Skip to main content
Category: Certification and Accreditation

IAF Multilateral Recognition Arrangement (MLA)

Also known as: IAF MLA, IAF Multilateral Recognition Agreement, Multilateral Recognition Arrangement, IAF MLA arrangement
Simply put

The IAF Multilateral Recognition Arrangement (MLA) is an agreement among accreditation bodies that lets accredited certifications and validation/verification statements issued in one country be recognized in others. Its goal is to support world trade by reducing technical barriers, so that a certification does not have to be repeated in each market. It works toward the principle of being certified once and accepted everywhere within the arrangement.

Formal definition

The IAF MLA is a multilateral arrangement through which signatory accreditation bodies mutually recognize each other's accredited certifications and validation/verification statements. According to IAF, it consists of a five-level arrangement (with levels 2 and 3 among those defined) and relies heavily on the MLAs of Recognized Regional Accreditation Groups. By facilitating mutual recognition among signatories, the arrangement contributes to the facilitation of world trade by eliminating technical barriers, and IAF works toward a single system of recognition. Accreditation Body Members must declare their common intention to join the arrangement. The scope of recognition depends on the specific levels and scopes to which an accreditation body is a signatory; recognition under the MLA pertains to accredited conformity assessment outputs and does not extend beyond the arrangement's defined scopes.

Why it matters

For organizations pursuing ISO/IEC 27001 certification, the value of the certificate depends heavily on the credibility of the accreditation chain behind it. The IAF MLA underpins that credibility by enabling accredited certifications issued in one country to be recognized by signatory accreditation bodies in others. In practice, this means a certificate issued under an accreditation body that is a signatory to the arrangement can carry weight across markets without the underlying certification having to be repeated in each jurisdiction, which is central to the arrangement's stated goal of facilitating world trade by eliminating technical barriers.

This matters most when compliance evidence crosses borders. A vendor certified in one region may need its certificate accepted by customers, regulators, or partners elsewhere; the MLA is the mechanism that supports 'certified once, accepted everywhere' within the arrangement's defined scope. Understanding whether a certification body's accreditation traces to an MLA signatory helps GRC teams assess whether a supplier's ISO 27001 certificate is likely to be recognized rather than treated as an unaccredited or self-declared claim.

It is important to note the boundaries of what the MLA does. Recognition under the arrangement pertains to accredited conformity assessment outputs and does not extend beyond the arrangement's defined levels and scopes. Being covered by the MLA speaks to the recognition of a certification's accreditation, not to the substantive security posture of any given organization; a certificate still attests only to the defined scope of the ISMS and does not, on its own, guarantee freedom from breaches.

Who it's relevant to

GRC and compliance managers
Teams managing an organization's ISO/IEC 27001 certification benefit from understanding whether their certification body's accreditation traces to an MLA signatory, since this affects whether the resulting certificate is likely to be recognized across the markets where the organization operates.
Vendor risk and third-party assessment teams
When evaluating suppliers' ISO 27001 certificates, these teams can use the MLA framework to assess whether a certificate is backed by an accreditation body that participates in mutual recognition, and within which defined scopes that recognition applies.
Organizations operating across multiple markets
Businesses that need a single certification to be accepted by customers, partners, or regulators in different countries rely on the MLA's goal of mutual recognition to reduce the need to repeat certification in each jurisdiction, within the arrangement's defined scopes.
Certification and accreditation bodies
Bodies seeking to have their accredited outputs recognized internationally must engage with the arrangement's structure, including declaring their common intention to join, and operate within the levels and scopes to which they are signatories.

Inside IAF MLA

Multilateral Recognition Arrangement
An arrangement among accreditation bodies, coordinated through the International Accreditation Forum (IAF), under which signatories agree to recognize the equivalence of each other's accreditation activities, supporting the principle that a certification issued once should be accepted broadly.
Accreditation Bodies as Signatories
The parties to the arrangement are national or regional accreditation bodies that accredit certification bodies. The MLA operates at the accreditation-body level rather than directly among certification bodies or certified organizations.
Scope of Recognition
Recognition applies to defined scopes, which may include management system certification such as ISO/IEC 27001. The specific scopes covered by a given signatory depend on what that accreditation body has been peer-evaluated for, so coverage varies and should be verified.
Peer Evaluation Basis
Signatory status is established and maintained through evaluation against agreed criteria, providing the underlying assurance that accreditation practices are performed to a comparable level among participants.
Chain of Confidence
The arrangement supports a chain linking the accreditation body, the certification body it accredits, and the certified organization, so that an ISO/IEC 27001 certificate issued under an MLA-recognized accreditation carries wider credibility.

Common questions

Answers to the questions practitioners most commonly ask about IAF MLA.

Does the IAF MLA mean an ISO 27001 certificate is automatically recognized in every country?
Not exactly. The IAF MLA supports cross-border recognition of certifications issued by certification bodies accredited by member accreditation bodies, so an ISO/IEC 27001 certificate issued under an MLA-covered accreditation scope is intended to be accepted internationally without re-certification. However, recognition depends on the certification being within the specific scope covered by the MLA and on the accreditation body being a signatory. Individual customers, regulators, or contracts may still impose their own acceptance requirements, so recognition in practice can vary.
Does the IAF MLA apply to a SOC 2 report the same way it applies to an ISO 27001 certificate?
No. The IAF MLA relates to accredited certifications, such as ISO/IEC 27001 issued by an accredited certification body. A SOC 2 report is an attestation examination performed by a licensed CPA firm under the AICPA's SSAE 18 standard, not an accredited certification, so it falls outside the IAF MLA framework. The two operate under different oversight structures, and the MLA's recognition mechanism does not extend to SOC 2 attestation reports.
How can we verify that our certification body's accreditation is covered by the IAF MLA?
Typically you would confirm that the certification body is accredited by an accreditation body that is a signatory to the IAF MLA, and that the accreditation covers the relevant scope, such as management system certification for ISO/IEC 27001. This information is usually available from the accreditation body and reflected on the certificate or accreditation mark. Where the specific coverage is unclear, it is advisable to request confirmation from the certification body rather than assume the MLA applies.
If a vendor presents an ISO 27001 certificate, how does the IAF MLA affect our acceptance decision?
The IAF MLA can give you additional assurance that a certificate issued under an MLA-covered accreditation was assessed against consistent international standards, which may reduce the need to independently re-verify the certification body's competence. However, you should still review the certificate's defined ISMS scope, since the certification covers only the boundaries stated. The MLA supports recognition of the accreditation, not a guarantee that the vendor's scope matches your specific requirements.
Does the IAF MLA guarantee that a certified organization is free from security incidents?
No. The IAF MLA concerns the recognition of accredited certifications across borders; it does not attest to an organization's security outcomes. An ISO/IEC 27001 certificate confirms that an ISMS meeting the standard's requirements was assessed within a defined scope at the time of the audit, and it does not guarantee freedom from breaches. The MLA does not change this limitation.
Should we require that a certificate be issued under an IAF MLA-covered accreditation in our vendor contracts?
In many engagements organizations prefer certificates issued under accreditation covered by the IAF MLA because it supports consistent international recognition, but whether to require it depends on your risk tolerance and the assurance you need. Some organizations accept certifications from bodies outside the MLA after additional due diligence. It is generally advisable to specify your expectations regarding accreditation and ISMS scope in contract language rather than assuming a universal standard applies.

Common misconceptions

The IAF MLA certifies organizations or issues certificates directly.
The MLA is an arrangement among accreditation bodies and does not certify organizations. ISO/IEC 27001 certificates are issued by accredited certification bodies against the ISMS requirements in clauses 4 through 10, with Annex A reference controls selected via a Statement of Applicability; the MLA only supports mutual recognition of the accreditation behind that certification.
MLA recognition means every certificate is automatically accepted everywhere for every purpose.
Recognition applies within the scopes for which a signatory has been evaluated and covers only the defined scope of the certified ISMS. Acceptance in practice can still depend on the accepting party's requirements, so coverage should be verified rather than assumed to be universal.
The IAF MLA also governs recognition of SOC 2 reports.
SOC 2 is an attestation examination performed by a licensed CPA firm under the AICPA SSAE 18 standard, resulting in a report rather than a certification. It is not an accredited certification and therefore falls outside the accreditation-based recognition mechanism the IAF MLA supports.

Best practices

Confirm that the certification body issuing an ISO/IEC 27001 certificate is accredited by an accreditation body that is a signatory to the IAF MLA for the relevant management system scope.
Verify that the MLA recognition applies to the specific scope you rely on, since a signatory's recognized scopes vary and coverage should not be assumed to be universal.
Check the defined scope of the certified ISMS on the certificate, as recognition extends only to what that scope covers.
Trace the chain of confidence from accreditation body to certification body to certified organization when evaluating the credibility of a certificate.
Do not treat MLA recognition of an ISO/IEC 27001 certificate as equivalent to, or interchangeable with, a SOC 2 report, since the two arise from different frameworks and recognition mechanisms.
Retain qualified language when representing MLA recognition to stakeholders, noting that acceptance can still depend on the accepting party's requirements.