Advisory & Conformity Assessment

Independent assessment against ISO guidelines

For ISO guideline standards and frameworks that are not certifiable management-system standards, we assess your alignment against the guideline and report our findings plainly.

What this service is — and isn't

Documents such as ISO/IEC 27002 and ISO 31000 are guidelines and codes of practice, not certifiable management-system standards. Formal accredited certification is not available or applicable for them. What we offer instead is a conformity assessment: we review your organization against the relevant guideline and report our findings.

This is clearly distinct from accredited management-system certification. Nothing on this page, or in any report we issue under it, should be read as an accredited certification — see Accreditation & Recognition for exactly what CCI's accreditation does and doesn't cover.

CCI does not provide management-system consultancy, documentation drafting or implementation support. Engaging ISOXPERT Management & IT Consultants — an independent consulting and technology firm under common ownership with CCI — any other consultant, or no consultant has no bearing on any certification decision, and equally no bearing on the outcome of any assessment we issue.

What you receive

A detailed assessment report against the relevant guideline and, where appropriate, a statement of conformity valid for one year — clearly identified as a conformity assessment, never as accredited management-system certification.

Guidelines and frameworks we assess against

Information Security & Privacy

ISO/IEC 27002, 27005, 27017, 27018, 27032, 27035, 27036, 27037, 27040, 27050, 29100, 29134

IT Governance, AI & Continuity

ISO/IEC 90003, ISO/IEC TR 38502, ISO/IEC TR 24028, ISO/IEC 24762

Risk, Resilience & Business Continuity

ISO 31000, ISO 22320, ISO 22313, ISO 45003

Sustainability & Responsible Business

ISO 20400, ISO 26000

Governance, Relationships & Auditing

ISO 19011, ISO 44001

Quality, Projects, Assets & Energy

ISO 10002, ISO 21502, ISO 50004, ISO 55002

Agriculture

Independent Organic Practice Assessment

Where a certifiable, accredited management-system standard exists alongside one of these guidelines — such as ISO/IEC 27001 for information security, or ISO 22301 for business continuity — organizations that want a certificate rather than an assessment report should look there instead.

Not sure which service fits?

Request a scoping discussion and we'll tell you plainly whether it's a conformity assessment or an accredited certification you need.