ISO Certification Companies: The 2026 Guide for AI-Era Buyers

Key takeaways

  • ISO does not certify anyone. Independent certification bodies audit your management system and issue the certificate; accreditation bodies (UKAS, ANAB, DAkkS, RvA, COFRAC, Accredia, ENAC and others) supervise those certification bodies.
  • The global ISO certification market is concentrated around BSI, SGS, Bureau Veritas, TUV, DNV, Intertek, LRQA, NQA, Schellman and Kiwa. Five of them hold roughly 28 to 32 percent of total revenues, with SGS and Bureau Veritas alone accounting for nearly 36 percent of certificate volume.
  • ISO/IEC 42001 (Artificial Intelligence Management System) is the new dividing line. Only a handful of certification bodies are fully accredited for it today: BSI (UKAS, RvA, ANAB), Schellman (ANAB), DNV, and NQA (UKAS, ANAB) lead the pack.
  • On 1 January 2026, IAF and ILAC merged into the Global Accreditation Cooperation Incorporated (GAC). The multilateral recognition (MLA) regime continues unchanged for end customers, but the legal entity behind it is new.
  • The lead auditor matters more than the brand on the certificate. Match the auditor’s industry track record to your stack (cloud-native SaaS, AI vendors, medical devices, regulated finance) before you sign.
Brass precision caliper symbolizing ISO certification companies and audit accreditation rigor

What “ISO certification companies” actually means

When a buyer types iso certification companies into Google, three different needs collide. Some are looking for a list of organizations that hold ISO certificates, so they can verify a supplier’s claim. Others want a certification body (also called a registrar) to audit them. A smaller group is trying to understand the certification ecosystem before deciding which standard to pursue. This guide is built for the last two, because that is where strategic decisions are made.

ISO is the International Organization for Standardization, based in Geneva. It publishes the standards (ISO 9001 for quality, ISO 14001 for environment, ISO 27001 for information security, ISO/IEC 42001 for AI management systems) but it does not certify anyone. The iso.org explainer is explicit: ISO does not perform certification or issue certificates, and it does not permit anyone to use the ISO logo in connection with certification.

The certification act itself is performed by external certification bodies, governed by the conformity assessment standard ISO/IEC 17021-1. Those bodies are in turn supervised by national accreditation bodies, governed by ISO/IEC 17011. That two-step independence is what gives an ISO certificate its weight in tenders, audits, and regulatory dossiers.

The regulatory framing is now also explicit in European AI law. The EU AI Act defines a conformity assessment body as “a body that performs third-party conformity assessment activities, including testing, certification and inspection” (Article 3(21)), and conformity assessment itself as “the process of demonstrating whether the requirements set out in [Chapter III, Section 2] have been fulfilled” (Article 3(20)). For high-risk AI providers, the same vocabulary now sits inside binding legislation, not just industry standards.

The four-tier hierarchy: ISO, accreditation bodies, certification bodies, certified organizations

Most articles that rank for this query skip the structure. It is worth a paragraph because it dictates which company you actually want to call.

Tier 1: ISO. Publishes the standards. Owns the trademarks. Does not certify, does not accredit.

Tier 2: Accreditation bodies. One per country, broadly. UKAS in the United Kingdom, ANAB in the United States, DAkkS in Germany, COFRAC in France, Accredia in Italy, ENAC in Spain, RvA in the Netherlands, IPAC in Portugal, JAS-ANZ in Australia and New Zealand, INMETRO in Brazil. Their job is to confirm that a certification body operates according to ISO/IEC 17021-1 and is competent in a specific scope (for example, ISO 27001 audits in financial services, or ISO/IEC 42001 audits for generative AI providers).

Tier 3: Certification bodies. These are the “ISO certification companies” in the strict sense. BSI, SGS, Bureau Veritas, TUV SUD, TUV Rheinland, DNV, Intertek, LRQA, NQA, Schellman, Kiwa, plus several hundred smaller, sector-focused or geography-focused firms. They send auditors, they review your management system, they issue the certificate.

Tier 4: Certified organizations. The clients of Tier 3. The IAF CertSearch database, hosted at iafcertsearch.org, lets anyone verify whether a specific company holds a specific certificate from a specific certification body under a specific accreditation. Use it before you trust a supplier’s certificate page.

The IAF and ILAC, which historically ran the multilateral recognition arrangements that make a UKAS certificate valid in Brazil and vice versa, merged into the Global Accreditation Cooperation Incorporated (GAC) on 1 January 2026. For practical purposes nothing changes overnight, but contracts and tender documents drafted after that date should now reference GAC instead of IAF.

The leading ISO certification companies in 2026

The list below is filtered through three lenses: global accreditation footprint, breadth of standards covered, and readiness for ISO/IEC 42001. We name the entity, the standards they are most known for, the accreditation bodies that back them, and the practical reason an enterprise might or might not pick them.

BSI Group

The British Standards Institution is the United Kingdom’s national standards body and a top-five global certification body. It holds UKAS, RvA, and ANAB accreditations, which gives certificates issued by BSI immediate recognition across the United Kingdom, the European Union, and North America. BSI was the first certification body in the world to be UKAS-accredited for ISO/IEC 42001, according to its own AI Management System page. For organizations whose roadmap stacks ISO 27001, ISO 27701, and ISO/IEC 42001, BSI is the cleanest one-stop option.

SGS Group

The Geneva-headquartered SGS is the largest testing, inspection, and certification company on the planet by revenue, with roughly 19 percent of global ISO certificate volume according to industry market sizing reports. It maintains accreditations from UKAS, ANAB, DAkkS, COFRAC, Accredia and dozens of national bodies. SGS is the safe choice for multinational rollouts where every regional subsidiary needs a local certificate that is mutually recognized.

Bureau Veritas

The French peer of SGS, with roughly 17 percent of global certificate volume. Strong in industrial sectors (energy, automotive, construction, marine) and increasingly active in management system certification for digital and data-intensive businesses. Bureau Veritas has a dedicated AI assurance practice and is expanding its ISO/IEC 42001 capacity, though regional accreditation coverage is still maturing.

TUV (TUV SUD, TUV Rheinland, TUV Nord)

The three TUV entities are sister organizations that compete in the same market. They dominate the DACH region (Germany, Austria, Switzerland) and are accredited by DAkkS, ANAB and others. TUV SUD and TUV Rheinland are the most active of the three in AI assurance services. They are typically the first call for industrial manufacturing customers and for any organization with a heavy German-language audit need.

DNV

A Norwegian foundation with a strong technical reputation, particularly in maritime, energy, healthcare and life sciences. DNV is an accredited third-party certification body for ISO/IEC 42001, per its own service page, and tends to deploy auditors with deeper engineering backgrounds than the average Tier-1 firm.

Intertek

UK-headquartered, broad sectoral footprint, strong in consumer products, electronics, and supply chain assurance. Holds UKAS, ANAB and many regional accreditations. Less visible than BSI in AI-specific narratives but a credible alternative for organizations that already use Intertek for product testing.

LRQA

Formerly Lloyd’s Register Quality Assurance, LRQA is UKAS-accredited and especially well-positioned in maritime, energy, food safety and supply chain. Its audit style leans toward operational rigor rather than documentation gymnastics.

NQA

A UK-based certification body that punches above its weight in tech-sector ISO 27001 audits and is UKAS- and ANAB-accredited for ISO/IEC 42001 according to its AI Management System page. NQA is a credible challenger to BSI for ISO 27001 plus 42001 combined audits, often at a meaningfully lower price point.

Schellman

A US-headquartered firm that became the first ANAB-accredited certification body for ISO/IEC 42001 in the United States, per Schellman’s AI governance page. For North American AI vendors, Schellman is the natural starting shortlist because of that early-mover position and because the firm is already deeply embedded in SOC 2, HIPAA, and ISO 27001 work for the same customer profile.

Kiwa NV

A Dutch certification body with deep RvA accreditation and a specialist footprint in construction, agriculture, energy, and food chain. Picked here because it represents a credible “non-Big-Five” alternative for organizations operating primarily in continental Europe.

ISO/IEC 42001: the AI standard reshaping the certification landscape

Published in December 2023, ISO/IEC 42001:2023 is the first international management system standard dedicated to artificial intelligence. Like ISO 27001 for information security, it specifies the policies, processes, controls, and continuous improvement loops an organization must implement to govern its AI systems through their lifecycle.

From 2024 through 2026, national accreditation bodies have rolled out their assessment programs at different speeds. UKAS, RvA, and ANAB were the early movers; DAkkS, COFRAC, Accredia and others are catching up. The ANAB ISO/IEC 42001 program page maintains the live list of US-accredited certification bodies; the equivalent UKAS register covers the United Kingdom.

The European Union dimension matters too. CEN-CENELEC is preparing the harmonized European standards that will eventually allow a presumption of conformity with the AI Act, including draft work referenced as prEN 18228 and prEN 18282. Those drafts are confidential while in development, but their existence means that whichever certification body invests now in ISO/IEC 42001 capacity is also building the team that will deliver AI Act conformity assessments later.

The practical takeaway: the certification body shortlist for AI-heavy organizations in 2026 is shorter than the generic SERP suggests. Confirm that the accreditation scope explicitly lists ISO/IEC 42001, not just “AI services,” before signing. The IAF CertSearch entry should mention the standard by ID.

How to choose your certification body

Five criteria, in the order experienced compliance leaders apply them:

  1. Accreditation for the exact standard, by a GAC MLA signatory. Check the certification body’s accreditation certificate, not its marketing page. Confirm the scope statement includes the management system standard you need (for example, ISO/IEC 42001:2023) and the sector codes that match your business. This is the only criterion that is non-negotiable.
  2. The lead auditor, not the brand. Ask which auditor will run the certification audit. Read their LinkedIn profile. Look for industry experience in your sector, not just years of audit work generally. As one industry roundup notes, excellent audits can come from budget certification bodies with stellar auditors, while disappointing audits can come from premium bodies with inexperienced ones.
  3. Geographic coverage. If you operate across jurisdictions, confirm the certification body can audit your subsidiaries with the same scope, or has reciprocal arrangements with sister organizations under the GAC MLA. A patchwork of single-country certificates is a procurement headache.
  4. Existing audit overlap. If your team already runs SOC 2, HIPAA, PCI DSS, or ISO 27001 audits with a given firm, adding ISO/IEC 42001 to that engagement often produces a lower combined effort and a cleaner evidence trail. Multi-standard certifiers (BSI, SGS, Bureau Veritas, NQA, Schellman) are designed for this.
  5. Cost and timeline, last. Typical first-year ISO 27001 audit fees range from USD 15,000 to 40,000 for a mid-sized SaaS organization; ISO/IEC 42001 first-year audits run higher, USD 20,000 to 50,000, because the standard is newer and auditor supply is thinner. Recertification audits happen every three years with annual surveillance in between.

What the EU AI Act says about conformity assessment

The EU AI Act bridges the long-standing ISO conformity assessment vocabulary into binding European law. Three definitions matter for any organization choosing a certification body in 2026.

Article 3(20) defines conformity assessment as “the process of demonstrating whether the requirements set out in [Chapter III, Section 2] have been fulfilled” (artificialintelligenceact.eu/article/3/).

Article 3(21) defines a conformity assessment body as “a body that performs third-party conformity assessment activities, including testing, certification and inspection”. Those bodies, when notified under the AI Act regime, will assess high-risk AI systems before they are placed on the EU market.

Article 3(24) defines the CE marking as “a marking by which a provider indicates that an AI system is in conformity with the requirements set out in Chapter III, Section 2 and other applicable Union legislation”.

Notified bodies under the AI Act are not the same legal entity as ISO certification bodies, but the skill set, the audit methodology, and in many cases the parent group overlap heavily. BSI, TUV SUD, Bureau Veritas, DNV and SGS all have notified-body arms in other CE-marking domains and are positioning for AI Act notification. An organization that picks a certification body with both an ISO/IEC 42001 accreditation and an AI Act notified-body application in flight buys optionality: one auditor relationship, two regulatory regimes.

Where AI Sigil fits in your certification journey

AI Sigil is not a certification body. It is the governance platform you run before the auditor walks in. Customers use it to inventory every AI system in their organization, map it to the controls required by ISO/IEC 42001, NIST AI RMF, and the EU AI Act, attach evidence to each control, and generate the audit-ready report the certification body actually reviews.

The practical effect: a Tier-1 certification body audit that would normally take 8 to 12 weeks of evidence gathering shrinks to the audit itself, because every artefact is already structured the way ISO/IEC 17021-1 auditors expect. AI Sigil customers typically pick their certification body from the list above based on accreditation and industry fit, then arrive at the engagement with their AI inventory, risk register, control mapping, and evidence pack already exportable.

The platform deliberately stops short of being an auditor. The independence between the organization under audit, the governance tool, and the certification body is exactly what makes the certificate worth something downstream.

FAQ

Does ISO itself certify companies? No. ISO publishes the standards but does not perform certification or issue certificates. Independent certification bodies, supervised by national accreditation bodies, do the audits and grant the certificates. ISO is explicit about this on its own certification page.

What is the difference between accreditation and certification? Certification is the third-party assurance that a specific organization’s management system meets a specific ISO standard. Accreditation is the formal recognition that the certification body issuing those certificates is itself competent and impartial. An ISO certificate from a non-accredited body is technically valid but carries little weight in tenders or regulatory dossiers.

Which is the largest ISO certification body? By issued-certificate volume, SGS leads with roughly 19 percent of the global market, followed by Bureau Veritas at around 17 percent. By revenue, the top five (SGS, Bureau Veritas, Intertek, TUV SUD, BSI) collectively hold 28 to 32 percent of the worldwide ISO certification services market.

How much does ISO certification cost? First-year ISO 27001 audits for a mid-sized SaaS organization typically range from USD 15,000 to 40,000, with annual surveillance audits and a recertification every three years. ISO/IEC 42001 first-year audits run 20 to 50 thousand US dollars depending on scope, geography, and auditor seniority. Multi-standard combined audits (for example, ISO 27001 plus ISO 27701 plus ISO/IEC 42001) reduce the per-standard cost by 15 to 30 percent when delivered by the same certification body.

Can the same body certify me to ISO 27001 and ISO/IEC 42001? Yes, if the certification body holds accreditation for both. BSI, NQA, Schellman, DNV, and several of the larger Tier-1 firms are accredited for both. A combined engagement is usually faster and cheaper than two separate ones because the evidence base overlaps substantially.

Who replaced IAF in 2026? The International Accreditation Forum (IAF) and the International Laboratory Accreditation Cooperation (ILAC) merged into the Global Accreditation Cooperation Incorporated (GAC) on 1 January 2026. The multilateral recognition arrangements (formerly the IAF MLA and ILAC MRA) now operate under GAC. Existing certificates remain valid and mutual recognition continues unchanged for end customers.

Conclusion

The phrase iso certification companies hides three different buyer journeys, but the answer for any of them comes back to the same short list. Pick a certification body that is accredited by a GAC MLA signatory for the exact standard you need, match the assigned lead auditor’s industry experience to your stack, and confirm that the body has either an ISO/IEC 42001 accreditation today or a credible roadmap for one. The market is large, but the credible shortlist for AI-era buyers is small: BSI, SGS, Bureau Veritas, TUV SUD, DNV, Intertek, LRQA, NQA, Schellman, and Kiwa cover roughly 95 percent of the demand worth shortlisting. AI Sigil sits one step earlier in the journey, turning your AI inventory into the evidence pack any of those auditors will want to see on day one.

China AI Regulation in 2026: Filings, Labels and Liability

China AI regulation explained for foreign firms: CAC filings, AI content labels, companion AI rules, 2026 enforcement and the evidence to keep ready.

CCPA Regulations 2026: ADMT, Risk Assessments and Audits

The CCPA regulations in force since January 2026 add ADMT duties from 1 January 2027, risk assessment filings in 2028 and audits to 2030. Dates and evidence.

What Is Adversarial AI? Attacks, Defenses & Governance

Adversarial AI attacks ML models through poisoning, evasion and prompt injection. See the attack types, defenses, and governance controls the EU AI Act now requires.

California AI Laws: Who Must Comply, and by When

California AI laws explained by role and date: SB 53, SB 942, SB 243, CCPA ADMT, FEHA rules and the bills Newsom signed in September 2026.

TRAIGA Compliance: The Texas AI Law, Operationalized

TRAIGA has been in force since January 2026. What the Texas AI law prohibits, how the NIST AI RMF safe harbour works, and the evidence you need to rely on it.

Vendor Due Diligence for AI: 12 Questions Checklists Miss

Standard vendor due diligence was built for a pre-AI supply chain. Here are the 12 AI-specific questions to add, and the legal duty behind them.