Your Rights as a KSQA Client
Clients of KSQA entrust us with sensitive information about their quality management systems, processes, suppliers, and personnel and with acting as competent, transparent stewards of the certification process, including keeping clients informed of anything that affects the validity or status of their certificate. This Client Protection Policy sets out the certification client rights, confidentiality, and data protection commitments KSQA upholds for every certified organization.
This page sets out what you are entitled to from KSQA as a certificate holder — prompt notification, confidential handling of your information, secure records, fair complaint resolution, and independent verification — and what KSQA expects from clients in return.
KSQA's notification and transfer-process commitments, described throughout this policy, reflect the current standard of practice.
🛡 Your Rights as a KSQA Client — At a Glance
Prompt NotificationAny accreditation or status change disclosed within 5 business days
Data ProtectionYour audit documentation treated as confidential and protected at all times
Access to Your RecordsRequest your full audit file within 10 business days at no charge
Transfer RightsSwitch to any accredited CB — OASIS docs uploaded within 10 business days, no charge
Independent VerificationVerify your certificate status yourself at oasis.sae.org at any time
Complaint RightsFile complaints with KSQA, IAS, or OASIS — with a documented escalation path
No RetaliationRaising a concern about KSQA does not affect your audit outcomes or certificate status
24-Hour EmergencySupply chain emergency affecting your certificate — we respond within 24 hours
Client Protection at a Glance
Improvements Implemented
As part of KSQA's continual improvement program, the following capabilities are active and current:
Mandatory Accreditation Monitoring
Accreditation status is proactively and continuously monitored through a dedicated compliance process.
Automated Client Notification
Workflow ensures every affected client is notified within 5 business days
Streamlined Transfer Process
OASIS documentation uploads for transfers committed within 10 business days
Dedicated Compliance Oversight
Compliance Manager role accountable for accreditation and notification obligations
Structured Complaint Procedures
Five-level escalation pathway documented and published for every client
Formalized Document Security
Access controls, secure transmission, and physical document handling formalized
Annual Auditor Ethics Training
All auditors and reviewers complete annual training including case-study review
Annual Policy Review
This policy and its controls formally reviewed at least once a year
A Commitment From KSQA Leadership
"At KSQA, we believe certification is built on trust. Our governance, communication procedures, client notification systems, and transparency practices are active, current, and continuously strengthened. Our commitment is simple: protect every client, communicate openly, and continuously improve."
Data Privacy
How KSQA collects, uses, stores, and manages personal and organizational data in connection with certification activities
KSQA collects and processes data in two categories: personal data relating to individuals (client contacts, auditor personnel, named quality managers), and organizational data relating to client quality management systems. Both categories attract protection obligations — personal data under applicable privacy regulations, and organizational data under the confidentiality requirements of ISO/IEC 17021-1.
- Only data necessary for certification is collected
- Data is never sold or used for marketing
- You can access, correct, or request deletion of your personal data
- Breach notification within 72 hours if it ever occurs
What Data KSQA Collects
KSQA collects only the data necessary to deliver certification services and meet accreditation obligations. Data collection is based on contractual necessity (to perform the audit), legal obligation (OASIS upload requirements), and legitimate interest (quality assurance).
- Client organization name, address, contact details
- Named contacts — Quality Manager, Management Representative
- QMS documentation and process descriptions provided for audit
- Audit findings, NCs, corrective action records
- OASIS-required data: certificate number, scope, audit dates, auditor
- Payment and billing information for audit fees
How Data Is Used
KSQA uses client data exclusively for certification-related purposes. Data collected for one purpose is not repurposed for another without separate disclosure and, where required, consent.
- Conducting audit activities and producing audit reports
- Uploading required records to OASIS per ICOP scheme obligations
- Issuing and maintaining ISO/AS9100 certificates
- IAS accreditation assessments — IAS has right to review client files
- Responding to client inquiries and complaints
- Sending accreditation status notifications within 5 business days
Data Sharing — Who Receives Your Data
KSQA does not sell or commercially share client data. Sharing is limited to parties with a legitimate, accreditation-based right to access.
- OASIS / IAQG: Certificate status, audit records — public database (required)
- IAS: Client files reviewed at annual surveillance assessments
- Probitas Authentication: Auditor-related records where relevant to credential review
- Legal / Regulatory: Where required by applicable law or court order
- Nobody else without your explicit written consent
Individual Privacy Rights
Named individuals in KSQA's records (Quality Managers, Management Representatives, audit attendees) have privacy rights applicable under their jurisdiction's data protection law. KSQA respects these rights and will respond to requests within 30 days.
- Right to know what personal data KSQA holds about you
- Right to correct inaccurate personal data
- Right to request deletion (subject to KSQA's retention obligations)
- Right to data portability — receive your data in a structured format
- Right to object to processing in specific circumstances
Data Retention
KSQA retains certification-related data for the minimum periods required by accreditation obligations and applicable law. Data is securely destroyed after the retention period.
- Audit reports and supporting documentation: 7 years from certificate expiry
- NC records and corrective actions: 7 years minimum
- Certificate documents: 7 years after certificate expiry or withdrawal
- Billing and payment records: 7 years (tax and legal requirement)
- OASIS entries: permanent (maintained by IAQG/SAE — outside KSQA control)
- Contact information: active during the engagement; deleted on request after
Data Breach Notification
In the event of any unauthorized access to, loss of, or disclosure of client data, KSQA will notify affected clients promptly — and where required by applicable law, will notify relevant regulatory authorities within required timescales.
- Affected clients notified within 72 hours of KSQA becoming aware of a breach
- Notification includes: nature of the breach, data affected, likely consequences, steps taken
- Where required: supervisory authority (e.g. ICO in UK, FTC in US) notified
- Breach record maintained internally and reviewed at next IAS surveillance
Data Classification — What KSQA Holds About You
| Data Type | Classification | Shared With | Retention | Your Access Right |
|---|---|---|---|---|
| Audit reports & QMS documentation | Confidential | KSQA audit team; IAS on assessment | 7 years from certificate expiry | ✓ On written request |
| Nonconformity records & corrective actions | Confidential | KSQA; client; IAS on assessment | 7 years minimum | ✓ On written request |
| Certificate status (issued, suspended, or withdrawn publicly viewable via OASIS at any time) | Public | Public via OASIS — required disclosure | Permanent in OASIS | ✓ Verify at oasis.sae.org |
| Client contact information | Restricted | KSQA management + client services | Active engagement; deleted on request | ✓ Access / correct / delete |
| Billing & payment records | Restricted | KSQA finance only | 7 years (legal obligation) | ✓ On written request |
| OASIS audit entries (dates, modality, scope) | Public | Public OASIS database | Permanent | ✓ Verify at oasis.sae.org |
| Complaint records | Restricted | KSQA compliance; IAS on assessment | 7 years minimum | ✓ Outcome disclosed to complainant |
Confidentiality
KSQA's obligation to protect information gathered during certification activities, and when disclosure is permitted
ISO/IEC 17021-1 Clause 8.4 requires that certification bodies treat all information obtained or created during certification activities as confidential — unless the client has explicitly agreed to its disclosure, or legal or accreditation obligations require it. This obligation applies to all KSQA personnel, contracted auditors, reviewers, and committee members.
- Confidentiality obligation never expires — even after engagement ends
- Disclosure is limited to IAS, IAQG/Probitas, and legal requirements
- Your full audit file is available within 10 business days on request
- Certificate transfers are supported with a 10-day OASIS upload commitment
🔒 What KSQA Treats as Confidential
- All QMS documentation provided by the client for review — procedures, work instructions, quality plans, records
- Audit findings, nonconformities, corrective action plans, and any observations raised during the audit
- Internal process descriptions, organizational charts, and staffing information encountered during audit
- Supplier names, subcontractor details, and supply chain information
- Financial information disclosed incidentally during audit (costing structures, contract values)
- Any information explicitly marked "Confidential," "Proprietary," or "Commercial in Confidence" by the client
- Personnel performance data and individual employee information
- Unpublished product or technology development information
✓ Permitted Disclosures — What KSQA May Share
- Certificate status (issued, suspended, withdrawn) — published in OASIS as a scheme requirement; this is a public record
- Audit records reviewed by IAS during annual surveillance assessments — IAS has the contractual right to review KSQA's client files
- Information required by applicable law, a court order, or a regulatory authority
- Information provided to Probitas Authentication or IAQG where required under IAQG International Certification Operating Procedure (ICOP) scheme oversight
- Anonymized, aggregated statistical data (total audits conducted, NCs raised by sector) with no client-identifiable information
- Information the client has explicitly authorized KSQA to share, in writing
Duration: The confidentiality obligation is indefinite — it does not expire when the certification engagement ends. Former clients' information is protected under the same rules as active clients'.
🔄 Your Right to Transfer — and KSQA's Obligation
Every KSQA client has the right to transfer their certification to another accredited certification body at any time. Because a receiving CB requires your prior audit history in OASIS before it can accept a transfer, KSQA maintains a firm, active 10-business-day upload timeline for every transfer request.
Initiating a Transfer
Email contact@ksqa.org with subject "Certificate Transfer Request — [Certificate Number]." No specific form required. Include the receiving CB's name if known.
KSQA's Upload Commitment
All required OASIS documentation uploaded within 10 business days of the written transfer request. No additional charge for transfer OASIS uploads.
What KSQA Must Upload
All audit reports, NC records, corrective action evidence, and certificate history for the full certification cycle — everything the receiving CB needs to accept the transfer.
Your Escalation Options
File a complaint via OASIS at oasis.sae.org or directly with IAS at iasonline.org. Reference accreditation numbers MSCB-207 (ISO 9001) or ASA-101 (AS9100).
Information Security
The technical and operational controls KSQA uses to protect client information from unauthorized access, loss, or disclosure
Information security for a certification body centers on protecting the audit documentation, QMS records, and client data held in connection with certification activities. KSQA uses the Audit-Care2 online system as the primary document management platform, supplemented by standard business security practices. The following controls are in place to protect information entrusted to KSQA.
- Client-facing portal with individual login access
- Access limited to personnel with a legitimate role in your certification
- Secure physical document handling and cross-cut shredding
- Formal business continuity plan in progress for Q3 2026
Audit-Care2 Online Portal Security
Client audit documentation and certification records are managed through the Audit-Care2 platform — KSQA's dedicated audit management system with client-facing access controls.
- Client-specific login access — each client sees only their own records
- Password-protected accounts with secure credential management
- Audit-Care2 access reviewed and revoked when engagement ends
- Client can download their own audit documentation at any time
- Platform: audit-care2.com
Email & Document Transmission
Audit reports, NC records, and other confidential documents transmitted by email are handled with appropriate care. Sensitive documents are not transmitted to unsecured or unverified recipients.
- Audit reports sent only to the client's named contact email on record
- Confidential documents not included in bulk or marketing communications
- Client contacts updated promptly when personnel changes are reported
- Documents marked as confidential in transmission
Access Control
Client information is accessible only to KSQA personnel with a legitimate, assigned role in that client's certification.
- Audit files accessible only to the assigned auditor, reviewer, and compliance manager
- Contracted auditors access only the specific client files for their assignment
- Access revoked immediately on engagement completion for contractors
- IAS assessors provided file access only during scheduled assessments
Physical Document Security
Where audit documentation is held in physical form (printed reports, handwritten notes from on-site audits), these are subject to controlled handling and secure disposal.
- Physical audit notes transferred to digital records and stored securely
- Physical documents not left unattended at client facilities post-audit
- Physical document disposal: cross-cut shredding — not standard recycling
- No client documents stored at personal residences of contracted auditors beyond the active audit period
Data Backup & Business Continuity
KSQA maintains backup procedures to ensure that audit records and client certification history are not permanently lost due to system failure, accidental deletion, or other technical incident.
- Digital audit records backed up through Audit-Care2 platform procedures
- OASIS entries provide an additional independent record of certificate history
- In the event of system failure, client records recoverable from backup within 48 hours
- Business continuity procedures reviewed on an ongoing basis, with the formal written plan.
Remote Audit Security
Given KSQA's heavy use of remote / virtual audits (via Microsoft Teams and similar platforms), specific information security considerations apply to the remote audit environment.
- Screen-shared client documentation not recorded without client consent
- Remote audit sessions conducted in private environments — not public spaces
- Client documentation shared via secure platforms — not personal file-sharing services
- Remote audit session records (where kept) stored with same access controls as physical files
Information Security Incident Response
Detect
Identify the incident — unauthorized access, data loss, breach, or system failure affecting client data
Contain
Isolate the affected system or information to prevent further unauthorized access or data loss
Assess
Determine what data was affected, who was impacted, and the likely consequences for affected clients
Notify
Affected clients notified within 72 hours; regulatory notification where legally required
Remediate
Root cause addressed; security controls updated; IAS notified if accreditation obligations are affected
Complaint Rights
Your right to raise concerns about KSQA — and the full escalation path available to you
- Raising a concern never affects your audit outcomes or certificate
- Every written complaint gets acknowledgment within 2 days, response within 10
- Five-level escalation path: KSQA → IAS → OASIS → Probitas → IAF
- 24-hour response for supply chain emergencies
Your Complaint Rights — Formally Stated
-
Right to Raise Any Concern Without Consequence
You have the absolute right to raise any concern about KSQA — audit quality, record accuracy, accreditation status, responsiveness, or conduct — without any consequence to your audit outcomes or certificate status. Raising a complaint does not affect your certification.
-
Right to a Written Response
Every complaint submitted in writing to KSQA will receive a written response. You will be informed of the outcome of the review, the action taken, and any applicable right to escalate if you are unsatisfied.
-
Right to Timely Resolution
KSQA commits to acknowledging all complaints within 2 business days of receipt and providing a substantive response within 10 business days. Complex complaints may require more time — but KSQA will keep you informed of progress.
-
Right to Escalate
If you are unsatisfied with KSQA's response — or if your complaint involves KSQA management directly — you have the right to escalate to IAS, OASIS, or other oversight bodies without any adverse consequence from KSQA.
-
Right to Be Kept Informed of Your Certificate Status
Any material change to your certificate status, including suspension, reinstatement, or withdrawal, is communicated to you within 5 business days of KSQA becoming aware of it as a formal, documented commitment.
Complaint Escalation Pathway
KSQA Direct Start Here
Submit your complaint directly to KSQA in the first instance. This allows us the opportunity to resolve it promptly and document the outcome.
- Email: contact@ksqa.org — Subject: "Formal Complaint — [Your Organization Name]"
- Include: certificate number, description of the concern, relevant dates, and your desired outcome
- Phone: (775) 372-8348 (follow up in writing)
International Accreditation Service (IAS) Your Next Level of Escalation
IAS is KSQA's accreditation body and has authority over KSQA's compliance with ISO/IEC 17021-1. If KSQA does not respond or respond satisfactorily, file a complaint with IAS directly.
- Website: iasonline.org
- Reference KSQA accreditation numbers: MSCB-207 (ISO 9001) or ASA-101 (AS9100)
- IAS can investigate KSQA's compliance and require corrective action
OASIS Complaint System For AS9100-specific matters
For AS9100-specific complaints — including audit quality, OASIS record accuracy, auditor conduct, or accreditation matters — the IAQG OASIS complaint system is the appropriate channel.
- Platform: oasis.sae.org
- File a complaint against the certification body (KSQA) or the auditor
- For your reference: OOASIS complaints remain active for 120 days from your last update, so keeping your case updated ensures it stays open throughout the review. ⏱ Active window: 120 days from last update.
Probitas Authentication For auditor conduct / credential concerns
For concerns specifically about auditor qualifications, conduct, or credentials, Probitas Authentication is the appropriate body.
- Website: probitas-auth.com
- Probitas manages IAQG auditor credentials and can investigate auditor conduct
- The Americas Auditor Review Committee is the decision-making body for credential matters
International Accreditation Forum (IAF) Your Final Level of Escalation
If you have filed a complaint with IAS and are unsatisfied with IAS's response — or if you believe IAS is failing in its oversight obligations — IAF can be contacted. IAS is a signatory to the IAF Multilateral Recognition Arrangement (MLA) and subject to IAF peer evaluation.
- Website: iaf.nu
- This is the final level of the formal accreditation oversight chain
- IAF has authority over IAS's standing as an MLA signatory
KSQA Response Time Commitments
Client Responsibilities
What KSQA expects from clients to enable effective certification and protect the integrity of the certification process
The certification process is a partnership. KSQA's obligations to clients are documented throughout this policy and the Trust Center. In return, clients accept certain responsibilities, the conditions necessary for the certification process to function with integrity. A certificate is only as credible as the audit on which it is based. If the audit is compromised by inaccurate client representations, the certificate loses its value for everyone who relies on it.
- Provide accurate information and appropriate audit access
- Keep contact details current so notifications reach you
- Use the certificate mark only within its certified scope
- Close nonconformities with genuine, evidence-based corrective action
Information & Access Obligations
Provide Accurate and Complete Information
All documentation, records, and information provided to KSQA for the purpose of certification must accurately represent the client's actual quality management system and practices.
Core obligationProvide Appropriate Audit Access
For on-site audits: provide the auditor with access to all processes, records, areas, and personnel within the certified scope. For remote audits: ensure all necessary documents can be shared via the agreed platform.
Required for valid auditDisclose Material Changes
Notify KSQA promptly if there are significant changes to your quality management system, scope of operations, key personnel, or any matter that materially affects your certification. Changes may require a review or additional audit activity.
Notify within 30 days of material changeMaintain Current Contact Details
Ensure KSQA always holds current contact information — particularly the email address to which accreditation notifications, audit reports, and certificate documents should be sent. Contact changes should be notified promptly.
Notify within 5 business days of changeProtect Audit Documentation
Audit reports and NC records provided by KSQA should be treated as confidential documents — shared internally only with personnel who need them and not shared with competitors or used in misleading marketing claims.
Confidential — internal useCertificate Use Obligations
Use the Certificate Mark Correctly
ISO certification marks and accreditation logos may only be used in connection with the certified scope. They must not be used on products, in advertising suggesting product certification, or in any way that misrepresents the nature of the certification.
IAF / IAS mark rules applySchedule Required Surveillance Audits
Annual surveillance audits are required to maintain certification currency. Clients must cooperate with KSQA's scheduling requests and not repeatedly delay or postpone required audits without documented justification.
Annual — required for certification maintenanceClose Nonconformities Genuinely
When NCs are raised, corrective actions submitted for closure must address the actual root cause and provide genuine objective evidence of improvement — not superficial documentation created solely to satisfy the NC closure requirement.
Evidence-based closure requiredDo Not Attempt to Influence Audit Outcomes
Clients must not offer gifts, payments, or other benefits to KSQA auditors or reviewers in connection with an audit or certification decision. Any such approach must be reported immediately by the recipient and may result in termination of the certification engagement.
Zero tolerance — see Ethics PolicyVerify Your Own Certificate Status
Clients are encouraged to independently verify their certificate status in the OASIS database at oasis.sae.org at any time, particularly before contract renewals or supply chain submission deadlines as an added layer of confidence alongside KSQA's own communications.
Independent verification recommendedVerify Your Certificate
Independent verification is one of your strongest client protections — here's how to use it
For additional confidence, the OASIS database and IAS accreditation records are independent, publicly accessible sources you can check at any time alongside KSQA's own communications, particularly useful before contract renewals or supply chain submission deadlines.
Check OASIS
Search your certificate at oasis.sae.org for real-time AS9100 certificate status, scope, and audit history.
Review Accreditation
Confirm KSQA's current accreditation status at iasonline.org — reference MSCB-207 (ISO 9001) or ASA-101 (AS9100).
Contact KSQA
Email contact@ksqa.org or call (775) 372-8348 with your certificate number for a direct status confirmation.
Request Audit File
Request your full audit file in writing — provided within 10 business days at no charge. See Data Privacy for details.
Frequently Asked Questions
Common questions about client rights, data protection, and certification transfer at KSQA
What is KSQA's Client Protection Policy?
It is the policy governing how KSQA protects client data privacy, confidentiality, and information security, and how it upholds complaint rights and client responsibilities throughout the certification relationship.
How is my audit information protected?
All information gathered during certification activities is treated as confidential under ISO/IEC 17021-1 Clause 8.4, accessible only to KSQA personnel with a legitimate role in your certification, IAS during accreditation assessments, and as required by law.
Can I request my audit file?
Yes. Email contact@ksqa.org with your certificate number — your full audit file is provided within 10 business days at no charge.
How long are my records retained?
Audit reports, nonconformity records, and certificate documents are retained a minimum of 7 years. OASIS entries are maintained permanently by IAQG/SAE, outside KSQA's control.
Can I transfer my certificate to another certification body?
Yes, at any time. KSQA commits to uploading all required OASIS documentation within 10 business days of a written transfer request, at no additional charge.
How quickly are complaints answered?
Every written complaint is acknowledged within 2 business days and receives a substantive response within 10 business days. Supply chain emergencies affecting a live certificate are responded to within 24 hours.
How is my data secured?
Through the Audit-Care2 client portal with individual login access, role-based access control, secure document transmission, and controlled physical document handling — see Information Security.
What happens if KSQA's accreditation status changes?
Affected clients are notified within 5 business days of KSQA becoming aware of any material accreditation or certificate status change, a formal, standing commitment. See Historical Transparency for a full, documented account of this framework's development.
Can I verify my certificate status online?
Yes. Search your certificate at oasis.sae.org at any time for an added layer of confidence alongside KSQA's own communications. See Verify Your Certificate.
Who can access my audit records?
Only the assigned auditor, reviewer, and compliance manager at KSQA, plus IAS during scheduled accreditation assessments. KSQA does not sell or commercially share client data.
How do I request deletion of my personal information?
Email contact@ksqa.org with subject "Data Rights Request." KSQA will respond within 10 business days and complete the request within 30 days, subject to any retention obligations that require certain records be kept.
Does raising a complaint affect my certification?
No. You have the absolute right to raise any concern about KSQA without any consequence to your audit outcomes or certificate status. This is a firm no-retaliation commitment.
What should I do if I disagree with a KSQA decision?
Submit a formal complaint to KSQA directly. If unresolved, escalate to IAS, then OASIS or Probitas Authentication depending on the nature of the concern, and finally IAF — see the full Complaint Escalation Pathway.
How do I report a concern about an auditor's conduct?
Contact KSQA directly, or escalate to Probitas Authentication, which manages IAQG auditor credentials and can investigate auditor conduct concerns.
Is my confidential information ever shared with competitors?
No. KSQA does not share client information with competitors under any circumstance. Disclosure is limited to IAS, IAQG/Probitas oversight, and legal requirements.
What am I responsible for as a KSQA client?
Providing accurate information, appropriate audit access, timely disclosure of material changes, current contact details, and genuine evidence-based nonconformity closures — see Client Responsibilities.
What happens during a supply chain emergency affecting my certificate?
KSQA responds to supply chain emergencies — where certificate status affects a live contract or shipment — within 24 hours, regardless of timezone.
Where can I see KSQA's full historical governance record?
KSQA publishes a full, factual account of the 2025–2026 client notification and transfer-process improvements in the Historical Transparency section below, and in more detail on the Trust & Transparency Center.
Document Control & Downloadable Resources
| Version | Date | Change |
|---|---|---|
| 1.0 | 2024 | Initial Client Protection Policy published |
| 2.0 | 2025 | Data privacy and confidentiality sections expanded |
| 3.0 | 2026 | 5-day notification commitment, 10-day transfer commitment, Compliance Manager role, FAQ, and Historical Transparency sections added |
Related Resources
Client Protection Commitments — Summary
5-Day Notification Any accreditation or material status change communicated to all affected clients within 5 business days, as a formal, standing commitment.
Confidential by Default All audit documentation treated as confidential indefinitely — shared only with IAS, IAQG, and as required by law
Your Records on Request Full audit file provided within 10 business days of written request — at no charge
Transfer in 10 Days All OASIS documentation for certificate transfer uploaded within 10 business days of written request — no charge, no obstruction
No Retaliation Raising a complaint or concern does not affect your audit outcomes, certificate status, or any commercial relationship with KSQA
Full Complaint Pathway KSQA → IAS → OASIS → Probitas → IAF — five escalation levels documented and accessible to every client
24-Hour Emergency Response Certificate emergencies affecting live supply chain contracts — response within 24 hours, regardless of timezone
Secure Portal Your audit documentation accessible via Audit-Care2 client portal — your login, your records, your access only
Need Assistance?
Our Client Protection Team can help with audit records, certificate verification, transfer requests, complaint resolution, data requests, and accreditation questions. All enquiries receive a response within 2 business days.