The following provides a technical overview of the standards required from certification bodies to be accepted by ICoCA for ICoCA certification.
ICoCA certification standards
To become an ICoCA certified member, a private security company (PSC) must be certified to an external standard which is recognised by ICoCA[1] for certification. The standard must also be issued by an accepted certification body. Currently the following recognised standards can be used for certification:
New standards can be proposed by ICoCA member companies, and it is anticipated that the number of accepted standards for certification will increase over time.[3]
Accepted certification bodies
ICoCA does not accept certifications from all certification bodies as many certification bodies do not operate to high, rigorous standards and therefore the certifications which they issue are not acceptable for ICoCA’s own certification.
A certification body can be accepted through two mechanisms:
Certification bodies directly accredited to an ICoCA recognised standard
The following accepted certification bodies are directly accredited to a recognised standard:
AES IQS Egypt Next Generation Company
CCS Icontec Intertek MSS Global
Certification bodies accredited to ISO 17021
The following accepted certification bodies are accredited to ISO 17021 and have passed ICoCA competency checks:
| DNV | DQS | Eurocert |
| IAS Register | Infinity Cert | Libero Assurance |
| QMS Global | SMG | TUV Austria Hellas |
| UNIT | UNBS | Apave |
What is the difference between a certification body being directly accredited to a recognised standard and being accredited through ISO 17021 and passing ICoCA competency checks?
A certification body which is accredited to a recognised standard is being regularly checked by the accreditation body (the Global ACI member) to ensure that they are certifying in line with the standard. The certification body may also be required to follow certain guidelines, such as UKAS’s CIS 9, UKAS’s CIS 10 or EGAC Guidance for Bodies Offering Certification of ISO 18788 Management System for Private Security Operations. A certification body which is accredited to ISO 18788 must also be accredited to ISO 17021.
A certification body with is accredited to ISO 17021 (but not accredited to a recognised standard) is being regularly checked by the accreditation body to ensure that they are operating in line with best practice for certification bodies. The accreditation body, amongst other areas, will check to ensure that the certification body is competent, consistent, impartial and independent, and reliable. They are however not being checked against the recognised standard itself.
Given the additional oversight that accreditation to a recognised standard brings, ICoCA encourages all certification bodies which are accepted through the ISO 17021 route to obtain accreditation to a recognised standard.
Certificates issued to PSCs by certification bodies accredited to a recognised standard are often visible through the Global ACI’s certification database. It should be noted however that use of this database by Global ACI MRA signatories may not be universal, given concerns over confidentiality.[4] Certificates issued by certification bodies which are only accredited to ISO 17021 will not appear on this database as they are not accredited to the recognised standard by a Global ACI member.
Information on ICoCA certification is available through the ICoCA website.
1.What if my certification body is accredited to ISO 17021 by a Global ACI MRA signatory but is not currently accepted by ICoCA?
Please contact the ICoCA Secretariat on secretariat@icoca.ch. The Secretariat can then see if the certification body can be accepted. Please note that as part of assessment process personnel from the certification body, including auditors, will need to be interviewed.
2. My certificate is from a certification body which does not hold accreditation from a national accreditation body which is a member of the Global ACI. What does mean?
Your certification cannot be accepted. National accreditation bodies must themselves be checked, to ensure that they are operating to high standards. If the certification body is using an accreditation body outside of the Global ACI structure, then it lacks this required assurance.
3. A certificate does not appear on Global ACI certification database (CertSearch), what does this mean?
If a certificate has been issued by an ICoCA-accepted certification body, to ISO 18788, PSC.1 or ISO 28007, and it does not appear on the Global ACI certification database then it means that the certification body is not specifically accredited to that standard by the national accreditation body. Only accredited certificates will appear on the CertSearch website. The ICoCA website can be used to verify such certificates which are used for ICoCA certification.
4. Why does ICoCA accept ISO 18788, PSC.1 and ISO 28007 certificates from certification bodies which are not specifically accredited to these standards by a national accreditation body (which is a member of the Global ACI)?
Only four national accreditation bodies (which are Global ACI MRA signatories) directly accredit certification bodies to ISO 18788. Only one certification body directly accredits certification bodies to ISO 28007. Because of the limited global uptake in these standards, ICoCA accepts certifications from certification bodies which are accredited to ISO 17021 by a national accreditation body which is a Global ACI MRA signatory, and which have gone through ICoCA competency checks.
5. What happens if my certification body is accepted by ICoCA through the ISO 17021 route, but now the national accreditation body has launched a scheme to directly accredit certifications to the standard to which my company is certified?
If a certification body is accredited to ISO 17021 from a national accreditation body which then launches a scheme to a standard, such as ISO 18788, then the certification body must then become directly accredited to ISO 18788. The certification body will have one year to achieve this accreditation. If direct accreditation from the national accreditation body to a standard then the certification body must become directly accredited to this standard.
For further information please contact ICoCA on secretariat@icoca.ch.
[1] Technically, the ICoCA Board of Directors, as per Article 11 procedures.
[2] Certification is to ISO 28000 using ISO 28007-1:2015, “Ships and marine technology – Guidelines for Private Maritime Security Companies (PMSC) providing privately contracted armed security personnel (PCASP) on board ships, Part 1 General”
[3] For more details please consult ICoCA’s Article 11 procedures, specially III. ICoCA Certification Procedure, Board Recognition of Standards.
[4] The German national accreditation body, DAKKS, has highlighted concerns over the database.