HomeSearch

Lenses
Business lenslens
Certifying body lenslens
End user / data subject lenslens
Front-line staff lenslens
Government lenslens
Human rights / privacy advocate lenslens
Policymaker (Government lens)lens
Regulator / enforcer (Government lens)lens
Africa
Egyptplanned
Ghanaplanned
Kenyaplanned
Moroccoplanned
Nigeriaplanned
Rwandaplanned
South Africaplanned
Asia-Pacific
Australiaplanned
Chinadrafting
Hong Kongplanned
Indiaplanned
Indonesiaplanned
Japanplanned
Malaysiaplanned
New Zealandplanned
Philippinesplanned
Singaporeplanned
South Koreaplanned
Thailandplanned
Vietnamplanned
Europe
European Uniondrafting
Switzerlandplanned
Türkiyeplanned
United Kingdomplanned
Latin America
Argentinaplanned
Brazilplanned
Chileplanned
Colombiaplanned
Peruplanned
Uruguayplanned
Middle East
Bahrainplanned
Israelplanned
Qatarplanned
Saudi Arabiaplanned
United Arab Emiratesplanned
North America
Canadaplanned
Mexicoplanned
United States (federal)drafting
United States
Californiadrafting
Coloradoplanned
Connecticutplanned
Delawareplanned
Floridaplanned
Indianaplanned
Iowaplanned
Kentuckyplanned
Marylandplanned
Minnesotaplanned
Montanaplanned
Nebraskaplanned
New Hampshireplanned
New Jerseyplanned
Ohioplanned
Oregonplanned
Rhode Islandplanned
Tennesseeplanned
Texasplanned
Utahplanned
Virginiaplanned
Menu

Certifying body

What is the scope of what we are attesting to.

Handbook §64 · 28 sections

Drafting material: not yet published or verified for publication. States what the sources say; not legal advice.

64.1 /

What this handbook is

The certifying body lens, assembled from the fifteen six-lens blocks that carry one.

A difficulty to state at the outset. This is the most consistently critical lens in the document, and this handbook is written for the reader it criticises. Softening it would make it useless; writing it as an attack would make it unreadable by the person who could act on it.

The resolution, and it is the one the lens blocks themselves adopt. The criticism is structural rather than about conduct. Section 26.15 records the base case — a body paid by the entity it assesses, in a market that rewards a clean opinion — and that is a description of an arrangement, not an accusation about anyone operating within it. Sections 64.20 to 64.24 are what an honest body can do inside those constraints, and section 64.25 records what no single body can fix alone.

What this handbook adds. The findings are scattered across eleven volumes and each block treats one context. Assembling them shows that the same three problems recur everywhere — scope, competence and liability — and that a fourth, scarcity, is specific to AI and changes the analysis rather than deepening it.

Vol. 42 · §64.1 · Currency 2026-09-03 · drafting

64.2 /

The reader this is written for

Five kinds of body, and the analysis differs.

A management system certification body, accredited under the ordinary route, certifying against a published standard. Sections 22.5 to 22.11 and section 22.21.

A data protection certification body, accredited under the specific Article 43 route against criteria approved by a supervisory authority. Sections 26 and 19.

A conformity assessment body for AI, and section 64.14 records that at the currency date there are essentially none.

And an assessor in an unregulated assurance market, per section 64.15, who has no accreditation, no approved criteria and no register — which section 43.22 records is the position of the bias-audit market in the United States.

And a monitoring body for a code of conduct, treated alongside the others because the role is adjacent and the finding about it is favourable. Section 38.14 records codes as accountability instruments and section 28.5 records the comparative result: codes produced more than certification did, and the reason given is that a code has a sponsoring body with an interest in adoption.

Why that matters to a reader of this handbook. Section 26.15’s finding is that public control of criteria is necessary and not sufficient, and that a public stake in the outcome is what determines whether a scheme produces anything. A code’s sponsoring body supplies a stake that certification lacks — it wants the code adopted, which means it wants the code to be worth adopting. Section 64.25 records that no action available to a certification body creates that stake; the code route is the one structure in Part IV where something like it exists.

Its limits. A monitoring body accredited to supervise a code is subject to the same scope, competence and liability problems at sections 64.5, 64.12 and 64.17. The difference is in who set the criteria and why, not in how they are applied.

What all five share. Someone pays them to say whether something is adequate.

What differs, and it matters for who can act. The first three and the fifth sit inside a chain with an accreditation layer above them; the assessor in an unregulated market does not, and section 64.15 records the consequence.

Vol. 42 · §64.2 · Currency 2026-09-03 · drafting

64.3 /

The chain, and where it has integrity

Stated before the criticism, because it is true and is routinely omitted.

The chain, from the top. Section 53.21: an international committee drafts a standard. National bodies vote and adopt it. Accreditation bodies accredit certification bodies against it. Certification bodies audit organisations.

Where the chain has real integrity, per section 20.17. National accreditation bodies are single, not-for-profit and non-competing by law — precisely so that the conflict at section 64.4 does not reach that level. That is a deliberate design feature and it works. A certification body cannot shop for a more permissive accreditor within its jurisdiction, because there is only one.

Why that matters for what follows. The conflict this handbook describes sits at the certification level and not above it. A body reading section 64.4 should not conclude that the whole structure is compromised; it should notice that the layer above it is the one part of the arrangement designed to resist exactly this pressure, and section 64.24 records what follows from that.

The one qualification. Section 25.15: no scheme recognises any other. The integrity is real within each chain and there is no coordination between them, which section 64.11 records is acute for destruction.

Vol. 42 · §64.3 · Currency 2026-09-03 · drafting

64.4 /

The conflict, stated exactly

Section 26.15 is the base case and every other block builds on it.

The arrangement. The body is paid by the entity it assesses, and the market rewards a clean opinion.

Why that is a structural statement rather than an accusation. No individual assessor need do anything improper for the effect to operate. It works through client selection, scope negotiation, and the commercial consequence of being the body that fails people. Section 64.25 records why no single body can opt out.

Where the document records it operating hardest. Section 64.5 for scope. Section 36.16 for destruction, which section 64.11 records as the purest available form.

The internal-audit version, so a reader recognises it elsewhere. Section 38.12 records that internal audit reports to management and management is accountable for the compliance being audited — the in-house form of the same arrangement. Section 38.12’s mitigations are the same ones available here: a reporting line that does not run through the assessed party, and external validation periodically. Neither eliminates the conflict.

What this handbook does not claim. That certification is worthless. Section 64.6 records what it does attest to, and section 57.10 records three legitimate uses.

Vol. 42 · §64.4 · Currency 2026-09-03 · drafting

64.5 /

Scope

Section 20.17 records it as the decision with the most consequence and the least visibility, and every other block agrees.

Who decides it. The client. Section 53.21 records the general position and section 62.12 the commercial one: a narrower scope is cheaper to achieve and produces a cleaner opinion, which suits both parties.

Why it is invisible. Section 22.24 records how to read a certificate and section 22.26 scope in practice. The scope statement is on the certificate and is rarely read. Section 20.17’s end-user lens records that a seal conveys that somebody checked something and nothing more.

Where the document records scope becoming an integrity problem, and the instances are worth reading together.

Transfers, per section 19.29: in a transfer context the scope that matters is the processing of the imported data at the importer, and it is trivially easy to define a scope that excludes the difficult part.

Accountability, per section 38.16: a management system certificate attests that a system for managing compliance exists and operates. It does not attest that the processing is lawful. Those are different objects and the market treats the first as evidence of the second.

Destruction, per section 36.16: a certificate covers the media handed over, not the data. The scope of what was destroyed is defined by the customer’s inventory, and the customer’s inventory is the thing most likely to be wrong.

AI, per section 40.40: a notified body assesses the quality management system and the technical documentation, not the system as deployed, in the deployer’s context, on the deployer’s data — which are the conditions under which harm occurs.

Vol. 42 · §64.5 · Currency 2026-09-03 · drafting

64.6 /

What a certificate attests to

Stated plainly, because a body that cannot say this precisely cannot defend its work.

That a defined set of requirements was assessed against a defined scope at a point in time, by a competent assessor, following a defined procedure, and the requirements were met.

That is a real statement and it has value. Section 57.10 records three legitimate uses: as a build reference, as evidence of care in an enforcement matter or a claim, and as a way to shorten a customer’s diligence.

What it also does, which is under-stated. Section 20.17’s business lens records that remediation before assessment is usually the largest cost and is the item that produces the actual security benefit. The certificate is the occasion; the improvement is real and happens before the assessment.

And section 39.7 records that adherence is a factor an authority may take into account when setting a penalty. That is a genuine consequence and it is worth saying to a client.

Vol. 42 · §64.6 · Currency 2026-09-03 · drafting

64.7 /

What a certificate cannot attest to

Section 57.11 gives the generalisation and it is the sharpest sentence available to this reader.

Where an obligation specifies an outcome at a level, a framework can require that the organisation address it and cannot require that it achieve it.

The instances. A standard can require oversight to be defined, assigned and documented, per section 57.7. It cannot require it to work, and section 55.13 records that the failure mode is a role that is defined, assigned, documented and unable to function. A standard can require performance to be evaluated. It cannot require a declared accuracy level on a stated population, which section 40.20 does.

What follows for a certificate. It cannot attest that processing is lawful, per section 38.16. It cannot attest that a system is safe. It cannot attest to an outcome it did not observe, which section 64.11 records is the whole of the destruction case.

And it is not a defence. Section 38.14: adherence is evidence, not a defence. A certified organisation processing unlawfully is processing unlawfully.

The AI-specific limit worth telling a client. Section 27.7: a presumption of conformity requires a cited harmonised standard, and section 53.14 records that none of the frameworks organisations actually hold is one.

Vol. 42 · §64.7 · Currency 2026-09-03 · drafting

64.8 /

The auditability paradox

Section 38.16 states it and it is the most useful analytical idea in this handbook.

Accountability is simultaneously the most auditable and the most fakeable stage in the lifecycle. Most auditable because it consists of documents that can be requested and read. Most fakeable because documents are cheap to produce and their quality is assessable only by someone who understands the underlying processing well enough to know what the assessment should have found.

What a competent assessor would have to do, per section 38.16. Select processing operations, establish independently what they involve, and test the record entry and the impact assessment against that.

What is typically done instead. Confirm that a record exists, that assessments were conducted for the operations the organisation identified as requiring them, and that the policy set is complete.

Section 38.16’s assessment of that, and it is the line to sit with. The typical approach tests the apparatus against itself, and section 38.15’s failure mode — a complete apparatus over absent substance — is invisible to it by construction.

Why this is not solvable by working harder. The independent establishment of what an operation involves is expensive, is not what the engagement was priced for, and produces findings the client did not expect. Section 64.25 records the market problem that follows.

Vol. 42 · §64.8 · Currency 2026-09-03 · drafting

64.9 /

The stages that audit well

Worth knowing, because a body that is clear about where its work is strong can be clear about where it is not.

Acquisition, and section 30.28 records it as unusually auditable. Most of it is externally visible. Whether a notice exists, contains the required content and is served at the required time. Whether the consent interface presents refusal as easily as acceptance, which is observable and testable. Whether withdrawal works and propagates. Whether the record at section 30.25 exists. Whether mandatory fields correspond to stated purposes.

Why that matters beyond the audit. Section 30.28’s regulator lens records that acquisition dominates enforcement records for the same reason: it is the stage assessable without entering the organisation. An assessor and a supervisory authority are looking at the same surface.

Security controls, where the control either operates or does not and the evidence is technical.

Documented process generally, where the question is whether the documented thing happens.

The common property. The assessor can observe the thing itself rather than a record of it. Section 64.10 records what happens when they cannot.

Vol. 42 · §64.9 · Currency 2026-09-03 · drafting

64.10 /

The stages that do not

Three, and they fail differently.

Destruction, where there is nothing to look at. Section 36.16: the outcome is an absence, and section 64.11 treats it.

Accountability, where there is a great deal to look at and looking is not assessing. Section 64.8.

Lawfulness, which is not an assessment question at all. Section 55.8 records that training data governance covers fitness for purpose and not lawfulness, and section 57.5 records that no framework asks whether the organisation was allowed to have the data, because lawfulness is a legal determination and management system standards do not make legal determinations. A body asked to certify that processing is lawful should decline, per section 64.23.

And a fourth that is specific to AI. Section 40.40: an assessment cannot establish how a model behaves across the distribution it will meet in deployment, because that distribution is unknown at assessment time and section 40.22 records that the system may continue to learn.

Vol. 42 · §64.10 · Currency 2026-09-03 · drafting

64.11 /

Destruction: the limit case

Section 36.16 records the purest form of every problem in this handbook, and a body doing destruction work should read this section before any other.

The chain, and it does not connect. Section 36.16: destruction assurance runs through information security management certification, specialist media destruction certification and facility accreditation, and cloud provider assurance reports. No route recognises another.

The scope problem in its sharpest form. A certificate covers the media handed over, not the data. A certificate accurately stating that forty drives were destroyed says nothing about the forty-first that was never collected, the replica in the warehouse, or the abandoned system at section 36.11. The assessor has no independent means of establishing what should have entered the process.

Why the conflict is worse here than anywhere else, and section 36.16 states it precisely. In ordinary certification the customer could in principle check the assessed thing and chooses not to. Here the customer cannot check even in principle, so the conflict is not mitigated by any residual possibility of detection. Section 36.16 records that a provider quietly reselling drives instead of shredding them would be discovered only by accident, and that there have been such cases.

What an honest body does about it, per section 36.10. Serial numbers of individual items, not a count or a weight. The method and achieved level. The date of destruction, not the date of collection, and the gap between them. The facility. A named signatory.

And the two failure modes section 36.10 names. Weight-based certificates, which cannot be reconciled to an inventory. And certificates issued on collection, which certify a plan.

Vol. 42 · §64.11 · Currency 2026-09-03 · drafting

64.12 /

Competence

Section 26.15 records it as where certification is weakest generally, and the problem is not effort.

The general form. Assessing whether a thing was done to an adequate level requires understanding the thing. Section 38.16 records that assessing whether an impact assessment reached a defensible conclusion requires substantive privacy judgement, not conformity checking.

Where it is acute. Section 36.16: assessing whether a cryptographic erase actually removed the key, or whether a firmware sanitise command was honoured, requires knowledge of storage technology, firmware behaviour and cryptography that is not part of a privacy or management systems auditor’s ordinary training. Section 36.16 records what happens instead: the auditor checks that a policy exists, that a procedure matches it, and that certificates are on file — an audit of documentation presented as an audit of destruction.

The honest response, and section 64.22 develops it. State what you did not assess. A scope statement that records the boundary of competence is more useful to a customer than one that implies coverage the assessment did not have.

Vol. 42 · §64.12 · Currency 2026-09-03 · drafting

64.13 /

The AI competence problem

A new competence requirement in an established market, and section 40.40 records it as genuinely new rather than an extension.

What it requires. Section 40.40: sectoral bodies certifying medical devices, machinery or vehicles under section 40.12 must acquire machine learning competence to assess an AI component.

Why that is harder than it sounds. The existing competence is in the sector — the device, the machine, the failure modes. The new competence is in a technique that behaves differently: section 40.22 records the attack surfaces, section 54.11 records that they are attacks on the statistical behaviour of a model rather than on a system’s confidentiality, integrity or availability, and section 55.11 records that a conventional security programme does not address them.

And section 40.40 records the assessment gap that competence alone does not close. Even a fully competent assessor cannot establish how a model behaves across the deployment distribution. Section 64.10.

What a body should not do. Assert coverage it cannot deliver. Section 27.13 records what an AI conformity claim is worth and section 64.26 records what to tell a customer.

Vol. 42 · §64.13 · Currency 2026-09-03 · drafting

64.14 /

Where there are no certifiers at all

Section 40.40 states the distinctive feature of the AI regime and it inverts the usual analysis: the problem is scarcity before it is conflict.

The position. Section 27.6: no notified bodies designated. Section 27.7: no harmonised standard cited. Section 27.5: the resulting deadlock — the route out of third-party assessment requires standards that did not exist, and the route into it requires bodies that did not exist.

And section 27.4 records that it may not matter for most systems. Internal control is the default route for the entire Annex III category, so the provider assesses itself whether or not bodies exist.

Why scarcity makes the conflict worse rather than better, per section 40.40. Where few bodies are designated, each holds relationships with the providers it assesses and there is little competitive discipline from the possibility of a second opinion.

What a body entering this market should understand about its position. Section 40.40: a deployer relying on a CE mark is relying on something that, for most Annex III systems, means the provider assessed itself. A designated body’s work is therefore a minority of the assessments in the market, and its value depends on being visibly different from self-assessment. Section 64.20 records how.

Vol. 42 · §64.14 · Currency 2026-09-03 · drafting

64.15 /

The unregulated assurance market

Section 43.22 records the American position and it is the case with the fewest safeguards examined anywhere.

The one mandated assessment. The independent bias audit at section 9.14. Section 43.22 records it as the closest thing in the United States to a required third-party AI assessment, and its design has none of the safeguards Part IV examined: no accreditation requirement for auditors, no approved methodology, no register of who is qualified, no supervisory approval of criteria, and no public body with an interest in the outcome.

Why section 43.22 assesses it as worse than the position at section 26.15. European certification is conflicted because the body is paid by the entity it assesses. Here the auditor is paid by the employer and there is not even public control of the criteria — so the assessed party influences both who assesses and what is assessed.

What the market optimises, per section 43.22. The observable output is a published summary. A buyer cannot distinguish a rigorous auditor from a permissive one, so competition operates on the summary rather than on the assessment.

And section 9.14 records the enforcement finding that governs the whole market. A state auditor concluded that enforcement of the mandate was ineffective after nearly three years. Section 43.22’s conclusion: where the mandate is not enforced, the audit’s value rests entirely on the reputational interest of the parties, and the party choosing the auditor is the party being audited.

Vol. 42 · §64.15 · Currency 2026-09-03 · drafting

64.16 /

Criteria: who writes them

Section 53.21 records the conflict one level above everything else in this handbook, and a certification body is downstream of it rather than responsible for it.

The mechanism. Section 53.15: a standard acquires the force of law through five routes and only one involves a legislature. Section 27.7: where a statute states an outcome and a standard states what satisfies it, the standard is the operative rule.

Who writes them. Section 53.16: national standards body delegations, funded and staffed substantially by industry, because standards bodies are membership organisations whose subscribers are the companies the standards govern.

Section 53.21’s statement of the conflict, and it is prior to section 64.4’s. Not an assessor paid by the assessed, but criteria drafted by the parties the criteria will govern. Section 53.21 adds the comparison: a conflicted assessor applying independent criteria is a lesser problem than an independent assessor applying criteria the assessed wrote.

Where the data protection route differs, and it is a real difference. Section 26.15 records that Article 42 criteria are approved by a public authority rather than by a private scheme owner, and section 19.29 records that this changes the work — the object is processing operations rather than a management system. Section 26.15’s finding is that public control of criteria is necessary and not sufficient: what determined the outcome in section 25’s authorisation schemes was a public stake, and section 26.15 records that the approving authority there does not participate in the market it approves criteria for.

Vol. 42 · §64.16 · Currency 2026-09-03 · drafting

64.17 /

Liability

The shortest section and the one with the clearest shape.

What a certificate says about liability. Section 36.16: certificates disclaim, and contractual liability is typically capped at the value of the service — which is small relative to the loss a failure would cause.

Where the economic exposure sits. With the customer. Section 36.16: the exposure sits with the controller and the assurance sits with the provider, which is the wrong way round and is not correctable by negotiation, because no destruction provider will accept breach-scale liability at destruction-scale pricing.

What the customer has against the body. Section 40.40: the CE mark carries the provider’s declaration, not the body’s guarantee. Section 57.11 and section 62.18: a customer relying on a supplier’s certificate has no recourse against the certifier.

And at the top of the chain. Section 53.21: a standards body bears none. It does not warrant that a standard is adequate and is not liable to anyone who relies on it.

Section 53.21’s summary, which is the sentence to carry. The chain has liability at the bottom and none at the top.

Vol. 42 · §64.17 · Currency 2026-09-03 · drafting

64.18 /

Evidence sufficiency

The practical question underneath everything at sections 64.8 to 64.13: what evidence is enough.

The general answer this document supports. Evidence of process is sufficient for a process obligation and insufficient for an outcome obligation. Section 57.11.

Which means the assessor’s first question is which kind the requirement is. A requirement that a risk assessment be conducted is a process requirement and a completed assessment evidences it. A requirement that a system achieve a declared accuracy is an outcome requirement and no document evidences it — section 56.8 records that the test is whether the declared performance matches a document somebody can produce, and section 64.7 records that the framework cannot require the level in any event.

The three evidence failures the document records.

Accepting the assessed party’s own scoping. Section 64.5 and section 36.16: the scope of what was destroyed is defined by an inventory the assessor cannot verify.

Accepting documentation as evidence of the thing documented. Section 64.8.

And accepting a count where an identification is required. Section 36.10: weight-based destruction certificates cannot be reconciled to an inventory.

Vol. 42 · §64.18 · Currency 2026-09-03 · drafting

64.19 /

Sampling

Section 36.15 records it as the only technique that tests outcome rather than process, and that almost nobody does it.

What it is. Checking. Examine media that was reported sanitised. Query a system reported purged. Attempt to retrieve a record reported deleted.

Section 36.15’s assessment. It is the single highest-value assurance activity available at that stage precisely because everything else is process evidence.

Why almost nobody does it. It costs more than reading a certificate. It is not what the engagement was priced for. And it produces findings.

Where else it applies, because section 36.15 records it for destruction and the logic generalises. Section 58.8 records what internal audit should test and it is the same technique: sample systems and trace each to a register entry; sample overrides and check what happened to them; sample a declared accuracy and ask for the document behind it. Section 56.14 gives a test and a failure sign per control family.

The recommendation for a body that wants its work to mean something. Offer sampling as a distinct, separately priced activity. It is the clearest way to be visibly different from a documentation review, and section 64.14 records that visible difference from self-assessment is where a designated body’s value lies.

Vol. 42 · §64.19 · Currency 2026-09-03 · drafting

64.20 /

What an honest body can do about scope

The first of four constructive sections, and scope is where a body has the most control.

Write the scope statement to be read by someone who was not in the room. Section 22.24 records how to read a certificate; most scope statements are written to satisfy the accreditation requirement rather than to inform a third party.

State what is excluded, not only what is included. A scope that lists inclusions leaves a reader to infer the boundary, and section 62.12 records that customers infer coverage from the existence of a certificate.

Refuse a scope that excludes the material risk. Section 19.29 records the transfer case: it is trivially easy to define a scope that excludes the difficult part. A body that certifies a scope carefully drawn around the problem has produced a document that is accurate and misleading.

And record the boundary of competence in it, per section 64.12 and section 64.22.

Why this is available to an individual body when other things are not. Scope is negotiated per engagement. Section 64.25 records that unilateral standard-raising costs clients; a clear scope statement costs nothing and differentiates the body’s product.

Vol. 42 · §64.20 · Currency 2026-09-03 · drafting

64.21 /

What an honest body can do about evidence

Second, and it follows section 64.18 and section 64.19.

Ask for the artefact, not the policy. Section 55.27 records that each control family produces exactly one primary artefact and names it. An organisation that cannot produce the artefact has not built the family, and asking for it is a one-question test.

Use section 56.14’s failure signs, which are observable without an audit. If every classification register entry has the same date, the trigger is not wired. If the override rate is zero, section 55.13 records that this is an answer.

Sample. Section 64.19.

Test the apparatus against something other than itself. Section 64.8: select operations, establish independently what they involve, and test the documentation against that. This is the expensive recommendation in this handbook and it is the one that distinguishes an assessment from a review.

And record what the evidence did not establish. A report that says what was tested and what was not is more useful, and more defensible, than one that implies uniform coverage.

The evidence question specific to AI, because section 64.13’s competence problem has an evidential half.

What can be evidenced. That an evaluation was run, on a stated dataset, with a stated methodology, producing stated numbers. That is a process and it evidences well.

What cannot. Section 40.20 requires performance to be declared on the persons or groups the system is intended to be used on. Section 55.7 records that establishing this requires attribute data the organisation may not hold, and section 56.7 that an organisation which never collected the attribute cannot test for bias on it.

Which produces a specific finding an assessor should be prepared to write. A declared accuracy with no disaggregation, from an organisation that does not hold the attribute data, is not a failure of the evaluation — it is a limit of what the organisation can evidence at all. Recording it as such is more accurate than recording a non-conformity, and more useful than recording nothing.

Vol. 42 · §64.21 · Currency 2026-09-03 · drafting

64.22 /

What an honest body can do about competence

Third, and it is mostly about saying so.

State what you did not assess and why. Section 64.12: an auditor without cryptographic competence who checks that a policy exists and certificates are on file has done a documentation review, and calling it that is accurate rather than damaging.

Do not accept engagements outside competence. Section 64.13 records the AI case: a sectoral body assessing a machine learning component is assessing something its accreditation scope may not have covered.

Build the competence or partner for it. Section 55.11 records that adversarial security is owned by security with model engineering and by neither alone; the assessment side has the same shape.

And be specific in the report about the limit at section 64.10 — that no assessment establishes how a model behaves across the deployment distribution. A customer told this once will not misread the certificate later.

Vol. 42 · §64.22 · Currency 2026-09-03 · drafting

64.23 /

Refusing and withdrawing

Fourth, and it is the power a body most rarely uses.

Refusing. Section 64.10: a body asked to certify that processing is lawful should decline, because lawfulness is a legal determination. A body asked to certify an outcome it cannot observe should decline or restate the engagement as a process assessment.

Withdrawing. Section 20.17 records that a supervisory authority may require a certification body to withdraw a certification and may withdraw accreditation. The body’s own power to withdraw is prior to that and is exercisable without anyone asking.

The diagnostic worth applying internally. How many certificates has this body withdrawn? Section 55.13 records the equivalent test for human oversight — a review process that has never changed an outcome is evidence rather than reassurance — and section 40.40 records the same logic. A body that has never withdrawn one has either an exceptional client base or a threshold nobody reaches.

The commercial reality, stated rather than hidden. Withdrawal costs the client relationship. Section 64.25 records why that is a market problem and not a character problem, and why the answer is at the accreditation and criteria level.

What to do on finding something serious, which is the operational question a body actually faces and which this handbook has not yet answered.

The first distinction. A non-conformity against the criteria is the body’s own business — it is graded, it produces a corrective action, and it is resolved or the certificate does not issue. Something unlawful is not, and section 64.10 records that lawfulness is a legal determination the body is not making.

What a body can do, and the powers are its own. Refuse to issue. Suspend. Withdraw, per section 64.23. Narrow the scope so the certificate does not speak to what was found — which is legitimate and must be visible, per section 64.20, because a silently narrowed scope conceals the finding rather than recording it.

Where a reporting route exists. Under the Article 43 route the body operates under supervisory authority oversight, and section 20.17 records that the authority may require a certification to be withdrawn and may withdraw accreditation. The relationship is supervisory rather than advisory, which means the authority is a route.

Where none exists, which is most of the time. Section 64.15 records the unregulated market: no accreditation, no register, no supervisory body. A finding there has nowhere to go except to the client.

The uncomfortable case, stated because the handbook would be dishonest without it. A body that finds evidence of a serious ongoing harm, in a scheme with no supervisory route, has a client obligation of confidence and no external obligation at all. Section 64.17 records that it also bears no liability for staying silent. This document does not resolve what such a body should do, and it records that the absence of any route is a feature of the scheme design rather than of the body’s choices.

The rest of the lifecycle, which section 22.25 records and which is where most of a body’s actual work sits.

Surveillance. Periodic assessment between certification and recertification, at reduced scope. The commercial pressure here is the inverse of the initial assessment’s: the relationship exists, the fee is smaller, and the incentive is to confirm rather than to look. Section 64.19’s recommendation applies with most force at surveillance, because it is where sampling costs least relative to what it can find.

Recertification, on the cycle the scheme sets, and section 26.15 records the Article 42 position at three years.

And the transition problem, which section 22.9 records and which a body should expect to recur. When a standard is revised, existing certificates are valid against the old version for a stated period and then expire. Section 22.9 records certificates that did. A body’s obligation is to tell clients early enough for the transition to be planned, and the commercial temptation is to leave it late enough that the transition assessment is unavoidable.

What a client should be able to see across the whole cycle. Which version. What scope. When it expires, and against what. Section 22.24 records how to read a certificate and section 64.26 what to say.

Vol. 42 · §64.23 · Currency 2026-09-03 · drafting

64.24 /

Participation in criteria development

The highest-leverage action available to a certification body and the one this document records as most under-used.

Section 26.15 and section 19.29 record it: participation in criteria development is open, is low-cost, and is where the standard is actually set.

Why a certification body is unusually well placed. Section 53.16 records that civil society presence in standards and criteria drafting is thin because participation requires sustained funding of specialist staff. A certification body already employs those people and is already in the room.

And it has an interest that diverges from the assessed party’s. Section 64.8 records that vague criteria make an assessment unfalsifiable and therefore commercially weightless. A body that wants its certificate to mean something has a direct commercial interest in criteria that are specific enough to fail against.

What to argue for, and the document supplies the list. Criteria that specify outcomes with levels rather than activities, per section 64.7 — accepting section 57.11’s limit that a framework cannot require achievement, criteria can at least require the level to be stated and evidenced. Sampling requirements, per section 64.19. Scope statement content requirements, per section 64.20. And published methodology, which section 43.22 records the unregulated market entirely lacks.

The comparison worth carrying. Section 53.21’s advocate lens identifies standards participation as the single highest-leverage and least-used item in the advocacy toolkit. A certification body arguing for demanding criteria is arguing for the same thing from inside the room.

Vol. 42 · §64.24 · Currency 2026-09-03 · drafting

64.25 /

The problem no single body can fix

Stated because sections 64.20 to 64.24 would otherwise read as though individual virtue were sufficient, and it is not.

The market problem. A body that unilaterally raises its standard loses clients to one that does not. Section 64.4 records the mechanism and section 43.22 records the market where it operates without any constraint: a buyer cannot distinguish a rigorous auditor from a permissive one, so competition operates on the observable output.

Which means the fixes are structural and sit above the individual body. At the accreditation level, which section 20.17 records has real integrity because national accreditation bodies are single, not-for-profit and non-competing by law. At the criteria level, per section 64.24. And at the supervisory level — section 20.17 records that authorities may set additional accreditation requirements, require withdrawal of a certification, and withdraw accreditation.

What that means for an individual body reading this handbook. Sections 64.20 to 64.23 are available to it now and will not change the market. Section 64.24 is the one that might, and it operates through a body that is already funded to be in the room.

And the honest limit. Section 26.15’s finding is that public control of criteria is necessary and not sufficient, and that a public stake in the outcome is what determines whether a scheme produces anything. No action available to a certification body creates that stake.

Vol. 42 · §64.25 · Currency 2026-09-03 · drafting

64.26 /

What to tell a customer

A short list, because most misunderstanding of certificates is created at the point of sale rather than at the point of use.

What the scope covers, and what it excludes. Section 64.20.

That it is evidence and not a defence. Section 38.14 and section 62.18.

That it attests to the requirements assessed, not to lawfulness. Sections 38.16 and 64.7.

What was not assessed, and why. Sections 64.12 and 64.22.

For AI specifically, and section 27.4 makes this unavoidable. That for most high-risk systems the default conformity route is self-assessment, so a CE mark on such a system means the provider assessed itself — and that a third-party assessed mark is indistinguishable from it on the product. A body doing genuine third-party work should say so explicitly, because nothing on the mark does.

And that none of the frameworks a customer is likely to hold carries a presumption of conformity, per section 27.7 and section 53.14.

The question a customer will actually ask, and it deserves a prepared answer: I already hold one certificate — does it cover this?

The general answer. Section 25.15: no scheme recognises any other. Section 22.28 records the integrated management system as the practical response — one set of arrangements assessed against several standards — which reduces the assessment cost and does not make one certificate stand for another.

The specific answer for AI, and section 57.9 makes it unusually clear. There is no Full cell in the coverage table. The most AI-specific certifiable standard covers four of the six control families partially and two not at all. A general security certificate covers one partially and five not at all, and section 62.18 records that treating it as AI coverage is the most common misreading in the area, because it is the certificate most organisations hold.

The part of that answer which is favourable and should not be omitted. Section 62.18 records the qualification: the extensions tell a different story. For incident response and vendor management, an organisation holding a general security certificate has genuinely built the control — those are the only two Full cells anywhere in the crosswalk — and the AI work is to extend it rather than to build it.

What a body should therefore be able to say in one sentence. Which of the customer’s obligations this certificate speaks to, which it touches partially, and which it does not reach at all — and section 54.19’s five genuinely new obligations are the dividing line, because no existing certificate helps with them.

Vol. 42 · §64.26 · Currency 2026-09-03 · drafting

64.27 /

The honest assessment

Three propositions.

The criticism is structural and the structure has one part that works. Section 64.3: the accreditation layer is single, not-for-profit and non-competing by law, precisely so the conflict does not reach it. That is the part of the arrangement designed to resist the pressure, and section 64.25 records that the available fixes run through it.

The same three problems recur in every context and a fourth is specific to AI. Scope, competence and liability, at sections 64.5, 64.12 and 64.17. And scarcity, at section 64.14, which inverts the analysis: for AI the problem is that there are almost no certifiers rather than that certifiers are conflicted.

The two things an individual body can do that would change what its certificates mean. Sample, per section 64.19, which is the only technique that tests outcome rather than process and which almost nobody does. And participate in criteria development, per section 64.24, where it is already funded to be in the room and has an interest that diverges from its clients’.

Vol. 42 · §64.27 · Currency 2026-09-03 · drafting

64.28 /

Sources and confidence

This handbook assembles material recorded in Volumes 01 to 41 and introduces no new facts. It inherits the confidence of everything it cites.

The flags that bear on this handbook rather than on a detail. Sections 27.6 and 27.7, on which section 64.14 is entirely built — no notified bodies designated and no harmonised standard cited. Section 53.14 flags whether that has changed, and if it has, sections 64.13, 64.14 and 64.26 all change with it. Section 40.4 and section 40.39, the Union phased application status. Section 9.14’s enforcement finding, marked [Secondary sources only] at source and used at section 64.15. And section 26.4’s EDPB opinion dates, marked [Secondary sources only] at source, which bear on section 64.16’s account of criteria approval.

What is this handbook’s own rather than assembled. Section 64.3, which states where the chain has integrity before the criticism — recorded at section 20.17 and never carried into the other blocks, and necessary if a body is to know which part of the structure it can rely on. Section 64.27’s observation that the same three problems recur and a fourth is specific to AI, which no single block states because each treats one context. And sections 64.20 to 64.25, the constructive half, which is assembled from remedies recorded singly across the document and which section 64.25 qualifies honestly: most of it is available to an individual body now and will not change the market.

What is not affected by any flag. That the conflict is structural rather than about conduct, at section 64.4. That scope is the decision with most consequence and least visibility, at section 64.5. That a framework can require an organisation to address an outcome and cannot require it to achieve one, at section 64.7. The auditability paradox at section 64.8. That destruction is the limit case because the customer cannot check even in principle, at section 64.11. That the chain has liability at the bottom and none at the top, at section 64.17. That sampling is the only technique that tests outcome and almost nobody does it, at section 64.19. And that criteria participation is the highest-leverage action available to a body already funded to be in the room, at section 64.24.

Forward reference. Section 65 is the front-line staff handbook and section 66 human rights and advocacy. Section 66 should be read against section 64.24: section 53.21’s advocate lens identifies standards participation as the single highest-leverage and least-used item in the advocacy toolkit, and section 64.24 records a party already in the room with an interest in the same outcome. Part VII carries no six-lens blocks; section 53.21 was the last in the document.

Vol. 42 · §64.28 · Currency 2026-09-03 · drafting