Confidentiality

At Business Systems Certification (BSC), we recognize that the certification and auditing process requires access to sensitive proprietary information, operational records, and strategic business data.

BCert is responsible for ensuring confidentiality is maintained by its employees, auditors and technical specialists relevant to any information with which they become acquainted as a result of their contact with clients involved in the certification process. Each employee, auditor and technical specialist is required to sign and conform to a Confidentiality Agreement which assures the confidentiality of client information at all times.

In strict compliance with international accreditation standards—specifically ISO/IEC 17021-1—we maintain enforceable policies and operational controls to guarantee that all proprietary information obtained or created during the performance of certification activities remains strictly confidential.

PrincipleOperational Implementation
Legally Enforceable CommitmentsEvery personnel member, including permanent staff, contracted technical experts, external auditors, and committee members, signs a legally binding Non-Disclosure Agreement (NDA) prior to assignment.
Controlled Information ScopeExcept for information made publicly accessible by the client, all data obtained during audits, technical reviews, application handling, and surveillance activities is treated as proprietary and confidential.
Third-Party ProtectionInformation about an applicant or certified client gained from sources other than the client (e.g., complainants, regulators, or market feedback) is treated as strictly confidential between the certification body and the source.
Secure Digital InfrastructureClient audit reports, working papers, and evidence files are stored in access-controlled, encrypted digital repositories with role-based permissions and activity logging.