ISO/IEC 17020 Audit Preparation for Inspection Companies
A ISO/IEC 17020 audit runs in 6 stages, beginning with gap analysis against iso/iec 17020 and the accreditation body's own requirement documents,.. Developed by the ISO Committee on Conformity Assessment (CASCO) in collaboration with CEN/CLC/JTC 1. Enforced by accreditation bodies — in the United States by ANAB (which runs a dedicated NDE inspection body programme), A2LA (which covers NDT under both ISO/IEC 17020 and ISO/IEC 17025), IAS and PJLA.
ISO/IEC 17020 contains requirements for the competence and impartiality of bodies performing inspection and for the consistent operation of their inspection activities. The third edition, ISO/IEC 17020:2026, was published in March 2026 and cancels and replaces the 2012 second edition. The headline change for an inspection firm is that the categorisation of independence collapses from types A, B and C to type A and type non-A, with the independence requirements sitting in normative Annex A and impartiality requirements applying equally to both types. The edition also adds definitions of item and client, adds a subclause on control of data and information and on actions to address risks and opportunities, incorporates the common CASCO elements, and replaces some prescriptive requirements with performance-based ones. What separates firms that clear an audit from firms that collect findings is not the quality of the documentation but whether it describes what actually happens.
Source: ISO/IEC 17020:2026 itself, read from the ISO-published preview: title page (third edition, 2026-03), Foreword (prepared by CASCO with CEN/CLC/JTC 1; cancels and replaces the second edition ISO/IEC 17020:2012; the listed main changes including type A / type non-A, the new item and client definitions, the new subclause on control of data and information and on actions to address risks and opportunities, the CASCO common elements, risk-based thinking and greater flexibility), Introduction (type A and type non-A reflect the level of independence; impartiality requirements apply equally to both), Clause 1 Scope, Clause 2 normative reference to ISO/IEC 17000:2020, Clause 3 definitions 3.1–3.8, Clause 4.1 and 4.2 verbatim, and the full table of contents including normative Annex A on independence requirements. Publication date: the standard's own title page gives 2026-03; European Accreditation states 31 March 2026 while ANAB's blog and UKAS's technical bulletin work from 27 March 2026 — the month is certain, the day is not, so treat 'March 2026' as the verified figure. Transition: three years from publication per an ILAC General Assembly resolution, with UKAS and ANAB citing 27 March 2029. Global ACI: ILAC's and IAF's own sites confirm Global Accreditation Cooperation Incorporated was registered as an Incorporated Society on 6 December 2024 and functions as a complete entity from 1 January 2026, with the ILAC MRA Mark transferred and the IAF MLA Mark licensed to it. A2LA R212, Specific Requirements — Nondestructive Testing Laboratory Accreditation Program, publication date 10 September 2025, read in full: general criteria are ISO/IEC 17025 for testing laboratories and ISO/IEC 17020 for inspection bodies; the nine technologies in scope; scope breakdown conventions. ANAB's NDE inspection body programme page (anab.ansi.org/accreditation/nde). IAS inspection agency accreditation to ISO/IEC 17020 (iasonline.org). Checked August 2026.
| Stage | What happens | What it tests |
|---|---|---|
| Stage 1 | Gap analysis against ISO/IEC 17020 and the accreditation body's own requirement documents, then application with a proposed scope — A2LA. | Where the paperwork is tested against itself |
| Stage 2 | Document review of the management system by the assessor, with clarifications and required changes identified and documented before the on-site. | Where the paperwork is tested against practice |
| Stage 3 | On-site assessment covering the management system plus witnessed inspections — the assessor observes real inspections against the written procedures, in. | Where the paperwork is tested against practice |
| Stage 4 | Nonconformity response and corrective action inside the accreditation body's window, with root cause and objective evidence of implementation | Where the paperwork is tested against practice |
| Stage 5 | Accreditation decision and issue of the scope of accreditation, with methods broken down to the most descriptive definition supportable and,. | Where the paperwork is tested against practice |
| Stage 6 | Surveillance and reassessment on the accreditation body's cycle, plus transition to ISO/IEC 17020:2026 within the three-year window that accreditation bodies. | Where the paperwork is tested against practice |
| Renewal | ISO/IEC 17020 sets no accreditation interval of its own — the accreditation body's cycle governs, with surveillance assessments between reassessments. What is fixed is the edition deadline. Accreditation bodies have announced a three-year transition from the publication of ISO/IEC 17020:2026, with UKAS and ANAB citing 27 March 2029 as the point after which only accreditation to the 2026 edition is recognised. Existing ISO/IEC 17020:2012-based accreditations remain valid until then, and the main work is re-justifying independence under the type A / type non-A model and evidencing ongoing impartiality risk monitoring. | Diarised from the certificate date, not the last audit |
How long does ISO/IEC 17020 audit preparation take?
Document work — the written practice, procedures and quality manual — takes weeks. What cannot be compressed is documented experience and records history: on-the-job hours accrue in real time, and calibration and certification history cannot be back-filled. Firms that start when the audit is scheduled rather than announced clear it without findings.
What does Developed by the ISO Committee on Conformity Assessment (CASCO) in collaboration with CEN/CLC/JTC 1. Enforced by accreditation bodies — in the United States by ANAB (which runs a dedicated NDE inspection body programme), A2LA (which covers NDT under both ISO/IEC 17020 and ISO/IEC 17025), IAS and PJLA. Since 1 January 2026 those bodies operate under the Global Accreditation Cooperation Incorporated (Global ACI) MRA, which replaced the separate ILAC MRA and IAF MLA when ILAC and IAF were wound up. look at first?
Records, not manuals. A manual states intent; records show practice. The usual opening move is to take a completed job and trace it back to the technician's certification, the instrument's calibration, the approved procedure and the report — and see whether all four reconcile.
What are the most common ISO/IEC 17020 findings?
Independence type asserted without an Annex A justification that matches actual ownership, group companies and commercial relationships — the type A / type non-A change makes previously comfortable type B and C claims worth re-arguing, Impartiality threats identified once at implementation and never monitored on an ongoing basis, including the relationships of personnel (4.1.3), Inspector remuneration linked to inspection outcomes or pass rates, which 4.1.7 treats as a direct nonconformity, Confidentiality commitments not legally enforceable, or not extended to contractors and personnel of external bodies (4.2.4), or the client not informed in advance of information the body intends to make public (4.2.1). Almost all of them are evidence problems rather than capability problems: the work was done correctly and the proof was not kept, or was kept somewhere the firm could not retrieve during the audit.
Can a consultant attend the ISO/IEC 17020 audit?
Yes, and it changes the outcome. Someone who has sat through the same audit at other firms answers in the auditor's own terms, produces the right record without a search, and stops a clarification turning into a finding. The firm still owns every answer — the consultant does not speak for it.
What happens after a ISO/IEC 17020 finding?
A corrective action with a deadline, and evidence of closure at the next audit. Repeat findings are treated far more seriously than first ones, because they show the corrective-action system itself is not working.
Does ISO/IEC 17020 require a pre-audit or gap assessment?
Not as a requirement, but the arithmetic favours it: a gap assessment finds the same evidence problems the auditor would, without the finding attached, and while there is still time to fix them. Firms entering their first ISO/IEC 17020 audit blind typically collect findings that a sampling exercise would have caught.
What the auditor asks to see
- Management system documentation under Clause 8 — policies and responsibilities, documented information, records control
- Independence declaration and type A / type non-A justification against normative Annex A, supported by the actual ownership and commercial relationships
- Impartiality risk register with evidence of ongoing monitoring of activities and of personnel relationships (4.1.3), and top management commitment to impartiality (4.1.5)
- Legally enforceable confidentiality commitments extending to employees, contractors, committee members and anyone acting on the body's behalf (4.2.1, 4.2.4)
- Legal entity evidence and arrangements covering liabilities arising from operations (5.2)
- Personnel competence criteria, authorisation records, training and ongoing monitoring records (6.1)
- Facilities and equipment records including calibration and traceability (6.2), and control of externally provided products and services including subcontracted NDT (6.3)
- Inspection methods and procedures, inspection records, and inspection reports or inspection certificates (7.2, 7.4, 7.6)
- Contract review records and control of data and information (7.1, 7.5)
- Appeals and complaints registers, internal audit records, management review records and corrective action records (7.7, 7.8, 8.5, 8.6, 8.7)
Findings to close before the audit
- Independence type asserted without an Annex A justification that matches actual ownership, group companies and commercial relationships — the type A / type non-A change makes previously comfortable type B and C claims worth re-arguing
- Impartiality threats identified once at implementation and never monitored on an ongoing basis, including the relationships of personnel (4.1.3)
- Inspector remuneration linked to inspection outcomes or pass rates, which 4.1.7 treats as a direct nonconformity
- Confidentiality commitments not legally enforceable, or not extended to contractors and personnel of external bodies (4.2.4), or the client not informed in advance of information the body intends to make public (4.2.1)
- Witnessed inspection deviates from the written procedure — what the technician actually does and what the controlled document says disagree
- Competence criteria stated only as a certification level with no evidence of authorisation and ongoing monitoring of each inspector (6.1)
- Subcontracted NDT or subcontracted calibration not controlled as an externally provided service (6.3)
- Appeals and complaints handled by the same person who made the original conformity decision, or not recorded at all (7.7, 7.8)
- Inspection reports missing required identification, dates or traceability to the item inspected and the method actually used (7.6)
Related: the ISO/IEC 17020 overview, outsourced ASNT Level III cover, written practice development, NDT procedure development, a programme gap assessment, interim Level III cover.