Skip to main content
Category: Governance and Roles

Accreditation Assessor

Also known as: Assessor, Accreditation Body Assessor
Simply put

An accreditation assessor is a subject-matter expert who evaluates organizations that want to be accredited to perform certification, testing, or inspection work. They review whether these organizations have the competence and processes needed to meet the requirements of a specific accreditation program. Their assessment helps the accreditation body decide whether to grant or maintain accreditation.

Formal definition

An accreditation assessor is an individual engaged by an accreditation body (such as ANAB or NVLAP) to conduct assessment activities against the requirements of a defined accreditation program, evaluating applicant and accredited conformity assessment bodies. Depending on the program and scope, assessors evaluate technical competence for specific areas of a desired scope of accreditation, as well as conformance to applicable management and program requirements. The assessor's role is distinct from that of an auditor performing a SOC 2 examination or a certification body auditor issuing an ISO/IEC 27001 certificate; accreditation assessment operates at the level of assessing the competence of the conformity assessment bodies themselves rather than certifying end-user organizations, and the precise qualification, training, and scope requirements vary by accreditation body and program.

Why it matters

Accreditation assessors sit at a level of the conformity assessment chain that most end-user organizations never interact with directly, yet their work underpins the credibility of the certifications and reports those organizations rely on. When a company receives an ISO/IEC 27001 certificate from a certification body, or engages a laboratory for testing, the trustworthiness of that outcome depends in part on whether the certifying or testing organization has itself been evaluated for competence and process conformance. Accreditation assessors perform that upstream evaluation, assessing whether conformity assessment bodies have the technical competence and processes to do what they claim.

Who it's relevant to

GRC and compliance managers
For professionals relying on ISO/IEC 27001 certificates or SOC 2 reports, understanding the accreditation assessor's role clarifies where trust in a certification originates. Accreditation assessment operates at the level of the conformity assessment bodies themselves, not the end-user organizations, which helps explain the distinction between being certified and being accredited to certify.
Certification and testing bodies
Organizations seeking or maintaining accreditation to perform certification, testing, or inspection work are the direct subjects of accreditation assessment. Their technical competence and conformance to management and program requirements are what the assessor evaluates, informing the accreditation body's decision to grant or maintain accreditation.
Subject-matter experts and prospective assessors
Technical experts considering assessor roles, such as those responding to openings for ANAB accreditation programs, should note that qualification, training, and scope requirements vary by accreditation body and program. An assessor's function is distinct from that of a SOC 2 examiner or an ISO/IEC 27001 certification body auditor, as it focuses on evaluating the competence of conformity assessment bodies rather than certifying end-user organizations.

Inside Accreditation Assessor

Accreditation Body
The organization that assesses and formally recognizes certification bodies as competent to issue certifications, such as ISO/IEC 27001 certificates. Accreditation operates a level above certification: the accreditation body evaluates the certification body, which in turn audits the client organization's ISMS.
Certification Body Assessment
The evaluation activity in which an accreditation body examines a certification body's competence, impartiality, and conformity with the relevant accreditation standards governing bodies that certify management systems. This assessment underpins the credibility of the certificates the body issues.
Scope of Recognition
The defined range of standards and sectors for which a certification body is accredited. An accreditation assessor's findings determine the boundaries within which a certification body may issue accredited certificates; recognition typically applies only within that defined scope.
Relationship to ISO 27001 Certification
For an ISO/IEC 27001 certificate to carry accredited status, it should be issued by a certification body that has been assessed and accredited. This differs from SOC 2, which is an attestation examination performed by a licensed CPA firm under AICPA SSAE 18 and does not involve an accreditation body in the same manner.

Common questions

Answers to the questions practitioners most commonly ask about Accreditation Assessor.

Is an accreditation assessor the same as the auditor who evaluates my organization for ISO 27001 or SOC 2?
No. An accreditation assessor evaluates the certification body or CPA firm itself, not your organization. In the ISO context, accreditation bodies assess whether a certification body is competent to issue ISO/IEC 27001 certificates against the applicable requirements. Your organization interacts with the certification body's auditors, not with the accreditation assessor. Because scope and terminology differ between the ISO certification pathway and the SOC 2 attestation pathway, it is worth noting that SOC 2 examinations are performed by licensed CPA firms under the AICPA framework and are overseen through professional peer review mechanisms rather than through the same accreditation-body model used for ISO certification bodies.
Does a favorable accreditation assessment of my certification body mean my own certificate or report is guaranteed to be valid or breach-proof?
No. Accreditation assessment addresses the competence and impartiality of the certification body or firm, not the quality or outcome of any individual engagement with your organization. An ISO 27001 certificate covers only the defined scope of your ISMS, and a SOC 2 report attests only to the controls and period covered; neither guarantees freedom from breaches. Accreditation supports confidence in the body issuing the credential, but it does not substitute for your organization's own controls, scope decisions, or ongoing operation of the management system.
How does the accreditation status of a certification body affect our choice of provider for ISO 27001?
In most engagements, organizations select an accredited certification body so that the resulting ISO/IEC 27001 certificate carries recognized standing. Accreditation typically signals that the body has been assessed as competent and impartial to certify against the standard. Depending on your market and stakeholder expectations, an accredited certificate may be preferred or required, so confirming a body's accreditation scope for information security management systems is a common step during provider selection.
What should we prepare for when a certification body is undergoing its own accreditation assessment?
An accreditation assessor may observe the certification body's auditors during live client engagements as part of witnessing activities. In practice, this can mean an additional observer is present during your ISO 27001 audit, focused on how the auditors perform rather than on your organization directly. You would typically coordinate logistics and confidentiality expectations with your certification body in advance, but the substantive audit of your ISMS remains the responsibility of the certification body's audit team.
Does accreditation of the certification body change the scope or clauses we are audited against?
No. The requirements you are certified against remain the ISMS requirements in clauses 4 through 10, with Annex A reference controls selected through your Statement of Applicability and informed by your risk assessment. Accreditation assessment governs the competence of the certifying body, not the content of the standard applied to your organization. Your scope, control selection, and applicable version of the standard continue to be determined by your organization's decisions and the standard's requirements.
How does accreditation oversight differ between the ISO 27001 and SOC 2 pathways in practice?
The two pathways use different oversight models. ISO/IEC 27001 certificates are issued by certification bodies whose competence is assessed by accreditation bodies through mechanisms such as accreditation assessment and witnessing. SOC 2 is an attestation examination performed by a licensed CPA firm under the AICPA framework and is subject to professional oversight appropriate to that profession rather than to the same accreditation-body arrangement. Because the frameworks are structured differently, confirming a provider's standing means checking the relevant model for each: accreditation scope for an ISO certification body, and professional licensing and standing for a CPA firm performing a SOC 2 examination.

Common misconceptions

An accreditation assessor audits the client organization's ISMS directly.
In most arrangements, the accreditation assessor evaluates the certification body, not the end client. The certification body audits the client's ISMS; the accreditation body assesses the certification body's competence and impartiality one level up the chain.
Accreditation and certification are the same thing, and either would apply to a SOC 2 engagement.
Accreditation and certification are distinct: accreditation recognizes a certification body's competence, while certification is issued to a client against a standard such as ISO/IEC 27001. SOC 2 involves neither; it is an attestation examination producing a report under SSAE 18, not a certificate issued by an accredited body.
An accredited certificate guarantees the certified organization is free from security incidents.
Accreditation supports the credibility of the certification process, but an ISO 27001 certificate covers only the defined scope of the ISMS and the conditions assessed. It does not guarantee freedom from breaches, and its assurance is bounded by the scope for which the certification body is accredited.

Best practices

Verify that an ISO/IEC 27001 certificate was issued by an accredited certification body, and confirm the certification body's scope of recognition covers the relevant standard and sector.
Keep the layers distinct when evaluating assurance: distinguish the accreditation body, the certification body, and the client organization, and understand which one performed which assessment.
Check the defined scope of the ISMS certificate rather than assuming organization-wide coverage, since accredited certification typically applies only within the stated boundaries.
Do not treat SOC 2 outcomes as involving an accreditation assessor; recognize that SOC 2 is a CPA-performed attestation report under SSAE 18, distinct from accredited certification.
When comparing framework outcomes, avoid assuming that an accredited ISO 27001 certificate and a SOC 2 report are equivalent, as mapping between the frameworks is partial and satisfying one does not automatically satisfy the other.
Confirm the version and scope details of any accreditation-related claim before relying on it, and describe recognition boundaries qualitatively where specific figures or references cannot be stated with confidence.