A certificate can easily be imitated. For years, verifying it required contacting the issuer and reconstructing the institutional chain. IAF CertSearch changed that relationship: it allows issuance, validity, scope and chain participants to be checked in a global register. This review organises the public evidence available as of 10 June 2026 and states what the register proves and what falls outside its scope.
What this review organises and what it leaves out
This article uses publications from the global forum, data from the global register, the official certificate count and registers of forgeries from other schemes. Criterion 16 defines the verifiable certificate, and Criterion 12 explains the chain of separations that produces it. This review does not audit bodies, attribute fraud to identifiable issuers or measure a market for which no census exists.
The evidence file · five dated findings
The system itself estimated the scale
In May 2024, IAF published that the IAF CertSearch team was detecting around twenty thousand fake certificates per year. This is a historical estimate for that channel, not the total size of the market. It only counts cases that reach the verification process; paperwork that nobody checks is left out.
The system itself signed the warning
The same publication described certification mills and set out two minimum checks: that the body is accredited by a member of the multilateral agreement and that the certificate appears in the register. The chosen defence is searchable; it does not depend on the design of the paperwork.
Uploading to the register ceased to be optional
Since 26 October 2024, the mandatory document IAF MD 28 has required accredited certification bodies to upload their data to the global register. The effect is measurable · by early 2025, there were 2.335 certification bodies and more than two and a half million certifications searchable online (IAF, 2025). A check that previously depended on the issuer's goodwill became a search taking minutes that any third party can perform without asking permission — and that «without asking permission» is the heart of the change.
The official count came to be built against the register
The 2024 edition of the ISO Survey reports 1.474.118 ISO 9001 certificates, a jump of around 76% over the previous year. The jump requires a caveat · it reflects the change in the survey's source and coverage — it came to be built on IAF CertSearch, with full coverage of Chinese accreditation — not real market growth (ISO Survey, 2025). That caveat, which a hurried reader files away as fine print, is the central news in the evidence file. Official data stopped being produced from bodies' declarations and came to be produced against the verifiable register. The system began to audit its own numbers, and the numbers moved.
The architecture was unified and forgeries are published
Since January 2026, the multilateral architecture maintained by IAF and ILAC has operated under one roof: Global Accreditation Cooperation Incorporated — Global ACI — which takes over the mutual recognition arrangements (Global ACI, 2026). The same direction is being followed beyond the perimeter of management system standards. The international sustainability certification scheme ISCC maintains an ongoing public register of detected fake certificates, document by document (ISCC, 2026). Publishing forgeries is no longer a defensive gesture. It is part of the design.
The three states of verifiability test
Criterion 16 distinguishes three states of a certificate from a third party's perspective. This review turns them into an operational test · take the most visible certificate in your operation and that of your critical supplier, and place each in its row.
| State | How it is checked | Expected response |
|---|---|---|
| Verifiable in minutes | Search the scheme's public register — IAF CertSearch for accredited management system standards — and check the issuer under an accreditation body that is a signatory to the multilateral agreement | The certificate appears with a legal entity name, standard, scope and validity matching the paperwork. The issuer is listed with accreditation covering that standard |
| Verifiable with friction | Email to the issuing body, a wait of days, confirmation dependent on the interested party | The verification arrives and is documented. The friction is recorded as a data point in the supplier assessment, because verification friction is a property of the document |
| Not verifiable | The paperwork exists · no searchable register supports it | The document is treated as a claim awaiting evidence (Criterion 02). The burden of proof shifts entirely to whoever presents it |
The test's threshold is time. The checks in the first state, together, take minutes. Where they take weeks, the data point for your assessment is friction. Where the document appears in no register, the data point is absence — and the next conversation is with whoever presented it.
Make checking the register part of your organisation's minimum due diligence. Every certificate of conformity — your own or a supplier's — is accepted after being checked against the scheme's public register, and the check is documented with its date, source and result. Verification friction is recorded as a data point in the supplier assessment. A document that appears in no searchable register is treated, for the purposes of the commercial decision, as a claim without evidence. Whoever presents it is given the opportunity to prove it.
For those presenting credible certificates, the same doctrine works in their favour · publish the verification link alongside the certificate. An organisation that facilitates its own verification earns the premium that the register created.
The evidence file shows a system that responded to forgery with searchable data. The register does not reassess the quality of the audit; it allows users to check that the declared issuance, scope and validity correspond to the accredited chain.