A complete guide to our audit process, certification decisions, and ongoing compliance monitoring from initial application through recertification.

What each certification covers.
Certification decisions are made, communicated, and managed transparently — at every stage.
Information Security Management. ISO/IEC 27001 is the leading international standard for Information Security Management Systems (ISMS). Certification demonstrates a structured, independently verified approach to protecting data and managing risk: stronger security and resilience, enhanced customer and partner trust, competitive advantage where certification is required, and streamlined regulatory compliance.
Artificial Intelligence Management. ISO/IEC 42001:2023 is the first international standard for Artificial Intelligence Management Systems (AIMS). It applies to any organization that provides or uses AI-based products or services, regardless of size or sector. Certification demonstrates responsible AI governance, management of AI-specific risks and impacts on individuals and society, readiness for emerging AI regulation, and independently verified trust and transparency in AI-driven products and services. Because ISO 42001 follows the same harmonized structure as ISO 27001, it integrates cleanly alongside an existing ISMS.
How certification works.
Our certification process conforms to ISO/IEC 27006 and ISO/IEC 42006. Every step is designed to be rigorous, transparent, and fair.
We follow the same proven, multi-stage process for both standards. For ISO/IEC 27001 we assess your Information Security Management System (ISMS); for ISO/IEC 42001 we assess your Artificial Intelligence Management System (AIMS).
PHASE ONE: Application & Scope Definition
Certification begins with a formal application. Your organization provides details about its structure, management system scope, and readiness. We review the application to confirm we have the competence and capacity to audit your industry and context. We provide a full proposal covering Stage 1, Stage 2, surveillance, and recertification timelines—before any work begins.
PHASE TWO: Stage 1 Audit - Readiness Review
Our auditors assess your management system documentation, policies, procedures, risk and impact assessments, and control frameworks to evaluate readiness for the full certification audit. This review identifies critical gaps before Stage 2. We deliver written findings and guidance. If significant deficiencies are present, we work with you to understand what must be addressed before proceeding.
PHASE THREE: Stage 2 Audit – Certification Audit
This is where certification is determined. Our team conducts an in-depth, on-site evaluation of management system implementation and effectiveness by interviewing personnel, observing operations, and testing that controls work as intended across departments and locations within scope. Non-conformities are discussed with your team, and organizations have the opportunity to address major findings before a certification decision is made.
PHASE FOUR: Certification Decision & Issuance
A dedicated Certification Committee—separate from the audit team — reviews the evidence and makes the certification decision. When requirements are met and findings are resolved, your certificate is issued and your organization is added to our public registry. Certificates are valid for three years.
Ongoing Surveillance Audits
Certification is a continuous commitment. Annual surveillance audits at 12 and 24 months verify that your management system remains effective and conforms to the requirements of the applicable standard. Each surveillance audit samples controls, reviews internal audits, management reviews, and management system objectives. A Surveillance Audit Report is issued following each visit with conclusions on continued certification validity.
Recertification Audit
Before your three-year certificate expires, we conduct a full recertification audit—a comprehensive review of your entire management system. Successful recertification results in a new certificate issued without interruption.
Certification decisions are made, communicated, and managed tranparently—at every stage.
Initial & Recertification
After a successful audit confirms that all requirementsof the applicable standard (ISO/IEC 27001 or ISO/IEC 42001) are met and findings addressed, the Certification Committee grants certification. A certificate is issued and the organization is added to the public registry.
Expanding or Reducing Scope
Certification scope may be expanded or reduced based on factors such as organizational changes, demonstrated management system performance, audit results, or the complexity and risk of certified activities. Any changes to the audit scope are formally documented, communicated in advance, and, where applicable, reflected in updated contractual arrangements.
Temporary Hold
Certification may be suspended if a serious compliance issue arises—such as a major non-conformity or failure to address critical audit findings within the agreed timeframe. The certificate is not valid during suspension, and the organization must pause any use of the certification mark and claims of certification until the suspension is lifted.
Permanent Revocation
Certification is permanently withdrawn if serious issues cannot be resolved or the organization cannot meet essential certification requirements within the given timeframe. The certificate is canceled, and the organization must cease all promotion of the certification and all use of the VikingCloud Audit &Certification mark and name.
Initial & Recertification
After a successful audit confirms that all ISO/IEC 27001 requirements are met and findings addressed, the Certification Committee grants certification. A certificate is issued and the organization is added to the public registry.
Expanding or Reducing Scope
Certification scope may be expanded or reduced based on factors such as organizational changes, demonstrated management system performance, audit results, or the complexity and risk of certified activities. Any changes to the audit scope are formally documented, communicated in advance, and, where applicable, reflected in updated contractual arrangements.
Temporary Hold
Certification may be suspended if a serious compliance issue arises—such as a major non-conformity or failure to address critical audit findings within the agreed timeframe. The certificate is not valid during suspension, and the organization must pause any use of the certification mark and claims of certification until the suspension is lifted.
Permanent Revocation
Certification is permanently withdrawn if serious issues cannot be resolved or the organization cannot meet essential certification requirements within the given timeframe. The certificate is canceled, and the organization must cease all promotion of the certification and all use of the VikingCloud Audit & Certification mark and name.
Independent certification decisions
Certification decisions are made exclusively by our Certification Committee senior personnel who had no involvement in conducting the audit. Auditors assess. They do not decide.
No consulting to clients we certify
VikingCloud Audit & Certification does not provide ISMS or AIMS consulting, implementation, or readiness services to organizations it certifies.
Conflicts of interest controls
All personnel must disclose potential conflicts before any engagement. Auditors who have previously consulted for or advised an organization on its management system may not audit that organization.
External impartiality committee
An independent committee of external stakeholders meets regularly to review our practices and identify threats objectively.
Our impartiality policy.
Governs how we identify, evaluate, and mitigate threats to impartiality—including financial, self-interest, familiarity, intimidation, and advocacy risks as defined under ISO/IEC 17021-1.
Submit an inquiry and our team will reach out to discuss your scope and readiness.