TC-001

Certification Agreement

BCERT LTD — A legally binding agreement governing ISO certification services between BCERT LTD and certified organisations. Rev 2.0 | 17 July 2026

DocumentTC-001 · Rev. 2.0
Issue Date17 July 2026
Next Review17 July 2027
Governing LawEngland and Wales
StandardISO/IEC 17021-1:2015
AccreditationIAS application in progress

BCERT LTD — Certification Agreement (TC-001)

Doc Ref: TC-001 | Rev: 2.0 | Issue date: 17 July 2026 | Next review: 17 July 2027

Governing law: England and Wales | Accreditation: IAS application in progress · ISO/IEC 17021-1:2015

Introduction

This Certification Agreement ("Agreement") governs the relationship between BCERT LTD, a company incorporated in England and Wales with its registered office at 7 Bell Yard, London, WC2A 2JR, United Kingdom ("BCERT LTD" or "the Certification Body"), and any organisation that applies for or holds certification issued by BCERT LTD ("the Client"). By submitting an application for certification or by maintaining a certification issued by BCERT LTD, the Client agrees to be bound by this Agreement in full. This Agreement applies to all certification schemes operated by BCERT LTD, including ISO 9001:2015 and ISO/IEC 27001:2022.

1. Definitions

TermDefinition
BCERT LTDThe Certification Body; a company incorporated in England and Wales, registered office at 7 Bell Yard, London, WC2A 2JR, operating under ISO/IEC 17021-1:2015 (IAS accreditation application in progress).
ClientAny organisation that applies for, holds, or has previously held certification issued by BCERT LTD.
CertificationThe formal recognition by BCERT LTD that a Client's management system conforms to the requirements of a specified standard.
CertificateThe document issued by BCERT LTD evidencing the grant of certification, specifying the Client's name, scope, standard, and validity dates.
Certification MarkThe BCERT LTD logo and/or certification mark as defined in BCERT's Mark Usage Procedure, licensed to certified clients for use within the permitted scope.
IAS Accreditation SymbolThe official symbol of the International Accreditation Service (IAS) indicating BCERT LTD's accredited status. Subject to strict rules of use as defined by IAS and this Agreement.
Combined MarkThe BCERT LTD Certification Mark displayed together with the IAS Accreditation Symbol, as permitted under applicable IAS rules.
Certification CycleThe three-year period comprising initial certification, surveillance audits, and recertification.
AuditA systematic, independent examination of a management system to determine the extent to which audit criteria are fulfilled.
NonconformityNon-fulfilment of a requirement of the applicable standard or of BCERT LTD's certification requirements. May be Major or Minor.
SuspensionA temporary cessation of the validity of the Client's certificate, during which the Client must not make use of the Certificate or Certification Mark.
WithdrawalPermanent termination of a Client's certification by BCERT LTD, whether voluntary or enforced.
Scope of CertificationThe defined boundary of the management system subject to certification, as agreed between BCERT LTD and the Client and stated on the Certificate.

2. BCERT LTD Obligations

BCERT LTD shall:

  1. Conduct all certification activities in accordance with ISO/IEC 17021-1:2015 and the applicable IAS accreditation requirements.
  2. Conduct audits impartially and assign competent audit personnel with appropriate qualifications and sector expertise relevant to the Client's scope and applicable standard.
  3. Notify the Client of the proposed audit team composition in advance, and address any substantiated objections to team members in accordance with BCERT LTD's Impartiality Policy.
  4. Provide the Client with an Audit Plan at least 5 working days before the commencement of any planned audit.
  5. Deliver the Audit Report to the Client within 10 working days of the completion of the audit.
  6. Maintain the confidentiality of all information obtained from the Client during certification activities, in accordance with Clause 12 of this Agreement.
  7. Handle all Client complaints and appeals in accordance with BCERT LTD's Complaints and Appeals Procedure.
  8. Inform the Client of any changes to certification requirements with adequate notice, allowing reasonable time for compliance.
  9. Maintain publicly accessible information on the certification status of all certified clients via the BCERT LTD certificate registry at bcert.uk/registry/.
  10. Notify the Client immediately if BCERT LTD's IAS accreditation is suspended, withdrawn, or materially affected, and advise the Client of the implications for their certification status.

2A. BCERT LTD's Right to Make Certification Decisions

Full descriptions of each certification decision process are publicly available at bcert.uk/process/ in accordance with ISO/IEC 17021-1:2015 Clause 8.1.1(b).

In accordance with ISO/IEC 17021-1:2015 Clause 6.1.3 and Clause 9.5, BCERT LTD retains full and sole responsibility for all certification decisions. No other party may direct, influence, or override BCERT LTD's certification decisions. BCERT LTD expressly reserves the exclusive right to:

  • Grant certification — where the management system has been assessed and found to conform to the requirements of the applicable standard;
  • Refuse certification — where the management system does not meet the requirements of the applicable standard, or where the Client has provided fraudulent or materially misleading information;
  • Maintain certification — confirming continuing conformance following a satisfactory surveillance audit;
  • Renew certification — issuing a new certificate following a successful recertification audit;
  • Suspend certification — temporarily withdrawing certification validity where the Client fails to meet its obligations under this Agreement;
  • Restore certification — reinstating a suspended certificate where the Client has resolved all grounds for suspension;
  • Withdraw certification — permanently revoking a certificate where grounds for withdrawal are established;
  • Extend or reduce the scope of certification — following a scope amendment audit or assessment.

3. Client Obligations

The Client shall:

  1. Maintain a management system that conforms to the requirements of the applicable standard(s) and all relevant legal and regulatory requirements throughout the certification cycle.
  2. Cooperate fully with BCERT LTD audit teams, providing access to all necessary personnel, documentation, processes, sites, and records required for audit purposes.
  3. Pay all certification fees as agreed in the certification contract within the specified payment terms.
  4. Notify BCERT LTD without undue delay of any significant changes, including changes to legal status, ownership, organisational structure, management, processes, or the scope of the management system.
  5. Implement corrective actions to address any nonconformities identified during audits within the timeframes agreed with BCERT LTD.
  6. Use the Certificate and Certification Mark only in accordance with Clause 8 of this Agreement and BCERT LTD's Mark Usage Procedure.
  7. Cease all use of the Certificate, Certification Mark, and any reference to certified status immediately upon suspension, withdrawal, or expiry of the certificate.
  8. Not make misleading, false, or unauthorised statements about certification status, scope, or the implications of certification to any third party.
  9. Permit BCERT LTD to conduct unannounced or short-notice audits where required under the applicable standard, IAF guidance, or accreditation requirements.
  10. Raise any complaint or appeal with BCERT LTD through the formal process before escalating the matter to IAS or any other external party.

4. Certification Scope

The scope of certification is defined in the Client's application, agreed between the parties, and stated on the Certificate issued by BCERT LTD. The scope specifies the processes, activities, products, services, sites, and/or organisational units covered by the certified management system.

Any proposed change to the certified scope must be notified to BCERT LTD in writing prior to implementation. BCERT LTD will assess whether the proposed change can be accommodated within the existing certification or whether additional audit activity, a scope amendment audit, or a new application is required.

5. Audit Process

Initial certification is conducted in two stages:

  • Stage 1 Audit — A documentation review and readiness assessment evaluating the Client's management system documentation, context, and readiness for Stage 2.
  • Stage 2 Audit — An on-site (or remote, where permitted) implementation audit evaluating the effectiveness of the management system in practice across all relevant processes, functions, and locations within the defined scope.

The certification decision is made independently of the audit team, by a designated BCERT LTD Certification Decision Maker not involved in the audit. Certification is granted only when all Major nonconformities have been closed and BCERT LTD is satisfied that the management system meets the applicable standard.

6. Certification Cycle (3 Years)

Each certificate issued by BCERT LTD is valid for a period of three years from the date of the initial certification decision, subject to satisfactory completion of surveillance audits and continued conformance. The certification cycle consists of:

  • Initial Certification — Stage 1 and Stage 2 audits leading to the first issuance of the certificate.
  • First Surveillance Audit — Conducted within 12 months of the initial certification date.
  • Second Surveillance Audit — Conducted within 24 months of the initial certification date.
  • Recertification Audit — A comprehensive audit conducted before the certificate expiry date, evaluating continued effectiveness and suitability of the complete management system.

Failure to complete required audits within the prescribed intervals may result in suspension or withdrawal of certification in accordance with Clause 10.

7. Surveillance Requirements

Surveillance audits are conducted in accordance with BCERT LTD's Audit Duration Procedure and IAF Mandatory Document MD5:2019. Surveillance audit durations are risk-based and calculated to ensure adequate coverage of the management system within each audit cycle.

Surveillance audits shall cover, as a minimum:

  • Internal audits and management review outputs
  • Actions taken on nonconformities identified in previous audits
  • Handling of complaints and feedback
  • Effectiveness of the management system in achieving the Client's objectives
  • Progress of planned activities aimed at continual improvement
  • Continued operational control of the certified scope

BCERT LTD reserves the right to conduct unannounced surveillance visits where required by the applicable standard, IAF guidance, or BCERT LTD's accreditation requirements. The Client must permit such visits and provide full cooperation.

8. Use of Certificate, Certification Mark, and IAS Accreditation Symbol

This clause sets out the conditions under which the Client is authorised to use the BCERT LTD Certificate, Certification Mark, and IAS Accreditation Symbol. All use must comply with both this Agreement and BCERT LTD's Mark Usage Procedure.

  • 8.1 Permitted Use: Upon being granted certification, the Client is granted a non-exclusive, non-transferable licence to use the BCERT LTD Certification Mark solely in connection with the certified scope, including marketing materials, the Client's official website, tender documents, proposals, and capability statements. All uses must accurately state the certified scope and include the relevant certificate number.
  • 8.2 Prohibition on Product Packaging: The Client MUST NOT use the Certification Mark, IAS Accreditation Symbol, or Combined Mark on products or product packaging.
  • 8.3 No Implied Endorsement: The Client MUST NOT use the marks in any manner that implies BCERT LTD or IAS endorses, approves, or recommends the Client's products, services, or commercial activities.
  • 8.4 Prohibition on Test/Inspection Documents: The Client MUST NOT allow the marks to appear on laboratory test reports, calibration certificates, inspection reports, or similar technical documents.
  • 8.5 Cessation Upon Suspension/Withdrawal: The Client's licence to use the marks ceases immediately upon suspension, withdrawal, or expiry of the certificate.
  • 8.6 General Prohibitions: The Client must not modify, alter, distort, recolour, transfer, sublicense, or otherwise misuse the marks.
  • 8.7 Consequences of Misuse: Any misuse may result in corrective action notice, formal nonconformity, suspension, or legal action by BCERT LTD.
  • 8.8 BCERT LTD's Right to Control Mark Usage: BCERT LTD retains the right to monitor, control, and direct the Client's use of the marks at all times during and after the certification relationship.

9. Changes Notification

The Client must notify BCERT LTD in writing, without undue delay, of any changes that could affect the management system or the validity of the certification, including but not limited to:

  • Change of legal entity name, trading name, company number, registered address, ownership structure, or acquisition/merger activity
  • Addition or removal of processes, products, services, activities, or sites within or adjacent to the certified scope
  • Changes to senior management responsible for the management system
  • Significant changes to processes, procedures, technology, or operational arrangements
  • Data breaches, security incidents, quality failures, regulatory investigations, or other events that may affect the certified management system
  • Changes in applicable law or regulatory requirements affecting the certified scope

10. Suspension and Withdrawal

Grounds for Suspension: Major nonconformity not resolved within agreed timeframe; Missed or overdue surveillance/recertification audit; Refusal to grant BCERT LTD or IAS auditors access; Misuse of Certification Mark or IAS Accreditation Symbol; Unassessed or undisclosed changes to certified scope; Non-payment of certification fees.

Grounds for Withdrawal: Suspension not resolved within 90 calendar days; Voluntary surrender of certification; Fraudulent representation or material misrepresentation; Systemic nonconformities demonstrating breakdown of the management system; Insolvency, dissolution, or cessation of trading.

During suspension: The Client must immediately cease all use of the Certificate, Certification Mark, IAS Accreditation Symbol, and Combined Mark. BCERT LTD will update the public registry to reflect the suspended status.

11. Complaints and Appeals

The Client has the right to submit a complaint or lodge an appeal in respect of any BCERT LTD certification decision or conduct of its personnel. All complaints and appeals are processed in accordance with BCERT LTD's Complaints and Appeals Procedure.

  • Acknowledgement: All complaints and appeals will be acknowledged in writing within 2 working days of receipt.
  • Resolution: BCERT LTD will endeavour to resolve all complaints and appeals within 10 working days.
  • Independence: All complaints and appeals are investigated by personnel independent of those involved in the matter under review.
  • Escalation to IAS: If not satisfied with the outcome, the matter may be escalated to IAS after exhausting BCERT LTD's internal process.

12. Confidentiality

BCERT LTD treats all information obtained from the Client during certification activities as strictly confidential. This includes management system documentation, audit findings, internal records, and any other commercially sensitive information disclosed in connection with certification.

BCERT LTD will not disclose Client information to third parties except: (a) as required by law, court order, or competent regulatory authority; (b) to IAS or its appointed witnesses during accreditation oversight activities; (c) with the Client's explicit written consent.

All BCERT LTD personnel and contracted auditors are bound by confidentiality obligations that survive the termination of their engagement.

13. Data Protection (UK GDPR)

BCERT LTD processes personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA 2018).

The lawful basis for processing personal data in connection with certification activities is: (a) Performance of a contract — processing necessary to provide certification services under this Agreement; (b) Legitimate interests — processing necessary for BCERT LTD's legitimate interests in operating an accredited certification body, including maintaining audit records, managing complaints, and fulfilling accreditation obligations.

Personal data obtained in connection with certification activities will be retained for a minimum of 5 years from the date of the relevant certification activity, in accordance with BCERT LTD's Document Retention Policy and accreditation requirements.

Data subjects have the right to access, rectify, or request deletion of their personal data, subject to applicable legal and accreditation retention requirements. For data protection enquiries, contact info@bcert.uk

14. Liability

Certification by BCERT LTD does not constitute a warranty, guarantee, or endorsement of the Client's products, services, or management practices. Certification signifies that the management system was assessed and found to meet the requirements of the applicable standard at the time of audit.

Limitation of liability: BCERT LTD's aggregate liability to the Client arising from or in connection with this Agreement shall not exceed the total fees paid by the Client to BCERT LTD in the twelve (12) months preceding the event giving rise to the claim.

Exclusion of consequential loss: BCERT LTD shall not be liable for any indirect, consequential, special, punitive, or exemplary loss or damage, including but not limited to loss of business, loss of profit, loss of revenue, loss of data, or reputational damage.

15. Termination

Either party may terminate this Agreement by providing 30 days' written notice to the other party.

BCERT LTD may terminate this Agreement with immediate effect if: (a) The Client engages in fraudulent activity or makes material misrepresentations to BCERT LTD; (b) The Client commits a serious or repeated breach of this Agreement that is not capable of remedy or is not remedied within any notice period given; (c) The Client is dissolved, enters administration, receivership, or liquidation proceedings, or ceases to trade.

Upon termination: The Client must immediately cease all use of the Certificate, Certification Mark, IAS Accreditation Symbol, and Combined Mark; The Client must remove all references to certified status from all websites, marketing materials, documentation, and other media.

16. Governing Law and Jurisdiction

This Agreement is governed by the laws of England and Wales. Any dispute arising out of or in connection with this Agreement that cannot be resolved through BCERT LTD's complaints and appeals process shall be subject to the exclusive jurisdiction of the courts of England and Wales.

17. ICT for Remote Audit Activities NEW

Where audits are conducted remotely using Information and Communication Technology (ICT), BCERT LTD shall:

  • (a) Complete an audit-specific ICT risk assessment (Form F/34) before each remote audit, covering the ICT tools to be used, connectivity requirements, confidentiality safeguards, and contingency arrangements;
  • (b) Agree the ICT platform and arrangements with the Client before the audit begins;
  • (c) Conduct a connectivity and infrastructure test with the Client no later than 5 working days before Stage 1;
  • (d) Ensure that remote audit activities are planned so that audit objectives can be achieved remotely;
  • (e) Maintain confidentiality of all information accessed during remote audit activities.

The Client shall:

  • (a) Provide working ICT infrastructure and named-account access for the agreed tools;
  • (b) Make personnel available per the audit plan with camera on during interviews;
  • (c) Ensure requested documented information and records are accessible and legible via the agreed ICT during the audit;
  • (d) Inform BCERT LTD without delay of any ICT restrictions, security policies, or incidents affecting the audit.

The specific ICT platform, tools, and arrangements for each audit cycle are recorded in Annex 1 to this Agreement (Mutual Agreement on the Use of ICT).

18. Remote Witnessing by the Accreditation Body NEW

The Client consents to the remote observation (witnessing) of audits by assessors of the International Accreditation Service (IAS) as observers of BCERT LTD's audit team performance. IAS assessors join agreed remote sessions as identified participants and are bound by confidentiality obligations. They do not audit the Client and will not disclose the Client's information. The Client's information is handled in accordance with IAS confidentiality rules and this Agreement.

19. Declarations and Representations NEW

By signing or electronically accepting this Agreement, the Client declares that:

  • (a) All information provided in the application for certification is true, accurate, and complete to the best of the Client's knowledge;
  • (b) The Client understands that BCERT LTD may request additional information or documentation to complete its review;
  • (c) The Client understands that submission of an application does not constitute a guarantee of certification;
  • (d) The Client acknowledges that BCERT LTD will use the information provided for application review, audit planning, and audit time calculation in accordance with ISO/IEC 17021-1:2015 and IAF MD 5;
  • (e) For transfer applications only: the Client consents to BCERT LTD contacting the previous certification body to obtain audit records in accordance with IAF MD 2:2023.

20. Surveillance Frequency NEW

Surveillance audits shall be conducted within the following timeframes:

  • (a) First surveillance audit: within 12 months of the certification decision date;
  • (b) Second surveillance audit: within 24 months of the certification decision date (and within 12 months of the first surveillance audit);
  • (c) Recertification audit: before the expiry of the current certificate.

Failure to complete a scheduled surveillance audit within the required timeframe is grounds for suspension of certification. BCERT LTD shall notify the Client at least 60 days before each scheduled surveillance audit.

Annex 1 — Mutual Agreement on the Use of ICT for Audit Activities and Remote Witnessing

This Annex is completed and signed separately for each certification cycle.

Parties: BCERT LTD (Certification Body) and the Client (Applicant/Certified Organisation)

Purpose: To document the mutual agreement on the use of Information and Communication Technology (ICT) for remote audit activities, including the agreed ICT platform(s), tools, security measures, confidentiality safeguards, connectivity requirements, contingency arrangements, and consent to remote witnessing by IAS assessors.

Audits Covered: This Annex applies to all remote audit activities conducted for the Client under this Certification Agreement, including Stage 1 audits, Stage 2 audits, surveillance audits, and recertification audits, unless otherwise specified.

Agreed ICT Platform: The specific ICT platform(s) and tools are agreed between the Client and BCERT LTD prior to each audit and documented in the Audit-Specific ICT Risk Assessment (Form F/34). The agreed platform(s) shall be capable of supporting video conferencing, document review, and screen sharing.

Security & Confidentiality: All ICT tools and platforms used shall comply with data protection requirements under UK GDPR and IAS confidentiality rules. All participants are bound by confidentiality obligations.

Connectivity Test Requirements: BCERT LTD shall conduct a connectivity and infrastructure test with the Client no later than 5 working days before the commencement of Stage 1 audit to verify that agreed ICT tools function correctly and that the Client's infrastructure can support the planned remote audit activities.

Contingency Arrangements: In the event of ICT failure, connectivity loss, or platform unavailability during a scheduled audit, both parties shall follow the contingency plan documented in the Audit Plan or otherwise agreed in writing prior to the audit.

Consent to IAS Remote Witnessing: The Client consents to the remote observation of audits by IAS assessors as observers of BCERT LTD's audit team performance. IAS assessors shall join agreed remote sessions as identified participants and shall be bound by IAS confidentiality obligations.

Client Responsibilities: The Client shall provide working ICT infrastructure, named-account access to agreed tools, available personnel per the audit plan with camera on during interviews, accessible documented information and records, and timely notification of any ICT restrictions, security policies, or incidents affecting the audit.

CB Responsibilities: BCERT LTD shall complete an audit-specific ICT risk assessment (Form F/34), agree the ICT platform and arrangements with the Client before audit commencement, conduct the connectivity test, ensure remote audit objectives are achievable, and maintain confidentiality of all information accessed during remote audit activities.

Document Authorisation
Document Reference TC-001 · Rev 2.0
Issue Date 17 July 2026
Next Review 17 July 2027
Revision Note — Rev. 2.0 (17 July 2026): Full update of TC-001 Certification Agreement. Major additions: NEW Section 17 — ICT for Remote Audit Activities (establishing requirements for remote audits using Information and Communication Technology, including ICT risk assessment, connectivity testing, and confidentiality safeguards). NEW Section 18 — Remote Witnessing by the Accreditation Body (documenting Client consent to IAS remote observation of audits). NEW Section 19 — Declarations and Representations (requiring Client declarations regarding accuracy of application information, understanding of certification process, and consent for transfer applications). NEW Section 20 — Surveillance Frequency (establishing specific timeframes for first surveillance, second surveillance, and recertification audits, with 60-day notification requirement). NEW Annex 1 — Mutual Agreement on the Use of ICT for Audit Activities and Remote Witnessing (documented for each certification cycle, covering parties, purpose, audits covered, agreed ICT platform—Google Workspace, security and confidentiality, connectivity test requirements, contingency arrangements, IAS remote witnessing consent, and mutual responsibilities). Metadata updated to Rev 2.0, Issue date 17 July 2026, Next review 17 July 2027. Accreditation status updated to IAS application in progress · ISO/IEC 17021-1:2015. Governing law confirmed as England and Wales.