top of page
Search

ISO/IEC 17024:2026 Unpacked: What Changed and Why It Matters for Certification Bodies

  • Apr 30
  • 7 min read


The transition from ISO/IEC 17024:2012 second edition to ISO/IEC 17024:2026 third edition represents a targeted modernization of the standard rather than a complete structural overhaul. The foundational principles of competence-based certification, impartiality, and reliable assessment remain unchanged. However, the 2026 revision strengthens alignment with current conformity assessment practices, introduces considerations for emerging technologies such as artificial intelligence, and enhances the management system framework to reflect a more risk-based and performance-driven approach. These updates ensure that certification bodies remain credible, consistent, and globally recognized while adapting to evolving industry expectations and technological advancements.

 

From a structural perspective, the 2026 edition largely retains the familiar clause sequence from the 2012 version, covering Scope through Management System Requirements, which supports continuity for existing accredited certification bodies. At the same time, the content within these clauses has been refined and expanded to improve clarity and operational depth. A key addition is Clause 6.5, which introduces requirements for the use of artificial intelligence in the certification process, including validation, monitoring, and human oversight. In addition, Clause 9 has been reorganized to clearly distinguish the assessment process from the application and examination processes, providing greater transparency in how competence is evaluated and verified.

 

Further enhancements are evident in Clause 10, where management system requirements are more explicitly aligned with modern ISO practices. This includes clearer expectations for policies and responsibilities, structured management review inputs and outputs, internal audits, corrective actions, and actions addressing risks and opportunities. Supporting clauses such as records, confidentiality, and security have also been strengthened to reflect increased reliance on digital systems and heightened data protection expectations. The inclusion of Annex B in the 2026 edition further supports implementation by clarifying the relationship between certification activities, complementing the principles outlined in Annex A and providing a more integrated view of the certification framework.

 

The following sections provide a clause-by-clause breakdown of the key updates introduced in the 2026 edition, highlighting what has changed and the practical implications for certification bodies.

 

Clause 4: General Requirements


Clauses 4.1 Legal Matters and 4.2 Responsibility for Decision on Certification remain unchanged in the 2026 edition, maintaining the requirement for certification bodies to operate as legal entities and retain full authority over certification decisions. Similarly, Clause 4.4 Finance and Liability continues without modification. The primary updates are introduced in Clause 4.3 Management of Impartiality, where the 2026 version strengthens transparency and oversight. Specifically, Clause 4.3.2 now explicitly requires certification bodies to make an impartiality statement publicly available, reinforcing accountability to stakeholders. In addition, a new requirement in Clause 4.3.5 addresses the use of artificial intelligence in certification activities, requiring certification bodies to document and demonstrate how risks to impartiality, including potential bias, are identified, minimized, or controlled. These changes reflect an increased focus on transparency and the responsible use of technology in maintaining impartial certification processes.

 

Clause 5: Structural Requirements

 

Clause 5 remains largely unchanged in the 2026 edition, with only minor editorial updates. In Clause 5.1, the title has been revised from Management and organization structure toManagement and organizational structure without any impact on the underlying requirements. Similarly, Clause 5.2 retains its original intent and requirements, with no substantive changes to the structure of the certification body in relation to training. The only update is the inclusion of the term “education” alongside “training” in both the title and the content, now referred to as “Structure of the certification body in relation to education or training”. This adjustment reflects broader terminology without altering the practical application of the clause.

 

Clause 6: Resource Requirements


Clause 6 introduces several refinements focused on personnel competence, governance, and clarity of responsibilities. The title of Clause 6.1 has been updated from “General personnel requirements” to “General requirements for personnel”. While Clause 6.1.1 remains unchanged, new provisions strengthen expectations around impartiality and competence management. Specifically, Clause 6.1.2 now explicitly requires that all personnel who could influence certification activities act impartially, and Clause 6.1.4 introduces a requirement for a defined process to manage personnel competence. In addition, several subclauses have been renumbered and consolidated for clarity, including the merging of previous requirements related to personnel records and competence, and the expansion of confidentiality and commitment provisions to include more detailed expectations.

 

Clause 6.2 has been updated in both title and scope, shifting from Personnel involved in the certification activities to Personnel involved in the assessment activitiesemphasizing the critical role of assessment in certification. Within Clause 6.2.2 Requirements for examiners, a new explicit provision requires certification bodies to ensure that interpretation or translation used during examinations does not compromise validity, reliability, or fairness. Furthermore, Clause 6.2.3 has been streamlined into a more concise structure, while explicitly expanding its scope to include individuals involved in developing examination content, thereby clarifying accountability across all assessment-related roles.

 

No changes have been introduced to Clause 6.3 Outsourcing and Clause 6.4 Other resources.

 

A significant addition in the 2026 edition is Clause 6.5, which establishes requirements for the use of artificial intelligence in the certification process. Where AI is applied, certification bodies are required to verify, manage, and continuously monitor its use to ensure intended outcomes, validate results through subject matter experts, and ensure that personnel overseeing AI have appropriate competence. The standard also mandates human oversight of AI, demonstration of validity, reliability, and fairness in its application, and transparency through disclosure to applicants, candidates, or certified persons, including obtaining their acknowledgement where AI is used in communication or interaction. This clause formalizes expectations for responsible and controlled integration of AI within certification activities.

 

Clause 7: Records and Information Requirements


Clause 7 Records and Information Requirements includes targeted updates focused on structure, data protection, and confidentiality controls. Within Clause 7.1, the previous provision 7.1.3 has been removed and repositioned elsewhere in the standard, indicating a refinement in how ongoing obligations of certified persons are addressed. Clause 7.2 Public Information has been streamlined from four provisions in the 2012 version to three in the 2026 edition, improving clarity and reducing redundancy without changing the overall intent. The most notable enhancements are within Clause 7.3 Confidentiality. While Clause 7.3.1 remains unchanged, a new explicit requirement in Clause 7.3.2 introduces the need for policies and procedures addressing data privacy and data protection, reflecting increased emphasis on handling sensitive information. Additionally, Clauses 7.3.2 and 7.3.3 from the previous version have been merged into a single provision 7.3.3, while Clauses 7.3.4 and 7.3.5 remain unchanged. A further new requirement, Clause 7.3.6, obligates certification bodies to identify threats to confidentiality and take actions to eliminate or minimize their impact, reinforcing a more proactive and risk-based approach to information security.

 

Clause 8: Certification Schemes

 

Clause 8 Certification Schemes, as the core of the standard, remains largely unchanged in the 2026 edition, maintaining its fundamental structure and requirements related to defining competence, job tasks, prerequisites, and assessment methods. Notably, a new Note 2 has been added under Clause 8.2, specifying that prerequisites may include qualifications, work experience, or similar criteria, and can be fulfilled either at the time of application or at any point prior to the certification decision. This addition provides greater flexibility and clarity in how certification bodies can structure and verify eligibility requirements without altering the overall intent of the clause.

 

Clause 9: Certification Process Requirements


Clause 9 Certification Process Requirements introduces limited but meaningful refinements, primarily in structure and clarity. The order of the first two subclauses has been revised, with the previous 9.1 Application Process and 9.2 Assessment Process now presented as 9.1 Assessment Process and 9.2 Application Process. This change places greater emphasis on assessment as the central element of certification. Within Clause 9.1, a new requirement 9.1.7 has been added to address the use of interpretation or translation, requiring certification bodies to ensure that such support does not affect the validity, reliability, or fairness of the assessment.

 

No substantive changes have been introduced to Clause 9.2 Application Process, 9.3 Examination Process, 9.4 Decision on Certification, 9.5 Suspending, Withdrawing or Reducing Scope, or 9.6 Recertification Process, with these clauses maintaining their original intent and requirements.

 

In Clause 9.7 Use of Certificates, Logos and Marks, Clauses 9.7.1 and 9.7.3 remain unchanged. However, Clause 9.7.2 has been expanded, with item c from the previous version now split into c and d for improved clarity. Additionally, the requirement previously included under Clause 7.1.3 has been relocated to Clause 9.7.2 as item g, consolidating obligations related to certified persons within the context of certificate use and representation.

 

Clause 9.8 Appeals Against Decisions on Certification remains largely unchanged, with the exception of Clause 9.8.4 from the previous version, which has been paraphrased and divided into two separate provisions 9.8.4 and 9.8.5 to enhance clarity and readability, without altering the underlying requirements.

 

Clause 9.9 Complaints has been restructured with minor updates to improve clarity and reinforce impartiality. Notably, Clause 9.9.8 now explicitly requires that the resolution of complaints be carried out, or reviewed and approved, by individuals not involved in the subject of the complaint, ensuring objectivity even in cases of limited resources. In addition, Clause 9.9.9 introduces a clear requirement that the investigation and resolution of complaints must not result in any discriminatory actions, strengthening fairness and integrity within the complaints-handling process.

 

Clause 10: Management System Requirements

 

Clause 10 in the 2026 edition has been restructured to align more closely with ISO management system frameworks, introducing clearer organization and a stronger emphasis on risk-based thinking. The previous Clauses 10.1 General, 10.2 General Management System Requirements, and 10.2.1 General from the 2012 version have been consolidated and streamlined into Clauses 10.1 General and 10.2 Policies and Responsibilities. In addition, documentation-related provisions, including 10.2.2 Management System Documentation, 10.2.3 Control of Documents, and 10.2.4 Control of Records, have been merged into a single Clause 10.7 Documented Information, reflecting a more integrated approach to managing documented processes and records.


Other clauses have been renumbered without significant content changes, including 10.3 Management Review, 10.4 Internal Audits, and 10.5 Corrective Actions.

 

A key enhancement in the 2026 edition is the introduction of Clause 10.6 Actions to Address Risks and Opportunities, which establishes a proactive, risk-based approach to managing certification activities. Certification bodies are now required to identify and evaluate risks and opportunities to ensure intended outcomes, enhance performance, prevent undesired impacts, and support continual improvement. Actions taken must be planned, integrated into the management system, and evaluated for effectiveness, with proportionality based on the potential impact on certification activities. As part of this shift, the standalone requirement for preventive actions previously Clause 10.2.8 has been removed. Its intent is now embedded within corrective actions through root cause analysis to prevent recurrence, and more explicitly within Clause 10.6, which focuses on anticipating and mitigating potential nonconformities before they occur.

 

If you are preparing to implement ISO/IEC 17024:2026, transition from the 2012 version, we support you at every stage. From full implementation and transition planning to targeted training for your team, we ensure you can apply the updated and new requirements in a practical way.


 
 
 

Comments


bottom of page