For decades, the market read the certificate as a verdict on the entire product and the entire organisation. That reading broke down in public on 4 September 2024. The final report of the Grenfell inquiry documented «systematic dishonesty» by panel manufacturers, misleading certificates and an issuing body that negotiated the wording of its certificates with the manufacturer itself (Grenfell Tower Inquiry, 2024). Seventy-two people had died. Each document in that chain claimed something narrower than what the market believed it was buying.


I use the term epistemic scope for the boundary between what a certificate actually attests to and what the reader wants to read into it. Confusing the two produces a false sense of operational security · the most costly form of nominal technical trust. A certificate is a piece of evidence · bounded, dated, valuable within its boundary. Reading it properly means reading the boundary first.

What a certificate attests to

A management system certificate is read through four facts before the logo · legal entity, standard and edition, scope, validity date. The third-party audit examines a sample of evidence against the applicable requirements and within that boundary. In ISO/IEC 27001, the Statement of Applicability documents the necessary controls and the justification for inclusions and exclusions. ISO 9001 does not use a Statement of Applicability: its boundaries are read in the scope and in the applicability of requirements documented by the organisation.

And there are four readings the document does not support, however often the organisation repeats them · that the entire operation runs under that system, that controls operate continuously between audits, that risks outside the inventory do not exist, that the system will detect an event its design did not anticipate. None of the four is a failing of the certifier in question · it is a structural property of the certification model. The standard knows it, the certifier knows it, the market forgets it.

The certificate covers what is declared. Its force ends where the decision not to look began.

The two reading errors

The first error dismisses the document as mere paper. It is the cynic's error, and it is cheap · a rigorous certification, read within its boundary, is among the best pieces of evidence an organisation can present. The second error turns the document into a reputational shield · it takes bounded evidence and resells it as a total promise the document never made. This criterion defends rigorous certification with the same hand that dismantles its ornamental use.

Time compounds the second error. Japan's Ministry of Transport recorded 142 irregularities in Daihatsu type-approval applications, across models in production and discontinued models, and ordered checks and corrections (MLIT, 2023-2024). It was not an ISO certification; it was another type of conformity assessment. The case is useful because of that difference: a dated approval does not become a permanent guarantee through commercial repetition.

Reading a certificate in full requires identifying the standard and its edition, the legal entity, the scope, the sites, the issuing body, the accreditation and the validity period. Audit reports and follow-up information are not always public; when a decision depends on them, they are requested separately. The logo answers none of those questions.

Four scenarios where the boundary takes its toll

Scenario A · the scope that travels through the supply chain. The customer requires its supplier to be certified. The supplier presents a valid certificate · for one plant. It dispatches from three. The scope of one site travels through the chain as an assurance for the entire operation, and each link enlarges it as it passes it on. When the incident comes from the uncertified plant, the paperwork was in order and the assurance never existed.

Scenario B · the board that replaces oversight with a certificate. The committee receives the renewed certification and reduces the frequency of internal review. The risk arises in a process excluded from the scope. When it materialises, the board's fiduciary responsibility is compromised · the certificate remained valid and the duty of oversight remained intact.

Scenario C · the regulator that reads the boundary. In regulated sectors, the supervisor may determine that the declared scope is insufficient for sector-specific requirements. The certification remains formally valid · and can no longer be relied upon before the very authority that mattered most.

Scenario D · the operation that outgrows the scope. The organisation grows, adds digital products, enters new markets. The certified scope becomes too narrow, and the update waits until the next audit. During that interval, the gap between what is certified and what is operated is risk without an owner.

A fifth scenario remains, cruder and more frequent than the market admits · the document that does not even attest to what it says, because it was bought or forged. That problem has its own piece in this series · the verifiable certificate.

The criterion's test

Question one · what is the documented scope, word for word? Ask for the full certificate and its annex, as well as the seal. Expected answer · the document within 48 hours, with the standard, version, legal entity, sites and exclusions legible.

Question two · does the scope match the actual operation? Cross-check what is declared against billing, staffing, contracts and active sites. Expected answer · documented alignment. An entire business line, a dispatching site or a critical process outside the scope constitutes material risk · and the next conversation takes place in the boardroom.

Question three · what limitations or exclusions did the organisation document? For ISO/IEC 27001, review the Statement of Applicability; for other standards, use the relevant document. Expected answer · a technical justification consistent with the scope and the applicable requirements.

Question four · what sample, findings and closures supported the last cycle? Expected answer · a history that can be reconstructed to the extent that the contract and confidentiality allow access to it. Several cycles without material findings justify reviewing the sample design; Criterion 11 develops that signal without turning it into a presumption of non-compliance.

One more boundary is declared before closing · the scope limits the territory the certificate covers; the sample limits the auditor's view within that territory. They are two distinct limits that add up, and the second has its own criterion in this series.

Rigorous certification survives its poor readers when the board learns to read boundaries. An honest document declares its own on the first page.