info@cetonix.com +91 (966) 512-1196 Mon–Fri, 09:30–18:00 IST
HomeAboutQuality & Impartiality Policy

Quality, impartiality and conflicts of interest

How Cetonix manages impartiality and conflicts of interest under ISO/IEC 17021-1:2015 — including the separation between certification, security testing and GRC services.

Cetonix is not a conformity assessment body. We coordinate certification through accredited CABs and we separately deliver penetration testing with our own in-house team. That structure creates one real conflict, and this page exists to name it rather than bury it.

Quality policy

Cetonix provides principled, credible and value-added coordination of certification, and independent technical security testing. We achieve this by ensuring:

  • Impartiality and objectivity in how we select and appoint conformity assessment bodies
  • Competent personnel, assessed against the requirements of the work they perform
  • Timely, fair complaint resolution, with a documented appeals route

This policy is reviewed periodically for relevance and suitability.

What we do and do not do

CertificationSecurity testing
Who holds the accreditationThe appointed CABNot applicable — accreditation under ISO/IEC 17021-1 does not govern penetration testing
Who performs the workAuditors engaged through the CABCetonix’s own in-house team
Who makes the decisionThe CAB, independently of CetonixCetonix issues the report in its own name
Whose name is on the outputThe CAB’s certificate, with its accreditation markCetonix
What Cetonix doesSelects and appoints the CAB, manages scope, scheduling, readiness and non-conformity closureScopes, tests, reports and retests

The conflict we have, stated plainly

If Cetonix arranges your certification audit and performs your penetration test, then a report we wrote becomes evidence in an audit whose auditors we appointed. Under ISO/IEC 27001:2022 a penetration test typically evidences Annex A 8.8 (technical vulnerability management) and A 8.29 (security testing in development and acceptance). The same commercial party sits on both sides of that evidence.

The certification decision is made by the CAB and not by us, which limits the exposure but does not remove it: we chose the CAB, and we wrote the evidence.

How we manage it

  • We disclose it in writing before you engage — not in a footnote at invoicing. If you are buying both, you will be told in the proposal.
  • You may decline the pairing. Using a different provider for either side costs you nothing with us and we will not price against it. If you would rather we only coordinate certification, or only test, say so.
  • We disclose the relationship to the appointed CAB so it can apply its own impartiality controls under ISO/IEC 17021-1 clause 5.2, including deciding whether to accept our report as evidence at all.
  • Different people. Personnel who deliver a security test for a client take no part in CAB selection, auditor appointment or non-conformity closure for that client, and no part in any certification activity for that client for two years afterwards.
  • We do not represent our report as accredited. A Cetonix penetration test report is a technical assessment issued by Cetonix. It carries no accreditation mark and we will not imply that it does.
  • Your auditor decides. If the CAB or its accreditation body considers the pairing inappropriate, their view governs and we will withdraw from one side of the engagement.

If you would prefer maximum separation, the cleanest arrangement is to have us coordinate certification and appoint an unrelated firm for the penetration test, or the reverse. We will tell you that on the call, and it is worth raising with your CAB before appointment rather than at surveillance.

How we select conformity assessment bodies

  • Selection is driven by accredited scope, the recognition your customers and markets require, sector competence and delivery capacity — in that order.
  • We name the proposed CAB in writing before you commit, so you can check its accreditation in the accreditation body’s public directory yourself.
  • Where commercial terms between Cetonix and a CAB could reasonably be seen to influence selection, they are disclosed on request.
  • We will not place a client with a CAB whose accredited scope does not cover the standard and scope being certified, whatever the commercial incentive.

Consultancy

Cetonix does not provide management system consultancy to organizations whose certification we coordinate, and does not conduct internal audits for them. Readiness support, gap assessment and remediation planning are offered only where Cetonix is not arranging the certification. Personnel who have provided consultancy to a client take no part in certification activities for that client for two years.

Complaints and appeals

Complaints about Cetonix’s own conduct are handled under our complaint handling process. Complaints or appeals about a certification decision are matters for the CAB that made the decision, and ultimately for its accreditation body — we will give you the correct contact and will not obstruct it.

Personnel

Cetonix and its personnel, internal and external, act impartially and do not allow commercial, financial or other pressures to compromise impartiality. All personnel are required to disclose any situation that may present a conflict of interest. This is recorded, used to identify threats to impartiality, and such personnel are not used unless it can be demonstrated that no conflict exists.

Talk to us about certification or a penetration test

Tell us the standard, the framework or the application. We come back with scope, timeline and a fixed quote.