Why This Policy Exists — and Why It Matters for a Certification Body
Certification bodies occupy a position of trust in the quality ecosystem. When KSQA issues an ISO 9001 or AS9100 certificate, supply chains, aerospace primes, regulators, and end customers make consequential decisions based on that certificate's implied assurance. The integrity of every audit behind a KSQA certificate is what supply chains, aerospace primes, regulators, and end customers rely on, and it is the standard this policy is built to uphold.
KSQA holds itself to the same standards it certifies others against. Where KSQA's own compliance record required correction, the current status and remediation are documented with verifiable registry links throughout this policy, so every claim here can be independently confirmed. This document does not pretend otherwise. This policy sets out the ethical standards KSQA holds itself to today, the safeguards now in place, and how each is independently verifiable.
This policy applies to KSQA's owner, all employed staff, all contracted auditors, and all individuals acting on behalf of KSQA in any capacity.
Why Organizations Choose KSQA
Business Ethics
The foundational values that govern every business decision KSQA makes
KSQA's business model is built on a simple premise: we are paid by clients to assess whether their quality management systems meet international standards, and our assessments must be accurate regardless of that payment relationship. This creates an inherent tension that every ethical certification body must actively manage, and KSQA's governance structure is built specifically to manage it.
Impartiality
Certification decisions are based solely on objective evidence — never on client relationships, pricing pressure, or personal interest
Accuracy
Every statement in an audit report, in OASIS, and in a certificate must reflect reality — not what is convenient or commercially preferable
Transparency
Material information — including accreditation suspensions, audit findings, and compliance failures — must be disclosed to affected parties promptly
Fairness
All clients are assessed against the same standard requirements, without favoritism, discrimination, or preferential treatment
Accountability
When errors or misconduct occur, they are acknowledged, documented, corrected, and prevented from recurring — not concealed
Responsibility
KSQA certificates affect aerospace supply chains, product safety, and public trust. We take that responsibility seriously in every audit
Business Ethics Commitments
Ethical Commercial Practices
KSQA competes for clients on the basis of price, quality, and service, backed by accurate marketing, fair competitive conduct, and certification outputs that hold their integrity in every engagement.
- Accurate representation of accreditation status and scope in all marketing materials
- Fixed, transparent pricing with no hidden fees or post-engagement surprises
- Honest communication about timelines, audit requirements, and likely outcomes
- Client engagements are accepted only within KSQA's verified competence and accreditation scope, ensuring every audit is performed by a qualified team.
- Prompt acknowledgment and correction when errors in our work are identified
Stakeholder Obligations
KSQA's certificates serve a purpose beyond the client relationship — they provide assurance to the entire supply chain that a quality management system has been independently verified. Our business ethics obligations extend to all parties who rely on that assurance.
- Aerospace primes and customers depend on AS9100 certificates to qualify suppliers — our audits must be genuinely rigorous
- End customers and the public depend on certified quality systems — certificate inflation or falsification is not merely a paperwork issue
- The accreditation system depends on certification bodies behaving with integrity — KSQA supports, not undermines, that system
- Competitors are entitled to fair market conditions — KSQA does not compete through unethical shortcuts
Professional Conduct
Behavioral standards for all KSQA auditors, staff, and representatives
Professional conduct standards define how KSQA personnel behave in every interaction — with clients, with oversight bodies, with contractors, and with each other. These standards are grounded in the competence and conduct requirements of ISO/IEC 17021-1 and the IAQG International Certification Operating Procedure (ICOP) scheme, which governs how accredited certification body personnel must behave.
✅ Required Professional Conduct
- Accurately record all audit details — location, modality, duration, attendees — in reports and OASIS entries
- Conduct audits objectively, based solely on evidence gathered against the applicable standard
- Maintain current competence through continuing professional development in relevant standards and industries
- Respond to client communications within agreed timescales (KSQA standard: 2 business days)
- Protect client confidential information at all times during and after the certification engagement
- Disclose any potential conflict of interest to the compliance function before undertaking an assignment
- Upload all required OASIS documentation within the timescales specified by the ICOP scheme
- Verify auditor credentials are current and valid before accepting any audit assignment
- Treat clients with respect and professionalism, regardless of audit findings
- Follow KSQA's documented audit procedures and quality management system requirements
🚫 Prohibited Professional Conduct
- Recording an audit as "on-site" when it was conducted remotely, or vice versa — this is falsification of an official regulatory record
- Issuing or recommending a certificate without completing all required audit stages and reviewing objective evidence
- Allowing a personal or family relationship to influence an audit finding, sign-off, or recommendation
- Accepting gifts, payments, or other incentives that could influence an audit outcome
- Discussing confidential client information with third parties not involved in the certification process
- Conducting audits in industries or to standards for which the auditor is not currently competent and credentialed
- Failing to report a known conflict of interest before commencing an audit assignment
- Ignoring or delaying required OASIS uploads or NC closure documentation
- Making verbal assurances about audit outcomes before the audit has been completed and reviewed
- Retaliating against a client, colleague, or third party who raises a legitimate concern about KSQA's conduct
Integrity Standards
The specific integrity requirements that apply to KSQA as an accredited certification body
For a certification body, integrity is not an abstract value — it is a specific, testable set of requirements embedded in the standards that govern KSQA's accreditation. The following integrity standards are drawn directly from ISO/IEC 17021-1, AS9104/1, and the IAQG ICOP scheme, translated into plain language.
Quick Reference — What Each Clause Covers
- Clause 5 — Impartiality and conflict-of-interest management
- Clause 5.2 — Specific threats to impartiality
- Clause 7.1 — Auditor competence requirements
- Clause 8.4 — Confidentiality requirements
- Clause 8.5 — Disclosure requirements
- Clause 9 — Audit record integrity
- Clause 9.5 — Certification decision independence
- Clause 9.8 — Complaints and appeals handling
Audit Record Integrity
Every entry in an audit report and in OASIS must accurately reflect what was actually observed, what was actually done, and how the audit was actually conducted. This includes the location (on-site / remote), the duration, the attendees, and the evidence reviewed. Any false entry in an official certification record — regardless of intent — constitutes a breach of audit record integrity and will be treated as a serious misconduct matter.
ISO/IEC 17021-1 Clause 9 · ICOP Scheme OASIS RequirementsImpartiality of Review
The individual who reviews and signs off on an audit report must be independent of the individual who conducted the audit. "Independent" means no personal, family, financial, or organizational relationship that could compromise objective judgment. Any reviewer with a personal or family relationship to the auditor does not meet this standard, regardless of technical competence, which is why KSQA requires independent-reviewer verification on every audit sign-off.
ISO/IEC 17021-1 Clause 5 — Impartiality RequirementsCertification Decision Independence
The decision to issue, maintain, suspend, or withdraw a certificate must be made on the basis of objective audit evidence alone — not on commercial considerations, client pressure, or the desire to maintain a client relationship. Certification decisions must be documented, traceable, and defensible against the applicable standard.
ISO/IEC 17021-1 Clause 9.5 — Certification DecisionAuditor Competence Integrity
KSQA will only assign auditors to audit clients in industries and to standards for which those auditors hold current, verified competence and (where required) current, verified IAQG credentials. Every KSQA auditor is assigned only within their verified, current competence and credential scope, with credential status checked before each assignment.
ISO/IEC 17021-1 Clause 7.1 · Probitas Authentication RequirementsDisclosure Integrity
KSQA will disclose material information to those who have a right to it — including accreditation status changes to clients, conflict-of-interest findings to IAS, and complaint outcomes to complainants. Withholding material information from parties who are entitled to it, or making misleading statements about KSQA's status, is a breach of disclosure integrity.
AS9104/1 Clause 7.3 · ISO/IEC 17021-1 Clause 8.5Financial Integrity
KSQA's fee structures will not be linked to audit outcomes. No discount, rebate, or payment arrangement will be contingent on achieving a particular certification result. The separation between the commercial relationship and the certification outcome is a non-negotiable integrity requirement for any accredited certification body.
ISO/IEC 17021-1 Clause 5.2 — Threats to ImpartialityResponse Integrity
When a complaint, concern, or finding is raised — by a client, an oversight body, or an independent watchdog — KSQA will engage honestly and constructively. Dismissing, deflecting, or covering up legitimate concerns is a breach of response integrity, both ethically and under the complaint-handling requirements of ISO/IEC 17021-1 Clause 9.8.
ISO/IEC 17021-1 Clause 9.8 — Complaints and AppealsAnti-Bribery Policy
KSQA's zero-tolerance position on bribery in all its forms
Bribery — in the context of a certification body — most commonly takes the form of a client or auditor creating a financial arrangement that influences audit findings or certification decisions. KSQA operates a zero-tolerance policy on bribery in all forms, consistent with the US Foreign Corrupt Practices Act (FCPA) where applicable and the standards of the UK Bribery Act as a reference framework. This policy applies to all KSQA personnel, contractors, and agents.
- Acceptance of meals of modest value during client site visits where client hospitality is customary and does not create an obligation
- Branded promotional items of nominal value (pens, notepads) from industry partners
- Reasonable reimbursement of legitimate travel and accommodation expenses for on-site audits
- Participation in industry events, conferences, and training where costs are covered by the organizer
- Standard referral relationships disclosed in writing and not linked to certification outcomes
- Gifts from clients after certification is complete, of nominal value, with no certification process pending
- Accepting or offering any payment, gift, or benefit in exchange for a favorable audit finding, certification recommendation, or certificate issuance
- Accepting cash, gift cards, or equivalent monetary value from clients at any stage of an active certification process
- Offering discounted or deferred fees in exchange for client agreement not to raise a complaint or switch certification bodies
- Directing clients to specific consultants or suppliers in exchange for undisclosed referral payments
- Accepting personal benefits (travel, accommodation, entertainment) of significant value that are not directly tied to a legitimate audit activity
- Facilitating payments to third parties to influence regulatory approvals, accreditation decisions, or oversight outcomes
- Soliciting any personal benefit from a client in connection with an audit or certification decision
Gifts & Hospitality Threshold
Reporting a Bribery Concern
Anyone who becomes aware of a bribery concern involving KSQA personnel — whether as a client, contractor, oversight body representative, or member of the public — is encouraged to report it. KSQA does not retaliate against good-faith reports.
📧 Internal Reporting
Contact KSQA's compliance function directly:
- Email: contact@ksqa.org
- Subject line: "Ethics Concern — Confidential"
- Response commitment: 5 business days
- All reports treated confidentially
🏛 External Reporting
For direct access to independent oversight bodies:
- IAS — iasonline.org
- OASIS complaint system — oasis.sae.org
- Probitas Authentication — for auditor-specific conduct concerns
Confidentiality
How KSQA protects client information — and the limits of that protection
KSQA collects and holds sensitive information about client organizations in the course of certification activities — quality management system documentation, nonconformity findings, process details, supplier information, and audit reports. Protecting that information is both an ethical obligation and a specific requirement of ISO/IEC 17021-1 Clause 8.4.
What confidentiality covers:
- All audit documentation provided by the client during Stage 1 and Stage 2 assessments
- Nonconformity findings and corrective action plans
- Internal process descriptions, quality manual content, and procedure documents
- Supplier names, subcontractor information, and supply chain data encountered during audit
- Financial information, pricing data, or commercial arrangements disclosed incidentally during audit
- Personnel information, organizational structure details, and staffing information
- Any information marked "Confidential" or "Proprietary" by the client
What confidentiality does not prevent:
- Disclosure to IAS during accreditation assessments — IAS has the right to review client files as part of KSQA's accreditation obligations
- Disclosure to the IAQG or Probitas Authentication in connection with scheme oversight activities
- Disclosure of a client's certificate status in the OASIS public database — this is a required public disclosure
- Disclosure required by applicable law, court order, or regulatory authority
- Use of anonymized, aggregated information for quality improvement purposes
Data Classification
| Data Category | Classification | Access | Retention |
|---|---|---|---|
| Client audit reports and supporting documentation | Confidential | KSQA audit team + IAS assessors only | 7 years minimum from certificate expiry |
| Nonconformity findings and corrective actions | Confidential | KSQA, client, IAS on assessment | 7 years minimum |
| Client QMS documentation (manuals, procedures) | Confidential | Assigned auditor only during active engagement | Destroyed after certification cycle unless retained for legal purposes |
| Certificate status (issued, suspended, withdrawn) | Public | Public via OASIS database — required disclosure | Permanent in OASIS |
| Client contact and billing information | Restricted | KSQA management + client services only | 7 years from last transaction |
| Auditor credentials and competence records | Internal | KSQA management + IAS on assessment | Duration of employment/engagement + 5 years |
| KSQA accreditation and IAS assessment records | Internal | KSQA management + IAS; key facts on public Trust pages | Permanent — historical record |
| Complaint records and outcomes | Restricted | KSQA compliance + IAS on assessment; complainant informed of outcome | 7 years minimum |
Ethics & Integrity Commitments — Summary
Business Ethics All business decisions are made ethically, transparently, and in the interest of all stakeholders — not just the paying client
Accurate Records Every audit record, OASIS entry, and certificate is maintained to accurately reflect how each audit was conducted, verified through dual-sign OASIS checklists.
Independent Review Audit sign-off is performed by an individual with no family or personal relationship to the auditor, under KSQA's independent-reviewer requirement.
Prompt Disclosure Material changes to accreditation status are communicated to all affected clients within 5 business days
Zero Bribery No payment, gift, or benefit influences an audit finding or certification decision — zero tolerance, no exceptions
Zero Tolerance for Process Corruption Record accuracy, review independence, and full disclosure are treated with the same seriousness as financial integrity, backed by dual-sign checklists and independent verification.
Confidentiality Client information is protected indefinitely, shared only with IAS and IAQG as required by accreditation obligations
No Retaliation Anyone who reports an ethics concern in good faith is protected from retaliation by any KSQA personnel or contractor
Annual Review This policy is reviewed annually and updated when regulatory requirements, accreditation standards, or identified failures require changes
Report a Concern or Contact Compliance
Two ways to reach KSQA's compliance function directly
Contact Compliance
Note: In production, this submission is sent to contact@ksqa.org.
Frequently Asked Questions
Common questions about this policy — type to filter
Why does KSQA have an Ethics Policy?
Certification bodies occupy a position of trust for clients, supply chains, and regulators, relying on the assumption that audits are conducted honestly. This policy sets out the ethical standards KSQA holds itself to and how those standards are verified and maintained.
How do I report an ethics concern?
Email contact@ksqa.org with the subject line "Ethics Concern — Confidential" for a response within 5 business days, or use KSQA's Whistleblower Program for confidential reporting. External reports can also be made to IAS, the OASIS complaint system, or Probitas Authentication.
What happens after a complaint?
Reports are investigated by KSQA's compliance function, documented, and responded to within 5 business days, with a clear, proportionate resolution process from corrective action plans through to formal reporting to IAS or Probitas Authentication when warranted.
How is confidentiality protected?
Client audit documentation, nonconformity findings, and QMS information are treated as confidential indefinitely and shared only with IAS, IAQG/Probitas, or as required by law. Certificate status itself is a required public disclosure via OASIS.
What is KSQA's anti-bribery stance?
Zero tolerance. No payment, gift, or benefit may influence an audit finding or certification decision. Gifts or hospitality over USD $50 must be declared in writing within 5 business days, and anything offered during an active audit engagement must be declined regardless of value.
How are conflicts of interest managed?
Auditors must disclose potential conflicts before accepting an assignment, and the individual reviewing and signing off on an audit report must be independent of the auditor — with no family, personal, financial, or organizational relationship that could compromise objective judgment. See the Impartiality Policy for full detail.
Does KSQA protect whistleblowers from retaliation?
Yes. Anyone who reports an ethics concern in good faith — client, colleague, contractor, or member of the public — is protected from retaliation by any KSQA personnel or contractor.
What counts as corruption at a certification body?
Beyond financial bribery, KSQA treats inaccurate audit record entries, outcome-influenced certification decisions, and non-disclosure of compliance status as forms of corruption, because each affects the data or process that supply chains rely on, which is why record accuracy and full disclosure are actively enforced controls.
Can I request a copy of my audit records?
Yes. Email contact@ksqa.org with your certificate number and KSQA will provide the requested documentation within 10 business days, at no charge — including for certificate transfer requests to another certification body.
Who owns and approves this policy?
The Ethics & Integrity Policy is owned by KSQA's President and reviewed annually, with compliance oversight from the Impartiality Committee. See the Document Control section near the top of this page for the current version, reviewer, and approval details.
How often is this policy reviewed and updated?
Annually at minimum, and whenever regulatory requirements, accreditation standards, or an identified failure require a change. The Revision History table near the top of this page tracks what changed and when.
No questions match your search. Try a different term, or email compliance directly.
Questions about KSQA's ethics commitments?
Report a concern, request policy documentation, or ask about our certification practices — we respond to all ethics-related inquiries within 5 business days.