Valid

GB/Z 27021.13-2025Conformity assessment - Requirements for bodies providing audit and certification of management systems - Part 13: Competence requirements for auditing and certification of compliance management systems (English PDF)

合格评定 管理体系审核认证机构要求 第13部分:合规管理体系审核与认证能力要求

Open the GB/Z 27021.13-2025 preview as PDF

Preview — first pages of GB/Z 27021.13-2025 (full document: 11 pages)

This is a limited preview

Buy now to download the full PDF (11 pages)

Issued by

SAMR; SAC

Level / Type

National · Recommended

Issue date

February 28, 2025

Implementation date

February 28, 2025

Scope

GB/Z 27021.13-2025 is the English-translated version of 合格评定 管理体系审核认证机构要求 第13部分:合规管理体系审核与认证能力要求.

GB/Z 27021.13-2025 is a national guiding technical document that fixes the specific competence requirements for the people who take part in auditing and certifying a compliance management system (CMS), supplementing the requirements already carried by ISO/IEC 17021-1. It is identical in content to ISO/IEC TS 17021-13:2021 and forms Part 13 of the GB/T 27021 series on requirements for bodies providing audit and certification of management systems. Clause 4 asks the certification body to determine the competence needed for each certification function described in Table A.1 of ISO/IEC 17021-1:2015 and to meet Clause 5 and Clause 6 of this document as well. Clause 5 addresses the audit team, covering the organizational context, laws and regulations and other requirements, compliance risk assessment and control, and knowledge of a CMS established and implemented in accordance with ISO 37301, including compliance culture, leadership, the compliance function, training, monitoring and reporting, raising concerns and investigating incidents. Clause 6 addresses the other personnel who review the application, select the team, set the audit time and take the certification decision. Annex A tabulates which knowledge each certification function needs. Terms follow ISO 37301 and ISO/IEC 17021-1.

Document preview — GB/Z 27021.13-2025

National Standard of the People's Republic of China

ICS
03.120.20
Classification
A 00

Issued by: State Administration for Market Regulation; Standardization Administration of the PRC

Contents

  • 1 Scope1
  • 2 Normative references1
  • 3 Terms and definitions1
  • 4 General competence requirements1
  • 5 Competence requirements for the compliance management system (CMS) audit team1
  • 5.1 Overall requirements1
  • 5.2 Organizational context2
  • 5.3 Laws, regulations and other requirements2
  • 5.4 Compliance risk assessment and control2
  • 5.5 Compliance management system (CMS)2
  • 6 Competence requirements for other personnel2
  • 6.1 Overall requirements2
  • 6.2 Organizational context3
  • Annex A (informative) Knowledge for CMS audit and certification4
  • Bibliography5

1 Scope

The document sets out the specific competence requirements for personnel taking part in the audit and certification of a compliance management system (CMS), and supplements the requirements already given in ISO/IEC 17021-1.

2 Normative references

Two documents are cited as indispensable through normative reference in the text; for dated references only the edition cited applies, and for undated references the latest edition, including all amendments, applies.

ISO/IEC 17021-1:2015 Conformity assessment—Requirements for bodies providing audit and certification of management systems—Part 1: Requirements. A note records the corresponding Chinese document GB/T 27021.1-2017 (ISO/IEC 17021-1:2015, IDT).

ISO 37301:2021 Compliance management systems—Requirements with guidance for use. A note records the corresponding Chinese document GB/T 35770-2022 (ISO 37301:2021, IDT).

3 Terms and definitions

The terms and definitions given in ISO 37301 and in ISO/IEC 17021-1 apply to this document.

4 General competence requirements

The certification body is to determine the competence requirements for each certification function described in Table A.1 of ISO/IEC 17021-1:2015. When determining those competence requirements, the certification body is to meet all the requirements of ISO/IEC 17021-1 together with the requirements given in Clause 5 and Clause 6 of this document.

Note 1 points to Annex A, which outlines the personnel competence requirements for the individual certification functions. Note 2 points to ISO 19011 for information on the principles of auditing.

5 Competence requirements for the CMS audit team

5.1.1 Every member of the audit team is to hold a defined level of competence, including the general competence described in ISO/IEC 17021-1, an understanding of the requirements of ISO 37301 and of how those requirements relate to one another, and the related knowledge described in 5.2 to 5.5.

5.1.2 The competence requirements laid down in 5.2 to 5.5 apply to the scope of the CMS to be audited. A note adds that the members of the audit team need not each hold the same competence, but that the competence of the team as a whole has to be enough to meet the objectives of the audit.

5.2.1 The audit team is to be able to understand the business activities and processes connected with the organization's compliance obligations and compliance risks.

5.2.2 The audit team is to hold the knowledge and skills needed to carry out research related to the organization, so as to identify and understand the applicable compliance obligations and compliance risks.

5.3.1 The audit team is to hold relevant knowledge and to understand different legal systems, laws and regulations, and is to hold the knowledge and skills needed to understand the various types of legal text and how they bear on the organization's compliance obligations.

5.3.2 The audit team is to hold knowledge of the legal framework applicable to the operation of the organization, and to understand the compliance obligations and compliance risks applicable within the scope of the CMS to be audited.

5.3.3 The audit team is to hold knowledge of other applicable requirements, so as to be able to understand how those requirements relate to the compliance obligations and compliance risks within the scope of the CMS to be audited. A note lists, as examples of other applicable requirements, directives, licence agreements, voluntary codes, standards of the organization and of the sector, contractual relationships, codes of practice and agreements with community groups or non-governmental organizations.

5.4.1 The audit team is to hold knowledge of the compliance risk assessment described in 4.6 of ISO 37301:2021.

5.4.2 The audit team is to hold and understand knowledge of the methods for assessing and treating compliance risks.

5.4.3 The audit team is to hold and understand knowledge of the evaluation of compliance controls.

5.5.1 The audit team is to hold and understand knowledge of establishing and implementing a CMS in accordance with ISO 37301.

5.5.2 The audit team is to hold at least the following knowledge related to the CMS: a) the drivers and indicators of a compliance culture; b) the leadership role that makes the CMS effective; c) the roles and responsibilities of the compliance function; d) compliance training; e) the processes for monitoring, measuring and reporting compliance performance; f) the mechanism for raising concerns and the process for resolving them; g) the process for investigating non-compliance incidents.

6 Competence requirements for other personnel

6.1 Other personnel are the persons who carry out the application review that determines the competence needed in the audit team, who select the members of the audit team and determine the audit time, and who review the audit report and take the certification decision. They are to hold the general competence described in ISO/IEC 17021-1, to understand the requirements of ISO 37301 and how those requirements relate to one another, and to hold the CMS knowledge described in 6.2.

6.2 Other personnel are to hold knowledge related to the operating context of the organization and are to understand the business activities and processes connected with the organization's compliance obligations within the scope of the CMS to be audited.

Annex A Knowledge for CMS audit and certification (informative)

Table A.1 outlines the knowledge needed for CMS audit and certification and shows the range of knowledge needed for each certification function; the competence requirements for each function are set out in Clause 4, Clause 5 and Clause 6.

The table carries one column for the knowledge area and three columns for the certification functions: carrying out the application review to determine the competence needed in the audit team, selecting the team members and determining the audit time; reviewing the audit report and taking the certification decision; and the audit team itself. Five knowledge areas appear as rows: overall requirements; organizational context; laws, regulations and other requirements; compliance risk assessment and control; and the compliance management system (CMS). The first two rows carry a cross-reference for all three functions; the last three rows carry a cross-reference only in the audit team column and a dash in the other two.

......
This preview omits tables, figures, formulas and parts of the technical clauses. The complete document — 11 pages — is available in the English PDF.

Referenced standards

Normative references

ISO/IEC 17021-1:2015 Conformity assessment—Requirements for bodies providing audit and certification of management systems—Part 1: Requirements. A note records the corresponding Chinese document GB/T 27021.1-2017 (ISO/IEC 17021-1:2015, IDT). · ISO 37301:2021 Compliance management systems—Requirements with guidance for use. A note records the corresponding Chinese document GB/T 35770-2022 (ISO 37301:2021, IDT).

How to Buy GB/Z 27021.13-2025

  1. 1Add to cart. Click the "Buy GB/Z 27021.13-2025" button on this page. You can add more standards before checkout.
  2. 2Checkout. Enter your email and billing details. Payment is processed securely by Stripe (cards, Apple Pay, Google Pay supported).
  3. 3Instant delivery (0–9 sec). Delivery is automatic: within seconds of payment you'll receive an email with a secure download link. The link stays valid for 72 hours.
  4. 4Invoice included. A tax invoice is attached to the confirmation email. Need a custom invoice? Contact us.

Related Standards

English PDF
11 pages
Instant delivery (0–9 sec)
Invoice included
View Cart

Secure payment via Stripe

Payments accepted

VisaMastercardAmerican ExpressApple PayGoogle PayStripe

GB/Z 27021.13-2025

$180.00

$155.00for partners