Overview
ISO/IEC 33002:2015 - Information technology - Process assessment - Requirements for performing process assessment - specifies the minimum requirements needed to perform objective, consistent, repeatable, and representative process assessments. The standard defines the structure and mandatory activities for assessments (planning, data collection, validation, rating and reporting), and it applies across all application domains and organization sizes. ISO/IEC 33002:2015 is part of the ISO/IEC 330xx family and supports process improvement, benchmarking, risk mitigation, and self-assessment.
Key Topics and Technical Requirements
- Documented assessment process: Assessments must follow a documented process capable of meeting the intended purpose, including defined activities, tailoring rules, and coverage criteria.
- Assessment activities: The standard mandates five core activities:
- Plan the assessment (scope, class, independence, communication, resources, rating and aggregation methods)
- Collect the data (gather objective evidence mapped to the process assessment model)
- Validate the data (ensure sufficiency, representativeness and consistency)
- Determine the results (use defined assessment indicators, rate process attributes, aggregate results)
- Report the assessment (document outputs, traceability and findings)
- Roles, responsibilities and competence: Assign and document roles (lead assessor, assessment team) and competence requirements for personnel involved.
- Classes of assessment: Defines multiple classes (Class 1, 2, 3) reflecting different confidence and coverage levels, with specific evidence and sampling requirements for each.
- Independence and impartiality: Annex A describes categories of independence for bodies and personnel to ensure unbiased assessments.
- Traceability and records: Maintain traceability between ratings and objective evidence; keep assessment records and outputs for verification.
Practical Applications and Who Would Use It
ISO/IEC 33002:2015 is used by:
- Internal process improvement teams conducting self-assessments and continuous improvement of software, systems engineering, and IT service processes.
- External assessors and certification bodies performing vendor evaluations, pre-contract or contractual suitability reviews, and benchmarking exercises.
- Quality, compliance and risk managers seeking an objective basis for process capability ratings, performance improvement plans, and mitigation of process-related risks.
- Organizations of all sizes and domains that need standardized assessment methods, reproducible audit trails, and defensible process evaluations.
Related Standards (if applicable)
Keywords: ISO/IEC 33002:2015, process assessment, assessment plan, objective evidence, process capability, assessment classes, process improvement, assessment report.