The trust chain: who checks the checkers

Lesson 1 of 5 in Certification, Audit, and Integrated Management Systems: ISO/IEC 42006.

A certificate is only worth the system of checks behind it. When a vendor slides an ‘ISO/IEC 42001 certified’ logo across the table, the first professional question is not what did they implement but who issued this, and who checks the issuer? Certification runs on a chain of institutional trust, and every link can be strong or hollow.

The chain has four links. At the top sits the International Accreditation Forum (IAF), whose multilateral recognition arrangement (MLA) is the reason a certificate issued in Singapore is trusted in Germany: signatory accreditation bodies peer-evaluate each other so that ‘accredited once, accepted everywhere’ roughly holds. Below the IAF sit the national accreditation bodies — ANAB in the United States, UKAS in the United Kingdom, DAkkS in Germany — which assess and accredit the certification bodies (CBs): the commercial firms (BSI, DNV, TÜV, SGS and hundreds of smaller ones) that actually send auditors into your building. At the bottom of the chain sits the certified organisation — you.

Notice what this means: nobody at ISO certifies anyone. ISO writes the standards; the conformity assessment industry applies them. ‘ISO certified us’ is a phrase that should end an interview.

The accreditation chain

  1. IAF — International Accreditation Forum

    The peak body. Its multilateral recognition arrangement (MLA) makes signatory accreditation bodies peer-evaluate one another, so an accredited certificate issued under one signatory is recognised under the others. The IAF also coordinates transition arrangements when a new standard (like ISO/IEC 42006) changes the rules for everyone below.

  2. Accreditation bodies — ANAB, UKAS, DAkkS, and national peers

    One (or a few) per country. They audit the auditors: assessing certification bodies against ISO/IEC 17021-1 plus the standard-specific overlay — for AIMS, ISO/IEC 42006:2025. They witness real audits, review CB competence files, and can suspend or withdraw a CB’s accreditation.

  3. Certification bodies — The firms that audit you

    Commercial businesses that plan and conduct Stage 1/Stage 2 audits, classify findings, make the certification decision, and run the three-year surveillance cycle. Their impartiality, competence, and confidentiality duties come from 17021-1; their AI-specific duties from 42006.

  4. Certified organisations — Holders of the certificate

    The organisations whose AI management system — not their AI products — has been audited and certified against ISO/IEC 42001. The certificate names a precise scope: which legal entities, sites, and AI activities are covered. Anything outside that scope statement is uncertified, whatever the marketing says.

The rules for the middle links matter to you even though you never sign a contract with an accreditation body. ISO/IEC 17021-1 is the baseline every management-system certification body must meet, and it rests on three pillars you should actively verify in any CB you engage:

Impartiality. A CB may not audit a management system it helped build. If a firm sold you AIMS consulting — wrote your risk methodology, drafted your Statement of Applicability — it cannot credibly certify the result, and 17021-1 prohibits exactly that combination. The two-year cooling-off norms and conflict-of-interest registers exist because the temptation to grade your own homework is commercial gravity.

Competence. The CB must demonstrate that its audit teams understand what they audit — which, for AI, was the gaping hole that ISO/IEC 42006 was written to fill (next lesson).

Confidentiality. Auditors see your risk registers, incident records, and model documentation. 17021-1 binds them to protect it — which is also why you can and should show auditors real evidence rather than sanitised theatre.

Key terms: accreditation body, certification body, IAF MLA, ISO/IEC 17021-1, conformity assessment

Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.