Role in the process
The certification body is the third party in the arrangement: it did not build your management system, it does not run it, and it does not advise on it. Its job is judgement. It plans the audit, deploys an audit team, evaluates the findings, takes the certification decision, and then carries out the surveillance.
One separation matters and is routinely blurred in conversation: the auditor conducts the audit and makes a recommendation. The certification decision is taken by the body in a step that is deliberately kept apart from the audit team. If the auditor tells you in the closing meeting that you are certified, they have overstated their own authority.
Accreditation is national, and recognised internationally
A certification body is itself overseen. Each country has an accreditation body that confirms a certification body is technically and organisationally competent for a defined scope: UKAS in the United Kingdom, ANAB in the United States, the RvA in the Netherlands. In Germany, DAkkS — the Deutsche Akkreditierungsstelle — accredits the certification bodies for ISO/IEC 27001.
Those national bodies recognise one another through arrangements at the level of the International Accreditation Forum, which is why an accredited certificate issued in one country is generally accepted in another. For a buyer, that is the practical significance: you are not comparing national schemes, you are checking that an accreditation exists at all and that it covers the right standard.
Germany has one wrinkle worth knowing when you assess a German supplier. Alongside the accredited route, ISO 27001 certification on the basis of BSI IT-Grundschutz runs through the BSI's own scheme rather than through DAkkS. A German certificate may therefore have been issued under either arrangement, and the certificate itself will say which.
The requirements on certification bodies are set out in ISO/IEC 17021-1, supplemented for information security management systems by ISO/IEC 27006-1:2024. They govern impartiality, auditor competence, audit planning and decision-making processes, among other things.
The point that matters in practice: an accreditation is never blanket. It applies to defined standards and fields of application. So do not check only whether a body is accredited; check what for.
Accredited and non-accredited certificates
Not every certificate on the market sits behind an accreditation. A body can issue a document that names ISO/IEC 27001 without operating under an accreditation for it. Such a certificate is not fraudulent, but it carries no external oversight of the body that issued it, and many procurement functions will not accept it. Where a supplier certificate is doing real work in your assessment, look for the accreditation mark and the accreditation body's registration number, and verify it in that body's directory.
Advising and certifying are mutually exclusive
A certification body may not advise on and certify the same management system: it would be auditing its own work. Impartiality is one of the core points at which accreditation bites.
That does not rule out general training on the standard. The line runs where concrete solutions for your system are developed. If a body offers to build your ISMS and then certify it, the offer is one to examine rather than to accept.
Choosing one
- Accreditation and its scope, matching your standard.
- Sector experience of the audit team, not only of the body.
- Audit language and availability on site at your locations.
- Procedures for findings, deadlines, appeals and follow-up audits.
- How they handle your scope, particularly with outsourcing and cloud components.
- A quotation covering the whole cycle, not only the first audit. As a rule a certificate runs for three years, with surveillance audits in between and recertification at the end, so a first-audit price tells you little about the total.
What a certification body does not do
It confirms conformity with a standard at a point in time and for a defined scope. What it does not confirm is security, freedom from defects, or compliance with legislation. A certificate is therefore an indicator in a supplier assessment, not a substitute for your own review. The scope may be cut quite differently from the service you buy.
Scope and the certificate
The certificate names the standard, the certifying body, the period of validity and, decisively, the scope. That wording determines what the certificate says anything about at all: sites, organisational units, processes and services included. Two certificates against the same standard can therefore mean very different amounts.
When you assess a provider's certificate, read the scope before the issue date. A certification covering only the head office and administrative functions says nothing about the operation of the platform you use.
Changing certification body
A change is possible, including mid-cycle. It normally runs as a transfer, in which the receiving body reviews the existing certificate, the most recent audit reports and the status of open nonconformities. A valid, non-suspended certificate is generally a precondition. Close open major nonconformities before a transfer, or it turns into a second initial audit.
What an auditor finds in Rizzqo
A certification audit works from samples, and the effort arises wherever evidence has to be assembled first. In Rizzqo the evidence sits on the object under examination: the answer to a requirement, its reasoning and the attached files hang on the asset the requirement applies to. Finalised answers carry a name and a timestamp, making them confirmed statements rather than drafts.
The statement of applicability remains a document of its own, to be presented in the certification procedure; Rizzqo does not generate it at the press of a button. What the platform contributes is the layer beneath it: for every attached requirement, one statement per object, with an owner, a reason and evidence in the same place.