The Global ACI transition is live — five compliance deadlines through December 2026

The Operating System Accredited ISO Certification Bodies Are Built On

IAF and ILAC have formally merged into Global ACI. Certificate mark requirements changed in April 2026. Audit report, branding, and document alignment deadlines run through December 2026. ISOApplication is the platform purpose-built to carry accredited Certification Bodies through this transition — and every audit cycle that follows it.

Start Free Trial — 7 Days Full Access
Watch the Platform Walkthrough 6 min
Built for accredited ISO Certification Bodies — from single-scheme CBs to multi-jurisdiction registrars
A multi-scheme registrar accredited under a leading European NAB A CB managing certifications across multiple international jurisdictions An accredited body running ISO 9001 · 14001 · 27001 · 42001 in one platform
§ 01 — The Global ACI Transition · Where your CB stands today

Five Deadlines. One Framework. One Platform.

In April 2026, the International Accreditation Forum (IAF) and the International Laboratory Accreditation Cooperation (ILAC) formally unified under a single body: Global Accreditation Cooperation Incorporated (Global ACI). This is not a rebrand — it is a structural reorganisation of global accreditation governance, with mandatory operational, documentary, and branding requirements on a published schedule. Each deadline below is auditable.

14 Apr 2026

Unified Global ACI MRA Mark on All New Certificates

Every certificate issued from this date must carry the unified Global ACI MRA mark. Certificates still bearing separate IAF MLA or ILAC MRA marks are non-compliant.

Platform: the unified mark is applied automatically to all certificate outputs — compliance by default, not configuration.

01 Jul 2026

Audit Reports Must Reference Global ACI Requirements

Stage 1 and Stage 2 reports must explicitly reference Global ACI harmonised procedures. Updating Word templates across a freelance auditor network is a coordinated operation.

Platform: a single centrally maintained report schema — update once, every auditor submits against it automatically.

01 Sep 2026

Formal Notification to Your Accreditation Body

A documented submission of your transition compliance status — not an informal conversation. Missing it creates a finding in your next peer review.

Platform: the AB Assessor Portal keeps a live compliance record — the notification is generated from existing data.

01 Oct 2026

Full Branding Transition Complete

Websites, letterheads, certificate templates, and email footers must remove the old IAF MLA and ILAC MRA marks. An organisation-wide change.

Platform: templates are maintained centrally — one update propagates to every document your CB issues.

31 Dec 2026

Full MD Series Document Alignment

Procedures and calculation methodologies must align with MD 1:2024, MD 5:2023, MD 2:2023, MD 22 and related documents — the most operationally complex deadline.

Platform: the calculation engine runs on locked, current MD logic — alignment is an outcome of running on the platform.

Every one of these deadlines has an operational answer in the platform.

See how ISOApplication maps to each requirement — and why CBs waiting until Q4 will face the same transition under significantly more time pressure.

§ 02 — See It In Action

Watch ISO Application run a full certification workflow

From client onboarding to certificate issuance — see how accredited CBs manage every step on one platform.

Full ISO 17021-1 workflow Client portal in action IAF MD-compliant manday engine Certificate issuance & QR registry
§ 03 — The Operational Gap

What the transition expects your operations to look like. What legacy systems deliver instead.

Your current state
Certificate templates in Word — still carrying the old IAF MLA mark
Audit report format varies by auditor — updating a freelance network is manual and slow
Manday allocations in spreadsheets not updated for MD 1:2024 revised logic
AB surveillance records assembled from emails before each peer review
No formal notification workflow to your accreditation body
Auditor competence matrices in shared spreadsheets, CPD tracked manually
Revenue calculations on formulae not yet updated for MD 5:2023
No version control when MD series documents are revised
What the transition requires
Every certificate carrying the unified Global ACI MRA mark, applied automatically
Enforced digital report schemas — all auditors submit on the current template automatically
Locked MD 1:2024 and MD 5:2023 calculation engine with auditable trace per cycle
Read-only AB Assessor Portal with live transition evidence — always ready
Structured workflow producing the September 1 accreditation body notification
Digital competence ledgers per auditor per scheme — CPD always current
MD 5:2023-aligned manday calculator — zero manual formula dependency
Global ACI guideline propagation with versioned change logs

The Global ACI audit report deadline marks the first operational compliance test since unification. If your report templates still reference IAF and they are Word files distributed to a network of contract auditors, the coordinated update required is significant. The platform eliminates it — by making central template control the default architecture, not a faster manual process.

§ 04 — The Platform

Every workflow your Certification Body runs — aligned to the Global ACI framework from day one.

Not retrofitted. Not patched. Built to the current standard.

IAF MD 5:2023 · Manday Allocation
38.5 mandays
PLATFORM SCHEMATIC · SEE THE LIVE PRODUCT IN YOUR TRIAL
Calculation traceMD 1:2024 and MD 5:2023 logic — locked, timestamped, exportable for NAB review in one action.
Multi-site samplingHeadcount bands computed against current IAF MD 1:2024 sampling tables — not a formula you maintain.
Revenue reconciliationPre-issue underquote detection — manday shortfall flagged before the contract is signed.
Auditor Network · Report Queue
PLATFORM SCHEMATIC · SEE THE LIVE PRODUCT IN YOUR TRIAL
Report schemaAll auditors submit on the current Global ACI-referenced schema — no Word files emailed to a shared inbox.
Magic-link accessSecure, temporary portal access — no user accounts to manage, no IT provisioning overhead.
CPD competence matrixCPD hours logged against each auditor's competence matrix per scheme — always current for peer review.
AB Assessor · Read-only Ledger
PLATFORM SCHEMATIC · SEE THE LIVE PRODUCT IN YOUR TRIAL
Disclosure scopeYou control exactly what the assessor sees — configure per review, not per document.
Transition evidenceGlobal ACI transition compliance record — the September 1 notification evidence is already here.
Compliance ledgerCryptographic audit trail — every logic trace is SHA-256 hashed and recorded with full attribution.
§ 05 — Four Portals. One Platform.

Every stakeholder has their own secure workspace

Purpose-built portals for each role — connected, and independently secured with role-based access control and full audit trails.

§ 06 — Three Pillars · One Platform · Zero Spreadsheets

Built for how accredited CBs actually operate. Aligned to where the regulation is going.

Technical Scheme Managers · Operations

The Automated IAF Calculation Engine

The only calculation engine purpose-built for IAF Mandatory Document compliance under Global ACI. Every manday allocation runs against locked, current logic — not a spreadsheet formula a reviewer can break.

  • IAF MD 1:2024 audit day calculation — current revision, locked
  • IAF MD 5:2023 manday allocation for QMS and EMS
  • ISO 9001 · 14001 · 27001 · 42001 integrated scope logic
  • Multi-site sampling against current headcount bands
  • Pre-issue revenue reconciliation before contract signature
Deadline coverage: 31 Dec 2026 — MD Series Alignment
Operations Directors · Scheme Admins

Connected Field Operations

Give your contract auditor network a secure portal — without managing accounts, distributing Word templates, or chasing CPD. The July 1 reporting requirement is a compliance problem; the platform solves it structurally.

  • Magic-link auditor access — no usernames or resets
  • Enforced digital report schemas on your template
  • Automated CPD tracking per auditor per scheme
  • Conflict of interest workflows with digital signatures
  • Unified Global ACI mark applied to all outputs
Deadline coverage: 01 Jul 2026 · 01 Oct 2026
Managing Directors · CCOs

The AB Assessor Portal

Your assessor needs to verify your compliance logic — not access client data or commercial terms. An isolated, read-only compliance view showing exactly what your peer review requires. Always current.

  • Read-only assessor access — no modification risk
  • Hash-verified logic traces with complete audit history
  • Global ACI transition evidence, documented
  • Configurable disclosure scope, per review
  • Audit-ready at all times — no preparation phase
Deadline coverage: 01 Sep 2026 · Ongoing readiness
§ 07 — Platform Capabilities

Built for accreditation-grade compliance from day one

Every feature designed against ISO 17021-1 and the current IAF MD series — not a workaround.

01

AI Manday Calculation Engine

Automated audit duration per IAF MD5 across all 12 ISO standards — IMS combinations, multi-site sampling (MD1), integration reductions (MD11), and complexity scoring.

IAF MD5
02

17-Step Certification Workflow

From CIF to certificate — every form gated, sequenced, and validated. Pre-Contract Review, Contract, 3-Year Programme, Stage 1 & 2, CAR, Decision.

ISO 17021-1
03

Impartiality Engine

Automated conflict-of-interest checks, auditor independence validation, and segregation of duties at every decision point — audit-ready by design.

Accreditation
04

12 ISO Standards Supported

ISO 9001, 14001, 45001, 27001, 27701, 22000, 50001, 13485, 20000, 22301, 37001, 42001 — with standard-specific form sections and clause mapping.

Multi-Standard
05

Digital Certificate & QR Registry

QR-coded PDF certificates with public verification registry, SHA-256 document hashing, and automatic 3-year surveillance scheduling.

Tamper-Proof
06

AI Copilot & NC Drafting

AI-assisted NC drafting, clause mapping, department planning suggestions, and platform analytics — powered by Claude.

AI Powered
View All Features
§ 08 — The Operational Case

What CBs recover when they move off spreadsheets

Eliminated
Manual MD formula maintenance — calculation logic is locked to the current revision, not a spreadsheet your team maintains
Continuous
Peer-review readiness — compliance evidence is live in the AB Assessor Portal, not assembled before each review
One schema
Every auditor submits on a single enforced template — the Technical Reviewer reconciliation bottleneck disappears
Pre-issue
Manday underquotes flagged before the contract is signed — no silent revenue leakage, no post-hoc correction

A spreadsheet error in an IAF manday calculation under MD 1:2024 is not an admin correction. It is revenue leakage, a client trust problem, and — in a Global ACI peer review — a potential finding against your accreditation. The platform removes that class of risk. Logic is locked against the current MD revision; every action is hash-verified in the audit trail; when the reviewer arrives, your evidence is already there.

§ 09 — Onboard in 3 Days

From signup to your first certification — in 72 hours

No lengthy implementation projects. No consultants. Your team is operational in three days.

1

Sign Up & Configure

Create your CB profile, upload your logo, set your accreditation scope and standards. About 30 minutes.

Day 1
2

Onboard Your Team

Invite auditors, operations staff, and reviewers. Role-based access is pre-configured; your client portal goes live automatically.

Day 2
3

Run Your First Certification

Open a new certification, assign your auditor, and follow the guided 17-step workflow. Issue your first certificate digitally.

Day 3
Start Your Free Trial
§ 10 — The Founding Partner Network

We already have the traffic. We're building the routing.

isoapplication.com has strong organic visibility across major search engines and AI platforms for ISO certification body discovery globally. When a multinational, government supplier, or financial institution searches for an accredited CB — particularly for ISO 42001, ISO 27001, and ISO 14064 — they arrive here. That traffic is real and growing.

We are building the Tier-1 Partner Routing Network: a direct-match system routing pre-qualified corporate inquiries to accredited CBs with the verified scope to serve them. No intermediary. No directory. No per-lead commission. When a qualified ISO 42001 inquiry comes from a firm in your scope and region, it goes to you.

Founding partner subscribers receive priority positioning in the routing queue at launch — and the founding subscription rate, locked for the lifetime of the account.

Organic Discovery AdvantageConsistently surfaced by search engines and AI assistants for ISO CB selection globally — qualified demand arrives here already.
Scope-Matched RoutingLeads filtered by standard, region, and accreditation scope — no unqualified traffic.
No Commission ModelDirect contact routing at launch — no marketplace fee, no per-lead charge.
ISO 42001 Demand AcceleratingEU AI Act deadlines are driving the fastest-growing standard in the inquiry pipeline.

Founding Partner Registration

Slots are capped per accreditation scope to preserve lead quality. Register to secure your scope position and lock the founding rate.

ISO 9001ISO 14001ISO 27001ISO 42001ISO 45001ISO 14064ISO 17021Other

Your details are used only to manage partner allocation and to contact you about the network launch. We do not share CB information with other partners.

You're registered. Now see it in action.

Your scope position is reserved and your founding subscription rate is locked from today. The fastest way to move forward is to see the platform against your own deadlines.

Prefer email first? We'll confirm your scope allocation and founding partner details by email shortly.

§ 11 — EU AI Act 2024/1689

The Enterprise Shield for EU AI Act compliance

Built for Certification Bodies managing client AI systems. If you already run ISO 42001, you're already most of the way there — our Bridge Engine maps existing audit evidence to EU AI Act Articles automatically.

Up to €35M or 7% of global turnover in fines for non-compliant high-risk AI systems under Article 99. The Shield generates the Annex IV Technical Dossier and Declaration of Conformity — your client's liability shield.

Auto
Mapped from existing ISO 42001 evidence
Annex IV
Auto-generated technical dossier
Aug '26
High-risk obligations deadline
Article 6 ClassificationAnnex III Risk TriageAnnex IV Dossier BuilderArticle 12 Record-keepingArticle 72 MonitoringDoC Generator
Request Early Access
Stage 1

AI System Product Passport

Per-system inventory with a dedicated passport for each AI model your clients operate — separate from your ISO scheme, no cross-contamination.

Stage 2

Legal Triage & Risk Classification

Branching wizard through Article 6 & Annex III, producing a formal Legal Risk Determination — Prohibited, High-Risk, or Limited Risk.

Stage 3 · Intelligence Bridge

ISO Evidence Auto-Mapping

Existing audit trails, evidence vaults, and CIF data are surfaced automatically against the relevant Articles — zero double-entry.

Stage 4

Continuous Conformity Monitor

Scans your ISO audit trail for substantial modifications (Article 3(23)). Model change detected → instant re-certification alert.

Output

EU Declaration of Conformity

Annex IV technical documentation and the Declaration of Conformity generated in one click — market-access ready for CE marking.

§ 12 — Independently Certified

Independently certified. Auditor-ready.

Operated by Fusionpact Technologies — independently certified across information security, AI governance, and quality management.

GDPR · DPDP
Aligned
Data protection by design — EU GDPR & India DPDP Act
ISO 27001
:2022
Information Security Management System — latest revision
ISO 42001
:2023
AI Management System — responsible AI governance & risk
ISO 9001
:2015
Quality Management System — consistent, auditable delivery
§ 13 — For Auditors · Free

Auditors: your professional workspace is free

Contract and staff auditors get a permanent, portable professional profile — independent of any single certification body.

CPD log that travels with you

Structured continuing-professional-development records, exportable for any scheme or registrar review.

Competence profile & scheme codes

Qualifications, witnessed audits, and technical-area codes in one verified profile.

One workspace across every CB

Assignments, findings, and evidence for every certification body you audit for — in one place.

Magic-link access

No passwords to manage. Secure, expiring links straight to your work.

Create your free auditor profile Your CB isn’t on the platform yet? Invite them — auditors are how CBs find us.
§ 14 — Enterprise Security Architecture

The technical assurance your IT Director needs to approve this

Row-Level Security (RLS)Every tenant's data is isolated at the database layer. Every query is scoped to your CB's tenant boundary and verified against database-level security policies.
Hardened Tenant BoundariesClient and auditor data is strictly partitioned per tenant. Subcontractor network access is scoped, permissioned, and fully auditable.
SOC 2 Type II Aligned ArchitectureDesigned and built to the SOC 2 Type II Trust Services Criteria for security, availability, and confidentiality; a Type II examination is currently underway with an independent CPA firm. Control documentation available to qualified enterprise accounts on request.
Encryption in Transit and at RestAll data encrypted in transit (TLS 1.3) and at rest without exception across every data tier.
Granular Role-Based Access ControlScoped tiers for every CB role — MD, Scheme Manager, Technical Reviewer, Contract Auditor, AB Assessor — each limited to their function.
Comprehensive Audit LoggingEvery action is logged with timestamp, user identity, and session context. Complete, attributable activity records across every portal.
Global ACI Framework AlignmentPlatform logic, data models, and workflows are aligned to the current Global ACI MD series revisions — not a previous version of the IAF standard.
Zero Uncontrolled Data ExposureNo client data in shared drives, email attachments, or local spreadsheets. Single access-controlled source of truth for every record.
§ 15 — Accreditation-Grade by the Numbers

Capability, not marketing claims

17
Workflow Forms
12
ISO Standards
IAF MDs 1–22
Full MD Series
ISO 17021
Accreditation-Grade Workflow
QR Registry
Tamper-Proof Certificates
§ 16 — From the Blog

Insights for ISO Certification Bodies

View All Articles
§ 17 — Questions Your Operations Team Will Ask

Answered before the internal review meeting

There is no operational blackout during migration. Most CBs have a live environment running within the first week. We provide a structured onboarding template mapping your certification records, client files, auditor competence matrices, and historical IAF calculation references to the platform schema. Your team operates on the platform while historical data migrates in parallel. Migration support is included with every subscription.

Both are addressed operationally. For the audit report requirement: Field Operations enforces a centrally maintained report schema — update once, every auditor submits against it automatically. For October 1: the unified Global ACI MRA mark is applied automatically to all certificate outputs; the April 14 mark requirement is met by default. For September 1: the AB Assessor Portal maintains your transition compliance record continuously — the notification is generated from live data, not assembled from scratch.

You configure a read-only access scope for your NAB reviewer and issue a time-limited portal link. They verify your IAF calculation logic, manday traces, Global ACI transition evidence, and documentation directly in the platform — without accessing client data, commercial terms, or internal operations. This replaces the manual review-pack process that compresses your team in the two weeks before every review. The portal is always current.

For a Certification Body, data assurance is primarily about isolation and control, not geography: your data must never be reachable by another CB, and every access must be governed and auditable. ISOApplication enforces this at the database layer — Row-Level Security, encryption in transit (TLS 1.3) and at rest, role-based access control, and comprehensive audit logging. No CB's data is ever commingled. For organisations with a specific in-jurisdiction residency requirement, we offer dedicated regional instances as an enterprise deployment option; contact us for a technical architecture brief.

Yes — multi-scheme operation is a core design requirement. The IAF Calculation Engine manages scheme-specific manday logic independently for each standard, including combined audit scope. Scheme Managers configure separate workflows, report templates, competence requirements, and calculation parameters per standard within a single instance. Each scheme's Global ACI MD alignment is managed independently — an MD revision affecting ISO 27001 does not cascade as a manual task across unrelated schemes.

The Global ACI transition is happening on a published schedule. Your operations need to reflect that.

Join the accredited ISO Certification Bodies running their operations on infrastructure built for the regulatory environment they actually operate in — not the one they operated in five years ago.

Request the Technical Architecture Brief
Migration support from day one No implementation cost to evaluate Architecture docs on request Global ACI aligned, not retrofitted