Skip to main content
Category: Certification and Accreditation

International Accreditation Forum

Also known as: IAF, IAF, International Accreditation Forum (IAF)
Simply put

The International Accreditation Forum (IAF) was the world association of conformity assessment accreditation bodies, the organizations that oversee and accredit the certification bodies issuing certificates such as ISO/IEC 27001. According to the evidence, the IAF ceased operations as of 1 January 2026, and its former website is now maintained for archival and reference purposes. Practitioners verifying the legitimacy of a certification body's accreditation should confirm the current arrangements in place after that date, as they may differ from historical IAF processes.

Formal definition

The IAF was described in the evidence as the world association of Conformity Assessment Accreditation Bodies, with a stated main function of developing a worldwide framework for accreditation activities; historically this supported mutual recognition among accreditation bodies so that certifications (including management system certifications such as ISO/IEC 27001) issued under one accredited body could be recognized across jurisdictions. The evidence indicates the IAF is no longer operational as of 1 January 2026, with its former web resources (including the CertSearch database, accreditation body listings, and recognised-AB pages) retained on an archival site. Because the provided evidence does not itself detail the successor structure or the current operational status of tools such as CertSearch beyond the archival notice, GRC professionals and auditors should independently confirm the current accreditation-verification arrangements and the live status of any certificate-verification service before relying on them; the specific successor organization and the current custodianship of these functions are not established within this evidence packet and should be verified against authoritative current sources.

Why it matters

For anyone relying on ISO/IEC 27001 certificates, the accreditation chain behind a certificate is what gives it credibility. A certification body issues the certificate, but that body must itself be accredited by a recognized accreditation body. Historically, the International Accreditation Forum (IAF) served as the world association of conformity assessment accreditation bodies, developing a worldwide framework for accreditation activities that supported mutual recognition so that a certificate issued under one accredited body could be recognized across jurisdictions. Understanding this structure matters because it is the mechanism that lets a compliance manager or auditor distinguish a meaningfully accredited certificate from an unaccredited one.

The practical significance has shifted because, according to the evidence, the IAF is no longer operational as of 1 January 2026, and its former website is now retained for archival and reference purposes. This means practitioners cannot assume that historical IAF processes and web resources still operate the way they once did. Because the IAF underpinned cross-border recognition of management system certifications, any GRC professional performing vendor due diligence, verifying a supplier's ISO 27001 certificate, or assessing the legitimacy of a certification body's accreditation should confirm which arrangements are currently in force rather than relying on the former IAF structure by default.

The key risk here is treating an archival reference as a live verification service. A certificate that appears valid may need to be checked against whatever current accreditation-verification arrangements have replaced IAF's historical functions. The provided evidence establishes only that the IAF has ceased operations and that its site is archival; it does not itself detail the successor structure or the live status of any verification tool. Practitioners should therefore independently confirm the current custodianship of accreditation-verification functions against authoritative current sources before relying on any single tool or listing.

Who it's relevant to

GRC and compliance managers performing vendor due diligence
When assessing a supplier's ISO/IEC 27001 certificate, compliance managers historically relied on the IAF-supported recognition framework to confirm that the issuing certification body was accredited. Because the evidence indicates the IAF ceased operations on 1 January 2026, these professionals should confirm the current accreditation-verification arrangements and the live status of any verification service before treating a certificate as validly accredited, rather than depending on former IAF processes or archived resources.
Auditors and assessors verifying accreditation chains
Auditors who trace the accreditation chain behind a certificate, from certified organization to certification body to accreditation body, need to know that the IAF is no longer operational as of 1 January 2026 and that its former web pages are archival. When verifying whether a certification body's accreditation is legitimate, they should independently confirm the current arrangements against authoritative current sources rather than relying on historical IAF listings that may no longer reflect live status.
Certification bodies and accreditation bodies
Organizations that issue or oversee certifications operated within the worldwide accreditation framework the IAF developed to support mutual recognition. With the IAF no longer operational as of 1 January 2026, these bodies and their clients should confirm the current custodianship of former IAF functions and any replacement recognition arrangements, since the specific successor structure is not established within this evidence and should be verified directly.
Security and procurement teams relying on certificate verification tools
Teams that check certificate validity through online verification services should be cautious about treating former IAF web resources as live tools, since the evidence states they are maintained for archival and reference purposes only. Before relying on any certificate-verification database, these teams should confirm its current operational status and custodianship against authoritative current sources, because the evidence packet does not establish the live status of such tools beyond the archival notice.

Inside IAF

International Accreditation Forum (IAF)
A former global association of accreditation bodies and other bodies interested in conformity assessment. In the context of ISO/IEC 27001 certification, the IAF's role related to fostering mutual recognition of accreditation so that certifications issued under one accredited body would be recognised across jurisdictions.
IAF Multilateral Recognition Arrangement (MLA)
A peer-evaluated arrangement historically operated by the IAF under which signatory accreditation bodies mutually recognised each other's accreditations, supporting cross-border acceptance of certificates such as those issued against ISO/IEC 27001. The arrangement was intended to reduce duplication of accreditation across markets.
Accreditation bodies vs. certification bodies
Accreditation bodies (the members addressed by IAF-related arrangements) assess and accredit certification bodies; certification bodies in turn audit and certify organisations' management systems. An ISO/IEC 27001 certificate is issued by an accredited certification body, not by the IAF itself.
Transition to Global Accreditation Cooperation Incorporated (Global ACI)
Public sources indicate that Global Accreditation Cooperation Incorporated was established to replace both IAF and ILAC as of 1 January 2026, consolidating the functions previously carried out by those bodies. Practitioners should confirm current governance arrangements against official sources, as the structure is transitional.
CertSearch verification database
A database used to verify the validity of accredited certifications. Per IAF GA Resolution 2025-11, ownership of the IAF CertSearch database was transferred to Global ACI, which now operates it as a live verification tool that continues to be updated, rather than as an archived resource.

Common questions

Answers to the questions practitioners most commonly ask about IAF.

Is the IAF CertSearch database no longer maintained or just kept as an archive?
CertSearch is not merely an archived resource. Ownership of the IAF CertSearch database was transferred to Global Accreditation Cooperation Incorporated (Global ACI), which operates it as a live verification tool that continues to be updated. If you need to verify the accreditation status behind a certificate, you should treat CertSearch as an active resource under its current operator rather than assuming it is frozen or historical.
Did the IAF simply cease operations without anything taking its place?
No. Rather than leaving a gap, public sources indicate that Global Accreditation Cooperation Incorporated replaced both the IAF and ILAC as of 1 January 2026. When you encounter references to IAF functions, such as its multilateral recognition arrangements, you should check whether responsibility for those functions now sits with Global ACI, since the successor structure carries forward the mutual-recognition role rather than discontinuing it.
How do I verify that an ISO 27001 certificate was issued under a recognised accreditation body?
In most cases you can confirm the accreditation chain by checking the certificate against the CertSearch database now operated by Global ACI, and by confirming that the certification body's accreditation body participates in the applicable multilateral recognition arrangement. Depending on the certificate, you may also verify the certification body's status directly with its national accreditation body. Bear in mind this confirms accreditation and scope of the certificate, not the day-to-day security posture of the certified organisation.
Where should I point vendor-management or procurement teams to check a supplier's certificate?
Point them to the live CertSearch tool operated by Global ACI as the primary lookup, supplemented by the certification body's own register where available. Advise them to record the certificate scope, the ISMS boundary, and the applicable ISO/IEC 27001 version, since a certificate covers only the defined scope of the ISMS and not the whole supplier organisation. This distinction typically matters most when the certified scope is narrower than the service you are procuring.
During an audit, how should I document reliance on accreditation-body recognition?
Retain evidence of the verification you performed, for example, the CertSearch record, the certificate itself, the certification body, and its accreditation body, along with the date checked. Because responsibility for the recognition arrangements has moved to Global ACI, note the source you relied upon so the reference remains traceable over time. This documentation supports your due-diligence record but does not, by itself, substitute for reviewing the certified organisation's own controls where your scope requires it.
Does confirming accreditation-body recognition tell me whether a supplier is actually secure?
No. Confirming recognition establishes that the certification was issued through an accredited chain and that the certificate is genuine within its stated scope. It does not guarantee freedom from breaches, nor does it attest to controls outside the ISMS scope. For a fuller assurance picture you would typically review the Statement of Applicability, the certificate scope, and, where relevant, complementary evidence such as a SOC 2 report, keeping in mind that satisfying one framework does not automatically satisfy the other.

Common misconceptions

The IAF issues ISO/IEC 27001 certificates.
The IAF did not issue certificates. ISO/IEC 27001 certificates are issued by accredited certification bodies; the IAF's role related to mutual recognition arrangements among accreditation bodies. Certification is issued by an accredited certification body, and any related recognition arrangement is a separate matter.
The IAF continues to operate its recognition arrangement and CertSearch as before.
Public sources indicate Global Accreditation Cooperation Incorporated replaced both IAF and ILAC as of 1 January 2026, and that ownership of the CertSearch database was transferred to Global ACI, which now operates it. Practitioners should treat present-tense references to IAF operations with caution and verify current arrangements against official sources.
CertSearch is now only an archival reference and no longer usable for verification.
According to the transfer described in IAF GA Resolution 2025-11, the CertSearch database is operated by Global ACI and continues to be updated as a live verification tool, not merely an archived resource.

Best practices

Verify the accreditation status of a certification body and the validity of an ISO/IEC 27001 certificate using the CertSearch database now operated by Global ACI, rather than relying solely on a certificate document.
Confirm current governance and recognition arrangements against official sources, as Global Accreditation Cooperation Incorporated was reported to replace both IAF and ILAC as of 1 January 2026 and the structure is transitional.
Distinguish clearly between accreditation bodies and certification bodies when assessing a supplier's ISO/IEC 27001 certificate, and confirm that the certification body is accredited.
When citing recognition arrangements or database ownership, reference the specific resolution or official announcement (for example IAF GA Resolution 2025-11) rather than assuming prior arrangements remain unchanged.
Avoid treating an ISO/IEC 27001 certificate as evidence beyond the defined scope of the ISMS it covers, and confirm the scope statement when relying on the certificate.
Re-check the currency of any verification or recognition status periodically, since ownership, operation, and governance of these arrangements have recently changed and may continue to evolve.