Hacker News new | ask | show | jobs
by ISO27Auditor 213 days ago
You don't need to use an external auditor that is your local audit provider, you just need to be sure that the audit provider (certification body) is accredited with an accreditation under IAF (eg IAS, UKAS, Dakks, COFRAC etc).

Any accredited certification body the world can audit you, and you can also save a lot by opting for a smaller certification body abroad instead of, for instance, one of the big names (I am an auditor for ISO 42001 and ISO 27001 as well)