You cannot tell whether an ISO certificate is genuine by looking at it. Forged certificates used to give themselves away through bad typography, wrong logos and clumsy wording. They do not any more. The only reliable way to verify a certificate is to check it against the register of the accreditation body for the region, independently of anything printed on the document itself.
In Australia and New Zealand that means two separate JAS-ANZ registers: one to confirm the certification body is actually accredited, and one to confirm the organisation actually holds the certificate. For overseas suppliers, the Global ACI list of recognised accreditation bodies will route you to the right register. This guide walks through both.

Why “spot the fake” checklists no longer work
Most advice on this topic is a checklist: look for spelling mistakes, check the logo, examine the fonts, be suspicious of a vague scope statement. That advice made sense when forging a document took real effort and skill.
It does not make sense now. The same tools that have made phishing emails and invoice scams far harder to spot have done exactly the same for certificates. A convincing forgery today has clean typography, a plausible certificate number, a sensible scope statement and a real certification body’s name and mark on it. Every visual tell that checklists rely on can be reproduced in minutes.
So treat the document as a source of search terms, not as evidence. It tells you what to look up. It proves nothing on its own.
The one rule that matters: never use the certificate’s own contact details
If a certificate is forged, so are the website address, phone number, QR code and email printed on it. Following them takes you to whatever the forger wants you to see, which may be a convincing replica of a certification body’s site with a working “verify” page.
Navigate to the accreditation body’s register yourself, by typing the address or searching for it independently. This single habit defeats the majority of certificate fraud.
How to check an ISO certificate in Australia and New Zealand
JAS-ANZ is the accreditation body for Australia and New Zealand, and it publishes two separate registers. You need to pass both, and this is the part most people miss.
| Check | Register | What it proves |
|---|---|---|
| 1. Is the auditor legitimate? | Accredited Bodies | The certification body is genuinely accredited, and for which schemes |
| 2. Is the certificate real? | Certified Organisations | This specific organisation holds this specific live certificate |
Passing only the first is the classic trap. A genuinely accredited certification body exists, its name and mark appear on the certificate, and the certificate was never issued by them. Passing only the second is equally hollow if the body that issued it was never accredited in the first place.
The certified organisations register searches on Certificate ID, Organisation Name, Certificate Holder, Suburb or City, and Certification Description. Take those details off the certificate in front of you and search on the certificate number first, since it is the least ambiguous.
Then confirm that what the register returns actually matches the document: the same legal entity name, the same standard, the same scope wording, the same sites, and current issue and expiry dates. A certificate that has lapsed or been withdrawn will show differently in the register from the PDF someone emailed you.
If you want to see the method work before you rely on it, search the certified organisations register for Streamline ISO Consultants. We are listed there, and it takes about ten seconds.
Checking an overseas supplier’s certificate
This is where most people get stuck, and it is mostly a terminology problem. Three different kinds of organisation are involved, and they are routinely confused:
| Term | What it does | Examples |
|---|---|---|
| Accreditation body (AB) | Recognises and accredits certification bodies. Usually one or two per country. | JAS-ANZ, UKAS, ANAB |
| Certification body (CB) | Audits organisations and issues certificates. Many per country. | SAI Global, BSI, SGS, Bureau Veritas |
| Certified organisation | The company that holds the certificate | your supplier |
The register you need is determined by where the certification body was accredited, not where your supplier trades. A Vietnamese manufacturer may hold a perfectly sound certificate from a certification body accredited in Germany. So start from the certification body named on the certificate and work backwards, not from the supplier’s address.
- Find the accreditation body. The Global ACI list of recognised accreditation bodies covers 126 bodies and filters by country.
- Go to that accreditation body’s register and confirm the certification body is accredited for the relevant standard and scheme.
- Confirm the certificate and organisation appear, with matching number, scope, sites and dates.
Where IAF CertSearch fits, and what changed on 1 January 2026
IAF CertSearch is a global database that consolidates data from accreditation bodies and certification bodies in one place. Certificates can be checked individually, in bulk, or through an API, which makes it useful if you are screening a supplier list rather than a single document. ISO points to it as a verification route.
Two caveats. First, it is not exhaustive, so absence from CertSearch is not proof of a fake and presence is not a substitute for the regional register. Second, and more importantly for anyone reading older guidance on this topic: the International Accreditation Forum ceased operations on 1 January 2026. Its own website now carries a notice confirming it is no longer operational and is maintained for archival reference only. ISO confirms that the Global Accreditation Cooperation Incorporated (Global ACI) has assumed the former roles of both the International Accreditation Forum and the International Laboratory Accreditation Cooperation (ILAC). The CertSearch database still operates, but any article describing the IAF as the current international authority is now out of date. We cover the change in full in our guide to Global ACI replacing the IAF and ILAC, including what it means for existing certificates and marks.
Accredited, unaccredited and outright fake
These are three different problems and they need different responses.
- Accredited. A real audit by a certification body that is itself accredited by a recognised accreditation body. This is what most contracts and tenders mean when they ask for certification.
- Unaccredited. A real audit, a real certificate, but no accreditation behind it. This is the most common problem in Australia. It is worth being precise here: ISO’s own position is that accreditation is not compulsory, and that non-accreditation does not automatically mean a certification body is disreputable. What it does mean is that nobody independent has confirmed their competence, and many tenders will not accept the certificate.
- Fake. No audit happened, or the certificate was never issued by the body named on it.
Our guide to ISO certification bodies in Australia sets out which bodies are accredited and what to look for when choosing one.
Are there really fake ISO certificates?
Yes. A study titled Faking ISO 9001 in China: An exploratory study found China leads the world in fake certificates, and identified four distinct types:
- Counterfeit certificates. A completely fabricated document, never issued by anyone.
- Unaccredited certificates. An unaccredited third party performs an audit and issues a certificate. This is the most common type in Australia.
- Paperworked ISO. An organisation uses another organisation’s management system to obtain certification.
- Implemented but not in use. A system exists on paper but was never put into practice, so it has no bearing on how the business actually operates.
The last two are worth dwelling on, because a register check will not catch them. The certificate is genuine and the accreditation is genuine. What is hollow is the system underneath. That is a harder problem, and it is the reason a management system should be built so that conformity is a by-product of the way the business already runs rather than a documentation exercise assembled before an audit.
Checking certificates by standard
The method is identical whichever standard you are checking. What changes is the scheme the certification body needs to be accredited for, which you can see in the accredited bodies register.
- ISO 9001 quality. The most commonly faked, simply because it is the most commonly requested in tenders.
- ISO/IEC 27001 information security. Increasingly requested in supplier due diligence, and increasingly faked alongside it. Check the scope carefully, since an ISMS scope that excludes the systems you actually care about is a common and entirely legitimate limitation that buyers miss.
- ISO 45001 health and safety. Frequently required for prequalification on construction and resources work.
- ISO 14001 environmental. Often requested alongside tender sustainability requirements.
- ISO/IEC 42001 AI management. New enough that buyers are still learning what a credible certificate looks like, which makes care worthwhile.
Whatever the standard, read the scope statement on the certificate against what you are actually buying. A certificate can be entirely genuine and still not cover the site, product or service you are relying on. Our guide to clause 4.3 and how scope is determined explains why certificate scope and management system scope are different documents, and what a properly written scope should tell you. For the underlying clause requirements across the standards, see our ISO clause guides.
What to do if you find a fake certificate
First establish the facts. Was the certificate holder aware it was not genuine? Does the management system actually conform with the standard, whatever the paperwork says? And what would it take to move to an accredited certification body?
If it is your own certificate and you were not aware, contact the company that issued it and try to resolve it directly. In our experience the threat of legal action sometimes achieves a refund, but more often it is an expensive lesson.
To escalate, follow the order ISO actually sets out, which is not the order most people assume:
- Complain to the certification body first. Identify it from the statement of certification, the certification mark being used, or by requesting a copy of the certificate.
- If that is not possible, email MSSComplaints@iso.org with full details and your contact information.
- For a false claim of accredited certification, including misuse of the IAF logo, email secretary@iaf.nu.
ISO says a response will be sent within 14 days. It cannot guarantee a resolution or accept liability, but it can facilitate dialogue between the parties. Note also that ISO does not perform certification or issue certificates itself, and does not permit anyone to use the ISO logo in connection with certification, so a certificate claiming to be issued by ISO is fake by definition.
To transfer to an accredited body, contact one of the certification bodies on our certification bodies page. They will want your most recent audit report, if you were given one. Be realistic: if the certificate was fake, the system underneath it probably has significant gaps, so a gap analysis is usually the sensible first step before booking a Stage 1.
Government grants and funding
If cost is what pushed you toward a cheap certificate in the first place, it is worth checking what assistance is available. See our guide to government grants and funding for ISO certification in Australia, and our breakdown of realistic ISO 9001 certification costs.
Checking an ISO certificate: FAQs
How do I check if a company is ISO 9001 certified?
Search the accreditation body’s register of certified organisations for the region where the certification body was accredited. In Australia and New Zealand that is the JAS-ANZ certified organisations register, searchable by certificate number, organisation name or city. Confirm the certification body itself appears in the accredited bodies register as well.
How can I check an ISO 27001 certification is genuine?
Exactly the same way as any other standard. Identify the certification body named on the certificate, confirm it is accredited for the ISO/IEC 27001 scheme in the relevant register, then confirm the certificate and organisation appear with matching scope and dates. Pay particular attention to the scope, because an ISMS scope can legitimately exclude the systems you care about.
How do I check the authenticity of an ISO certificate?
Not by examining the document. Use the certificate only to obtain the certificate number, the certification body name and the standard, then verify those against the accreditation body’s register, reached independently rather than through any link or number printed on the certificate.
Does ISO issue ISO certificates?
No. ISO writes the standards but does not perform certification, does not issue certificates, and does not allow the ISO logo to be used in connection with certification. Certification is carried out by independent certification bodies. A certificate claiming to be issued by ISO is fake.
Is an unaccredited certificate always fake?
No. ISO’s position is that accreditation is not compulsory and that a lack of accreditation does not automatically mean a certification body is disreputable. But without accreditation there is no independent confirmation of that body’s competence, and many tenders and contracts will not accept the certificate.
What if a certificate does not appear on IAF CertSearch?
That alone does not prove it is fake, because not every certification body publishes there. Check the register of the accreditation body for the relevant region, which is the authoritative source, before drawing any conclusion.
Can I tell a fake certificate by looking at it?
Not reliably, and much less so than a few years ago. Forgeries now routinely have correct logos, clean typography, plausible certificate numbers and sensible scope wording. Visual inspection can raise suspicion but it cannot confirm authenticity. Only a register check can.
How Streamline can help
Streamline designs, implements, audits and mentors practical ISO management systems for Australian businesses. If you have discovered a problem with your certificate, we can tell you honestly how much of your existing system is salvageable and what it will take to certify properly with an accredited body. If you are checking a supplier, we can help you work out whether the certificate they have given you actually covers what you are buying.
We build systems that certify first time, and you deal directly with an experienced ISO auditor. See our management system design services, our independent internal audit, or how an ISO consultant can help.
Speak with an experienced ISO auditor
If you need a certificate checked or a system built properly, contact us. Email hello@streamline.business or call Brisbane 07 3667 8280, Sydney 02 8315 7780 or Melbourne 03 9034 3990.
Stay in the Loop
Get an email when we post an article. Your email address will not be used for marketing, and you can unsubscribe at any time.
We handle your details in line with our privacy policy.











