Global Code of Conduct

A Global Standard for Responsible Action, Promoting Ethical Behavior Worldwide

Empowering global connections for inspiring cross-cultural and jurisdictional harmony.

ISO/IEC 17021-1 PCI SSC QSA Program Anti-Bribery
Globally enforced
ISO/IEC 17021-1 · PCI SSC QSA
Six Guiding Principles
Signed by every assessor and employee, applied across every engagement worldwide.
IntegrityPrinciple 1
IndependencePrinciple 2
ObjectivityPrinciple 3
ConfidentialityPrinciple 4
Anti-bribery & whistleblower protection built in
Trusted by compliance teams across ANZ
Our Principles

Six Principles Every Auditor Lives By

The professional standards that govern how we work, drawn from ISO/IEC 17021-1 and the PCI SSC QSA code of professional responsibility.

Integrity

Auditors have a duty to adhere to the highest standards of behaviour by being professional and honest in their work and their relationships with clients.

Independence

In all matters relating to the audit work, the independence of auditors should not be impaired by personal or external interests.

Objectivity

Auditors’ objective assessments should be free from undue influence by reflexivity and external influence. The accuracy of reports bears their strength from objectivity and impartiality.

Confidentiality

Auditors should not disclose information obtained in the auditing process to third parties, either verbally or in writing.

Professional Secrecy

Auditors should not disclose information obtained in the auditing process to third parties, either orally or in writing.

Competency

The auditors shall engage only in services they have the necessary knowledge, skills, and experience.

Built on Global Standards

Two Frameworks, One Code

Our conduct is held to the world’s leading certification and payment-security professional standards — wherever in the world we operate.

Certification Bodies

ISO/IEC 17021-1

The international requirements for bodies providing audit and certification of management systems — demanding impartiality, competence, consistency and confidentiality from every assessor.

Payment Security

PCI DSS & PCI SSC QSA

The PCI Security Standards Council’s code of professional responsibility for Qualified Security Assessors — requiring independence, confidentiality and freedom from conflicts of interest on every PCI DSS assessment.

Policy

Anti-Bribery Policy

Cianaa has a strong anti-bribery policy to prevent and prohibit bribery in all forms within our organization and in our business dealings with third parties.

Our zero-tolerance stance applies to every employee, contractor and partner, in every jurisdiction in which we operate — supporting the independence and integrity that our certifications depend on.

Speak Up

Any person captured by this policy who suspects that a fraudulent or corrupt act is occurring or has occurred must report this immediately. All information about suspected fraud or corruption is to be treated confidentially.

Send Now →
Treated confidentially Non-retaliation Investigated promptly
Ethical by Standard

Ethics You Can Audit

Our global code of conduct is what makes every Cianaa assessment credible. Have a question about how we hold ourselves to it?

Talk to Our Team →
Code of Conduct FAQ

Frequently Asked Questions

Who does the Global Code of Conduct apply to?
Every Cianaa auditor, employee, contractor and partner — in every country we operate in. The code is signed and applied across all ISO and PCI DSS engagements.
Which standards underpin the code?
It is built on two global frameworks: ISO/IEC 17021-1 (requirements for certification bodies) and the PCI Security Standards Council’s code of professional responsibility for Qualified Security Assessors.
How do I report suspected fraud or corruption?
Use the Speak Up channel above to report immediately. All reports are treated confidentially, protected from retaliation, and investigated promptly.