Proks is committed to conducting certification and audit activities impartially and to protecting the confidentiality of information obtained or created during certification activities. Proks ensures that:
Impartiality
- Impartiality as a fundamental principle: All conformity assessment activities are conducted impartially. Proks is responsible for impartiality and does not permit any commercial, financial, or other influences that could compromise impartiality.
- Top management commitment and policy: Top management is committed to impartiality and pursues an impartiality policy confirming that Proks understands the importance of impartiality in the certification of management systems, manages conflicts of interest, and ensures the objectivity of certification activities.
- Conflicts of interest and risk management: Proks maintains a documented process for identifying, analyzing, evaluating, treating, monitoring, and documenting risks to impartiality arising from its activities and relationships (e.g. ownership, governance, management, personnel, shared resources, finances, contracts, training, marketing, sales commissions, or other incentives). When threats to impartiality are identified, Proks documents and demonstrates how these threats are eliminated or minimized, and documents any remaining risks. Top management reviews the residual risks to determine whether they remain within acceptable limits.
- Consultation with interested parties: Proks consults appropriate interested parties on matters affecting impartiality, including openness and public perception. The consultation is structured to ensure balanced representation, with no single interest predominating. (This may be achieved through an impartiality committee).
- Independent decision-making: Members of the impartiality committee, certification committee, and appeals committee carry out their duties independently and are protected from commercial, financial, or other influences that could affect their decisions.
- No consulting and no conflict-generating services: Proks and its personnel (including contractors and persons acting on its behalf), as well as all parts of the same legal entity and any organizations under Proks's organizational control, do not offer consulting services to certified clients or applicants (e.g. designing, implementing, or maintaining a client's management system) that could compromise impartiality. For ISMS certification, Proks does not conduct internal information security reviews of the client's ISMS to be certified and is independent of the body or persons that perform the internal ISMS audit. Proks does not offer or perform internal audits for its certified clients.
- Certification restrictions to protect impartiality: Proks does not certify organizations where relationships pose an unacceptable risk to impartiality (including cases where ownership/management relationships constitute a conflict of interest). Proks does not grant privileges or discriminatory advantages based on membership in associations, unions, chambers, NGOs, or similar groups.
- Restriction on certifying certification bodies: Proks does not certify another certification body for its quality management system.
- Equal access and non-discrimination: Access to certification services is open to all applicants within Proks's scope of competence and activity. Services do not depend on the size of the applicant, membership in an association/group, or the number of existing certified clients. No unnecessary financial burdens or discriminatory conditions are imposed; all binding rules are applied uniformly to all clients.
Confidentiality
- Responsibility and Binding Commitments: Proks is responsible, through legally enforceable agreements, for the management of all information obtained or created during certification activities at all levels of its structure, including committees and external bodies/persons acting on its behalf.
- Public Information: Proks shall inform the client in advance of any information it intends to make publicly available. All other information, with the exception of information made publicly available by the client, shall be treated as confidential.
- Disclosure Controls: Information about a specific client shall not be disclosed to a third party without their written consent, unless required by applicable laws, regulations, or authorized contractual arrangements (e.g., accreditation requirements). Where disclosure is required by law, Proks shall inform the client of the information provided, unless prohibited by law.
- Information from Other Sources: Information about the client obtained from sources other than the client (e.g., complainants, regulatory authorities) shall be treated as confidential in accordance with Proks' confidentiality policy.
- Confidentiality Obligations: All personnel (including committee members, contractors, and external personnel acting on behalf of Proks) shall keep confidential all information obtained or created during certification activities, unless otherwise required by law. This obligation continues even after the termination of employment or engagement.
- Secure Handling: Proks maintains documented processes and, where necessary, equipment and facilities to ensure the secure handling, storage, transmission, retention, and disposal of confidential information.
- ISMS Access to Sensitive Records (ISO/IEC 27006-1): Prior to an ISMS certification audit, Proks requests that the client specify any ISMS-related information that cannot be made available to the audit team due to confidential or sensitive content. Proks determines whether the ISMS can be adequately audited without this information; if not, Proks informs the client that the audit cannot take place until appropriate access arrangements have been established.
Alper Öztürk
Managing Director
05.01.2026