Skip to main content
ASSUREVANCEASSURANCE BODY
ISO 27001 Requirements How it works FAQs Verify Start an application

Legal information

Assessment Rules

Effective date: 29 August 2026. These rules apply to the Assurevance ISO/IEC 27001:2022 programme.

1. Purpose and scope

These rules describe the assessment and credential process for the Assurevance ISO/IEC 27001:2022 programme. They must be read with the programme page, Terms, Privacy Notice, Credential Use Policy, and any applicant-specific agreement.

2. Eligibility and application

An applicant must be a legally constituted organisation, appoint an authorised contact, submit complete and accurate information, and provide evidence sufficient for the stated programme scope. We may reject or pause incomplete, misleading, unauthorised, unlawful, or unverifiable applications.

3. Assessment process

  1. Application receipt and completeness check.
  2. Conflict-of-interest and eligibility review.
  3. Evidence review against the applicable ISO/IEC 27001:2022 programme requirements and the scope submitted by the applicant.
  4. Clarification requests, where needed.
  5. Decision by an authorised Assurevance decision-maker who has not carried out the assessment where reasonably practicable.
  6. Issue, decline, or request for further work; reasons are recorded.

No credential may be issued solely on payment or self-declaration where the approved programme requires independently reviewed evidence. The final decision and authorised scope are recorded in the credential record.

4. Validity and surveillance

Unless the issued record states otherwise, a credential is valid for 12 months from issue. Holders must notify us promptly of material changes affecting the approved scope, legal entity, or supporting evidence. Renewal requires a current review of the information and evidence Assurevance considers necessary for the applicable scope.

5. Impartiality and records

Personnel must declare and manage actual or potential conflicts. We retain assessment records, decision rationale, and status history for as long as reasonably necessary to operate the programme, maintain the public registry, respond to disputes, and meet legal obligations.

6. Nonconformity, suspension, and revocation

We may require corrective information, suspend, revoke, expire, correct, or replace a credential when evidence is inaccurate, requirements are no longer met, the credential is misused, fees remain unresolved, or law requires it. The public verification record will show the current status.

Related policies
Terms of Service Privacy Notice Cookie Notice Credential Use Policy Assessment Rules Complaints and Appeals Accessibility Statement Refunds and Cancellation Policy
ASSUREVANCEASSURANCE BODY

Evidence-led management-system assurance with credentials that can be checked in a public registry.

Explore

ISO/IEC 27001 Requirements guide Programme pathway Frequently asked questions

Registry & support

Verify a credential Contact the assurance team Complaints and appeals Assessment rules

Policies

Terms Privacy Credential use Accessibility