Page 6 - Sept NL 2016a
P. 6
A2LA Updates
Continued from page 5 its clients and potential clients. The the changes have been communicated
client then has an opportunity to object to clients in some manner, and to take
ISO/IEC 17065 Explanations: to the use of external resources, or to some action to verify that the changes
request clarification on the matter. have been implemented by its clients.
QUESTION: Per section 4.2.3 of If clarification is requested, the If the scheme specifies any further
ISO/IEC 17065, is our organization certification body is expected to answer actions, such as mandating immediate
required to keep records of all of the client’s question, and identify the re-evaluation of any certified product,
the risks to impartiality we have potential entity that would be used then the certification body has further
investigated, even those which were before the evaluation activity takes tasks to undertake.
determined not to be actual risks? place in order to allow the customer the
opportunity to object to the use of that In the case of a scheme owner sending
RESPONSE: A2LA expects certification particular external resource, while still out email notifications, actions taken
bodies to keep records of any risks that accepting the possible use of a different by the CB to assure themselves that
have been identified, as well as records external evaluation resource. the communication has taken place
of the actions taken to mitigate the may be minimal (but caution should
risks identified. This information is Records of correspondence are required still be taken in the event that a client
required to be passed to the Mechanism to demonstrate that the CB has given is not receiving those notifications). In
for Safeguarding Impartiality (as adequate notice to the client and, if other cases, such as the CB being the
required by clause 4.2.4), which is then necessary, has identified the specific scheme owner, a notification blast (e.g.,
required to take this into account and subcontractor if so requested. via email or letter) to all clients could
provide feedback to the CB during its be submitted as evidence of the steps
management review (clause 8.5.2). The critical idea in this clause is that the CB has taken to comply with this
the CB has given the client a reasonable requirement.
While not required, it is recommended opportunity to object to the use of
as a positive support to the principles of outside evaluation resources, whether With regard to actions taken to verify
certification to keep records of all areas that be objecting to a specific entity implementation, these will depend
where an investigation into risks took (such as a chosen test lab) or objecting on the instructions included (or not
place, even when no risk is ultimately to the entire concept of outsourcing. included) by the scheme owner. This
identified. These records may help might include re-evaluation of certified
to assure stakeholders that the CB’s (Note that ISO/IEC 17065 does not products (as mentioned previously), a
operations are transparent and explicitly require the certification body re-review of currently certified product
impartial, and may further help the to receive a written approval from the documentation and evaluation results
certification body in future risk analysis client to initiate the subcontracting, to verify that the product continues to
exercises in the event situations but it may be beneficial for a comply with certification requirements,
with its personnel or organizational certification body to attempt to obtain an audit of client facilities, or even a
relationships change. this documented approval) simple evaluation of products at the
next scheduled certification renewal
QUESTION: My organization issues QUESTION: Our organization is point without taking immediate action.
a blanket statement on our contracts considering operating a scheme
which states “your product may be sent where the scheme owner notifies the However, in the event that the scheme
to an outside laboratory for testing in clients of changes to the certification or scheme owner is silent on actions to
the event we are unable to perform requirements themselves, and does not be taken, the certification body is still
timely evaluation” – does this meet require any re-verification of compliance required to take some action of their
the requirements of section 6.2.2.4(f) of until the current certification expires. own choosing to verify implementation
ISO/IEC 17065? Does clause 7.10.1 of ISO/IEC 17065 of the changes by the client. This could
still apply to our organization, and if include (for example) an analysis of the
RESPONSE: Clause 6.2.2.4(f) requires so, how? changes to determine whether or not re-
the certification body to notify the client evaluation is necessary, with a record
in advance of subcontracting in order RESPONSE: Clause 7.10.1 is required of this analysis being kept. If any action
for the client to have the opportunity to to be implemented by all certification is necessary, as per clause 7.10.3, it
object to that action. A2LA understands bodies, regardless of what changes shall be performed in accordance with
that certification bodies may not always and subsequent action (or inaction) is the appropriate part of section 7 of the
immediately know what outside entity stated by the scheme. standard, with records kept of those
will be used to perform evaluation tasks activities as required by section 7.12.
when taking on an application. In all cases of certification changes,
it remains the responsibility of the Continued on page 7
At a minimum, the certification body accredited certification body to be aware
may issue a blanket statement (or of these changes, to gain assurance that
make known in some other clear
manner) of possible subcontracting to
6