Official sources — checked 27 September 2026

Who is allowed to do what.

Most of what gets said about ISO certification is folklore. So every claim on this page is a direct quotation from ISO, the Singapore Government or the Singapore Accreditation Council, with the link to the source underneath it. Check them yourself — that is the point of the page.

The five roles

A great deal of confusion disappears once you know who does what. Only one of these five hands out certificates.

Writes the rules

ISO (Geneva)

Writes standards like ISO 9001, ISO 14001 and ISO 45001. It has no relationship with your company, never sees your documents, and cannot certify you or anyone else.

Accredits the certifiers

Singapore Accreditation Council

Managed by Enterprise Singapore, a government agency. SAC checks that a certification body is competent and impartial before it is allowed to issue certificates. Managed by Enterprise Singapore.

Issues the certificate

The certification body

An accredited, independent firm — TÜV SÜD PSB, SGS, EHS Universal and others. It audits your system and issues the certificate. Your company hires them directly, and pays them directly.

Us

The consultant

Builds the system and the evidence so you are ready for that audit. By the rules, a consultant can never also be your certifier — which is exactly why the role exists.

Owns everything

Your company

The management system and every document in it are yours. Your management approves them. The certificate is issued to your company and belongs to your company — not to us.

There is no such thing as a certified ISO consultant

This surprises people, because the market is full of consultants implying otherwise. It is not a matter of opinion — ISO says it plainly.

ISO — official guidance

“Individuals are not certified to ISO 9001, although they can complete auditor training or lead auditor qualifications.”

Source: ISO, “ISO 9001 explained”

Why ISO 10019 exists

ISO 10019:2005 “provides guidance for the selection of quality management system consultants and the use of their services… It gives guidance on the process for evaluating the competence of a quality management system consultant.”

Source: ISO 10019:2005 — Guidelines for the selection of quality management system consultants. Published 2005, last reviewed and confirmed 2021, still current.

What it means in plain terms. ISO publishes no licence, register or qualification for consultants, so nobody can be “ISO certified” as a consultant. When a firm advertises that, they are almost always describing an individual training certificate from a professional body — which is a genuinely useful thing to hold, but it is not issued by ISO and no certification body asks for it. The honest question is not “what certificate do you hold?” It is “show me a system you built, and tell me how it did in the audit.”

Nobody certifies your documents, and there is no portal

Two questions we are asked constantly. Both have the same shape of answer: there is no approval step you have to pass before anything counts.

ISO — the official position

“ISO does not perform certification or issue certificates, and it does not permit anyone to use the ISO logo in connection with certification. Certification is performed by external certification bodies, thus a company or organization cannot be certified by ISO.”

Source: ISO, Certification

So what actually happens

STEP 1

You prepare

Your system and documents are written. Your own management approves and signs them. No external approval is required at any stage.

STEP 2

You apply

Your company signs an application and a contract with a certification body. It is an application form — not a submission of your documents.

STEP 3

Stage 1 audit

The auditor reviews the documentation to see whether you are ready. Findings at this stage are normal, not a failure.

STEP 4

Stage 2 audit

On site. The auditor checks the system is genuinely being used, by sampling your records and talking to your people.

STEP 5

Certificate

The certification body makes the decision and issues the certificate to your company. Valid three years, with annual surveillance audits.

ISO & IAF — auditing practices guidance

“This 1st stage is primarily for scoping and planning the subsequent part of the certification audit (Stage 2) and to allow an auditor to obtain an understanding of the organization and to evaluate if that organization is ready for certification.” It includes “ensuring that the client has prepared and is using any necessary management system documentation.”

Source: ISO/TC 176 Auditing Practices Group — Guidance on two stage initial certification audit

The only thing that gets “submitted” anywhere is a corrective action plan, and it goes to the auditor you already hired. Your actual documents are read by the auditor during Stage 1 and stay with your company. There is no central register, no filing deadline and no portal — not in Singapore and not anywhere else.

Consultancy and certification must be two different companies

This is not our opinion either. It is the Singapore Government telling businesses how to buy these two services.

Enterprise Singapore — government agency

“Your business might need services such as consultancy and training, as well as audit and certifications. However, potential conflicts of interest may arise. As consultancy and certification are two separate processes, you are advised to call for two different tenders so that different service providers can carry these services out effectively.”

Source: Enterprise Singapore — Get Tested, Inspected or Certified by a Conformity Assessment Body

Enterprise Singapore — same page, on getting help

“Provide training to essential employees that will be impacted. Consider seeking help from external consultants or training providers if needed.”

Source: Enterprise Singapore — the same government guidance that separates the two services also points companies towards consultants.

Our promise, stated plainly. We are not a certification body. We do not issue certificates. We do not accept a commission or a referral fee from any certification body, and the audit fee is passed through to you at cost. If a consultant ever offers to both prepare your system and certify it, one of those two things is not real.

The law has teeth on this

Singapore does not treat false certification claims as a marketing problem. It treats them as an offence.

Enterprise Singapore Act 2018 — Singapore law

A person who misuses an accreditation mark or certification mark, or uses a certificate to convey the impression that they hold a valid accreditation or certification when they do not, “shall be guilty of an offence and shall be liable on conviction to a fine not exceeding $50,000 or to imprisonment for a term not exceeding 3 years or to both.”

Source: Enterprise Singapore Act 2018, section 47 — Singapore Statutes Online, Attorney-General's Chambers.

Straight answers

Do I need a certified or licensed ISO consultant?

No — and there is no such licence to have. ISO states that individuals are not certified to ISO 9001, and it publishes nothing at all for consultants. No certification body and no Singapore authority requires your consultant to hold a certificate. The reason ISO 10019 exists is to tell companies how to judge a consultant's competence — which is the assessment you should actually be making.

So when you compare consultants, ask what they have built, what happened at the audit, and whether they can explain your sector's rules. A training certificate on a website proves very little either way.

Do we submit our documents to a portal? Do they need to be certified first?

Neither. There is no ISO portal — ISO never receives anything from a certified company, and its only existing document-submission system is for writing the standards themselves. No outside party certifies your documents either.

What happens is this: your company applies to a certification body, then the auditor reads your documentation during the Stage 1 audit. The only approval your documents ever need is your own management signing them. And the only item you send anywhere is a corrective action plan — to the auditor you hired.

Then who actually checks whether the documents are any good?

The auditor does — during Stage 1, in front of you. That is not an approval process you pre-clear; it is the audit itself. If something is missing, they raise a finding and you fix it. Stage 1 findings are routine, and the certification body is required to tell you formally so you can correct things before Stage 2.

Does the certification body have to be accredited?

ISO is straight about this: accreditation “is not compulsory, and non-accreditation does not necessarily mean the certification body is not reputable.” But only accredited certificates carry international recognition under the mutual recognition arrangements, and Enterprise Singapore advises engaging a body accredited by the Singapore Accreditation Council. In practice: if your certificate needs to satisfy a tender, a client or a supply chain, use an SAC-accredited body and check its accreditation covers the exact standard you want.

How do we check a certification body or a certificate is genuine?

Two places. SAC publishes the accreditation status and scope of every accredited body in Singapore — search for the body by its full name. Internationally, certificates issued by accredited bodies can be verified through the IAF's global database, CertSearch. Both are free and take about five minutes. We would rather you checked than trusted.

Every source used on this page

Original documents, not summaries of them.

  1. ISO — Certification. “ISO does not perform certification or issue certificates…” iso.org/certification.html
  2. ISO — ISO 9001 explained. “ISO does not certify organizations…” and “Individuals are not certified to ISO 9001…” iso.org — ISO 9001 explained
  3. ISO 10019:2005 — Guidelines for the selection of quality management system consultants and use of their services. iso.org/standard/35651.html
  4. ISO/TC 176 Auditing Practices Group — Guidance on two stage initial certification audit. committee.iso.org (PDF)
  5. Enterprise Singapore — Get Tested, Inspected or Certified by a Conformity Assessment Body. Singapore government guidance on consultancy and certification being separate. enterprisesg.gov.sg
  6. Singapore Accreditation Council — Management System Certification Bodies, and SAC CT 01 Accreditation Process for Certification Bodies. SAC is managed by Enterprise Singapore. sac-accreditation.gov.sg
  7. Enterprise Singapore Act 2018, section 47. Improper use of accreditation and certification marks. Singapore Statutes Online
  8. IAF CertSearch. International verification of accredited certificates. iafcertsearch.org

All sources retrieved and quoted 16 September 2026. Standards and regulations change — if you are reading this long after that date, check the links rather than trusting the page.

Still not sure what you need?

A 20-minute review. We tell you which standard you actually need, roughly what it will take, and whether you are ready to start. No pitch, no obligation.