FAQ Section

How many certification bodies in China? What are the "agencies" in China?

What is the difference between ISO 9001, ISO9002 and ISO 9003? Is ISO 9001 better than ISO 9003?

How to choose a suitable certification body?

How accreditation bodies affect my choice of certification body?

Is longer surveillance audit interval save more cost?

What is ISO 27001? Is it only apply to IT industry?


How many certification bodies in China? What are the "agencies" in China?

In China, there are over 50 certification bodies. Among the 50 certification bodies, around 20 certification bodies are operated by the Chinese Government Bodies while others are mainly organizations based in US and Europe.

The "agencies" are operated as a coordinator between the clients and the certification bodies and sometimes may provide auditor support to certification bodies. However, they are ineligible to issue certificates under their names.

[back]

    

What is the difference between ISO 9001, ISO9002 and ISO 9003? Is ISO 9001 better than ISO 9003?

ISO 9001

For companies involved in Design/Development, Production, Installation and Servicing.

ISO 9002

For companies involved in Production, Installation and Servicing.

ISO 9003 For companies involved in Final Inspection and Testing of Products and Services

Three standards are established for companies with different nature and it cannot be said that which standard is better. Organizations should choose the standard which match their scope to be certified.

However, in ISO 9001:2000, the three standards will be integrated. After the official publication of ISO 9001:2000, ISO 9002 and ISO 9003 will no longer exist. For organizations certified for ISO 9001/9002/9003:1994, they have to transit to the new version within the grace period.

[back]

    

How to choose a suitable certification body?

When choosing the certification body, it is recommended to consider the following factors:

Market Recognition
Choosing the certification body which is well-known to your customers or in the industry will be more practical.

Frequency of surveillance audit
More frequent the surveillance audit may serve as a mechanism to monitor the operation of the system. However, organizations should choose the appropriate frequency of surveillance audit that matches their necessity.

Certification fee and the certificate maintenance fee
Certification fee is the fee paid for the first successful audit.
Certification maintenance fee is the fee paid for successful surveillance audit. Therefore, it is highly recommended to calculate the total of the certification fee and the certification maintenance fee to compare the prices offered by different certification bodies.

[back]

    

How accreditation bodies affect my choice of certification body?

In different countries, there are different accreditation bodies. For example, if a company usually export the products to US, choosing the certification body which is accredited by RAB is more appropriate. That is, it is recommended to choose the certification body which is accredited by the countries that your business partners are from.

[back]

    

Is longer surveillance audit interval save more cost?

It is uncertain.

Longer surveillance audit usually charges more man days. Therefore, it is recommended to consider the total cost:

[Number of man days required x Cost per man day] + Administration Cost = Total Cost

Since different certification bodies require different man days for same surveillance audit period, also, the administration fee(e.g. annual fee, certification fee) are usually different, comparing the total cost will be more practical.

[back]

    

What is ISO 27001? Is it only apply to IT industry?

ISO 27001 is the specification for Information Security Management. It can be regarded as a code of practice for information security.

Although it sounds like a system only for IT industry, ISO 27001 can be applied to all industries because Confidentiality, integrity and availability of information are vital to maintain competitive edge, cash-flow, profitability, legal compliance and corporate image. ISO 27001 can thus be served as the basis for contractual relationship and the basis for 3rd party certification.

Moreover, ISO 27001 is a system certification rather than product certification. Also, instead of targeting to refine the technical aspect (e.g. building firewall), ISO 27001 focus much on establishing a Management Framework.

We have more details for the system and are ready to discuss your concerns, please feel free to contact us.

[back]