Overview
ISO/IEC 17021-3:2017 specifies additional competence requirements for personnel involved in the audit and certification of Quality Management Systems (QMS). It complements ISO/IEC 17021‑1 by defining the specific QMS knowledge and skills auditors, audit teams, reviewers and certification decision‑makers need when assessing QMS based on ISO 9001 (and applicable to other QMS applications). The standard was published in 2017 and updates prior technical guidance to reflect ISO 9001:2015 concepts.
Key topics and requirements
- Scope and purpose: Adds QMS‑specific competence requirements to the generic requirements in ISO/IEC 17021‑1. Applicable primarily to QMS audits based on ISO 9001.
- Audit team competence: An audit team must have the collective competence necessary to meet audit objectives. Individual members need not possess every competency if the team as a whole does.
- Fundamental QMS knowledge (auditors must know):
- Quality management principles and related terminology
- The process approach and monitoring/measurement
- PDCA cycle (plan‑do‑check‑act)
- Role of leadership in QMS
- Risk‑based thinking: determining risks and opportunities
- Documented information structures and quality tools/methods
- Context of the organization: Auditors need business‑sector knowledge to evaluate whether an organization has identified relevant external/internal issues, interested parties’ needs, and appropriate QMS scope.
- Client‑specific knowledge: Familiarity with terminology, technology, statutory/regulatory requirements, product/service/process characteristics, infrastructure and external provision affecting product/service quality; and how organization type, size and governance affect QMS implementation.
- Competence for reviewers/decision makers: Knowledge of fundamental QMS concepts, process approach, risk‑based thinking and scope applicability when reviewing audit reports and making certification decisions.
- Annex A: Informative summary of required knowledge areas for different certification functions.
Practical applications
- Helps certification bodies define role‑based competence criteria, selection and training of auditors, and audit team composition.
- Guides audit team leaders and HR/training providers in designing competency matrices, learning plans and continuing professional development.
- Supports accreditation bodies and assessors when evaluating certification body personnel competence.
- Useful to organizations preparing for certification to understand auditor expectations (context analysis, risk‑based approach, leadership).
Who should use this standard
- Certification bodies offering QMS certification
- QMS auditors, lead auditors and technical experts
- Personnel responsible for audit report review and certification decisions
- Accreditation assessors, training providers and organizations seeking ISO 9001 certification
Related standards
Keywords: ISO/IEC 17021-3:2017, QMS auditing, competence requirements, certification bodies, ISO 9001, audit team, risk-based thinking, context of the organization.