BS ISO 28003 is the standard that contains principles and requirements for bodies providing the audit and certification of supply chain security management systems according to management system specifications and standards such as BS ISO 28000.
It defines the minimum requirements of a certification body and its associated auditors, recognizing the unique need for confidentiality when auditing and certifying/registering a client organization.
Requirements for supply chain security management systems can originate from a number of sources, and BS ISO 28003 was developed to assist in the certification of supply chain security management systems that fulfil the requirements of BS ISO 28000 Specification for security management systems for the supply chain, and other supply chain security management system standards.
BS ISO 28003 may also be used to support certification of supply chain security management systems that are based on other specified supply chain security management system requirements.
Certification of a supply chain security management system is sometimes also called registration, and certification bodies are sometimes called registrars.
A certification body can be nongovernmental or governmental (with or without regulatory authority). BS ISO 28003 can be used as a criteria document for accreditation or peer assessment or other audit processes.
BS ISO 28003 is intended for use by bodies that carry out audit and certification of supply chain security management systems. Certification of supply chain security management systems is a third party conformity assessment activity. Bodies performing this activity are therefore third party conformity assessment bodies, named 'certification body/bodies' in this BS ISO 28003. This wording should not be an obstacle to the use of BS ISO 28003 by bodies with other designations that undertake activities covered by the scope of BS ISO 28003. Indeed, this International Standard will be usable by any body involved in the assessment of supply chain security management systems.
Certification of supply chain security management systems of an organization is one means of providing assurance that the organization has implemented a system for supply chain security management in line with its policy.
Certification of supply chain security management systems will be delivered by certification bodies accredited by a recognized body, such as International Accreditation Forum (IAF) members.
BS ISO 28003 specifies requirements for certification bodies. Observance of these requirements is intended to ensure that certification bodies operate supply chain security management systems certification in a competent, consistent and reliable manner, thereby facilitating the recognition of such bodies and the acceptance of their certifications on a national and international basis. This International Standard will serve as a foundation for facilitating the recognition of supply chain security management systems certification in the interests of international trade.
Certification of a supply chain security management system provides independent verification that the supply chain security management system of the organization
Certification of a supply chain security management system thereby provides value to the organization, its customers and interested parties.
BS ISO 28003 aims at being the basis for recognition of the competence of certification bodies in their provision of supply chain security management system certification.
BS ISO 28003 can be used as the basis for recognition of the competence of certification bodies in their provision of supply chain security management system certification (such recognition may be in the form of notification, peer assessment, or direct recognition by regulatory authorities or industry consortia).
Observance of the requirements in BS ISO 28003 is intended to ensure that certification bodies operate supply chain security management system certification in a competent, consistent and reliable manner, thereby facilitating the recognition of such bodies and the acceptance of their certifications on a national and international basis. BS ISO 28003 will serve as a foundation for facilitating the recognition of supply chain security management system certification in the interests of international trade.
Certification activities involve the audit of an organization's supply chain security management system. The form of attestation of conformity of an organization's supply chain security management system to a specific standard (for example ISO 28000) or other specified requirements is normally a certification document or a certificate.
It is for the organization being certified to develop its own supply chain security management systems (including ISO 28000 supply chain security management system, other sets of specified supply chain security management system requirements, quality systems, environmental supply chain security management systems or occupational health and safety supply chain security management systems) and, other than where relevant legislative requirements specify to the contrary, it is for the organization to decide how the various components of these are to be arranged.
The degree of integration between the various supply chain security management system components will vary from organization to organization. It is therefore appropriate for certification bodies that operate in accordance with this International Standard to take into account the culture and practices of their clients in respect of the integration of their supply chain security management system within the wider organization.
ISO 28003:2007