Public accountability and corrective action

Complaints and Concerns

Any person may raise a good-faith concern about ICEQC activities, standards integrity, a certified scope, public information or the use of an ICEQC certificate or mark.

A confidential and accessible complaint review meeting

Complaint jurisdiction and basis

A complaint concerns service, conduct, accessibility, confidentiality, impartiality, standards integrity, a certified object or another matter within the published complaint jurisdiction. An appeal is different: it challenges an eligible certification or procedural decision through the designated appeal process. A report of suspected certificate or mark misuse may be submitted through the misuse-reporting route.

A submission should identify the matter, relevant organisation or record, material facts, dates, supporting information, any urgent risk, requested confidentiality and the outcome sought. Anonymous information may be considered where it is sufficiently specific and credible, but anonymity can limit verification, procedural fairness and the ability to communicate an outcome.

Submitting a complaint does not establish a breach. ICEQC assesses jurisdiction and risk, appoints personnel with appropriate independence, obtains and tests relevant information, allows a materially affected party a fair opportunity to respond where appropriate, records the conclusion and implements proportionate action. Good-faith participation is protected against retaliation by ICEQC.

ICEQC-GOV-001 · Clause 34

Freedom to raise integrity concerns

A participant, employee, contractor, applicant, certified client, learner or other affected person shall be able to raise a good-faith concern about standards integrity, misleading certification identity, conflict of interest, procedural failure or misuse of authority through an accessible published route.

The route shall permit the person to explain the subject and supporting information without being required to characterize it correctly as a complaint, appeal, disclosure or technical comment before ICEQC determines the appropriate jurisdiction.

Confidentiality may be provided to the extent lawful and compatible with fair determination, but anonymity shall not be promised where disclosure is necessary to protect a person, answer an allegation or comply with law.

A concern shall not be rejected solely because it is critical, inconvenient, submitted in non-technical language or raised by a person without membership or commercial relationship.

The existence of the route does not validate every allegation, and any resulting adverse institutional or certification action shall be made only by the competent authority under the applicable due process.

ICEQC-GOV-001 · Clause 35

Protection against retaliation

No person shall suffer retaliation by ICEQC for making a good-faith standards comment, objection, complaint, appeal, integrity disclosure or request for correction, or for declining to support a proposed consensus.

Retaliation includes improper exclusion, threat, unfavorable certification treatment, disclosure intended to cause harm, withdrawal of an unrelated opportunity or pressure to abandon a legitimate concern.

This protection does not prevent proportionate action concerning abusive conduct, deliberate falsehood, unlawful disclosure, harassment or a conflict that genuinely affects participation, provided the action is based on the conduct and not the protected disagreement.

A person alleging retaliation shall have access to a review independent of the function concerned.

Where retaliation is substantiated, corrective action shall address both the individual effect and any systemic condition capable of discouraging future participation, while publication shall be limited to information necessary for accountability and lawful protection.

ICEQC-GOV-001 · Clause 50

Governance nonconformity and corrective action

A substantiated failure by ICEQC to follow a published governance requirement shall be treated as a governance nonconformity and shall not be hidden by reclassifying the affected act as informal or administrative.

ICEQC shall determine the nature, extent, cause and public effect of the failure; contain any continuing risk; correct affected records or actions where possible; and address the cause in proportion to recurrence and impact.

The remedy may include renewed review, restored participation opportunity, reconsultation, corrected publication, withdrawal, independent oversight or confirmation that the failure did not affect normative validity, with reasons.

Governance corrective action shall be separate from an applicant's certification finding and shall not be assigned to a certified client.

Public disclosure shall be sufficient to protect reliance and explain any change in status while respecting lawful confidentiality and the fairness of ongoing proceedings.

ICEQC-GOV-001 · Clause 51

Complaints about the standards system

Any person may submit a complaint concerning accessibility, conduct, conflict management, misleading communication, failure to consider a comment, misuse of identity or another aspect of the standards system.

ICEQC shall make the route, scope, expected stages, confidentiality approach and possible outcomes publicly understandable and shall direct a misclassified submission to the appropriate process where reasonably possible.

Complaint handling shall be impartial and shall give a person whose conduct is materially criticized a fair opportunity to respond before an adverse conclusion, subject to protective measures where risk requires.

The outcome shall state the issue, applicable rule, information considered, conclusion, reasons and any corrective or referral action.

A complaint does not automatically suspend a standard or certification, but the competent authority may impose a proportionate interim protection where continued reliance could cause material harm.

ICEQC-CER-001 · Clause 103

Access to complaint and appeal processes

ICEQC shall maintain accessible, documented and impartial processes for complaints and appeals.

The processes shall be available without discrimination and shall not require a person to waive a lawful right as a condition of access.

Information on how to submit a complaint or appeal, the required information and principal time controls shall be publicly available.

A person may request reasonable communication assistance where this is necessary to understand or use the process.

Use of a complaint or appeal process shall not result in retaliation, discriminatory treatment or an improper certification disadvantage.

ICEQC-CER-001 · Clause 104

Complaints concerning a certified client or object

ICEQC may receive a complaint concerning a certified client, certified object, certification claim or matter reasonably connected with continuing conformity.

ICEQC shall determine whether the complaint:

ICEQC shall not act as the ordinary complaint department of a certified client or decide private disputes outside the certification scope.

ICEQC may require the certified client to provide:

A single complaint may justify certification action where its nature or evidence indicates serious risk, integrity failure or possible systemic nonconformity.

Absence of multiple complaints shall not by itself establish conformity.

  • concerns a matter within the certified scope or certification obligations
  • contains sufficient information for meaningful review
  • presents a possible urgent risk
  • requires prior use of the certified client's own complaint process, unless that process is unavailable, inappropriate or likely to prejudice protection or evidence; and
  • requires surveillance, special review or another certification action
  • the relevant complaint record
  • the response and remedial action
  • evidence of investigation and communication
  • related incident, trend or governance information; and
  • evidence that affected persons were treated fairly and protected from retaliation

ICEQC-CER-001 · Clause 105

Complaints concerning ICEQC activities

A person may complain about an ICEQC service, conduct, delay, communication, assessor, reviewer, decision process, confidentiality matter, conflict concern or public record.

A complaint shall be handled by a person who was not the subject of the complaint and who is sufficiently independent of the activity concerned.

Where a complaint concerns a certification decision and seeks a different decision, ICEQC shall inform the complainant that the matter may constitute an appeal and shall apply the appropriate process.

A service complaint does not suspend a certification decision or time limit unless ICEQC expressly determines otherwise.

ICEQC shall identify and correct any confirmed process failure and shall consider whether the same failure may affect another case.

ICEQC-CER-001 · Clause 106

Complaint handling

ICEQC shall acknowledge receipt of a complaint within five business days.

ICEQC shall conduct an initial review normally within 10 business days to determine jurisdiction, urgency, required information, responsible handler and next action.

The complainant shall be informed where:

The complaint handler shall gather and verify information proportionate to the nature and potential consequence of the matter.

ICEQC shall target issue of a complaint outcome within 45 calendar days after receipt of sufficient information. Where this is not reasonably practicable, ICEQC shall explain the delay and provide a revised date.

The outcome shall state, as appropriate:

The certified client and complainant shall be informed of the outcome to the extent permitted by confidentiality, privacy, safety and procedural fairness requirements.

  • further information is required
  • the matter is outside ICEQC's role
  • the matter is referred to another ICEQC process
  • urgent protective action is taken; or
  • the expected completion time materially changes
  • the matter considered
  • the conclusion
  • action taken or required
  • any limitation on information that may be disclosed; and
  • any available review or escalation route

ICEQC-CER-001 · Clause 110

Confidentiality and protection in complaints and appeals

Complaint and appeal information shall be accessed only by persons who require it for authorized handling, review, action or oversight.

ICEQC shall protect the identity of a complainant where reasonably possible and requested, but shall not promise anonymity where disclosure is necessary for fairness, verification, safety or a lawful requirement.

A confidential or anonymous complaint may be considered where sufficient verifiable information is available.

ICEQC shall not disclose more information than is necessary to obtain a response, resolve the matter, protect affected persons or maintain certification integrity.

A person shall not be disadvantaged for making a complaint, giving evidence or using an appeal process in good faith.

Knowingly false or malicious information may be addressed as an integrity matter, but an unsubstantiated complaint is not, without more, a malicious complaint.

ICEQC-CER-001 · Clause 111

Complaint and appeal records and learning

ICEQC shall maintain controlled records of complaints and appeals, including:

ICEQC shall periodically analyse complaint and appeal information for recurring issues, inconsistency, delay, conflict risk and opportunities to improve scheme operation.

Systemic correction shall be assigned, monitored and verified for effectiveness.

Analysis shall preserve confidentiality and shall not convert complaint volume into a ranking of certified clients.

Information from complaints and appeals may inform surveillance and scheme review where its reliability and relevance are established.

  • receipt and acknowledgement
  • jurisdiction and risk triage
  • assigned personnel and independence checks
  • evidence and communications
  • analysis and outcome
  • action, correction and verification; and
  • time performance

ICEQC-CER-001 · Clause 124

Operational quality control

ICEQC shall maintain operational controls sufficient to ensure that certification activities are planned, performed, reviewed, decided, recorded and communicated in accordance with this document.

Controls shall address:

ICEQC shall perform planned internal evaluation of its certification operations and shall take corrective action where its own rules are not fulfilled.

A certification record affected by an internal process failure shall be reviewed to determine whether the finding, decision, scope, status or public information remains reliable.

Where reliability is affected, ICEQC shall correct the record and take any necessary client or public-protection action.

  • document and edition control
  • application and case completeness
  • competence and assignment authorization
  • evidence and sample traceability
  • technical review and decision separation
  • certificate and register accuracy
  • time controls and overdue action
  • information protection
  • complaints, appeals, incidents and nonconforming internal work
  • data integrity and system access; and
  • corrective action and management oversight

ICEQC-CER-001 · Clause 125

Confidentiality obligation

Information obtained or created during certification activity shall be treated as confidential unless it is public, lawfully obtained without a confidentiality obligation, authorized for disclosure or required to be disclosed under clause 126.

ICEQC shall inform personnel and controlled service providers of their continuing confidentiality obligations.

Confidentiality applies to oral, written, visual, electronic and inferred information, including:

Information shall not be used for personal advantage, unrelated research, marketing, competitive activity or any purpose outside authorized certification activity.

Confidentiality obligations continue after a person's role, contract or the client's certification ends.

  • learner and personnel information
  • internal records and systems
  • commercial, technical and security information
  • assessment evidence and interview content
  • complaints, incidents and legal matters
  • findings before controlled notification; and
  • pending decisions and reviews

ICEQC-CER-001 · Clause 126

Permitted and required disclosure

ICEQC may disclose information where:

Where lawful and practicable, ICEQC shall notify the affected client before compelled disclosure and shall identify the information to be disclosed.

Disclosure shall be limited to information necessary for the authorized purpose.

A public certification status, approved scope, certificate number and other register information are not confidential to the extent required for public verification.

ICEQC shall record a material non-routine disclosure, its authority, extent and recipient.

  • the person entitled to control the information has given valid authorization
  • disclosure is necessary to operate the public register or identify certification status
  • disclosure is required by law or a binding lawful process
  • disclosure is necessary to address a serious and imminent risk to a person
  • disclosure is necessary to investigate fraud, misuse or another material integrity matter; or
  • disclosure is made to an authorized person under enforceable confidentiality and for a necessary certification purpose

ICEQC-CER-001 · Clause 127

Privacy and data minimization

ICEQC shall collect and use personal information only to the extent reasonably necessary for certification, verification, protection, administration, legal obligation or system integrity.

Assessment planning shall prefer evidence that demonstrates the required control while minimizing unnecessary personal data.

Where possible and reliable:

De-identification shall not be used where identity is material to verifying authenticity, eligibility, safeguarding, authorization or traceability.

ICEQC shall not require broad system access where a controlled view, selected export, screen share or other limited method provides sufficient evidence.

A client shall inform ICEQC of material restrictions on collection or disclosure early enough for an appropriate evidence route to be planned.

  • samples shall be de-identified or masked
  • direct identifiers unrelated to the requirement shall be removed
  • access shall be limited rather than copies retained
  • learner information shall be aggregated; and
  • sensitive content shall not be recorded in the assessment report

ICEQC-CER-001 · Clause 128

Information security

ICEQC shall protect certification information against unauthorized access, use, disclosure, alteration, loss, destruction and unavailability.

Controls shall be proportionate to information sensitivity and shall include, as applicable:

Certification information shall be stored only in approved systems or controlled locations.

Download to a local device, portable media or personal account is prohibited unless expressly authorized and protected.

Access shall be removed promptly when no longer required.

  • verified user identity and role-based access
  • strong authentication
  • secure transfer and storage
  • device and session control
  • access logging and periodic review
  • backup and recovery
  • secure disposal
  • incident detection and response
  • personnel confidentiality and security awareness; and
  • service-provider security obligations

ICEQC-CER-001 · Clause 130

Information incident management

ICEQC shall maintain a controlled process for actual or suspected loss, disclosure, alteration, unauthorized access or unavailability of certification information.

An incident shall be assessed promptly for:

Where an incident may have altered, destroyed or exposed assessment evidence, ICEQC shall determine whether replacement evidence, reassessment or decision review is required.

Material incidents and actions shall be recorded, investigated and reviewed for recurrence.

A certified client shall notify ICEQC of an information incident where it materially affects the certified object, required records, certification evidence or public reliance.

  • affected information and persons
  • sensitivity and volume
  • continuing exposure
  • effect on evidence reliability or certification status
  • containment and recovery needs
  • notification obligations; and
  • corrective action

ICEQC-CER-001 · Clause 131

Certification records

ICEQC shall create and maintain records sufficient to demonstrate that each certification activity and decision was performed under the applicable rules.

The minimum controlled records are specified in Schedule 10.

A certification record shall be:

An alteration to a controlled record shall preserve the original content or an auditable change history, the reason, date and authorizing person.

Informal notes containing material evidence or rationale shall be transferred into the controlled case record or retained as part of that record.

  • identifiable to the case, object, scope and activity
  • dated and attributable to its creator or approver
  • protected against unauthorized alteration
  • retrievable throughout its retention period
  • linked to the applicable document edition; and
  • sufficient for an authorized person to reconstruct the material basis of the conclusion

ICEQC-CER-001 · Clause 132

Record retention and disposal

Unless a longer period is required by an applicable scheme, agreement or lawful obligation, ICEQC shall retain the complete certification record for the current certification cycle and the immediately preceding cycle, and in all cases for not less than seven years after the final activity to which the record relates.

Complaint, appeal, integrity and enforcement records shall be retained for not less than seven years after closure or for as long as necessary to support an active restriction or historical public status.

Personnel authorization and competence records shall be retained during authorization and for not less than seven years after the authorization ends.

Records subject to a preservation notice, dispute, investigation or pending action shall not be destroyed until the hold is formally released.

At the end of retention, information shall be securely deleted, destroyed or irreversibly de-identified according to its medium and sensitivity.

Disposal shall be documented where the information is sensitive or the record category is material to certification integrity.

ICEQC-CER-001 · Clause 152

Internal integrity concerns

ICEQC personnel and controlled service providers shall report suspected internal misconduct, conflict, unauthorized disclosure, result manipulation, record alteration or other integrity failure.

A report shall be protected from retaliation and handled outside the authority of a person implicated in the concern.

ICEQC shall determine whether affected certification cases, decisions, documents, public records or clients require review or correction.

Confirmed internal misconduct shall result in corrective, authorization, contractual or other action proportionate to the matter.

ICEQC shall preserve sufficient records to demonstrate that the integrity of affected certification outcomes was evaluated.