Back to Columns
ISMS & Certification10 min read

ISMS-AC, UKAS and ANAB: Choosing an Accreditation Body

September 14, 2026

ISMS-AC, UKAS and ANAB: Choosing an Accreditation Body
Share this article

Ask certification bodies for quotes and the proposals come back sprinkled with "ISMS-AC accredited," "UKAS accredited." This is where most project owners stumble. What is the difference between accreditation and certification? Does a different accreditation body mean a different certificate?

The short answer: the standard is the same ISO/IEC 27001 in every case. What differs is who vouches for the competence of the certification body — and that difference shapes how your counterparties read your certificate.

This article covers the two-tier structure, the differences between the main accreditation bodies, what accreditation actually guarantees, and how to choose based on who your customers are. For the overall picture, see What Is an ISMS (ISO/IEC 27001)?.

Disclaimer: This article is general information. The handling of accreditation and certification, and each body's accredited scope, are governed by the publications of the accreditation and certification bodies themselves. Always verify current status at source.

Who Vouches for Whom

ISMS certification has three tiers.

TierNameRoleExamples
1Accreditation bodyAssesses the competence of certification bodies and accredits them; does not audit organisations itselfISMS-AC (Japan), UKAS (UK), ANAB (US)
2Certification bodyAudits an organisation's ISMS and issues the certificateBSI, JQA, Bureau Veritas, SGS, DQS
3The certified organisationBuilds and operates the ISMSYou

You contract with a certification body. You never deal with the accreditation body directly. The accreditation body's job is to check that the certification body audits properly.

The structure exists to prevent a certification body vouching for its own audit quality. Certificates issued by unaccredited bodies can physically exist, but nobody independent stands behind the audit that produced them. To a customer, an unaccredited certificate is one they have no way to verify.

Accreditation bodies are not isolated from one another either. The International Accreditation Forum (IAF) provides a mutual recognition framework under which participating bodies' accreditations are, in principle, treated as equivalent. ISMS-AC, UKAS, and ANAB all sit inside it.

How the Main Bodies Differ

BodyBaseCharacterWhere it is read
ISMS-AC (Information Management System Accreditation Center)JapanOperates Japan's ISMS conformity assessment scheme; publishes a searchable register of certified organisations in JapaneseProcurement by Japanese hospitals, pharma, local government
UKASUnited KingdomThe UK national accreditation body; well recognised across Europe and the CommonwealthEuropean customers, global SaaS vendor assessments
ANABUnited StatesThe US accreditation body; well recognised in North AmericaUS counterparties, US investor due diligence

The requirements are the same ISO/IEC 27001 in all three cases. What the audit looks at does not change materially by accreditation body. Two things do differ:

  1. Verifiability of the register. ISMS-AC publishes certified organisations in Japanese, so a Japanese buyer can check you easily
  2. Familiarity of the mark. A UKAS mark needs no explanation to a British or European reviewer; ISMS-AC does. And the reverse is equally true

So the criterion is not the content of the standard but who reads the certificate.

On choosing the certification body itself, see Choosing a Certification Body and Comparing the Major Certification Bodies.

What Accreditation Actually Guarantees

"If an unaccredited certificate is cheaper, why not?" is a fair question. Here is what accreditation underwrites.

  • Auditor competence requirements. Accredited bodies are externally checked on auditor qualifications, experience, and continuing development
  • Reasonableness of audit effort. The framework sets expectations for auditor-days relative to headcount and scope, making implausibly short audits hard to sustain
  • Independence of the certification body. Requirements exist to avoid conflicts of interest, such as the same party doing consulting and certification
  • An appeals route. If you dispute an audit outcome, there is a tier above the certification body

In practice the second point bites harder than the fourth. A certificate obtained through an unaccredited audit at a fraction of the usual effort tends to get picked apart during a customer's security review. Auditor-days and scope statements on a certificate are exactly what a reader inspects.

And the most overlooked item is the scope written on the certificate. Whatever the accreditation body, a scope that diverges from reality will not persuade anyone. Does it say "whole company," or is it confined to one service? Customers read that line. See Defining ISMS Scope.

Choosing by Who Your Customers Are

Count the people who will read the certificate.

Customer mixRecommendationWhy
Mostly Japanese hospitals, pharma, governmentA body accredited by ISMS-ACEasiest for domestic buyers to verify from public records
Domestic now, overseas plannedISMS-AC primarily, but choose a body that can also issue under an overseas accreditationSwitching certification bodies later is costly
Real European customersA UKAS-accredited certificate alongsideNo explaining required to European procurement
US counterparties or investorsAn ANAB-accredited certificate alongsideSmoother North American due diligence

"Alongside" is the operative word: internationally active certification bodies often hold multiple accreditations. Which accreditations a given body can issue under varies, so ask at the quotation stage — it belongs on the must-ask list for competitive quotes.

If overseas expansion is the driver, note that some counterparties will ask for SOC 2 rather than ISMS — see ISMS vs SOC 2. And if cloud add-ons (ISO 27017 and 27018) or the privacy extension (ISO 27701) are on the roadmap, check that the body can audit those too, to avoid having to switch later.

For how hospitals read supplier certifications, see Security Check Sheets for Vendors and The Three-Ministry Guidelines.

Conclusion

  1. ISMS certification is three tiers: accreditation body → certification body → your organisation. You contract with the middle one
  2. ISMS-AC, UKAS, and ANAB all certify against the same ISO/IEC 27001; recognition and verifiability are what differ
  3. Accreditation underwrites auditor competence, plausible audit effort, independence, and an appeals route
  4. Customers read more than the accreditation name — the scope on the certificate must match reality
  5. Choose by who reads the certificate: ISMS-AC domestically, UKAS for Europe, ANAB for North America
  6. In competitive quotes, always confirm which accreditations a body can issue under and whether it can audit future add-ons (27017/27018/27701)

Pottech supports ISMS certification with a focus on healthcare. For certification body selection we obtain and compare competitive quotes — including from JUSE, JSA-SOL, and ICMS — and lead the project from scope design through the audit itself.

See ISMS Certification Support for scope and pricing, or contact us to discuss your situation.

References and Sources

Note: accredited scopes and scheme rules change. Always confirm what a certification body can issue against its own published material and its quotation.

Share this article

Related Articles

ISMS & Certification

Reading the 37 Organizational Controls

The 37 organizational controls of Annex A.5, grouped into eight clusters rather than translated one by one: policy and governance, assets and classification, access policy, suppliers and cloud, threat intelligence, incident management, continuity, and compliance. What each cluster is asking for, and what you end up producing.

September 14, 2026
ISMS & Certification

Annex A 2022: 93 Controls Across Four Themes

A map of the 93 Annex A controls in ISO/IEC 27001:2022 across four themes — 37 organizational, 8 people, 14 physical, 34 technological. Why there is no duty to implement all 93, how inclusion and exclusion are justified in the Statement of Applicability, what the attributes are for, and the order a healthcare company should work in.

September 14, 2026
ISMS & Certification

Reading the 8 People Controls

The 8 people controls of Annex A.6, grouped into entry, employment, exit, where people work, and reporting culture. How they connect to existing employment rules, how to handle segregation of duties when the team is too small for it, and how far to go on remote working — written for healthcare companies.

September 14, 2026
ISMS & Certification

Reading the 14 Physical Controls

The 14 physical controls of Annex A.7 in five clusters, with a concrete treatment of what a fully remote, cloud-only organisation can exclude and what must be reassigned to home-working rules and supplier management — data centres, media and disposal, and equipment off premises.

September 14, 2026
AI Karte

Explore AI Karte

An AI-native EHR connecting reception, documentation, accounting, claims, and analytics into one cycle.

View the product page

ISMS Certification Support as an Option

From scope design and documentation to training, internal audit, and dealing with the certification body. Pottech supports healthcare companies through ISO/IEC 27001 certification end to end.