The Components of a Credible Conformity Assessment Scheme

11/10/2026

A conformity assessment scheme (CAS) is more than a standard. The standard sets the normative requirements. The scheme decides who assesses conformity, how, how often, what happens when things go wrong and what certified clients may claim. When schemes fail, the cause is rarely the technical requirements. It is usually a missing or weak component around them.

These are the ten components I look for when reviewing a scheme.

1. Scope, intended outcomes and strategies

A credible scheme starts from a documented context assessment: the issues and risks in its sector and geography, and where it can realistically make a difference. From this the scheme owner defines the scheme's scope, its intended outcomes and impacts, and the strategies it will use to achieve them.

Check: Can you explain why your scheme covers what it covers, and what change it is meant to deliver?

2. Governance and stakeholder engagement

The scheme owner needs clearly defined decision-making bodies, documented decisions and safeguards against any single interest dominating. Decisions on the content of the standard should aim for consensus within a balanced and diverse group, including those directly affected. Stakeholders should have real opportunities to give input, with active efforts to reach under-represented groups.

3. The standard and its normative requirements

Requirements for the object of conformity assessment (a product, process, service, management system or person) must be clear and auditable, and must include compliance with applicable statutory and regulatory requirements. Vague requirements produce inconsistent assessments, however good the auditors are.

Check: Could two auditors read the same requirement and reach the same verdict?

4. The conformity assessment system and system alignment

The scheme owner must choose a conformity assessment model that fits the scheme: its intended impacts, its audience and the claims it allows. That means certification, verification or another model, with defined audit frequency, sampling, grading of nonconformities and certification decisions. The choice should be documented and justified, and ideally tested before full roll-out. This is what the IAF-ISEAL guidance calls system alignment.

5. Conformity assessment bodies and their oversight

Which conformity assessment bodies (CABs) may operate the scheme, and on what conditions? That usually means accreditation by an accreditation body (AB) to ISO/IEC 17065 or ISO/IEC 17021-1, plus a licence agreement with the scheme owner. Accreditation alone is not enough. The scheme owner needs its own oversight: performance indicators, review of reports and decisions, witness assessments, data shared with ABs and a clear escalation path for underperforming CABs.

6. Competency

The scheme owner must ensure that its own personnel are competent in the issues the scheme covers. It must also define competency requirements for the key personnel of its partner CABs and ABs. Regular auditor calibration keeps the standard applied consistently across countries and CABs. Calibration is often the first thing cut when budgets are tight, and the first weakness evaluators find.

7. Claims and communications

What may a certified client say, on which products, and with which logo? Claims and communications, both the scheme owner's own and those it allows clients to make, must be clear, relevant and accurate. They must also be substantiated: consistent with the scheme's scope, the standard, the conformity assessment model and the available performance data. Logo licensing agreements and market monitoring make this enforceable.

8. Integrity and risk management

A credible scheme expects misuse and is designed to catch it. That takes a risk management plan for threats to the scheme's integrity, including a policy of association for clients, partners and CABs whose practices undermine the scheme. It also takes an open, accessible dispute resolution system for complaints and grievances, and a sanctions framework applied consistently.

9. Monitoring, evaluation and data

The scheme owner should monitor and evaluate whether the scheme delivers its intended outcomes, how effective it is and whether it causes unintended negative effects. This relies on data management systems that collect, analyse and protect data, from audit results to CAB performance.

10. Learning, improvement and transparency

Finally, the scheme must learn. Findings from monitoring and evaluation, stakeholder input and emerging trends should feed documented revisions of the standard and scheme components, so the scheme stays fit for purpose. Key information should be public and easy to find: scope and intended outcomes, the rationale for the conformity assessment model, the dispute resolution process and monitoring reports.

How the components fit together

These components work as a system. A strong standard with weak CAB oversight produces certificates the market cannot trust. Strict sanctions without an accessible dispute resolution system are rarely triggered. Good data without governance to act on it changes nothing. When I review a scheme, the most useful question is not "is each component present?" but "does each one feed the others?"

Where to start

If you own or manage a scheme, map your current documents against these ten components. Gaps usually show up quickly, typically in system alignment, CAB oversight, competency and monitoring and evaluation. These are also the areas that accreditation bodies, benchmarking organisations and regulators look at first.

Are you preparing your scheme for accreditation or benchmarking, or looking for support with CB oversight? Let's talk.

Further reading: IAF and ISEAL, Key Elements of Sustainability Conformity Assessment Schemes (July 2024).

ISEAL, Credibility Principles.