Standards we certify to
Six standards. We certify the management system — not your products, not your services, and not your people. Each page below says what a certificate against that standard does assert, and what it does not.
Information security
How you determine information security risks, choose controls against them, and check whether those controls actually work.
Healthcare information security, Abu Dhabi
The Department of Health – Abu Dhabi information and cyber security standard for healthcare entities operating in the emirate.
Artificial intelligence
How you govern the AI systems you develop, provide or use — impacts, data and model control, human oversight, accountability.
Quality management
How you consistently deliver what you have promised customers, and what you do when you do not.
Environmental management
How you identify the environmental effects of what you do, control them, and meet the obligations that apply to you.
Occupational health and safety
How you identify what can hurt people at work, control it, and involve workers in doing so.
Audit time is not one calculation
Each standard has its own basis for determining how many audit days are required, set by a different document, and the numbers are not interchangeable. ISO 9001, ISO 14001 and ISO 45001 use the tables in IAF MD 5 — but different tables, weighted for different things. ISO/IEC 27001 uses ISO/IEC 27006-1. ISO/IEC 42001 uses ISO/IEC 42006. ADHICS follows the Department of Health – Abu Dhabi's own requirements.
Where more than one standard is certified together, the shared parts of the management system are audited once rather than repeatedly, and the combined figure is meaningfully less than separate audits would come to.
We show you the calculation with the quotation, and no part of the fee depends on whether we certify you. How audit time and fees are worked out →
Accredited and unaccredited certification are different things
An accreditation body accredits a certification body scheme by scheme — not as a blanket approval. A body accredited for ISO/IEC 27001 is not thereby accredited for ISO/IEC 42001, and each scheme has its own criteria document, its own competence requirements and its own witness assessment.
The chip on each card above says whether an accreditation scheme exists for that standard. Separately, and importantly: UMA does not yet hold accreditation for any of them. Our accreditation status →