Start a new topic and get direct answers from the Expert Advice Community.
CREATE NEW TOPIC +Guest
The main difference is that ISO/IEC 27701:2025 is a stand-alone standard, whereas the 2019 version was an extension of ISO/IEC 27001. This means organizations can now be certified for their Privacy Information Management System (PIMS) without requiring an existing ISO/IEC 27001 certification.
When it comes to traceability, the AS9100 standard does not give detailed requirements on how to do this, but only says that you need to control the unique identity if that is a requirement, and retain documents necessary to ensure this traceability.
So, as per the standard, your question goes back to what your customer's requirements are. If your customer allows waivers on traceability, then that is acceptable, but if not, then it is not acceptable. As the standard is used by any organization within aerospace, the requirements only describe what needs to be done but need to be supplemented with the customer and legal requirements.
For a bit more on the traceability requirements in AS9100, see the article: How to meet traceability requirements in an AS9100D-based QMS, https://advisera.com/9100academy/blog/2019/06/05/as9100-traceability-requirements-how-to-meet-them/
We have the same problem here
Well, in this case certification will remain with organisation which is certified and not with your contract or with you. Incase there is any process movement to the small business, it should be included as a part of certified scope or managed as a controlled external provider.