ISO Certification · Accreditation

What Is an Accredited ISO Certification Body?

A certification body audits your management system against a standard and issues the certificate. "Accredited" is the part that tells you whether that certificate means anything once it leaves your own filing cabinet.

What a Certification Body Actually Does

A certification body is the organization that audits your management system against an ISO standard and decides whether to issue the certificate. It doesn't write your policies, close your gaps, or tell you how to structure your risk register — that's implementation work, and a certification body that also did your implementation work would be auditing its own homework.

The certification body's job starts once you believe you're ready: a Stage 1 review to check your documentation and scope, a Stage 2 audit to test whether the system actually operates the way it's documented, and then annual surveillance audits to confirm it keeps operating that way. What it checks depends entirely on the standard — an ISO 9001 audit tests process control and customer satisfaction; an ISO 27001 audit tests an information security management system; an ISO 42001 audit tests an AI management system's risk and oversight controls.

The term "certification body" gets used loosely to mean almost anyone offering compliance help. It shouldn't. A certification body is a specific, accredited role — and that distinction is exactly what the rest of this page is about.

What "Accredited" Actually Means

Accreditation is a second layer of audit, one level up. A national accreditation body evaluates the certification body itself — its auditors' competence, its impartiality controls, its technical processes — against ISO/IEC 17021-1, the standard that governs management system certification bodies. Only once it passes does the certification body get accredited to issue certificates in a specific scope: a specific standard, in specific industries.

This is the part that actually protects the buyer. Anyone can print a document that says "ISO 27001 Certified" on it. Accreditation is the independent check confirming the organization that issued it was itself competent and impartial enough for that certificate to be trusted by someone who wasn't in the room for the audit — a customer, a regulator, a procurement team running a security questionnaire.

Accreditation bodies are themselves overseen by the International Accreditation Forum (IAF). Through the IAF's Multilateral Recognition Arrangement (MLA), a certificate issued by an accredited body in one country is recognized in every other country whose accreditation body is also an MLA signatory — which is the entire point of certifying against an international standard rather than a private, single-market one.

TermWhat it actually is
Certification bodyAudits your management system and issues the certificate
Accreditation bodyA national body (e.g. UAF, ANAB, UKAS, JAS-ANZ) that audits the certification body itself
IAFThe international body whose MLA makes accredited certificates recognized across borders
IAF CertSearchThe public database where any of the above can be verified directly

How to Verify a Certification Body Is Actually Accredited

This takes about five minutes and doesn't require calling anyone.

  1. 01
    Find the accreditation mark on the certificateA genuine accredited certificate carries the accreditation body's logo and a specific accreditation number — not just the certification body's own logo and a signature.
  2. 02
    Confirm the standard is actually in that body's scopeAccreditation is granted per standard and per industry, not as a blanket approval — ISO 27001 accreditation is evaluated separately from ISO 9001 or ISO 42001 accreditation, even at the same certification body.
  3. 03
    Look it up on IAF CertSearchIAF CertSearch lets you check any accredited certificate directly against the issuing body's registered scope, independent of what the certification body's own website claims.
  4. 04
    Check the accreditation body's own public registerEach national accreditation body (UAF, ANAB, UKAS, JAS-ANZ, and others) publishes its own register of the certification bodies and scopes it has accredited.

Accredify Global is accredited under UAF, an IAF MLA signatory — you can verify our own accreditation scope on IAF CertSearch before you take our word for anything in this article.

Verify our accreditation

Certification Bodies by Standard

Accreditation is scoped, so the same certification body isn't automatically your certification body for every standard you're pursuing — if you're still narrowing down which standard you actually need, start there first. What each one is actually checking:

ISO 9001 certification body

Audits a quality management system: process control, corrective action, and whether customer requirements are consistently met.

ISO 27001 certification body

Audits an information security management system (ISMS) against Annex A controls — access management, incident response, risk treatment.

ISO 42001 certification body

Audits an AI management system: risk and impact assessment, human oversight, and accountability for how AI systems are built or deployed.

ISO 14001 certification body

Audits an environmental management system — how environmental risk is identified, controlled, and continually reduced.

ISO 45001 certification body

Audits an occupational health and safety management system, including hazard identification and incident investigation.

ISO 13485 certification body

Audits a medical device quality management system against regulatory and traceability requirements specific to that industry.

"ISMS certification" is shorthand for ISO 27001 certification specifically — the ISMS is the management system ISO 27001 requires you to build, and it's what an ISO 27001 certification body is actually auditing.

Certification Body vs. Consultant vs. Auditor

These three get used interchangeably in casual conversation and shouldn't be. Each one is doing a different job, and mixing up which is which is the fastest way to end up with an impartiality problem an accredited body will flag at Stage 1.

Certification body

Independent. Audits the finished management system and issues the accredited certificate. Cannot also have built the system it's certifying.

Consultant

Helps you build the management system: writing policies, running gap assessments, implementing controls. Prepares you for the audit; doesn't perform it.

CPA firm (SOC 2 only)

A separate category again — SOC 2 is an attestation from a licensed CPA firm under AICPA standards, not a certification from an accredited body at all.

Weighing ISO 27001 against SOC 2 specifically is a different question from certification body vs. consultant — see our ISO 27001 vs. SOC 2 comparison if that's what's actually in front of you.

Not sure whether you need a certification body or a consultant first?

A short scope review will tell you honestly which one you actually need next.

Request a Scope Review

Red Flags: Non-Accredited Bodies and "Pay-to-Pass" Certificates

A handful of patterns show up consistently around non-accredited or low-quality certification: a certificate with no accreditation logo anywhere on it; a quote that promises certification in a fixed number of days regardless of audit findings; an organization that offers to both build your management system and certify it; and a certification cost that's dramatically below every accredited quote you've received for the same scope.

None of these automatically mean fraud. But every one of them is a reason to check the accreditation register yourself before a customer, auditor, or regulator does it for you — usually at a worse moment, like mid-procurement or mid-audit.

Accredited ISO Certification

Not sure which certification body you actually need?

Accredify Global is accredited under UAF, an IAF MLA signatory, across ISO 9001, 27001, 42001, 14001, 45001, 13485, and more — every engagement led by a senior auditor in your industry, with a fixed-fee proposal after a short scoping call and no hidden costs after that.

Book your free scope review →

Frequently Asked Questions

What does an ISO certification body actually do?
A certification body audits your management system against the requirements of a standard, such as ISO 9001 or ISO 27001, and issues the certificate if you conform. It doesn't help you build the system first — that's a consultant's job. The certification body has to stay independent of the implementation work so its audit opinion is impartial.

Is my certification body accredited?
Check the certificate itself for an accreditation body logo and accreditation number, then verify that scope on the accreditation body's own public register or on IAF CertSearch. A certificate with no accreditation mark, or one that doesn't list your specific standard and industry in scope, is the two most common ways a certificate turns out not to be recognized.

What's the difference between an ISO 27001 certification body and an ISO 27001 consultant?
A consultant helps you build the ISMS: writing policies, running risk assessments, closing gaps. A certification body audits that ISMS afterward and issues the certificate. Under ISO 17021-1 (the standard certification bodies themselves are accredited against), the two roles can't be the same organization for the same client — that's a conflict of interest, not a convenience.

Does every ISO standard need a different certification body?
No, but the certification body needs to be separately accredited for each standard and industry scope it certifies. A body accredited for ISO 9001 isn't automatically accredited for ISO 27001 or ISO 42001 — each scope is evaluated and added individually, which is exactly what to check before assuming one body can handle every standard you need.

What is IAF CertSearch?
IAF CertSearch is a public database, run by the International Accreditation Forum, where you can look up whether a specific certificate was issued by a body that's actually accredited under the IAF's Multilateral Recognition Arrangement (MLA). It's the fastest way to check a certificate without contacting the certification body directly.

Can a non-accredited body still issue a valid ISO certificate?
It can issue a document that looks like a certificate, but without accreditation there's no independent oversight confirming the audit was done competently and impartially. Most enterprise procurement teams, regulators, and cross-border customers will either reject an unaccredited certificate outright or ask questions that stall the deal — which defeats the reason most companies certify in the first place.

Request Proposal - ISO, SOC & Compliance Services
Please select at least one option
08P19

Ready to Start Your Certification or Compliance Journey?

Tell us your requirement — we'll help identify the right certification, framework, and timeline. Free 15-minute consultation available.