Blog
Compliance
ISO 9001
ISO 27001
GDPR
August 24, 2026
Approx min read

Certifying a group: one certificate, several entities

Somewhere between the second acquisition and the third office, the compliance question changes shape. It stops being "how do we get certified" and becomes "how many certificates are we buying, and who owns them".

The answer is usually one certificate, and the route to it is well defined. The rules that allow it are also the rules that decide how much a problem in one part of the group costs the rest of it, and they are worth reading before anyone commits to a scope.

The document your certification body is working to

Certification of an organisation operating across several sites or entities is governed by IAF MD 1:2023, Issue 3, issued on 18 October 2023. Accreditation bodies apply it, and so do the certification bodies they accredit, which is why it decides what your own auditor can and cannot do with a group.

The Forum itself no longer exists. It ceased operations on 1 January 2026 and its work passed to Global Accreditation Cooperation Incorporated, which has confirmed that IAF mandatory documents stay valid until equivalent Global ACI documents are adopted. Plenty of articles on this subject also still quote the 2018 issue, so check both the issue and the source before relying on anything you read.

Its central provision is short and it settles the question most groups arrive with. Clause 3.3.1: "A multi-site organization need not be a unique legal entity, but all sites shall have a legal or contractual link with the central function of the organization and be subject to a single management system, which is laid down, established and subject to continuous surveillance and internal audits by the central function."

Separate companies can sit under one certificate. The condition is the single management system and the link to a central function, and the standard is specific about what both mean.

What a multi-site group has to be able to show

Section 5 lists the eligibility criteria. Six of them, and each one is a question a group is either ready to answer or is not.

There is a single management system, and it is subject to a centralised management review. Three systems that resemble one another are three systems, and a certification body reads them that way.

There is an identified central function. It is part of the organisation and cannot be subcontracted to anyone outside it, which rules out handing the whole thing to a consultancy and calling that the centre. It does not have to be the headquarters, and the note to clause 5.6 confirms there is no requirement for it to sit in a single location.

That central function has organisational authority to define, establish and maintain the system, and it is responsible for collecting and analysing data from every site. It must be able to demonstrate authority to initiate change, and the clause names six areas without limiting itself to them: documentation and system changes, management review, complaints, evaluation of corrective actions, internal audit planning and results, and the statutory and regulatory requirements attached to the standard.

Every site sits inside the internal audit programme.

For most groups the hard one is the central function. Compliance often grew up inside whichever company needed the certificate first, and that company has no authority over its sister businesses. Naming a group compliance owner with real authority is the change that makes certification possible, and it usually has to happen before a certification body will look at you.

Sampling, and why it is not automatic

A group of twenty sites does not get twenty audits. The certification body samples, using the square root of the number of sites at initial certification, 0.6 times the square root for the annual surveillance sample, and the same as an initial audit at recertification, which can drop to 0.8 times the square root where the system has proved effective across the cycle. Each figure is rounded up to the next whole number, so twenty sites means five at initial certification and not four and a half. The central function is audited at initial certification, at every recertification and at least once a calendar year as part of surveillance.

Two conditions sit in front of that arithmetic. Sampling is permitted where the sites are each performing very similar processes and activities. And clause 6.1.1.2 puts it plainly: "Not all organizations fulfilling the definition of 'multi-site organization' will be eligible for sampling."

A group of five companies doing five different things is a multi-site organisation that may well be audited site by site. That is a budget question and a diary question, and it is better asked at the scoping call than discovered at stage two.

One site can cost the group its certificate

Section 7 is where the group business case usually goes wrong, because it changes how certification should be priced and it rarely gets read.

At the certification decision, a major nonconformity at any one site denies certification to the whole multi-site organisation, pending satisfactory corrective action. Clause 7.7.3 applies that denial to every listed site, whatever the finding was and wherever it was raised.

The obvious workaround is closed. Clause 7.7.4 states that it is not admissible to exclude the problematic site from the scope in order to get past the nonconformity.

And maintenance works the same way. Clause 7.8.4: "The certification documentation will be withdrawn in its entirety if any of the sites does not fulfil the necessary provisions for the maintenance of the certification."

So the weakest entity in the group sets the position of every other one. If one company runs its access reviews properly and its sister company does not, the certificate the sales team is quoting belongs to both of them.

The subsidiary that wants its own certificate

This comes up whenever a buyer asks one company in the group for evidence and gets handed a certificate with the parent's name on it.

Certification bodies can issue site-level documents, and clause 7.8.3 sets out exactly what they must say. They have to state that it is the management system of the whole organisation which is certified. They have to carry traceability to the main certificate, such as a code. They have to include the statement "the validity of this certificate depends on the validity of the main certificate". And they cannot be issued in the name of the site or legal entity, or suggest that entity is certified, because the certified party is the organisation.

Worth knowing before someone promises a buyer a standalone certificate for one subsidiary. The document exists, and it says something more careful than the buyer is expecting.

The certification documentation has to name every site and address, and where one site covers only part of the organisation's scope, it carries that site's sub-scope. Buyers read scope statements closely, so the wording is worth drafting with the same care as the contract it supports.

What one certificate does not merge

Data protection accountability does not consolidate. Article 30(1) of the UK GDPR requires that "each controller and, where applicable, the controller's representative, shall maintain a record of processing activities under its responsibility", and Article 5(2) makes each controller responsible for demonstrating its own compliance.

One management system, one certificate, and separate records of processing for each controller in the group. Groups that merge the two end up with a single record that describes nobody accurately, and it is the first document a regulator or an acquirer asks to see.

Settle these before the scoping call

Whether there is one management system or several in practice, whatever the policy documents say.

Who the central function is, by name, and whether that person has authority over entities they do not work for.

Whether the entities do similar enough work to be sampled, because that decides the cost.

Running one system across several entities with Naq

The Naq platform automates GDPR, Cyber Essentials, ISO 27001, ISO 9001 and the NHS DSPT against one library of controls and evidence, so a control mapped once counts towards every framework whose requirements it satisfies.

For a group, the useful part is that the same framework can be run more than once, so a parent and a subsidiary with different scopes each have their own instance, both drawing on the same controls and evidence. Policies and risks carry a named owner and a named approver, with a review date set at sign-off, so responsibility belongs to a person in a specific entity. Every control carries a named owner. Meaningful actions are written to the record's activity stream, and field edits show the previous and the new value. Records are archived instead of deleted, which is the trail a certification body looks for when it asks how the central function exercises control.

Where a group wants named expert support alongside the platform, Naq's in-house Clinical Safety Officers and virtual Data Protection Officers sit next to it.

The ISO 27001 and ISO 9001 framework pages carry the requirement detail, and compliance across several entities sets out how Naq works when there is more than one of everything. If your question is about running the same framework twice across entities, that is covered in holding the same framework twice.

If you are scoping certification across more than one company, book a fifteen-minute demo and bring your entity list.