What Clause 6 of ISO 17100 Actually Covers
Most of the attention in ISO 17100 falls on Clause 5, which governs the translation workflow itself. But Clause 6 is where the standard shifts from producing a translation to managing everything that happens after it leaves the translator's desk. That includes how feedback is gathered and handled, how project files are archived, and how client data is protected throughout the process.
On this page
For translation service providers (TSPs) pursuing or maintaining ISO 17100 certification, Clause 6 is often where gaps appear. The production workflow gets documented carefully because it is visible and sequential. Post production activities are easier to overlook because they feel less urgent once the deliverable is out the door. Auditors know this, and they look accordingly.
This article walks through each component of Clause 6 in practical terms, explains what auditors examine when they assess conformity, and identifies the most common weaknesses found in certified and pre-certification TSPs.
Clause 6.1: Feedback and Complaints
Clause 6.1 requires the TSP to have a process for receiving, evaluating, and acting on feedback from clients. This includes complaints, but it also extends to positive feedback and general comments about service quality. The standard does not prescribe a specific format or channel, but it does require that the process is defined and that feedback informs continual improvement.
What the Standard Expects
The TSP must be able to demonstrate that feedback is not simply received and filed. It needs to flow into a review process where patterns are identified and improvements are considered. A complaint that a terminology choice was inconsistent across chapters, for example, should not just be acknowledged and closed. It should prompt a review of whether the translation memory or glossary management process is adequate.
Auditors will ask to see records of feedback received over the past audit period. They will look for evidence that complaints were investigated, that root causes were identified where appropriate, and that the TSP took some form of action. Where no complaints have been received, auditors will probe whether the feedback mechanism is actually accessible and communicated to clients, or whether it simply does not exist in any meaningful form.
Common Weaknesses in Practice
The most frequent finding in this area is that the TSP has a feedback email address or form, but no defined process for what happens next. Feedback arrives, project managers read it, and it informs their thinking informally. That is not sufficient for ISO 17100 conformity. The process needs to be documented, records need to be kept, and there needs to be a connection between feedback and the management review or continual improvement process.
A second common weakness is treating feedback and complaints as the same thing. Complaints require a more structured response, including acknowledgement, investigation, and closure. General feedback may be handled more lightly, but the distinction should be clear in the TSP's procedure.
Exemplar Global Recognised Training ProviderRTP No. 310970Clause 6.2: Post Production Services
Clause 6.2 addresses services that may be required after the primary translation deliverable has been handed over. This includes desktop publishing, formatting, back translation, and similar activities. The clause is relatively brief, but it carries an important implication: if the TSP offers these services, they must be managed with the same rigour as the core translation services covered by the standard.
Scope and Applicability
Not every TSP offers post production services in this sense. A boutique translation agency focused purely on delivering translated text may have nothing to address under this clause. However, many TSPs do offer formatting, localisation of graphics, or layout adaptation, and those activities fall within scope if they are part of the certified service offering.
Auditors will check whether the TSP's scope of certification accurately reflects what it actually delivers. If a TSP is certified under ISO 17100 and routinely provides desktop publishing as part of its service, but has no defined process for managing that activity, there is a conformity gap. The scope of the management system needs to match the scope of the service.
What Auditors Look For
The key question is whether post production services are planned, controlled, and reviewed with the same attention given to translation and revision. That means defined processes, competent personnel or subcontractors, and documented outputs. If desktop publishing is outsourced, the TSP needs to demonstrate how it manages that external provider, including how quality is verified before the final product is delivered to the client.
This connects directly to the broader ISO 17100 requirement to manage subcontractors. If you want a detailed look at how the standard handles resource management and subcontractor competence, the article on ISO 17100 Clause 3 resources, competence records and infrastructure requirements covers that ground thoroughly.
Clause 6.3: Archiving
Clause 6.3 requires the TSP to define and implement a process for archiving project files. This includes source documents, translated files, translation memories, glossaries, reference materials, and any correspondence that forms part of the project record. The standard requires that the TSP and client agree on archiving arrangements, including retention periods and access rights.
Why Archiving Matters in Translation
Translation projects generate a significant volume of assets. A single large project might involve multiple source files, several translators working on different sections, a shared translation memory, a project-specific glossary, and revision records. If those assets are not archived in an organised and accessible way, the TSP cannot support the client if questions arise after delivery, cannot reuse assets efficiently on future projects, and cannot demonstrate the integrity of the process if a dispute occurs.
From an audit perspective, archiving is also evidence. An auditor reviewing a nonconformity raised during a previous cycle will want to see the project file to understand what happened. If files are deleted, corrupted, or stored in a way that makes retrieval impractical, the TSP has a problem that goes beyond inconvenience.
What the Standard Requires in Practice
The archiving process needs to be documented. It should specify what is archived, where it is stored, how long it is retained, who has access, and how files are protected against loss or unauthorised access. Retention periods should be agreed with clients, and those agreements should be recorded, typically in the project agreement or a separate service level agreement.
Auditors will ask to see the archiving procedure and will test it against actual projects. They will ask a project manager to locate a completed project from six or twelve months ago and retrieve the source files, the final translation, and the revision record. If that takes more than a few minutes or requires guesswork about where files might be stored, that is a finding waiting to be written.
Translation Memory and Glossary Archiving
Translation memories and glossaries deserve specific attention. These are assets that belong to the client in most commercial arrangements, and the standard requires clarity about who owns them, how they are maintained, and what happens to them at the end of a project or client relationship. If a TSP uses a translation memory across multiple client projects without clear separation, there is a confidentiality risk that overlaps with Clause 6.4.
A well-managed TSP will have a clear policy on translation memory ownership, a process for exporting client-specific assets on request, and a retention schedule that aligns with the client agreement. Auditors will ask about this specifically, particularly in cases where the TSP uses cloud-based translation management systems where data governance may be less obvious.
Clause 6.4: Data Protection and Confidentiality
Clause 6.4 is the data protection requirement in ISO 17100. It requires the TSP to have processes in place to protect client data throughout the project lifecycle, including during production, after delivery, and during archiving. It also requires that the TSP manages the confidentiality obligations of everyone who works on a project, including employees, freelance translators, revisers, and any other subcontractors.
The Scope of Data Protection Under ISO 17100
ISO 17100 does not replace or replicate data protection legislation. In Australia, that means the Privacy Act 1988 and the Australian Privacy Principles remain the primary legal framework. What Clause 6.4 adds is a management system requirement: the TSP must have defined processes for protecting data, not just a general intention to comply with the law.
Those processes need to address how client documents are handled, where they are stored, who can access them, how they are transmitted, and what happens to them after the project is complete. If a TSP sends source documents to a freelance translator by email without any confidentiality agreement in place, that is a gap under Clause 6.4 regardless of whether a data breach has actually occurred.
Confidentiality Agreements and Subcontractor Management
The standard requires that the TSP ensures confidentiality obligations are understood and accepted by all personnel working on a project. For employees, this is typically addressed through employment contracts and internal policies. For freelance translators and revisers, it requires specific confidentiality agreements or non-disclosure agreements that are signed before work commences.
Auditors will ask to see examples of confidentiality agreements used with freelancers. They will check whether the agreements are current, whether they cover the specific types of data handled by the TSP, and whether there is a process for ensuring agreements are in place before a new subcontractor is engaged on a project. A TSP that uses a pool of fifty freelancers but cannot demonstrate that all fifty have signed current NDAs has a clear conformity gap.
Data Transmission and Storage Security
How data is transmitted and stored is increasingly scrutinised in ISO 17100 audits, particularly as more TSPs move to cloud-based translation management platforms. Auditors will ask about the platforms used, where data is hosted, what security controls are in place, and whether the TSP has assessed the data protection implications of using those platforms for client content.
This does not require a formal ISO 27001 implementation, but it does require that the TSP has thought through the risks and has some documented controls in place. A TSP that uses a well-known cloud translation platform but has never reviewed its data processing agreement with that vendor, and has no record of doing so, is exposed under Clause 6.4.
Client-Specific Confidentiality Requirements
Some clients impose specific confidentiality requirements that go beyond the TSP's standard practice. Legal firms may require that documents are not stored on cloud platforms. Pharmaceutical companies may require that translators sign project-specific NDAs. Government clients may have classification requirements that affect how documents can be handled and transmitted.
ISO 17100 expects the TSP to capture these requirements during the pre-production phase, which is covered in Clause 4, and to ensure they are implemented throughout the project. If a client's specific requirements are recorded in the project agreement but are not communicated to the translators and revisers working on the project, there is a breakdown in the system. Auditors will trace this path from the agreement through to the project brief or instructions given to the production team.
For context on how client requirements are captured before production begins, the article on ISO 17100 Clause 4 pre production: enquiries, quotations and agreements explains the pre-production requirements in detail.
How Clause 6 Connects to the Rest of the Standard
Post production requirements do not sit in isolation. They connect directly to the production processes in Clause 5, the resource and competence requirements in Clause 3, and the pre-production agreements in Clause 4. An auditor taking a process-based approach will trace the thread from initial client enquiry through production and into post production, looking for consistency and completeness at every stage.
The feedback process in Clause 6.1 connects to the continual improvement requirements that run through the standard as a whole. Feedback that is not acted on represents a missed improvement opportunity and a conformity gap. The archiving requirements in Clause 6.3 support the ability to demonstrate conformity during audits, because project records are the primary evidence base for everything that happened during production. And the data protection requirements in Clause 6.4 underpin the trust that clients place in the TSP when they share sensitive content.
If you are building or auditing an ISO 17100 management system and want to understand how the production workflow requirements feed into these post production obligations, the article on ISO 17100 Clause 5 production: inside the mandatory translation workflow is worth reading alongside this one.
Exemplar Global Recognised Training ProviderRTP No. 310970Preparing for an ISO 17100 Audit: Clause 6 Checklist
If you are preparing for a certification or surveillance audit, the following points summarise what auditors will typically examine under Clause 6.
- Feedback process: Is there a documented procedure for receiving, evaluating, and acting on client feedback and complaints? Are records maintained? Is there a link to management review or continual improvement?
- Post production services: If the TSP offers services beyond translation and revision, are those services within the certified scope? Are they managed with defined processes and competent personnel?
- Archiving procedure: Is there a documented archiving process? Does it cover what is archived, where, for how long, and who can access it? Are retention periods agreed with clients?
- Translation memory and glossary management: Is ownership of client assets clear? Can the TSP retrieve and export client-specific assets on request? Is there appropriate separation between client assets?
- Confidentiality agreements: Are NDAs or confidentiality agreements in place with all freelance translators, revisers, and other subcontractors? Is there a process for ensuring agreements are signed before work commences?
- Data transmission and storage: Are controls in place for how client documents are transmitted and stored? Has the TSP reviewed data processing agreements with cloud platform vendors?
- Client-specific requirements: Are client confidentiality requirements captured in project agreements and communicated to the production team?
Practical Advice for TSPs and Internal Auditors
If you are conducting an internal audit of your own ISO 17100 system, Clause 6 is worth spending real time on. Start by pulling three or four completed project files from the past six months and working through them against each Clause 6 requirement. Can you find the feedback record for each project? Is the archive complete and retrievable? Is the confidentiality agreement for each freelancer involved in those projects on file?
That practical exercise will tell you more about the state of your post production processes than any checklist review. The gaps that emerge are almost always process gaps rather than knowledge gaps. People know that feedback should be recorded and that NDAs should be signed. The issue is that the process does not make it easy or automatic, so it happens inconsistently.
For internal auditors working in translation businesses, building audit questions that trace specific projects through the Clause 6 requirements is far more effective than asking general questions about whether procedures exist. Ask a project manager to walk you through what happened after a specific project was delivered. Ask them where the files are now. Ask them who signed the NDA for the freelancer who worked on it. The answers will tell you whether the system is working.
If you want to develop stronger auditing skills that you can apply across ISO standards including ISO 17100, the team at Audit Workshop delivers practical internal auditor and lead auditor training that focuses on real-world audit technique rather than theory. Whether you are new to auditing or looking to formalise your skills, the training is built around the kind of process-based thinking that makes Clause 6 audits actually productive.













