The procurement meeting is nearly over when someone asks the question that should have come first: “Is this certification body actually accredited for the standard we need?”
A confident sales presentation is not an answer. Neither is a certificate displayed on the provider’s website, an impressive client list, or a promise that the audit can be completed unusually quickly. If your organization needs credible ISO certification, the body carrying out the certification must be accredited for the relevant activity, under the relevant requirements, by a recognized accreditation body.
That sounds straightforward until you start checking the details. Accreditation is not a general seal of approval that automatically covers every standard, industry, country, or service a certification body chooses to advertise. The practical work lies in matching your requirements to the body’s actual scope.
Start with the accreditation, not the quotation
For management-system certification, the certification body must be accredited according to ISO/IEC 17021-1. That is the framework used to assess organizations that audit and certify management systems. It addresses matters such as competence, impartiality, consistency, and the way certification activities are managed.
The phrase “accredited certification body” therefore needs to be followed by a second question: accredited for what?
A body may be accredited for ISO 9001 but not ISO 14001. It may cover ISO/IEC 27001 in some sectors or locations but not have the relevant scope for your organization. A provider that can conduct an audit is not necessarily a provider whose certificate will carry the recognition your customers, regulators, tender documents, or business partners expect.
Ask for the accreditation certificate and the detailed scope. Check that the scope names the standard you require, such as ISO 9001, ISO 14001, or ISO/IEC 27001. If your organization operates in a specialized field, examine the technical or industry categories as well. The words on a sales page are not a substitute for the formal scope issued by the accreditation body.
This is where buyers often make an expensive shortcut: they treat the certification body’s ability to discuss a standard as proof that it is authorized to certify against it. Those are different things. A consultant can explain ISO/IEC 27001. A non-accredited body can offer an audit. Only a certification body with the appropriate accreditation scope can provide the particular accredited certification you are seeking.
Identify the accreditation body and its recognition
Once a certification body gives you its accreditation details, verify them independently through the relevant accreditation body’s directory or official records. In the United States, ANAB maintains a directory of certification bodies and separates accredited organizations from applicants, suspended accreditations, and withdrawn or cancelled accreditations.
That distinction matters. An applicant is not the same as an accredited body. A suspended body is not in the same position as one with an active accreditation. A company may still have a functioning website and sales department after its accreditation status has changed, which is precisely why relying on marketing material alone is risky.
ANAB holds signatory status under the IAF Multilateral Recognition Arrangement for ISO/IEC 17021-1 management-system certification. Its recognition includes level 5 scopes for standards including ISO 9001, ISO 14001, ISO 22000, ISO/IEC 27001, ISO 13485, and ISO 45001. That does not mean every organization listed by ANAB is accredited for every one of those standards. The individual entry and scope still have to be checked.
The international recognition system is also undergoing a transition. From January 1, 2026, Global ACI operates as the successor to IAF and ILAC. IAF MLA marks remain valid during the transition, with their use expected to continue until no earlier than January 1, 2029. A mark by itself is not the whole verification process, but understanding the transition can prevent unnecessary alarm when older terminology still appears in valid accreditation documentation.
Verify the current status just before signing
Do not check accreditation once and file the result away. Verify the status close to the date of contract signing, and again if a long delay separates the contract from the audit. Accreditation can be suspended, withdrawn, or cancelled after a proposal has been issued.
ANAB’s 2026 records included the cancellation of AudIT3 and Quality Systems Registrars on June 22, 2026, and Ernst & Young CertifyPoint on February 24, 2026. Those examples make a simple point: a recognizable name does not guarantee a current accreditation status. The directory entry matters more than the reputation carried by the brand.
A short check can prevent a remarkably awkward conversation with a customer who later asks why your certificate cannot be verified through the expected accreditation chain.
Examine the certification body’s scope in practical terms
The formal scope is necessary, but it may not answer every operational question. Ask whether the body routinely audits organizations of your size and complexity. A certification body experienced with small offices may approach a multinational manufacturing operation very differently from a body accustomed to large industrial sites. Neither profile is automatically superior; the mismatch is the problem.
Describe your organization accurately before requesting a quotation. Include the number of sites, activities performed, shifts, outsourced processes, remote operations, regulatory constraints, and any locations that must appear on the certificate. If you minimize the complexity to obtain a lower quote, the audit plan may change later, along with the price and schedule.
A credible certification body should be willing to explain how it determines audit time and which sites or functions will be sampled. Be cautious of a quote that is dramatically cheaper because it says almost nothing. A low figure may reflect a genuine efficiency, but it may also leave important audit requirements unresolved until the last minute.
The certificate’s wording deserves attention too. Ask what organizational activities and locations will be included, which accreditation mark may appear, and whether the certification will be accepted by the parties that matter to your business. “Internationally recognized” is a useful sales phrase only after someone explains the recognition arrangement behind it.
Assess the auditors, not just the company
Accreditation applies to the certification body, but the quality of your audit will depend heavily on the people assigned to it. Request information about the proposed audit team’s experience with your standard, sector, technologies, and regulatory environment. You do not need to demand a particular auditor simply because that person has the most familiar name. You do need confidence that the team understands the risks it is expected to evaluate.
For an information-security certification, for example, an auditor should be able to engage with governance, risk treatment, access controls, incident management, suppliers, and the organization’s actual operating environment. A generic checklist approach may produce a tidy report while missing the weaknesses that prompted the organization to seek certification in the first place.
Ask how conflicts of interest are managed. If the same provider offers consulting, training, internal audits, and certification, find out how those services are separated. Certification requires impartiality. A body that helped design your management system may not be able to certify it without restrictions or safeguards, even if its sales team presents the arrangement as convenient.
You should also understand the complaint and appeal process before trouble occurs. A serious certification body will be able to describe how decisions are made, who reviews disputes, and how certification decisions remain independent from commercial pressure.
Compare contracts instead of day rates
Price comparisons become misleading when one proposal includes the complete certification cycle and another covers only the initial audit. Request a clear description of the activities included: application review, initial certification audits, surveillance audits, recertification, travel, additional sites, translation, and handling of major changes.
Clarify what happens if the audit identifies nonconformities. The certification body should explain the process for corrective-action review and the circumstances that could require additional audit time. Nobody should expect a clean report simply because the contract was signed, but nobody should be surprised by basic procedural requirements either.
Look at the decision process as well. The person who conducts the audit may not be the person who makes the certification decision, and that separation is part of maintaining confidence in the result. Ask who reviews the audit evidence, how long the decision normally takes, and what documents you will receive.
A provider promising certification with almost no preparation may be selling speed rather than assurance. Certification is not a rubber stamp for a management system that exists only in a folder. If the process appears designed to avoid difficult findings, the resulting certificate may be less useful precisely because it was easy to obtain.
Treat marketing claims as leads, not evidence
Search results, industry awards, customer logos, and polished brochures can help create a shortlist. They cannot establish accreditation. Verify the body’s legal identity, accreditation number, active status, and exact scope through the accreditation directory. Make sure the name in the contract matches the name in the accreditation record; similar trading names can create needless confusion.
If a provider resists these questions or responds with vague assurances, remove it from the shortlist. A competent certification body should expect a prospective client to check its credentials. Reluctance is not proof of misconduct, but it is a poor basis for a relationship built around independent scrutiny.
The final choice should leave a paper trail: the accreditation body, the applicable ISO/IEC 17021-1 scope, the standard and sector covered, the participating sites, the audit stages, the proposed team, the fees, and the rules for complaints and appeals. That document will be far more useful than a reassuring conversation in which everyone nodded at the right moments.
