Overview
ISO/IEC TS 17021-14:2022 is a technical specification developed by ISO and IEC that outlines the competence requirements for personnel involved in the audit and certification of management systems for records (MSR). This standard is intended to complement ISO/IEC 17021-1, which addresses the requirements for bodies providing audit and certification of management systems broadly.
This document ensures that certification bodies assign properly qualified personnel to the audit and certification of MSR, which is especially important for organizations seeking to certify their records management systems, such as those developed according to ISO 30301. ISO/IEC TS 17021-14:2022 is also applicable for broader MSR contexts beyond ISO 30301.
Key Topics
Core Competence Requirements:
ISO/IEC TS 17021-14:2022 requires that audit and certification personnel possess:
- Generic competence: As described in ISO/IEC 17021-1, covering standard audit skills and processes.
- MSR-specific knowledge: Including core records management concepts, policies, and terminology.
- Discipline-specific skills: Understanding records processes, metadata, technological tools, controls, and legal/regulatory requirements.
- Context of the organization: Ability to assess internal/external influences, stakeholder needs, and strategic relevance of the MSR scope.
- Client-specific knowledge: Awareness of organizational structure, products, services, operational environments, and sector regulations.
- Risk-based thinking: Applying risk assessment and management principles to records systems.
Competencies for Key Roles:
- Auditors: Required to understand the fundamental concepts of MSR, specific records processes, organizational contexts, and technical/sector-specific knowledge.
- Certification decision personnel: Must possess knowledge to review audit reports, understand records management principles, risk-based approaches, and MSR scoping.
Applications
ISO/IEC TS 17021-14:2022 is primarily used by:
- Certification bodies: Ensuring qualified audit teams for assessing and certifying management systems for records in compliance with international standards.
- Organizations seeking MSR certification: Supporting compliance with ISO 30301 by engaging with certification bodies that use qualified personnel.
- Consultants and auditors: Guiding professional development and training to meet competence expectations for MSR audits.
The standard supports effective management of records by:
- Improving organizational accountability, risk management, and business continuity.
- Protecting the integrity and reliability of records in digital and physical environments.
- Addressing evolving business, legal, and technological requirements across all sectors.
Benefits include:
- Greater confidence in the certification process for MSR.
- Enhanced ability to meet legal and regulatory obligations for records management.
- Strengthened stakeholder trust through adherence to internationally recognized competence criteria.
Related Standards
When implementing or auditing management systems for records, organizations and certification bodies may also reference:
- ISO/IEC 17021-1: Conformity assessment - Requirements for bodies providing audit and certification of management systems.
- ISO 30301: Management systems for records - Requirements.
- ISO 30300: Records management - Core concepts and vocabulary.
- ISO 19011: Guidelines for auditing management systems.
- ISO 15489-1: Records management - Concepts and principles.
- ISO 23081 series: Metadata for records management.
- ISO 13008: Digital conversion and migration process.
- ISO 17068: Trusted third party repository for digital records.
Certification bodies and organizations adopting ISO/IEC TS 17021-14:2022 demonstrate commitment to best practices in MSR auditing and certification, ensuring robust, compliant, and effective records management systems.