Skip to content
Policy

Governance Policy

GMSQUEST's governance and accountability structure for certification operations under ISO/IEC 17021-1:2015 and ISO/IEC 27006-1:2024.

Purpose

GMSQuest Certification Private Limited establishes, implements, and maintains effective governance and accountability for all certification operations, ensuring impartiality, competence, and compliance with ISO/IEC 17021-1:2015, ISO/IEC 27006-1:2024 and ISO/IEC 27001:2022.

Scope

Applies to all GMSQuest personnel, auditors, contractors, and committees involved in management system certification activities. It covers leadership, impartiality, confidentiality, and certification-decision authority.

Governance Objectives

  1. 01Maintain transparent leadership and accountability.
  2. 02Ensure freedom from any commercial, financial, or other pressures compromising impartiality.
  3. 03Protect confidentiality and information security of all clients.
  4. 04Demonstrate legal responsibility for all certification decisions.
  5. 05Continually improve governance effectiveness through review and monitoring.

Governance Structure

  • Top Management — responsible for resources, policies, reviews, and impartiality.
  • Impartiality Committee — oversees risks and independence, reporting to Top Management.
  • Certification Decision Function — independent decision makers per CB-PR-09, covering Annex C and audit reporting (9.4.3.2).
  • Technical & Operational Management — manages ISMS competence, remote audits, and audit-time determinations.
  • Confidentiality and Data Security — enforced through confidentiality agreements.
  • Remote Audit Governance — governed by the Audit Manager, ensuring compliance with 9.1.3.3.

Roles and Responsibilities

  • Managing Director — strategic direction, impartiality, resource allocation.
  • Certification Director — oversight of operations and decisions.
  • Technical Manager / Scheme Manager — competence and Annex C & E control.
  • Audit Manager — audit planning and remote audit governance.
  • Decision Maker — independent certification approval.
  • Impartiality Committee — reviews impartiality risks.
  • Quality Manager — internal audits, document control, governance reporting.

Impartiality and Independence

All impartiality risks are assessed and recorded in the Impartiality Risk Register. No auditor or decision-maker is involved in consultancy with clients. Financial independence is maintained through structured policies.

Accountability and Legal Responsibility

GMSQuest Certification Private Limited, a registered company under the Companies Act of India (CIN: U74900KA2025PTC197580), accepts full responsibility for all certification decisions and issued certificates. GMSQuest retains ownership of all audit records and certification data.

Governance Oversight and Review

Governance effectiveness is reviewed in each Management Review Meeting, covering:

  • Impartiality risks
  • Remote audit performance
  • Audit-time determinations (Annex C)
  • ISMS Annex E alignment
  • Client feedback and improvement actions

Findings are documented in Management Review Minutes and reviewed annually.

Your Organization. Global Standards.

Let’s Get You Certified.