The Requirement That Multiplies
Impartiality is foundational to certification body credibility. ISO/IEC 17021-1:2015 requires that CBs identify, analyze, and document threats to impartiality. In practice, this means every member of every audit team needs to declare that they have no conflicts of interest with the client being audited — before the audit begins.
This is not a one-time check. It happens for every audit. Every team member. Every time.
Consider a mid-sized CB — call them Apex Certification — running 50 audits per month. Average team size is three: a lead auditor, a technical expert, and sometimes a trainee. That is 150 impartiality declarations per month. 1,800 per year.
Now consider what the manual process looks like for each one.
The Manual Process
- 1. The planner assigns the audit team
- 2. The planner opens the impartiality declaration template (usually a Word document identified as FR.224 or similar in the CB's document management system)
- 3. The planner fills in the auditor's name, the client name, the audit dates, and the standard
- 4. The planner emails the completed form to the auditor
- 5. The auditor opens the attachment, reviews it, prints it, signs it, scans it, and emails it back
- 6. The planner downloads the signed document and files it in the correct client folder
- 7. The planner repeats this for each team member
- 8. The planner tracks which declarations have been returned and follows up on missing ones
For a single audit with three team members, that is roughly 20 minutes of administrative work — assuming no one forgets, no email gets lost, and no file gets saved in the wrong folder. At 50 audits per month, that is over 16 hours of pure administrative labor just for impartiality declarations. And that is the optimistic estimate.
What Goes Wrong
The accreditation body assessor pulls a random audit file during the office assessment. They want to see the impartiality declarations for every team member. Here is what they find:
- •The lead auditor's declaration is signed and filed correctly
- •The technical expert's declaration is missing — the planner sent it, the expert forgot to return it, and no one followed up
- •The trainee's declaration is in the folder, but it references the wrong client name because the planner copied the previous template and forgot to update one field
Two findings. One is a nonconformity for missing documentation. The other is a nonconformity for inaccurate records. Both are avoidable. Both result from a process that relies entirely on human diligence at scale.
A Scenario at Scale
Now imagine Apex Certification grows to 100 audits per month. The declaration volume doubles to 300 per month. The planner who was barely keeping up at 50 audits is now drowning. They hire a second planner. Now two people are managing declarations in parallel, with no shared visibility into which ones are complete and which ones are outstanding. Files get saved in inconsistent locations. Follow-up emails overlap.
The AB assessor returns. This time they pull five audit files. Two are missing declarations. One has declarations signed after the audit started — a clear violation of the requirement that impartiality be assessed before the audit. Apex is now facing a systemic finding.
How Certiva Handles Impartiality Declarations
In Certiva, impartiality declarations are not a manual task. They are an automatic output of the team assignment process.
Generation: When a planner assigns an auditor to an audit engagement, the system automatically generates an impartiality declaration using the CB's own template (FR.224 or equivalent). The declaration is pre-populated with the auditor's name, the client details, the audit dates, and the applicable standard. Each team member gets their own individual declaration.
Signing: Each team member sees the declaration in their auditor portal under pending actions. They open the document, review the pre-populated content, and apply their visual signature in-browser. The signature is flattened into the PDF with a timestamp. No printing, no scanning, no emailing.
Gating: This is where the system enforces the requirement rather than relying on human memory. The Stage 1 audit phase cannot begin until all team members have signed their impartiality declarations. The system checks the signing status. If any declaration is unsigned, the audit remains gated. The planner can see at a glance which team members have signed and which have not.
Tracking: Every declaration is stored within the audit record, linked to the specific team member and engagement. When the AB assessor pulls the audit file, every declaration is exactly where it should be — signed, dated, and associated with the correct audit.
The Math Changes Completely
Back to Apex Certification's 50 audits per month with three-person teams:
- •Manual process: 150 emails sent, 150 attachments tracked, 150 files downloaded and stored, unknown number of follow-ups. Estimated 16+ hours per month of administrative time.
- •Certiva: 150 declarations auto-generated when teams are assigned. Each auditor signs in their portal when they are ready. The planner's involvement is zero unless they need to follow up on a specific unsigned declaration — and the system shows them exactly which ones those are.
The time savings are significant, but they are not the real benefit. The real benefit is compliance certainty. Every audit has the correct declarations. Every declaration is signed before the audit begins. Every document is filed in the right place. When the assessor pulls any audit file at random, the declarations are there.
Why This Matters Beyond Compliance
Impartiality declarations are one of those requirements that feel like paperwork until they are missing. An AB finding for inadequate impartiality management is not a minor procedural issue — it goes to the core of the CB's credibility. If a CB cannot demonstrate that it systematically assesses conflicts of interest, the value of every certificate it issues is in question.
Automating declaration generation and enforcing signing gates is not about reducing paperwork for its own sake. It is about building a system where compliance is structural rather than behavioral. You are not relying on 30 individual auditors to remember to sign and return a document. You are relying on a system that generates the document, presents it for signing, and blocks the audit until signing is complete.
That is the difference between a process that works when everyone remembers and a process that works regardless.