Evidence · Impartiality · Judgment · Decision

Independent evidence. Impartial judgment. Clear certification boundaries.

I deliver independent assurance and personally conduct official management-system certification audits through engagements with accredited certification bodies—while keeping advisory, auditing, and certification decisions explicitly separated.

Independent mandates and multiple certification-body engagements worldwide.

01Criteria before opinion
02Evidence before conclusion
03Impartiality before mandate
04CB decision before certificate

Readiness, independent assurance, and certification are not interchangeable.

The scope, independence model, authority, output, and decision owner change according to the engagement type.

01

Direct advisory mandate

Advisory and readiness

Build & prepare

Design or improve the management system, risk process, controls, evidence, internal audit, management review, corrective actions, and readiness for future scrutiny.

02

Direct independent mandate

Independent assurance

Evaluate & report

Assess defined criteria, evaluate design and operating evidence, identify gaps and residual exposure, and provide impartial findings outside a certification decision.

03

Certification-body governed

Official certification audit

Audit through a CB

Personally perform formal third-party certification audits only when appointed by an accredited certification body and within the approved standard, competence, geography, sector, and impartiality scope.

!Certification authority

TaherAmine.org does not issue management-system certificates. Formal certification audits are conducted only through certification-body appointments. The CB controls the audit program, technical review, independent certification decision, certificate issuance, surveillance, suspension, withdrawal, and renewal.

A certificate, an audit, and confidence are different things.

Credible assurance depends on the right criteria, engagement type, evidence, competence, impartiality, reporting, and decision authority.

01

The wrong engagement type

Organizations ask for an audit when they need readiness support—or expect advisory input during a formal audit whose impartiality must be protected.

02

Evidence assembled for the event

Documents are created for the audit window while ownership, operating records, management oversight, corrective action, and continual improvement remain weak.

03

Control claims without traceability

Policies state intent, but the chain from risk and obligation to control, owner, implementation, evidence, monitoring, exception, and decision cannot be followed.

04

Certification confused with assurance

A certificate is treated as proof that every risk is controlled, every technology is secure, or every future failure has been prevented.

05

Findings without systemic correction

Nonconformities are closed narrowly while root cause, similar exposure, governance weakness, management accountability, and recurrence risk remain unresolved.

06

Unclear certification authority

Auditor judgment, technical review, certification decision, certificate issuance, surveillance, suspension, and withdrawal are incorrectly treated as one responsibility.

Management systems and assurance disciplines.

Every formal audit remains subject to the appointing CB’s scheme, competence, sector, geography, authorization, availability, and impartiality controls.

ISMSISO/IEC 27001

Information Security Management

Official certification-audit work covering scope, context, leadership, risk, controls, performance evaluation, corrective action, and continual improvement when appointed within approved CB scope.

BCMSISO 22301

Business Continuity Management

Formal assessment of continuity governance, business impact, risk, strategies, plans, exercises, performance, recovery confidence, and management-system effectiveness.

PIMSISO/IEC 27701

Privacy Information Management

Audit work examining privacy roles, processing context, risk, control responsibilities, evidence, accountability, monitoring, and integration with information-security governance.

STARCSA STAR Level 2

Cloud Security Assurance

Third-party cloud-control assurance within applicable scheme, competence, authorization, certification-body, and audit-program requirements.

+Approved audit scope only

Other management-system standards

Additional standards may be audited only where the appointing certification body confirms the applicable competence, scope, authorization, and impartiality conditions.

Assurance must be traceable, defensible, and appropriately limited.

The strength of the conclusion depends on criteria, evidence, sampling, competence, impartiality, professional judgment, and transparent reporting.

CRT

Defined criteria

Scope, standard, scheme rules, applicable requirements, audit objectives, boundaries, sites, functions, and exclusions are explicit.

TRC

Traceability

Findings connect criteria, sampled evidence, interviews, records, observations, systems, control ownership, and audit conclusions.

SAM

Defensible sampling

Sampling reflects risk, complexity, locations, processes, technology, prior findings, change, and the evidence available at audit time.

IMP

Impartiality

Conflicts, prior relationships, advisory activity, financial interests, competence, and independence are evaluated and governed.

JDG

Professional judgment

Evidence is evaluated against criteria with appropriate competence, skepticism, context, consistency, and transparent limitations.

REP

Decision-ready reporting

Conclusions distinguish evidence, findings, nonconformities, observations, limitations, follow-up needs, and responsibilities.

The audit informs the decision. The CB owns the decision.

This illustrates a typical management-system certification flow; the appointing CB’s governed process and scheme rules always control the mandate.

  1. 01

    CB mandate & impartiality

    The certification body manages the client contract, contract review, audit program, auditor appointment, competence confirmation, impartiality controls, and certification scope.

  2. 02

    Audit planning

    Objectives, criteria, scope, sites, duration, team responsibilities, sampling approach, audit plan, logistics, communication, confidentiality, and prior information are established.

  3. 03

    Stage 1 evaluation

    Where applicable, assess documented and implemented readiness, scope, context, risk, management-system design, internal evaluation, significant issues, and preparedness for the next stage.

  4. 04

    Stage 2 evaluation

    Evaluate implementation and effectiveness through interviews, records, observation, technical and operational evidence, process sampling, control results, and management oversight.

  5. 05

    Reporting & follow-up

    Present evidence-based conclusions, nonconformities and other findings, receive corrective-action information through the governed process, and perform follow-up where assigned.

  6. 06

    Independent CB decision

    The certification body reviews the audit package and makes the certification decision independently of the audit team, then governs the certificate lifecycle and ongoing program.

Four roles. Four different authorities.

Keeping these responsibilities separate protects impartiality, prevents misleading claims, and makes the assurance outcome defensible.

01

Advisor / readiness partner

Can

Design, guide, prepare, facilitate, review, and support implementation and improvement.

Cannot

Act as the certification auditor for the same conflicting scope or promise a certification outcome.

02

Independent assessor

Can

Evaluate defined criteria and evidence, report findings, limitations, and residual exposure outside formal certification.

Cannot

Issue an accredited management-system certificate or represent the work as a CB certification decision.

03

CB-appointed certification auditor

Can

Plan and perform the assigned audit, evaluate evidence, report nonconformities and conclusions, and make permitted audit recommendations.

Cannot

Consult during the audit, issue the certificate, or make the final independent certification decision.

04

Accredited certification body

Can

Govern the audit program, competence and impartiality, contract, technical review, certification decision, certificate, surveillance, suspension, and withdrawal.

Cannot

Delegate its independent certification decision to the individual auditor or to TaherAmine.org.

Start with the outcome and authority you actually need.

The correct route protects independence, avoids procurement confusion, and makes sure the final output has the authority you expect.

  1. 01

    Organization seeking readiness

    Engage TaherAmine.org directly

    Use an advisory mandate to prepare or improve the management system, controls, evidence, internal assurance, corrective action, and executive governance.

  2. 02

    Organization seeking independent assurance

    Engage TaherAmine.org directly

    Define the criteria, independence needs, evidence, reporting audience, limitations, and decision the non-certification assessment must support.

  3. 03

    Organization seeking certification

    Contract through a certification body

    Select an appropriate accredited certification body. The CB controls the formal program and may appoint Taher as auditor where scope, competence, geography, availability, and impartiality permit.

  4. 04

    Certification body seeking an auditor

    Discuss a CB auditor mandate

    Certification bodies can discuss auditor availability, standards, sectors, languages, geography, delivery model, records, authorization, and scheme-specific competence requirements.

Stage 1 ISMS certification audit in a managed-security environment.

Enterprise managed-security service · Client and certification-body identities withheld for confidentiality

The context

A managed-security environment entered the formal certification process and required Stage 1 evaluation of management-system scope, context, risk, documentation, implementation readiness, internal evaluation, and management oversight.

The mandate

Perform the assigned certification audit on behalf of the certification body, evaluate sampled evidence against the applicable criteria, preserve impartiality, and report findings through the CB-governed process.

The boundary

The audit conclusions and formal report were returned to the certification body. The CB retained responsibility for technical review, subsequent audit-program decisions, certification decisions, and the certificate lifecycle.

Outputs aligned to the engagement authority.

Certification-audit deliverables follow the appointing CB’s controlled process. Advisory and independent-assurance outputs are clearly labeled and never presented as accredited certification.

  1. 01

    Audit or assurance scope and criteria

  2. 02

    Impartiality and conflict-of-interest declarations

  3. 03

    Audit plan and evidence-sampling approach

  4. 04

    Stage 1 audit report when formally assigned

  5. 05

    Stage 2 audit report when formally assigned

  6. 06

    Evidence-based findings and nonconformities

  7. 07

    Executive assurance summary

  8. 08

    Corrective-action review records where assigned

  9. 09

    Follow-up or closure-verification evidence

  10. 10

    Independent assessment and residual-risk report

  11. 11

    Readiness gap and evidence-architecture report under advisory scope

  12. 12

    Management-system improvement roadmap under a separate mandate

No ambiguity about certification authority.

Can Taher personally conduct our official certification audit?

Yes, when an accredited certification body appoints him and confirms the relevant standard, scheme, sector, geography, competence, availability, and impartiality requirements. The formal contract and certification program are governed by the certification body.

Does TaherAmine.org issue ISO or management-system certificates?

No. TaherAmine.org is not the certification body and does not independently issue, suspend, withdraw, or renew accredited management-system certificates. Those responsibilities remain with the responsible certification body.

Who makes the final certification decision?

The certification body makes the certification decision through its governed independent review process. The audit team evaluates evidence and reports conclusions, findings, and permitted recommendations but does not issue the certificate.

Can you prepare us for certification and then perform the official audit?

Not under a conflicting arrangement. Advisory and readiness work must remain separate from formal certification-audit responsibilities in accordance with certification-body rules, impartiality requirements, and applicable professional obligations.

Can an organization request Taher as its preferred auditor?

An organization may express a preference to its certification body, but the CB retains responsibility for auditor selection, competence, impartiality, availability, rotation, scheme rules, and the audit program. Appointment is never guaranteed.

Which standards can be covered?

Primary audit experience includes ISMS, BCMS, PIMS, and CSA STAR-related assurance. Other standards may be covered only when the appointing CB confirms that the specific audit falls within approved competence and scheme scope.

Can you guarantee certification or a finding-free audit?

No. No credible advisor, auditor, or certification body should guarantee certification, a particular recommendation, or the absence of findings. Conclusions depend on the applicable criteria and evidence available during the governed process.

Is independent assurance the same as certification?

No. Independent assurance can evaluate defined criteria and provide impartial findings and conclusions, but it does not become accredited certification unless performed within an authorized certification-body scheme and followed by the CB’s independent decision process.

Start with the assurance question—not the label.

Whether you represent an organization seeking readiness or independent assurance, or a certification body seeking an experienced auditor, the first conversation will clarify the correct authority, scope, independence model, and route.

Discuss the correct pathway

Independent · Impartial · Confidential