Certification Standards
We publish, separately and clearly, the standards covered by our international accreditations and those we certify under our own scheme.
Standards within our IAS / UAF accreditation
- ISO 9001IAS accredited
Quality Management Systems
The foundational international standard. It confirms that an organisation has a consistent way of working that delivers products and services of dependable quality.
- ISO 14001IAS accredited
Environmental Management Systems
Confirms that an organisation identifies the environmental impact of its activities, complies with the law, and reduces that impact over time.
- ISO 45001UAF accredited
Occupational Health and Safety Management Systems
Confirms that an organisation identifies hazards in advance and manages them, so that people are not injured or made ill by their work.
- ISO 37001IAS accredited
Anti-Bribery Management Systems
Confirms that an organisation has identified where bribery could occur in its business and has controls, reporting channels and investigation procedures in place.
- ISO/IEC 27001UAF accredited
Information Security Management Systems
Confirms that an organisation knows what information it holds, what could go wrong with it, and has chosen and applied controls accordingly.
Standards certified under our own scheme
The standards below are not covered by the IAS or UAF accreditation scopes. ITS certifies them under its own scheme. We state this clearly so that you can verify exactly what is accredited.
- ISO 22000Own scheme
Food Safety Management Systems
Confirms that everyone in the food chain — growers, processors, packers, transporters and caterers — controls the hazards that could make food unsafe.
- ISO 22716Own scheme
Cosmetics — Good Manufacturing Practices
The international standard for how cosmetics must be made — hygiene, premises, equipment, raw materials and records.
- ISO 13485Own scheme
Medical Devices — Quality Management Systems
Confirms that a medical device organisation controls design, manufacture and traceability to the level regulators require.
- ISO 22301Own scheme
Business Continuity Management Systems
Confirms that an organisation can keep its critical activities running — or restore them quickly — through disruption such as disaster, outage or system failure.
- ISO 10002Own scheme
Quality Management — Customer Satisfaction / Complaints Handling
Confirms that an organisation receives, handles and learns from customer complaints rather than letting them disappear.
- ISO 21001Own scheme
Educational Organizations — Management Systems (EOMS)
Confirms that an educational organisation designs, delivers and evaluates learning that genuinely benefits learners. It is the successor to the withdrawn ISO 29990.
- ISO 37301Own scheme
Compliance Management Systems
Confirms that an organisation has identified every law, regulation, contract term and internal rule it must observe, and manages compliance with them.
- ISO 50001Own scheme
Energy Management Systems
Confirms that an organisation knows where its energy goes, measures it properly, and reduces consumption in a way that can be verified.
- ISO/IEC 42001Own scheme
Artificial Intelligence Management Systems
The world's first certifiable management system standard for artificial intelligence. It confirms that AI is developed, supplied and used responsibly.
- ISO/IEC 27701Own scheme
Privacy Information Management Systems
Confirms that an organisation manages personal information — where it comes from, where it is held, who it is shared with, and when it is deleted. **Since the 2025 revision it can be certified on its own, without ISO/IEC 27001.**
- ISO/IEC 20000-1Own scheme
IT Service Management Systems
Confirms that an organisation delivers IT services at the level it promised, and restores them by a defined procedure when they fail.
- ISO/IEC 27017Own scheme
Cloud Services Information Security
Sets out who is responsible for what between cloud provider and cloud customer, and the security controls that follow. Certified as an extension of ISO/IEC 27001.
- ISO/IEC 27018Own scheme
Protection of PII in Public Clouds
Sets out what an organisation must do when it **processes other people's personal information** in a public cloud. Certified as an extension of ISO/IEC 27001.
Certifying more than one standard
ISO standards overlap considerably. An integrated audit of several standards reduces both audit duration and cost, and lets you keep a single set of documents. Tell us which standards you are considering and we will advise on the combination when we issue the quotation.
Request a Quote