- Customer audits supplier = second-party.
- Independent CB audit for certification = third-party.
Tip 4: Memorize the draft sequence. NWIP, WD, CD, DIS, FDIS, IS, plus the five-year systematic review. Remember that only editorial changes are allowed at FDIS stage.
Tip 5: Know which standards are requirements and which are guidance.
- Requirements (shall): ISO/IEC 27001, 17021-1, 27006-1, 17011.
- Guidance (should): ISO 19011, ISO/IEC 27002, 27003, 27005, 27007.
Tip 6: Remember that consensus is not unanimity. If an option says a standard requires unanimous approval, eliminate it.
Tip 7: Remember that standards are voluntary. A standard becomes mandatory only through legislation, regulation or contract.
Tip 8: Treat impartiality as a frequent scenario theme. If a CB or auditor previously consulted for the auditee, or has financial ties to it, the correct answer usually identifies a threat to impartiality.
Tip 9: Know the certification cycle numbers.
- Three-year certificate validity.
- Surveillance at least once per calendar year.
- The first surveillance audit within 12 months of the certification decision.
- Recertification before expiry.
- Stage 1 and Stage 2 for initial certification.
Tip 11: For essay or scenario answers, use a structure.
- Define the term.
- Identify the relevant standard or body.
- Apply it to the scenario.
- Conclude with the audit implication, for example whether a certificate is credible or whether impartiality is compromised.
6. Sample Practice Questions
Q1. Which body assesses a certification body's competence to issue ISO/IEC 27001 certificates?
Answer: An accreditation body, operating to ISO/IEC 17011.
Q2. A bank audits its cloud provider against contractual security requirements. What type of audit is this?
Answer: A second-party audit.
Q3. At which stage can only editorial changes be made to a draft standard?
Answer: The FDIS (approval) stage.
Q4. Which standard contains requirements specific to bodies certifying ISMS?
Answer: ISO/IEC 27006-1, used together with ISO/IEC 17021-1.
Q5. Is ISO 19011 a certifiable standard?
Answer: No. It provides guidelines for auditing management systems.
7. Summary
Standards development gives ISO/IEC 27001 its legitimacy through a transparent, consensus-driven process led by ISO, IEC and JTC 1/SC 27. Conformity assessment gives certification its credibility through a layered system:
- organizations implement standards;
- certification bodies certify them under ISO/IEC 17021-1 and 27006-1;
- accreditation bodies accredit the CBs under ISO/IEC 17011;
- IAF mutual recognition makes certificates trusted worldwide.
- Master the vocabulary.
- Keep the roles distinct.
- Memorize the development stages.
- Always ask who is attesting what, to whom, and under which standard.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!