IAF Multilateral Recognition Arrangement (MLA)
The IAF Multilateral Recognition Arrangement (MLA) is an agreement among accreditation bodies that lets accredited certifications and validation/verification statements issued in one country be recognized in others. Its goal is to support world trade by reducing technical barriers, so that a certification does not have to be repeated in each market. It works toward the principle of being certified once and accepted everywhere within the arrangement.
The IAF MLA is a multilateral arrangement through which signatory accreditation bodies mutually recognize each other's accredited certifications and validation/verification statements. According to IAF, it consists of a five-level arrangement (with levels 2 and 3 among those defined) and relies heavily on the MLAs of Recognized Regional Accreditation Groups. By facilitating mutual recognition among signatories, the arrangement contributes to the facilitation of world trade by eliminating technical barriers, and IAF works toward a single system of recognition. Accreditation Body Members must declare their common intention to join the arrangement. The scope of recognition depends on the specific levels and scopes to which an accreditation body is a signatory; recognition under the MLA pertains to accredited conformity assessment outputs and does not extend beyond the arrangement's defined scopes.
Why it matters
For organizations pursuing ISO/IEC 27001 certification, the value of the certificate depends heavily on the credibility of the accreditation chain behind it. The IAF MLA underpins that credibility by enabling accredited certifications issued in one country to be recognized by signatory accreditation bodies in others. In practice, this means a certificate issued under an accreditation body that is a signatory to the arrangement can carry weight across markets without the underlying certification having to be repeated in each jurisdiction, which is central to the arrangement's stated goal of facilitating world trade by eliminating technical barriers.
This matters most when compliance evidence crosses borders. A vendor certified in one region may need its certificate accepted by customers, regulators, or partners elsewhere; the MLA is the mechanism that supports 'certified once, accepted everywhere' within the arrangement's defined scope. Understanding whether a certification body's accreditation traces to an MLA signatory helps GRC teams assess whether a supplier's ISO 27001 certificate is likely to be recognized rather than treated as an unaccredited or self-declared claim.
It is important to note the boundaries of what the MLA does. Recognition under the arrangement pertains to accredited conformity assessment outputs and does not extend beyond the arrangement's defined levels and scopes. Being covered by the MLA speaks to the recognition of a certification's accreditation, not to the substantive security posture of any given organization; a certificate still attests only to the defined scope of the ISMS and does not, on its own, guarantee freedom from breaches.
Who it's relevant to
Inside IAF MLA
Common questions
Answers to the questions practitioners most commonly ask about IAF MLA.