← Public Policy Library

Independence safeguards

Subcontractor and External Assessor Independence Policy

Applies Clause5afe competence, confidentiality, conflict, supervision, and outcome-independence requirements to external assessors and subcontracted certification work.

Controlling public principle

The rule an outsider should be able to rely on

External assessors are subject to Clause5afe competence, confidentiality, security, conflict, consulting-firewall, and outcome-independence controls, and Clause5afe remains accountable for their work.

Qualification

External does not mean exempt

Before assignment, an external assessor must satisfy the applicable competence requirements, complete independence and ethics training, execute confidentiality and data-handling obligations, and enter the controlled assessor register.

Engagement screening

Conflicts are checked for every assignment

Prior work, financial interests, family relationships, employment discussions, vendor ties, consulting activity, and other actual or perceived conflicts are reviewed before each engagement and throughout the assignment.

Consulting firewall

An assessor cannot certify their own advice or implementation

External personnel may collect and evaluate evidence within their authorized role. They may not provide implementation, remediation, vendor selection, readiness, or outcome advice to the certification client.

Supervision

Clause5afe owns the quality and the decision

Clause5afe assigns, supervises, reviews, and accepts responsibility for external work. External assessors do not independently issue certification decisions, and their work remains subject to the same review and documentation controls as internal work.

Compensation and data

Outcome-independent pay and controlled evidence

Compensation may reflect authorized work but not pass rates, favorable findings, client satisfaction with outcomes, or certification volume incentives. Evidence access is limited to what the assignment requires and remains subject to Clause5afe confidentiality and security controls.

Authority boundary

What this policy does not authorize

Clause5afe may use qualified external expertise, but it cannot outsource accountability, decision authority, confidentiality obligations, or independence.

Controlled information

What remains outside the public layer

  • Vendor contracts and rates
  • Individual assessor records
  • Proprietary supervision and quality-review material

Connected governance

Follow the policy into the institution.