Confidentiality
How ISAO protects confidential information, and what it publishes.
ISAO receives confidential information from certification bodies, auditors, their clients and complainants. This policy explains how we protect it.
What we keep confidential
Information obtained during applications, assessments, surveillance, complaints and appeals is confidential. This includes assessment reports, certification files, client lists and commercial information.
What we publish
So that the register is useful, ISAO publishes:
- for accredited bodies: name, location, accreditation number, scope of accreditation and status
- for certificates: holder name and location, standard, scope, sites, dates, issuing body and status
- for registered auditors who agree to be listed: name, grade, standards and status
There is no public list of certified organisations: a certificate is found on the register by its number, its verification code or the name of the organisation that holds it.
Who can see confidential information
Only ISAO staff, assessors and committee members who need it for their work. All of them sign a confidentiality agreement, and access to our systems is logged.
Disclosure required by law
If the law requires ISAO to disclose confidential information, we tell the organisation concerned first, unless the law prevents us from doing so.
