ISO 20252 and Research Quality Standards Explained
What ISO 20252 and ISO 27001 cover, what certification means for buyers, and how industry codes from ESOMAR and the Insights Association fit in.

In this article
Procurement teams love a certificate. I get it: it's a quick filter. But a logo on a website tells you less than people think, and the absence of one doesn't always mean a provider is careless. Here's how to read the standards landscape in market research.
Key takeaways
- ISO 20252 covers process quality in market, opinion and social research.
- ISO 27001 covers information security management. SOC 2 is its common US counterpart.
- ESOMAR and Insights Association codes set ethical rules, not process audits.
- Ask for scope and evidence, not just the badge.
Why standards matter to buyers
They give you a shared language for what "good process" means: documented project steps, trained staff, traceable decisions, and a way to fix mistakes. For multi-country work with several subcontractors, that consistency matters a lot.
ISO 20252 in brief
ISO 20252 is the international standard for market, opinion and social research, including data analytics. It sets requirements for how projects are specified, fielded, processed and reported, and it includes requirements for access panels, such as how panel members are recruited, validated and managed. The current version dates from 2019.
ISO 27001 and SOC 2
ISO 27001 certifies that an organization runs an information security management system: risk assessment, access controls, incident response and so on. SOC 2 is an audit framework more common in the US, covering security, availability, processing integrity, confidentiality and privacy. Our systems are designed to align with SOC 2 Type II; details are in the security policy.
Industry codes
The ICC/ESOMAR International Code and the Insights Association Code of Standards set ethical ground rules: respondent consent, transparency, protecting personal data, separating research from marketing. They're not audits, but they're the baseline every serious provider should commit to in writing.
What to ask suppliers
- Which certifications do you hold, and what's the scope? A certificate covering one office doesn't cover your project in another country.
- When was the last audit?
- Can you show evidence beyond the badge: a quality report, a removal log, a DPA?
- For sample, have you answered ESOMAR's "37 Questions to Help Buyers of Online Sample"?
Standards are a floor. How a provider handles data quality project by project is what you'll actually feel in the results.
FAQ
What is ISO 20252?
It's the international quality standard for market, opinion and social research, defining requirements for how research projects and access panels are managed from specification to reporting.
Is ISO certification required for market research?
No, it isn't legally required. Some buyers and public-sector tenders ask for it, and many good providers follow its practices without formal certification.



