Want to learn more about our services? Book a 15-minute consultation with our team today!

ISO Certification Program

Pease Bell CPAs currently offers certification services for:

  • ISO 27001 – Information Security Management Systems

We specialize in ISO 27001 certification to help organizations demonstrate robust information security management. For more details or to request a quote, please contact us at [email protected] or visit https://www.peasebell.com/.

Our Certification Process

Audit Process & Timeline

At Pease Bell CPAs, our ISO 27001 audit process is designed to be transparent, impartial, and supportive of your organization's information security objectives. We follow internationally recognized standards and continuously refine our approach to deliver the highest level of service.

The overall timeline varies based on factors such as organization size, complexity, scope, and ISMS maturity, ranging from a few months to over a year. Our goal is to provide an efficient, straightforward certification audit. Below is an overview of the process and timeline for each step.

1. Application & Planning

  • Initial Inquiry: Begin by submitting an application for ISO 27001 certification. We'll review your organization's scope, locations, and objectives.
  • Scope Definition: We work with you to define the boundaries of your Information Security Management System (ISMS), ensuring all relevant processes and assets are included.
  • Audit Plan: Our team develops a customized audit plan, outlining objectives, timelines, and required resources.

2. Pre-Certification Gap Assessment (Optional)

A pre-certification assessment is highly recommended for companies undergoing certification for the first time. It helps save time and money by identifying areas for improvement before the certification audit.

  • Gap Analysis: We review your entire management system, including scope, policies, procedures, risk assessments, Statement of Applicability (SOA), and processes, by requesting documentation and conducting interviews to uncover any weaknesses or oversights.
  • Gap Identification: We provide a detailed report identifying gaps against the requirements of the standard, giving you the chance to address them before the certification audit. A pre-certification assessment identifies gaps only: Pease Bell does not provide recommendations, solutions, or implementation advice, and the results of a pre-certification assessment have no bearing on the outcome of any subsequent certification audit or certification decision.
  • Typical Duration: Typically, a few weeks, depending on your organization's availability.
  • ISMS Implementation: Implementing your ISMS is your organization's responsibility (or that of your separate ISMS consultant). Pease Bell cannot provide implementation consulting and must remain independent. This phase is usually the longest part of the process, often taking several months for most organizations.

3. Stage 1 Audit: Documentation & Readiness Review

  • Document Review: Our auditors assess your organization's ISMS documentation (policies, procedures, risk assessments, Statement of Applicability) to ensure it is established and implemented in alignment with ISO 27001:2022 mandatory requirements.
  • Readiness Review: We evaluate your preparedness for the Stage 2 audit, identify areas needing improvement, and provide a window of 2–8 weeks for corrective actions before proceeding to Stage 2.
  • Typical Duration: 1-2 weeks.
  • Remediation: Areas requiring improvement are typically addressed within 2–8 weeks after being identified and communicated. If issues are not resolved within the agreed timeframe, a second Stage 1 audit may be required before moving to Stage 2.

4. Stage 2 Audit: Implementation & Effectiveness

  • On-Site or Remote Audit: Our auditors conduct a thorough review of your ISMS implementation, including interviews, process walkthroughs, and evidence collection.
  • Nonconformity Reporting: All findings and nonconformities are documented in a detailed report.
  • Corrective Actions: You address any nonconformities and submit evidence of corrective actions within the timeframe provided by Pease Bell.
  • Typical Duration: Varies significantly and is communicated in the Audit Plan but typically takes 1–4 weeks.

5. Certification Decision

  • Certification Review: Our team reviews all audit findings and corrective actions.
  • Certification Issuance: Certification is issued once all major nonconformities have been verified as corrected and plans for any minor nonconformities have been reviewed and accepted. It is valid for three years, contingent on the successful completion of two surveillance audits in the following two years.
  • Typical Duration: 1-2 weeks.
  • Scope Changes: Requests to expand or reduce the certification scope are assessed and updated as needed.

6. Surveillance & Recertification

  • Surveillance Audits: Annual audits are conducted to ensure ongoing compliance and continual improvement of your ISMS.
  • Recertification Audits: Every three years, a full audit is performed to renew your certification.
  • Special Audits: Additional audits may be scheduled if significant changes occur or upon request.

7. Impartiality & Confidentiality

  • Pease Bell is committed to impartiality and confidentiality throughout the audit process. Our auditors are independent, and all client information is handled securely.

8. Client Support

  • We provide clear guidance on the corrective action submission process, audit scheduling, and certification maintenance requirements.
  • Our team is available for questions and support throughout your ISO 27001 certification journey.

For more details or to request a quote, please contact us at [email protected] or visit https://www.peasebell.com/.

Certification Decisions & Certificate Lifecycle

Pease Bell CPAs is committed to impartial, transparent, and consistent certification practices in accordance with ISO/IEC 17021-1:2015. The following outlines our processes for granting, refusing, maintaining, renewing, suspending, restoring, or withdrawing certification, as well as expanding or reducing the scope of certification.

1. Granting Certification

  • Certification is granted after successful completion of the audit process, including resolution of all major nonconformities.
  • Certification decisions are made by qualified personnel independent of the audit team, ensuring impartiality.
  • Clients receive formal notification and a certificate specifying the scope and validity period.

2. Refusing Certification

  • Certification may be refused if the management system does not meet the requirements of the relevant standard or if nonconformities are not resolved within the required timeframe.
  • Clients are notified in writing of the reasons for refusal and provided with guidance on corrective actions and the process for re-application.

3. Maintaining Certification

  • Ongoing certification is maintained through regular surveillance audits and reviews to confirm continued conformity.
  • The first surveillance audit must be conducted within twelve (12) months from the initial certification decision and subsequent surveillance and recertification audit must occur within twelve (12) months from the end of the most recent surveillance or recertification, as applicable.
  • Failure to maintain compliance may result in suspension or withdrawal.

4. Renewing Certification

  • Recertification audits are conducted prior to certificate expiry to confirm ongoing effectiveness and relevance of the management system.
  • Successful completion results in renewal of certification for a new cycle.

5. Suspending Certification

  • Certification may be suspended if:
    • The management system persistently or seriously fails to meet requirements,
    • The client does not allow required audits,
    • The client requests suspension,
    • There is a breach of contract.
  • Suspension is temporary and in most cases will not exceed six (6) months; the suspension period is set case-by-case based on the nature of the issue and the client's corrective action plan. Clients are notified of the reasons for suspension and the actions required for reinstatement.
  • Public references to the affected certification will be updated to indicate its suspended status and can be reversed upon resolution of the underlying issue.
  • If the issue is not resolved within the communicated timeframe, certification will be withdrawn.

6. Restoring Certification

  • Certification may be restored if the issues leading to suspension are resolved within the timeframe established by Pease Bell.
  • Restoration after withdrawal requires a new application and completion of the full initial certification process, as well as execution of a new certificate agreement prior to being reconsidered for certification.

7. Withdrawing Certification

  • Certification may be withdrawn if:
    • Issues leading to suspension are not resolved,
    • The management system no longer conforms to requirements,
    • The client voluntarily withdraws.
  • Upon withdrawal, all references to certification and use of certification marks must cease.

8. Expanding or Reducing Scope

  • Expanding Scope: Clients may request to expand the scope of certification. Pease Bell's certification decision maker will review the request and determine if additional audit activities are necessary.
  • Reducing Scope: If parts of the management system no longer meet requirements, the scope may be reduced accordingly. Pease Bell's certification decision maker will approve the request from the Company for scope reduction if no longer applicable. Pease Bell's certification decision maker will refuse scope reduction if the reduction is to avoid non conformities.

Commitment to Impartiality & Transparency

All certification decisions are made by competent personnel independent of the audit process. Pease Bell CPAs does not provide management system consultancy to maintain impartiality. Our processes are publicly available and designed to ensure fairness, objectivity, and compliance with international standards.

Impartiality

At Pease Bell CPAs, impartiality is the foundation of our certification activities. We are fully committed to conducting all conformity assessment and certification services with independence, objectivity, and integrity, in strict compliance with ISO/IEC 17021-1:2015. This section constitutes Pease Bell's public policy on impartiality, maintained and published in accordance with ISO/IEC 17021-1:2015 §8.1.1(f).

Key Principles

  • No Bias or Undue Influence: All certification decisions are made impartially, free from commercial, financial, or other pressures that could compromise objectivity. Certification decisions are made by competent personnel who did not participate in the audit, and no fee, discount, or waiver is ever contingent on a certification decision or an audit outcome.
  • Top Management Commitment: Impartiality oversight is led directly by Top Management, which maintains a documented impartiality risk assessment and reviews it at least annually as part of management review — and whenever a new risk is identified — to confirm that threats to impartiality are eliminated or minimized and that any residual risk is acceptable.
  • Conflict of Interest Management: All personnel, including employees and contractors, are required to disclose any potential conflicts of interest. We proactively identify, assess, and mitigate risks to impartiality through structured oversight, per-engagement conflict-of-interest screening before any engagement is accepted, and annual independence representations by all personnel.
  • No Consultancy or Internal Audit Services: Pease Bell CPAs does not provide management system consultancy or internal audit services to certified clients, nor do we certify any management system for which we have provided such services within the past two years. We do not outsource audits to management system consultancy organizations, our certification activities are not marketed or offered as linked with the activities of any consultancy, and personnel who have provided consultancy to a client do not participate in that client's certification activities for a minimum of two years.
  • Transparent Processes: This policy is published on our website, and impartiality-related feedback from clients, complainants, and other interested parties is welcome at any time through the contact below; all such feedback is reviewed as part of management review.
  • Continuous Improvement: Our impartiality policy and risk management approach are reviewed annually and updated as needed, based on internal audits, management review, and feedback received.

Reporting Concerns

If you have any concerns regarding impartiality or potential conflicts of interest in our certification activities, please contact us at [email protected]. All concerns are treated confidentially and investigated promptly.

Use of the Pease Bell Name & Certification Mark
Pease Bell CPAs ISO 27001 certification mark

This policy provides information to organizations certified by Pease Bell CPAs regarding the authorized marketing, public announcement, and use of our name and certification mark ("the Mark"). These requirements are part of the legally enforceable certification agreement. Pease Bell CPAs reserves the right to take corrective or legal action for any breach of these terms.

Authorized Use

  • The Mark may only be used by clients with a valid, active certification and only in reference to the certified management system and scope.
  • The Mark must not be used on products, product packaging, laboratory test, calibration, or inspection reports, or in any way that could imply product, process, or service certification.
  • The Mark may not be modified in any way, including form, font, or color.

Accurate Representation

  • All references to certification must include:
    • Identification (e.g., brand or name) of the certified client,
    • The type of management system and applicable standard (e.g., ISO 27001 – Information Security Management System),
    • The certification body (Pease Bell CPAs) issuing the certificate.
  • References must accurately reflect the scope and validity of certification and must not imply certification of activities, sites, products, or services outside the certified scope.
  • The Mark may only be used during periods of active certification.

Prohibited Use

  • Clients must not make or permit any misleading statements regarding their certification.
  • The certification document, mark, or any part thereof must not be used in a misleading or deceptive manner.
  • Certification must not be referenced in a way that brings Pease Bell CPAs or the certification system into disrepute or causes loss of public trust.

Changes in Certification Status

  • Upon suspension or withdrawal of certification, clients must immediately discontinue use of the Mark and all advertising or public references to certification.
  • If the scope of certification is reduced, all relevant advertising and references must be amended accordingly.
  • The Mark is not eligible for use in connection with any product or service not within the certified scope.

Enforcement

  • Pease Bell CPAs exercises proper control over the use of its name, certification mark, and logo. Actions for misuse include correction, suspension, withdrawal of certification, publication of transgression, and, if necessary, legal action.

Contact and Further Information

For questions regarding the use of Pease Bell CPAs' name, certification mark, or logo, or to request our detailed usage guidelines, please contact us at [email protected].

Complaints & Appeals

Pease Bell CPAs is committed to transparency, impartiality, and continual improvement in all certification activities. We welcome feedback and provide clear processes for handling information requests, complaints, and appeals.

Information Requests

Clients and interested parties may request information about our certification services, processes, or the status of certifications.

  • Requests can be submitted by emailing [email protected]
  • We aim to acknowledge all requests within 5 business days and provide a response as promptly as possible.

Complaints

If you have concerns about our certification services, audit process, or the conduct of Pease Bell CPAs personnel, you may submit a complaint.

  • Complaints may be submitted by emailing [email protected]
  • All complaints are treated confidentially and impartially.
  • We acknowledge receipt of complaints within 5 business days and investigate according to our published procedure.
  • Complainants will be informed of the outcome and any corrective actions taken.

Appeals

If you disagree with a certification decision or audit finding, you may file an appeal.

  • Appeals must be submitted by emailing [email protected] and the email should include relevant details and supporting documentation.
  • Appeals are reviewed by personnel independent of the original decision-makers.
  • We acknowledge appeals within 5 business days and communicate progress and final decisions to the appellant.
  • Submission of an appeal will not result in any discriminatory action.

Commitment to Fairness

All complaints and appeals are handled impartially, confidentially, and in accordance with ISO/IEC 17021-1:2015. We strive to resolve all matters promptly and fairly, and to continually improve our processes based on feedback.

To submit a request, complaint, or appeal, please contact us at [email protected].

Information Requests & Certificate Validation

Inquiries may be submitted directly to Pease Bell CPAs, including areas where we operate, certificate status, and information for our certified clients by emailing [email protected].

Contact

For questions about the Pease Bell ISO certification program, including certificate validity, complaints, appeals, or information requests: [email protected]