Audit Integrity & Independent Verification Policy
Every KSQA audit follows documented controls designed to ensure accuracy, impartiality, independence, and full compliance with ISO/IEC 17021-1 and AS9104 requirements. These controls have been strengthened following our 2025–2026 improvement program.
Why Clients Trust KSQA's Audits
YOUR RIGHTS & ASSURANCES: Built into every engagement
Why Audit Integrity Is the Foundation of Everything KSQA Does
A certification body's audit is the foundation on which every certificate's credibility is built. When an AS9100 or ISO 9001 auditor evaluates a client's quality management system and records findings in an official report and in the OASIS database, aerospace primes, government agencies, supply chain managers, and end customers make high-stakes decisions relying on findings that are accurate and honestly recorded by design.
This policy sets out the principles, structural controls, and independent verification checkpoints that protect certification integrity and the accuracy of every KSQA audit — from planning through certificate issuance and annual surveillance. As an independent, third-party certification body, KSQA builds its credibility through the integrity of every ISO certification process it delivers. This page also includes KSQA's Continuous Improvement Disclosure, documenting how governance controls have strengthened over time: see Continuous Improvement Timeline and Historical Disclosure near the end of this page.
How a KSQA Audit Works
Audit Integrity KPIs
| Independent review required before every certificate | ✓ |
| Auditor competency reviewed annually | ✓ |
| Dual verification active on every OASIS entry | ✓ |
| Client confirmation process in place | ✓ |
| Internal audits completed annually | ✓ |
| Major nonconformities (NCs) closed with verified evidence before issuance. | ✓ |
Audit Principles
The foundational values that govern how every KSQA audit is planned, conducted, and reported
These principles are operational requirements embedded in the standards that govern KSQA's accreditation — ISO/IEC 17021-1, AS9104/1, and the IAQG ICOP scheme. Every auditor and reviewer operating under KSQA's authority applies these principles in every engagement.
Objectivity
Every audit finding must be grounded in objective evidence gathered against the requirements of the applicable standard. The auditor's relationship with the client — positive or negative — must not influence the findings recorded.
- Findings are supported by documented evidence, not auditor impression
- Every nonconformity is identified and documented strictly on its evidentiary merits, independent of the client relationship.
- Findings are determined solely by the evidence gathered against the applicable standard.
- All major nonconformities are raised and documented, regardless of consequence
Accuracy
Every statement in an audit report and every entry in OASIS must accurately reflect what was observed, where, when, by whom, and how. Every statement in an audit report and every OASIS entry is held to one standard: complete accuracy in every detail, every time.
- Audit modality (on-site vs. remote) recorded correctly in every OASIS entry
- Audit dates, duration, and attendee lists accurately stated in reports
- Nonconformities accurately described with specific evidence references
- Material findings are reported in full, with complete precision, every time.
Independence
The auditor conducting the assessment and the reviewer signing off on the report must be free of personal, financial, and organizational conflicts of interest. Independence is a structural requirement built into every KSQA audit under ISO/IEC 17021-1 Clause 5.
- No family or personal relationship between auditor and reviewer
- No financial interest in the client beyond the audit fee
- No prior consulting relationship that could compromise objectivity
- Annual impartiality declarations required from all personnel
Competence
Every KSQA auditor must hold verifiable competence — through education, experience, and (for AS9100) current IAQG credentials via Probitas Authentication — for the specific standard and industry scope being audited.
- OASIS credential status verified before every AS9100 audit assignment
- Competence records maintained and reviewed annually
- Scope limitations respected — no auditing outside credentialed areas
- Continuing professional development tracked and documented
Confidentiality
All information gathered during an audit — quality system documentation, nonconformity details, process descriptions, supplier information — is treated as confidential and shared only as required by accreditation obligations.
- Audit documentation stored securely in the Audit-Care2 system
- Shared with IAS only during accreditation assessments
- No disclosure to third parties without client consent or legal obligation
- Retained for minimum 7 years then securely destroyed
Transparency
Clients are entitled to understand their audit findings, the basis for certification decisions, and any changes to KSQA's accreditation status that affect their certificate. Transparency with oversight bodies (IAS, IAQG) is equally required.
- Nonconformities clearly explained with standard references
- Certification decisions communicated with documented rationale
- Accreditation status changes disclosed within 5 business days
- Full cooperation with IAS assessments and oversight investigations
ISO/IEC 17021-1:2015
Primary standard governing all management system certification body operations — impartiality (Cl.5), competence (Cl.6), process requirements (Cl.7), management system (Cl.8). All six principles above are grounded in this standard.
AS9104/1 & ICOP Scheme
Additional requirements for aerospace certification bodies — including OASIS record accuracy, client notification obligations, auditor credentialing through Probitas, and on-site audit requirements for AS9100.
Probitas Authentication
IAQG's auditor credentialing body — manages OASIS credentials for AS9100 auditors. All KSQA AS9100 auditors must hold current Probitas credentials. Credential status is a mandatory pre-assignment check.
IAF Mandatory Documents (IAF MD) set detailed rules that accreditation bodies and certification bodies must follow, including:
IAF MD 2 (transfer), IAF MD 5 (audit duration), IAF MD 11 (accreditation mark use) — additional requirements for management system certification bodies operating within IAF MLA recognition.
Audit Independence
Structural and behavioral requirements ensuring audits are free from conflicts of interest
Independence in auditing means the people conducting and reviewing audits are structurally free from pressures that could compromise their objectivity. ISO/IEC 17021-1 Clause 5 identifies six specific "threat categories" that must be analyzed, documented, and mitigated — and KSQA maintains a specific, named control for each one.
Independence Threat Categories (ISO/IEC 17021-1 Clause 5)
| Threat Type | Description | KSQA Example | KSQA Control | Status |
|---|---|---|---|---|
| Self-interest | Financial or other interest that could inappropriately influence judgment | Losing a client creates pressure not to raise nonconformities | Fixed pricing not linked to outcomes; findings policy applies regardless of client size | ✓ Controlled |
| Self-review | Reviewing one's own previous work or recommendations | Auditor who designed or advised on a QMS then auditing it | KSQA does not provide advisory or system-design services; there is a clean separation between advisory work and audit work. | ✓ Controlled |
| Familiarity | Long relationship with client leading to over-trust of their representations | Multi-year client audited without sufficient skepticism | Evidence-based findings required regardless of relationship length, with periodic auditor rotation in active development as an added safeguard. | 🔵 Enhanced Oversight |
| Personal relationship | Family or personal relationship between auditor and reviewer | A reviewer with a family or personal relationship to the auditor being asked to sign off on their report | Reviewer independence confirmed and declared in writing before every sign-off; see Continuous Improvement Timeline for how KSQA's independence controls have evolved. | 🔵 Structural Control |
| Intimidation | Actual or perceived threats that influence the auditor's judgment | Client threatening to leave if a nonconformity is raised | Escalation process to KSQA management; auditor protected from direct commercial pressure | ✓ Controlled |
| Advocacy | Promoting a client's position to a degree that compromises objectivity | Auditor helping client argue against oversight body findings | Policy prohibition on advocacy activities by KSQA auditors on behalf of clients | ✓ Controlled |
Independence Requirements for KSQA Auditors & Reviewers
- Annual signed impartiality declaration — covering all known relationships with current and prospective audit clients
- Disclosure of any new potential conflict of interest within 5 business days of becoming aware of it
- Reviewer must confirm no family, personal, or financial relationship with the auditor before signing off on any report
- OASIS credential check completed and documented before each AS9100 audit assignment
- Any gift or benefit from a client declared to KSQA compliance before or within 5 days of receipt
- Recusal from any audit where a conflict of interest exists or cannot be adequately mitigated
- Cooperation with IAS, IAQG, or Probitas investigations without prior clearance from KSQA management
- Reviewing or signing off on audit reports authored by a family member, partner, or close personal associate
- Conducting an audit for a client where the auditor has provided advisory, coaching, or system design assistance in the past 2 years.
- Allowing a client's commercial value to influence the severity, number, or documentation of audit findings
- Accepting any benefit from a client that is contingent on a favorable audit outcome
- Representing the client in disputes with IAS, IAQG, or other oversight bodies
- Delaying disclosure of a known conflict of interest to avoid disrupting an active audit or certification process
- Using KSQA's access to client quality systems for any purpose beyond the scope of the certification audit
Quality Controls
The gate-by-gate controls that prevent defects from entering KSQA's certification outputs
Quality controls in a certification body function as checkpoints in the ISO certification process — each one designed to catch a specific category of error before it can progress to the next stage. Seven gates run from pre-audit planning through the annual management review, and every certificate KSQA issues has passed through all seven.
Pre-Audit Planning Control GATE
Before any audit is assigned, KSQA must confirm that the auditor is qualified and free of conflicts for the specific client, standard, and scope.
- Auditor competence verified against the client's industry code and applicable standard
- OASIS credential status checked and documented (AS9100 assignments)
- Impartiality check — no conflicts identified between auditor and client
- Audit plan prepared and sent to client confirming scope, dates, and modality (on-site or remote)
- Client confirmation of audit plan received before audit commences
Stage 1 (Document Review) Quality Control GATE
The Stage 1 review assesses the client's documented quality management system against the requirements of the applicable standard. This stage must produce a documented Stage 1 report with specific findings before Stage 2 can proceed.
- Stage 1 report must identify the scope, standard, key processes reviewed, and any areas of concern
- Client must receive the Stage 1 report and have opportunity to address gaps before Stage 2
- Stage 1 cannot be combined with Stage 2 without documented justification and client agreement
- Minimum required intervals between Stage 1 and Stage 2 respected per ICOP scheme requirements
Stage 2 (On-Site / Remote Audit) Execution Control GATE
The Stage 2 audit evaluates the implementation and effectiveness of the QMS against the applicable standard. This is where the modality (on-site vs. remote) decision is made and must be accurately documented.
- On-site audits: Required at least once per certification cycle for AS9100 — specifically required where process observation or physical evidence review is needed
- Remote audits: May be used where the ICOP scheme permits, but must be recorded accurately in OASIS — ICT field (the OASIS data field recording whether remote information and communication technology was used) must show "YES" if any remote tools (Teams, Zoom, etc.) were used
- Audit must cover all applicable standard clauses and the full certified scope
- All nonconformities must be raised, classified (major/minor), and described with objective evidence
- Opening and closing meetings documented; attendees recorded
OASIS Entry Accuracy Control GATE — NEW
A dual-sign control ensuring every OASIS audit entry is verified against supporting evidence by a second, independent individual before submission.
- Checklist item 1: What was the audit modality? (On-site / Remote / Hybrid) — Auditor declares
- Checklist item 2: What supporting evidence exists? (Travel records, platform logs, client confirmation) — Auditor provides
- Checklist item 3: Does the OASIS ICT field accurately reflect the modality? — Independent verifier confirms
- Checklist item 4: If remote: Is "YES" recorded in the ICT field? — Independent verifier confirms
- Both signatures required before OASIS entry is finalized
- Supporting evidence retained with the audit file
Nonconformity Closure Verification GATE
Before a certificate is issued or maintained, all major nonconformities must be closed with verified objective evidence of effective corrective action. Minor nonconformities must have documented corrective action plans.
- Auditor reviews and accepts or rejects corrective action evidence for each NC
- Major NC closure must be verified before certificate issuance — no exceptions
- NC closure documented in OASIS within required timescales
- Client access to NC records provided via Audit-Care2 portal
Certificate Issuance Authorization GATE
Before any certificate is issued, KSQA must confirm that all gate requirements above are satisfied, that the accreditation is currently active, and that the independent reviewer has authorized issuance.
- IAS accreditation status confirmed active in the IAS registry at time of issuance
- All required OASIS entries complete and accurate
- All major NCs closed with verified evidence
- Authorization completed by a reviewer independent of the auditor who conducted the audit, consistent with KSQA's independence controls.
- KSQA standard: certificate issued within 2–3 days of authorization (vs. 30–45 days industry norm)
Internal Audit & Management Review ANNUAL GATE
KSQA's own quality management system is subject to an annual internal audit covering all clauses of ISO/IEC 17021-1 and applicable ICOP scheme requirements. Results feed into an annual management review.
- Internal audit covers: impartiality controls, competence records, OASIS upload timeliness, client complaint log, NCs raised and closed, and accreditation status management
- Management review outputs include: compliance KPI review, improvement actions, policy updates
- Results published in Annual Transparency Report (from 2026)
Quality Control Metrics
Documentation Standards
What must be documented, how, when, and for how long — with specific requirements for modality recording
Required Audit Documents by Stage
Audit Program & Plan
Required before Stage 1 commences. Must be sent to and confirmed by the client.
- Scope of certification
- Applicable standard(s) and revision
- Audit dates and proposed modality
- Auditor name(s) and credential references
- Processes and sites to be covered
Stage 1 Report
Documents the document review — must be provided to the client before Stage 2 proceeds.
- QMS documents reviewed with specific references
- Areas of concern or gaps noted with standard clause references
- Readiness assessment for Stage 2
- Signed and dated by conducting auditor
- Client acknowledgment recorded
Stage 2 Audit Report
The core audit document — must accurately reflect everything observed and verified.
- Audit modality — on-site / remote / hybrid (must match OASIS)
- Exact audit dates, times, and duration
- All attendees by name and role
- All standard clauses evaluated with evidence noted
- All nonconformities raised with classification and evidence
- Audit summary and certification recommendation
Nonconformity Records
Each NC must be documented as a standalone record linked to the audit report.
- NC reference number and classification (major / minor)
- Standard clause reference
- Specific objective evidence supporting the NC
- Client corrective action plan
- Auditor acceptance / rejection of corrective action evidence
- Closure date and verification evidence
OASIS Database Entries
Official public record — every entry must match the audit report exactly.
- Audit type (Stage 1 / Stage 2 / Surveillance / Recertification)
- Audit dates (must match report)
- ICT used? (YES if any remote component)
- CB and auditor identifiers
- Certificate status action
- Modality Accuracy Checklist — second signature required
Certificate Document
Issued only after all gates are cleared and independent reviewer has authorized.
- Client name and address (certified scope)
- Standard and revision
- KSQA accreditation number (MSCB-207 or ASA-101)
- Certificate issue date and expiry date
- IAF Multilateral Recognition Arrangement (MLA) mark (only when accreditation is active)
- Authorized signatory — independent reviewer, not auditor
Document Retention Requirements
| Document Type | Minimum Retention Period | Storage | Access |
|---|---|---|---|
| Audit plans and programs | 7 years from certification cycle end | Audit-Care2 system | KSQA + client + IAS on assessment |
| Stage 1 and Stage 2 audit reports | 7 years minimum from certificate expiry | Audit-Care2 system | KSQA + client + IAS on assessment |
| Nonconformity records and corrective actions | 7 years minimum | Audit-Care2 system + OASIS | KSQA + client + IAS on assessment |
| Modality Accuracy Checklists (new) | 7 years minimum from audit date | Audit-Care2 system | KSQA + IAS on assessment |
| OASIS database entries | Permanent (OASIS maintained by IAQG/SAE) | OASIS public database | Public |
| Certificate documents | 7 years after certificate expiry or withdrawal | Audit-Care2 system + client copy | KSQA + client + IAS on assessment |
| Impartiality declarations | Duration of engagement + 5 years | KSQA compliance records | KSQA + IAS on assessment |
| Auditor competence records | Duration of engagement + 5 years | KSQA compliance records | KSQA + IAS on assessment |
Audit Verification
How KSQA verifies its own audit work — and how clients and oversight bodies can verify independently
Audit verification operates at two levels: internal verification (KSQA checking its own work before outputs are finalized) and external verification (IAS, IAQG, Probitas, and clients checking KSQA's accredited certification work through publicly available databases and assessment processes). Both levels run in parallel on every audit, so no single check is ever the only safeguard.
1. Modality Accuracy Checklist (New)
Before any OASIS audit entry is finalized, the two-person Modality Accuracy Checklist must be completed. The auditor declares the modality and provides supporting evidence; the independent verifier (not a family member) confirms the OASIS entry is accurate before submission.
Control added: July 2026 🔵 New Control2. Independent Report Review
Every audit report must be reviewed by an individual who did not conduct the audit and has no personal relationship with the auditor. The reviewer checks technical accuracy, completeness, evidence quality, standard clause coverage, and NC classification before the report is released to the client or used as the basis for certification decisions.
ISO/IEC 17021-1 Clause 9.5 🔵 Reviewer function active today; dedicated appointment in progress, see Governance & Leadership for current status.3. OASIS Self-Verification
After every OASIS upload, KSQA confirms that the public OASIS entry matches the internal audit report. Any discrepancy triggers an immediate investigation and corrective action. KSQA also monitors its own accreditation status (ASA-101, MSCB-207) in OASIS on a weekly basis.
Platform: oasis.sae.org · Frequency: After each upload + weekly accreditation check ✓ Active4. IAS Annual Surveillance Assessment
IAS conducts an annual surveillance assessment of KSQA's operations — reviewing a sample of audit files, OASIS entries, client records, and compliance with ISO/IEC 17021-1. KSQA provides full access to all records for IAS review. Any IAS findings are addressed through documented corrective action plans.
ISO/IEC 17011 · Frequency: Annual ✓ Active5. Probitas Credential Verification
For all AS9100 audits, auditor credential status is verified in OASIS before assignment. A monthly credential status check for all KSQA AS9100 auditors runs in addition to the pre-assignment check.
Platform: oasis.sae.org / Probitas Authentication · Frequency: Before each assignment + monthly 🔵 Enhanced Frequency6. Client Verification Confirmation
After every completed audit, KSQA sends the client a confirmation of the OASIS entry — asking the client to confirm that the audit was conducted as described, including the modality. This client-facing check provides an independent data point to verify report accuracy before the entry is considered final.
New procedure — effective July 2026 🔵 New Procedure7. Client-Initiated Verification Rights
Any client who believes their OASIS record is inaccurate — including modality, dates, or NC records — has the right to request a full file review. KSQA will provide the requested audit documentation within 10 business days and correct any verified errors within 5 business days of confirmation.
Client right — formal request to contact@ksqa.org ✓ Right Always Existed — Now Formally PublishedReview Process
The structured review system that sits between audit completion and certificate issuance
The review process is the final quality gate in KSQA's certification decision process — the last point at which errors or gaps in evidence can be caught before a certification decision becomes official.
Five-Stage Review Workflow
Completeness Check
Before assessing technical content, the reviewer confirms that all required report elements are present and that no mandatory fields are blank.
- All standard clauses present with findings or justification for exclusion
- All NCs documented with evidence references
- Audit dates, modality, and attendees stated
- OASIS Modality Accuracy Checklist attached and signed by auditor
- NC closure evidence attached (if applicable)
Modality & Record Accuracy
The reviewer specifically checks that the audit modality stated in the report matches the OASIS ICT field entry and is supported by the attached evidence.
- Report modality vs. OASIS ICT field — must match exactly
- Supporting evidence for modality reviewed (travel records or platform logs)
- Client confirmation of modality reviewed if available
- Any discrepancy triggers automatic return to auditor for explanation and correction before proceeding
Technical Content Review
The reviewer assesses whether the audit was conducted with appropriate rigor and whether the findings accurately reflect the evidence gathered against the standard's requirements.
- NC classifications (major vs. minor) justified by the evidence cited
- No clauses marked "conforming" without documented evidence
- Audit scope fully covered — no unexplained gaps in clause coverage
- NC corrective actions verified as addressing root cause, not just symptoms
- Certification recommendation consistent with findings
Independence Confirmation
Before signing off on any report, the reviewer explicitly confirms their independence from the auditor and from the client for this specific engagement.
- No family or personal relationship with the auditor who conducted the audit
- No prior advisory or employment relationship with the client.
- No financial interest in the certification outcome beyond standard employment
- Declaration signed and dated — retained with the audit file
Certification Authorization
After all four preceding stages are complete, the reviewer signs the certificate issuance authorization. This signature triggers KSQA's 2–3 day certificate issuance process.
- All completeness, modality, technical, and independence checks completed
- IAS accreditation confirmed active at time of authorization
- Authorization signed by reviewer — not by the auditor who conducted the audit
- Client notified; certificate issued within 2–3 business days
- Authorization document retained in audit file for IAS review
Continuous Improvement Timeline
How KSQA's audit integrity controls have developed, and where they're headed next
Internal Review Program Strengthened
KSQA enhanced its internal review of AS9100 audit records as part of an ongoing commitment to accuracy and governance.
Independent Controls Added
New pre-audit competence and conflict-of-interest checks introduced ahead of every assignment.
Dual Verification Introduced
Every OASIS modality entry now requires two independent signatures before submission.
Transparency Center Launched
Public disclosure of governance, compliance, and audit integrity information at /trust.
Enhanced Governance
Impartiality Committee oversight and the annual internal audit / management review program formalized.
Continuous Improvement
Independent reviewer appointment, expanded verification checkpoints, and ongoing annual policy review.
Lessons Learned
The principle behind every independence safeguard on this page, and why it matters
Genuine independence requires structural separation, with no personal or family ties between the people conducting and reviewing an audit. That principle is why KSQA maintains dual sign-off on every OASIS entry, independent report review, client confirmation of audit records, and a reviewer role being filled by someone with no personal relationship to KSQA's auditing personnel. Together, these safeguards reflect an ongoing commitment to strong, structurally independent certification governance.
👤 Independent Reviewer — Qualifications (Publishing Upon Appointment)
Once appointed, KSQA will publish the independent reviewer's credentials on this page, giving clients direct access to evaluate their qualifications themselves. The fields below are what will be published:
For the current status of this appointment, contact contact@ksqa.org or see Governance & Leadership.
Audit Integrity Commitments — Summary
Objectivity EEvery finding is based solely on documented evidence, evaluated against the applicable standard.
Accurate Records OASIS modality entries match reality, verified by a second person using the Modality Accuracy Checklist
True Independence No family or personal relationship between auditor and reviewer functions today, with a dedicated independent reviewer appointment on track.
Verified Competence OASIS credential check before every AS9100 assignment + monthly standing check
7 Quality Gates Pre-audit through annual review — each gate a documented checkpoint with required evidence
7-Year Retention All audit documentation retained for 7 years minimum from certificate expiry — available to IAS and clients
Public Verifiability Every certificate can be independently verified in OASIS, IAS registry, and IAF CertSearch
Client Verification Rights Any client can request their full audit file within 10 business days — no charge
5-Stage Review Structured review workflow from completeness check through independence declaration to authorization
Frequently Asked Questions
Quick answers about how KSQA protects the accuracy and independence of every audit
What is audit integrity?
Audit integrity is the set of principles and controls — objectivity, accuracy, independence, competence, confidentiality, and transparency — that ensure a certification audit's findings are accurate, evidence-based, and free from conflicts of interest.
How does KSQA verify audits?
KSQA verifies audits through a two-person Modality Accuracy Checklist, independent report review, OASIS self-verification after every upload, and annual IAS surveillance assessments — combining internal and external checks.
How are certification decisions reviewed?
Every certification decision passes through a five-stage review workflow — completeness check, modality and record accuracy, technical content review, independence confirmation, and final certification authorization — before a certificate is issued.
What is the OASIS verification process?
OASIS is the public database used by IAQG/SAE to record AS9100 audit details. KSQA verifies that every OASIS entry matches its internal audit report, checks its own accreditation status weekly, and clients can independently confirm certificate and auditor credential status at oasis.sae.org.
How does KSQA prevent conflicts of interest?
KSQA analyzes six ISO/IEC 17021-1 Clause 5 threat categories — self-interest, self-review, familiarity, personal relationship, intimidation, and advocacy — and requires signed annual impartiality declarations, auditor/reviewer separation, and recusal wherever a conflict cannot be adequately mitigated.
Choose an Accredited Certification Body You Can Verify at Every Step
We are committed to complete transparency.
- ✔ Review our governance
- ✔ Request an audit file
- ✔ Speak with our compliance team
Our Commitment
At KSQA, every audit affects our clients' reputation, supply chain relationships, and business growth. That is why we continuously strengthen our audit process to protect every certification decision.
Every audit is reviewed with independence. Every certification decision is evidence-based. Every client has the right to transparency. Every question receives a documented, thorough response. Our goal is not only compliance. Our goal is confidence.