IAF MD 2 – Certificate transfers
Transfers of accredited management system certifications (e.g. ISO 9001 or ISO/IEC 27001) between certification bodies may be possible in a wide variety of scenarios and are intended to maintain the integrity of accredited management system certifications. The following reasons may lead to a transfer:
- Change of certification body in the course of a recertification
- Change of certification body in the course of a surveillance audit
- Change of certification body because the certification body that issued the certificate has lost its accreditation
There are minimum requirements for the transfer of certificates that must be complied with during this transfer process. The relevant requirements can be found in the IAF MD 2 document.
General requirements
The following summarises the general requirements that must be taken into account:
- Formally: "Only certifications covered by accreditation from an IAF or local signatory at Level 3 and, where necessary, Levels 4 and 5 shall be eligible for transfer." This means that certification bodies which are not accredited for ISO/IEC 27001, for example, may not take over ISO/IEC 27001 certificates.
- Only certificates that are active – and therefore not suspended or expired – can be transferred.
- If a certification body loses its accreditation, the transfer must be completed within six months or by the expiry of the certification, whichever occurs earlier.
Process for transferring a certificate
In the following, we distinguish between the issuing certification body (CERT-Old) and the accepting certification body (CERT-New). Aside from technical requirements, CERT-New must carry out an assessment of the procedure and the certificate. This assessment includes at least a document review of the management system. It can be supplemented by a visit to the sites within the scope, as well as an effectiveness review of the implemented measures, if effectiveness cannot be established from the document review or in the case of evident major deficiencies. The assessment must cover at least the following aspects, and its findings must be fully documented:
- confirmation that the client's certification falls within the accredited scope of both the issuing and the accepting certification body,
- reasons for requesting a transfer,
- that the site or sites requesting the transfer hold a valid accredited certification,
- the audit reports of the initial certification or the most recent recertification, as well as the latest surveillance report, and
- the status of any outstanding non-conformities arising from previous audits, as well as all other relevant documentation on the certification process.
If the audit reports are not made available, or the surveillance or recertification audit was not completed as required by the previous certification body's audit programme, the accepting certification body must carry out a new initial certification audit for the management systems concerned.
Clause 2.2.4 of the IAF MD 2 document sets out which criteria must be assessed in detail.
When is a transfer not possible?
There can be several reasons why certificates may not or cannot be transferred. The main reasons usually do not concern formal aspects, but rather that the assessment cannot be completed successfully.
Cooperation between CERT-Old and CERT-New is also important in this context. On request, CERT-Old must provide CERT-New with the necessary documents and information so that the assessment can be carried out. If CERT-New has not been able to establish communication with the issuing certification body, the reasons must be recorded and all necessary efforts must be made to obtain the required information from other sources (e.g. directly via the client).
What happens after the transfer?
If no issues were identified during the assessment, the certification cycle is based on the previous certification cycle and the accepting certification body takes over the audit programme for the remainder of the certification cycle.
As an accredited certification body, RSM Certification GmbH can take over existing certificates for ISO/IEC 27001 and ISO 9001 (EAC codes 33 and 35), among others.
This entry does not claim to cover all individual requirements of IAF MD 2:2023 in full. Rather, it is intended as a summary of the key requirements – particularly from a customer perspective.