Confidentiality Management

Home > Confidentiality Management

Confidentiality Management Procedure

Protecting Client Information with Integrity

ICV is committed to maintaining the highest standards of confidentiality for all client information obtained during audit and certification activities. Our documented procedure ensures that sensitive data is protected through legally enforceable agreements, secure storage, controlled access, and strict disclosure protocols — in full compliance with ISO 17021-1:2015 requirements.

  • 1.0 Purpose

    To lay down documented guidelines for management of client's confidentiality.

  • 2.0 Scope

    This procedure is applicable to all categories of clients who have signed a contract for audit and certification with ICV.

  • 3.0 Authority

    The CEO of the CB/CAB is authorized to approve this SOP, while the MR is authorized to issue its controlled copies. The SOP can be amended only by the CEO of the CB.

  • 4.0 Responsibility

    Primary: All staff members directly involved in the certification process. Secondary: All staff members of the Certification Body.

5.0 Procedure

Our confidentiality management procedure covers agreements, information handling, controlled disclosure, secure storage, and personnel obligations — ensuring complete protection of client data throughout the certification lifecycle.

  1. STEP-01

    Confidentiality Agreements


    To inspire trust in the certification body, ICV has established legally enforceable agreements with individuals, committees and external bodies (if any) and individuals working on its behalf, which binds them to maintain confidentiality of the information obtained or created during the performance of audit and certification activities.

    • Ref: Record of Confidentiality Agreements
  2. STEP-02

    Client Information Protection


    All client-related information, except that which has been made publicly accessible by the client, is treated as confidential. ICV has informed its clients in advance about the type of their information that the CB intends to place in the public domain.

    • Ref: Contract Form for Clients (ICV/F/04)
  3. STEP-03

    Disclosure to Interested Parties


    Confidential information required to be made available to interested parties (e.g. legal or regulatory authorities) under ISO 17021-1:2015 standard, is disclosed on the basis of the certification contract signed by the client.

    • Ref: Client's Contract Form
  4. STEP-04

    Disclosure to Government Authorities


    Confidential information of the client required to be disclosed to government authorities as per their written request, is disclosed to them, and the client is informed about the information shared with legal authorities, unless prohibited by law.

    • Ref: Record of Govt. Requests for Information and Its Reply
  5. STEP-05

    Client Consent Required


    Confidential information of clients other than those described in para 5.3 and para 5.4, is not disclosed to anyone without getting written consent or permission from the client.

  6. STEP-06

    Third-Party Information


    Information about the client received from sources other than the client (e.g. complainant, regulators) is treated as confidential. Record of such information and of subsequent action, if any, is retained in the client's audit file.

    • Ref: Client File
  7. STEP-07

    Personnel Obligations


    ICV has made its personnel, including any committee members, contractors, personnel of external bodies or individuals acting on the certification body's behalf, legally bound to keep confidential all information obtained or created during the performance of the certification body's activities.

    • Ref: Agreement / Declaration of Confidentiality
  8. STEP-08

    Physical Record Security


    ICV has made provisions to secure and preserve hard records of confidential information of the clients. Hard files are kept in lockable almirahs and cupboards, accessible only to the CEO, Technical Director and the Operations Manager.

  9. STEP-09

    Electronic Data Protection


    Confidential information in electronic data files is kept password protected, accessible only to the CEO, Technical Director and Operations Manager.

  10. STEP-10

    Regulatory Body Sharing


    ICV takes prior permission from its clients as per its audit and certification contract signed by the client, regarding possible sharing of their confidential information contained in audit reports or files, with certification-related regulatory bodies, if any.

    • Ref: Client's Contract Form

Records & References

The following records are maintained to demonstrate compliance with confidentiality requirements:

  • Record of Confidentiality Agreements / Declarations
  • Record of Requests Seeking Client's Information and Subsequent Action
  • Client File

Refer: Cl. 8.5 of ISO 17021-1:2015  |  Section 8.5 of the ICV Manual

Get In Touch With Our Team