In 2006, the ISO committee for conformity assessment (CASCO) developed ISO/IEC 17021, which sets out
requirements for third party certification of management systems and which was based in part on the guidelines
contained in the first edition of this International Standard.
The second edition of ISO/IEC 17021, published in 2011, was extended to transform the guidance offered in
this International Standard into requirements for management system certification audits. It is in this context
that this second edition of this International Standard provides guidance for all users, including small and
medium-sized organizations, and concentrates on what are commonly termed “internal audits” (first party)
and “audits conducted by customers on their suppliers” (second party). While those involved in management
system certification audits follow the requirements of ISO/IEC 17021:2011, they might also find the guidance in
this International Standard useful.