Accredited vs. Certified: Clearing up the ISO confusion

In the corporate and compliance landscape, terminology carries immense weight. Yet, two of the most frequently used terms in risk management, procurement, and quality assurance are routinely mixed up: "Accredited" and "Certified."
It is exceptionally common to hear executives confidently declare that their organisation is "ISO 9001 Accredited" or that they only work with "ISO 27001 Accredited vendors." While the intent behind these statements is clear, the terminology is technically incorrect.
Under the international rules established by the International Organisation for Standardisation (ISO), businesses and organisations cannot be accredited to an ISO standard. Understanding why this distinction matters is vital for maintaining professional credibility, preparing bid responses, and evaluating third-party supply chains.
What is Certification?
When a business implements an ISO management system such as ISO 9001 (Quality Management), ISO 27001 (Information Security), or ISO 14001 (Environmental Management) it modifies its processes to meet the standard's strict criteria. Once ready, an external registrar or auditing firm reviews the business. If the business passes, the auditing firm issues a certificate. Therefore, the business is ISO Certified.
What is Accreditation?
To ensure that certificates carry global validity, weight, and integrity, the auditing firms themselves must be evaluated.
An official, national-level authority known as an Accreditation Body - such as UKAS in the United Kingdom - evaluates the auditing firms. They check their competence, impartiality, and adherence to international guidelines. When an auditing firm passes the vetting process, they become Accredited.
Think of the ISO ecosystem exactly like higher education:
The student (your company): You study the material, pass your final exams, and graduate. The university awards you a degree. You are now certified as holding that degree. You are not "accredited."
The university (the auditing firm): The institution has the authority to test you and hand out degrees because a higher governing board reviewed its curriculum and faculty. The university holds institutional accreditation.
Why getting the terminology right matters
Misusing these words isn't just a matter of semantics. In high-stakes business environments, using the wrong terminology can have real-world implications:
Credibility with procurement teams: Enterprise procurement professionals and sharp legal departments know the difference. Claiming your company is "ISO accredited" in a bid response can signal a lack of maturity or deep understanding of your own compliance frameworks.
The threat of unaccredited certificates: Because the word "certification" can be used by anyone, some unaccredited certification bodies operate without any oversight, selling cheap, invalid "ISO certificates" online without conducting thorough audits. Knowing the distinction prompts you to ask your registrars: "Are you accredited, and by whom?"
International trust: True accredited certifications are recognised globally via mutual recognition agreements like the International Accreditation Forum (IAF). Ensuring your auditor is accredited guarantees your certificate will be accepted by international clients.
The golden rule to remember
If you want to ensure your sales team, marketing materials, and leadership stay aligned with global compliance language, memorise this simple rule:
"Organisations get certified. The auditors get accredited."

By shifting your language from "ISO Accredited" to "ISO Certified," you demonstrate technical precision, protect your corporate reputation, and ensure that your compliance accomplishments stand up to professional scrutiny.


Comments