Legal information
Assessment Rules
Effective date: 29 August 2026. These rules apply to the Assurevance ISO/IEC 27001:2022 programme.
1. Purpose and scope
These rules describe the assessment and credential process for the Assurevance ISO/IEC 27001:2022 programme. They must be read with the programme page, Terms, Privacy Notice, Credential Use Policy, and any applicant-specific agreement.
2. Eligibility and application
An applicant must be a legally constituted organisation, appoint an authorised contact, submit complete and accurate information, and provide evidence sufficient for the stated programme scope. We may reject or pause incomplete, misleading, unauthorised, unlawful, or unverifiable applications.
3. Assessment process
- Application receipt and completeness check.
- Conflict-of-interest and eligibility review.
- Evidence review against the applicable ISO/IEC 27001:2022 programme requirements and the scope submitted by the applicant.
- Clarification requests, where needed.
- Decision by an authorised Assurevance decision-maker who has not carried out the assessment where reasonably practicable.
- Issue, decline, or request for further work; reasons are recorded.
No credential may be issued solely on payment or self-declaration where the approved programme requires independently reviewed evidence. The final decision and authorised scope are recorded in the credential record.
4. Validity and surveillance
Unless the issued record states otherwise, a credential is valid for 12 months from issue. Holders must notify us promptly of material changes affecting the approved scope, legal entity, or supporting evidence. Renewal requires a current review of the information and evidence Assurevance considers necessary for the applicable scope.
5. Impartiality and records
Personnel must declare and manage actual or potential conflicts. We retain assessment records, decision rationale, and status history for as long as reasonably necessary to operate the programme, maintain the public registry, respond to disputes, and meet legal obligations.
6. Nonconformity, suspension, and revocation
We may require corrective information, suspend, revoke, expire, correct, or replace a credential when evidence is inaccurate, requirements are no longer met, the credential is misused, fees remain unresolved, or law requires it. The public verification record will show the current status.