- Home
- Trust Centre
- What we protect, and the few cases where we cannot.
What we protect, and the few cases where we cannot.
Information obtained during an engagement belongs to the client. It is used for the engagement and for nothing else.
Client information.
- Information obtained during an engagement is treated as confidential and is not disclosed to a third party without written consent, except where required by law or by the accreditation and programme requirements.
- Personnel, subcontractors and technical experts are bound by the same obligation before they are given access.
- Access is limited to those who need it for the engagement.
- Information is transmitted through controlled routes; general email is not a controlled route for evidence files.
- Records are retained for the period defined in the management system, then disposed of under a controlled procedure.
When we must disclose — and what we do about it.
Disclosure may be required by law, by a court or authority, or by the accreditation body in the course of assessing us. Where the law permits, the client is notified of the information disclosed and to whom, unless notification is itself prohibited.
Where the accreditation body assesses our work, it examines engagement files. That access is part of what accreditation means, and it is covered by the accreditation body’s own confidentiality obligations.
The small set of things we do publish.
Public information is limited to: our accreditation status and scope; the existence and status of a statement when queried through Statement Check; and any case summary for which written client permission exists. Nothing else about an engagement is published — including the conclusion reached.
Describe the claim — not the service.
Tell us what must be relied on, who will rely on it and by what date. We will confirm the correct programme, evidence requirement and responsible entity — or tell you it is outside our scope.
