Accreditation in progress (IAS), not yet accredited Learn more
Services About us Certificate check Contact

Last updated: 8 September 2026 DOC-030 · v1.0

These Rules for Certification apply to all organisations applying to United Certification Services LLC (hereinafter „certification body“) for certification of their management system or holding such certification (hereinafter „client“). They form an integral part of the Certification Agreement and rank immediately after it.

1. Application and Amendment of these Rules

These Rules are controlled and versioned as a separate document and are published at www.unitedcert.org. The version applicable is the version published at the time the agreement is concluded; separate transmission is not required. Subsequent amendments take effect in accordance with section 5 of the Certification Agreement.

Where certification requirements change, including the revision of a certification standard, the certification body grants a reasonable transition period, communicates the duration and course of the transition and verifies implementation at the next audit. The transition periods laid down by the accreditation body and by the IAF are decisive. Before these Rules are amended, the views of the impartiality committee are taken into account.

2. General Obligations of the Client

The client undertakes:

  • to maintain, apply and continually improve the certified management system
  • to comply with all requirements of the certification standard and with the legal requirements applicable to its activities
  • to provide auditors with all information required for the assessment, completely and truthfully
  • to keep records of all complaints relating to the certified scope and to make them available to the certification body on request
  • to nominate a contact person responsible to the certification body for the management system and to notify any change without delay
  • not to use the certification in a manner that brings the certification body or the accreditation system into disrepute

3. Cooperation and Access

The client provides the documentation to be reviewed in due time, grants access to all sites, processes, areas, records and personnel required for the audit, and provides suitable premises. It permits the attendance of observers, auditors in training and representatives of the accreditation body.

For ISO/IEC 27001 certifications, the client shall state before the audit whether any records of the information security management system cannot be presented due to confidential or particularly sensitive content; the certification body decides whether certification is possible under those conditions.

4. Notifiable Changes

The client is obliged to inform the certification body in text form without delay, and in any event within 14 calendar days, of all changes which may affect the ability of the management system to fulfil the requirements of the standard. This concerns in particular changes:

  • of the legal form, company name, ownership or shareholding structure
  • of the address, the sites or the contact details, including the addition or abandonment of sites
  • of the management, the technical or decision-making personnel and the nominated contact person
  • of the headcount, shift operation or the extent of outsourced processes
  • of the fields of activity, products, services or processes covered by the scope
  • of the management system itself, its documentation or material procedures
  • of the Statement of Applicability (SoA) for ISO/IEC 27001 certifications
  • of the legal status, in particular insolvency petition, liquidation or transfer of business

The certification body evaluates the change and decides whether an additional audit, an adjustment of the audit programme or an amendment of the certificate is required. Changes of scope are handled as an amendment in accordance with section 9 of the Certification Agreement.

5. Notification of Serious Incidents

The client shall inform the certification body without delay of serious incidents and breaches of law that require the involvement of a regulatory authority and affect the certified scope, in particular significant environmental incidents as well as official orders and administrative fine proceedings related to the scope. The notification shall state the date and time, a description of the incident, its effects and the corrections and corrective actions taken.

The certification body may then schedule a special audit and decide on measures up to and including suspension or withdrawal of certification.

6. Types of Audit and Procedure

The certification audit is conducted in two stages. The stage 1 audit serves to evaluate the documentation, the site-specific conditions and audit readiness; the stage 2 audit evaluates the implementation and effectiveness of the management system on site. The results of the stage 1 audit may make it necessary to postpone the stage 2 audit.

Surveillance audits take place at least once each calendar year, except in years in which a recertification audit is conducted. The first surveillance audit must be conducted within twelve months of the date of the certification decision (ISO/IEC 17021-1:2015, Cl. 9.1.3.3). A postponement upon substantiated request is permissible only to the extent that the above deadlines are not exceeded thereby.

The recertification audit must be conducted before expiry of the certificate; nonconformities must be closed before expiry. If the validity is exceeded, certification may be restored within six months of expiry provided the outstanding recertification activities are completed; otherwise at least a stage 2 audit must be conducted (ISO/IEC 17021-1:2015, Cl. 9.6.3.2).

Follow-up audits, special audits and short-notice audits may be conducted in order to verify nonconformities on site, investigate complaints, evaluate changes or monitor a suspended certification. The resulting costs are borne by the client unless the certification body is responsible for the cause.

Audit time is determined for ISO 9001 and ISO 14001 in accordance with IAF MD 5 and for ISO/IEC 27001 in accordance with ISO/IEC 27006-1:2024 Annex C. For multi-site organisations, sampling is carried out in accordance with IAF MD 1; the central function is always audited.

7. Nonconformities and Deadlines

Findings are classified as major nonconformity, minor nonconformity or opportunity for improvement and handed over to the client in documented form.

For major nonconformities, root cause analysis, correction and corrective action must be evidenced within 90 calendar days of the last audit day; effectiveness is normally verified on site. For minor nonconformities, evidence must be provided in documented form within 90 calendar days; effectiveness is evaluated at the next audit at the latest.

If the deadlines are not met, the certification procedure is terminated or the existing certification is suspended in accordance with section 10. For major nonconformities, certification is only granted or maintained once the correction and corrective action have been verified; for minor nonconformities, once the planned correction and corrective action have been reviewed and accepted. If the correction and corrective action for a major nonconformity cannot be verified within six months of the last day of the stage 2 audit, a new stage 2 audit is conducted before the certification decision.

8. Certification Decision and Certificate

The certification decision is taken exclusively by the certification body through a person or panel not involved in the audit. The decision is based solely on the audit results; commercial considerations do not enter into it.

On initial certification, the certificate is valid for three years from the date of the certification decision; on recertification, the new expiry date is based on the expiry date of the previous certificate. Validity is subject to surveillance audits being conducted on time and with a positive result. It applies exclusively to the scope, the sites and the standard stated therein and does not create rights for third parties.

The certificate remains the property of the certification body. In the event of suspension, withdrawal or termination of certification, all original certificates issued must be returned upon request and electronic copies deleted.

9. Use of the Certificate, Marks and Accreditation Symbol

The client may advertise the certification provided the statement accurately reflects the content of the certificate and is limited to the certified scope. Use of the certification body’s mark and of the accreditation symbol is governed by the requirements of the certification body and by the mark rules of the accreditation body (IAS AC477); IAF ML 2 applies in addition to the IAF MLA mark.

The following are not permitted in particular:

  • use on products, product packaging or in a manner that gives the impression of product certification
  • use on laboratory test reports, calibration certificates or inspection reports
  • incorporation of the mark or the certification into the company name
  • any presentation suggesting that non-certified areas, sites or activities are certified
  • any use during a suspension or after withdrawal of certification

In the event of misuse, the certification body demands cessation and may suspend or withdraw the certification and publish the breach. For each case of culpable continued use after receipt of a warning, liquidated damages of EUR 3,000.00 fall due; both parties reserve the right to prove lower or higher damage. The costs of investigating a proven misuse are borne by the client.

10. Suspension of Certification

Certification is suspended if, in particular:

  • the certified management system persistently or seriously fails to meet the certification requirements
  • corrective actions are not completed within the deadlines set out in section 7
  • surveillance or recertification audits are not made possible in due time
  • the certificate or the marks are misused and the breach is not appropriately remedied
  • the client fails to meet payment obligations when due despite a reminder
  • the client itself requests suspension

The suspension is notified to the client in writing after a hearing, together with the conditions for lifting it. It is limited to a maximum of six months. During the suspension the client may no longer claim the certification or refer to it. The suspension status is made publicly available. The costs arising from suspension and reinstatement are borne by the client.

11. Withdrawal and Restriction of Certification

Certification is withdrawn if the conditions for lifting a suspension are not met within the period set, in the event of deliberate non-compliance with normative requirements, fraudulent misrepresentation or untrue information, continued misuse of the marks, and abandonment of the certified business activity. Payment default is a ground for suspension under section 10; it leads to withdrawal only if the conditions for lifting the suspension are not met within the period set.

Certification is restricted if parts of the scope persistently fail to meet the requirements or if the client abandons parts of the certified area. The restriction is implemented by issuing a new certificate with a reduced scope; the obligations under the Certification Agreement remain unaffected.

Decisions on suspension, restriction and withdrawal are notified to the client in writing and made publicly available.

12. Transfer of Existing Certifications

The transfer of an accredited certification held with another certification body is carried out in accordance with IAF MD 2. For this purpose the client discloses the complete audit records of the current cycle, open nonconformities and complaints, and the status of the previous certification.

13. Appeals and Complaints

The client may appeal in writing against any decision of the certification body, in particular against refusal, restriction, suspension or withdrawal of certification, within 30 calendar days of receipt of the decision. See Complaints and appeals.

Complaints about the certification body, its staff, auditors or about certified clients may be submitted at any time by any person or organisation. See Complaints and appeals. Complaints about a certified client are communicated to that client.

Appeals and complaints are handled and decided by persons who were not involved in the matter concerned. Both procedures are free of charge for the submitting party; submission does not result in any discriminatory treatment.

14. Confidentiality

The certification body treats all information obtained in the course of its certification activities as confidential and uses it exclusively for certification purposes. All auditors, staff, technical experts, committee members and observers sign a confidentiality declaration.

Disclosure to third parties takes place only with the client’s consent, to the accreditation body within the scope of accreditation oversight, or by virtue of statutory obligation. In the latter two cases the client is informed in advance where legally permissible.

15. Publicly Available Information

The certification body maintains a register of all certificates issued and provides information on the validity status of a certification upon request. Published are the name of the certified client, the standard, the scope, the sites covered and the issue and expiry dates; for ISO/IEC 27001 certifications, additionally the version of the Statement of Applicability. Suspended and withdrawn certifications are identified as such.

The certification body reports granted, suspended and withdrawn accredited certifications to the database specified by the accreditation body. The client consents to this reporting.

16. Impartiality and Prohibition of Consultancy

The certification body does not provide management system consultancy and does not certify a management system for which it or a related body has provided consultancy within the preceding two years. Before each audit the risk to impartiality is assessed and documented. For this purpose the client states whether and by whom it has been advised.

The client may object to the appointment of an auditor on objective grounds. The certification body reviews the objection and, in response to a valid objection, appoints another auditor (ISO/IEC 17021-1:2015, Cl. 9.2.3.5).

17. Cessation of Certification Activities

If the certification body ceases its activities or its accreditation is suspended or withdrawn, it informs all certified clients without delay. The further procedure, the support with the transfer and the bearing of costs are governed by section 18 of the Certification Agreement. Records are safeguarded until the end of the retention period.

These Rules are drawn up in German and English. In the event of discrepancies, the German version prevails.