top of page

Compliant vs. Certified: Why Independence Is the Real Foundation

  • Writer: Adam Witthauer
    Adam Witthauer
  • 12 hours ago
  • 7 min read

In last week’s article I discussed some of the benefits of obtaining compliance to either ISO 9001 or AS9100. This week I’ll discuss the difference between compliance and certification, and why independence and impartiality are important at every level. In subsequent articles we will review the clauses, how they benefit customer satisfaction, some examples of what it takes to be conforming to these requirements and how conformance can benefit operations.


The idea to write this series came to me while buying some cheap seat covers from my local auto parts store. When I got home and opened the box, this is what I was greeted with. I was immediately giddy as I recognized the ISO 9001 clauses that required these things. They should have put this on the outside of the box! It then occurred to me that the average retail auto parts shopper probably doesn’t have the same appreciation for these things as I do.


Seat cover box listing facets of ISO 9001
Look at the ISO clauses advertised on my $50 seat covers!

I also remember a time when, despite having a solid background in manufacturing, I hadn’t yet developed the appreciation for a solid framework that improves your odds of always making good parts. My goal is to bring this understanding to a larger audience, who may not have spent nearly as much time in an ISO 9001 or AS9100 environment.

What does it mean to be compliant?

You may have seen businesses that advertise that they are ISO 9001 Compliant. This statement is a self-proclamation, and while it’s not backed up by anything besides the company’s word, it still sends a signal. Out of curiosity, I decided to research my $50 seat covers. They bore the Dickies brand, which is better known for work pants. While there are companies that offer longer-lasting work pants that are higher-grade, Dickies has always offered a pretty good bang for the buck and, at least in my personal experience, good quality.


Dickies is a division of Workwear Outfitters. On their corporate website, they have a page dedicated to ISO 9001, which includes a quality statement and quality objectives. There is no mention of certification, and also no mention of which revision of ISO 9001 they are referring to. They also make no statement of being in compliance; it is possible their QMS may not meet all applicable clauses.


At the same time, their Quality Statement, at least from publicly available data, appears to conform to Clause 5.2.1 of ISO 9001:2015 for a quality policy, and the availability of this quality policy on their public website conforms to some of the requirements of Clause 5.2.2 in communicating the quality policy. Their Quality Objectives appear to conform to Clause 6.2.1, based on what is available on this web page. Their stated objective (as of July 2026) of >= 99.5% on their Customer Delight Index sounds like a commendable goal.


What does it mean to be certified?

The next step up from proclaiming compliance is to have an independent third party assess their conformance to a published standard. A Certification Body, more commonly known as a registrar, can do this. A registrar is granted authority by an Accreditation Body to issue certificates to this standard, and after initial certification the registrar will perform periodic surveillance and recertification audits to this standard to ensure conformance is maintained over time.


Certification comes with a price. Auditors require extensive experience and training, with most having decades of experience. For a small to medium manufacturer, maintaining certification can cost a few thousand dollars per year, and this cost can rapidly increase for larger organizations. For this reason the market access argument discussed in my previous article is perhaps the most compelling justification for small to medium contract manufacturers, for reasons that will become clearer below.


How to choose between compliant vs. certified?

Let’s go back to the example with Dickies seat covers. Workwear Outfitters includes a dozen or so brands, some of which are quite large, popular, and well-established. They could have scores of manufacturing facilities, and certification costs could be very significant. At the same time, as I mentioned previously, the average retail shopper of work pants or cheap seat covers often doesn’t know or even care what ISO 9001 is. The market access argument is insignificant here. So in the case of Workwear Outfitters, while building an ISO 9001-based quality management system supports their quality objectives and corporate quality strategy, they may not get a return on investment for certification.


The automotive market varies widely in regulation. Selling $50 seat covers at a consumer chain auto parts store is essentially unregulated. However, if Dickies decided to expand their business and provide seat coverings for OEMS, the OEMs could require ISO 9001 certification. If there are critical product safety requirements, which there appear to be with their “laser deploy” airbag deployment system for seat covers that cover airbags, an automotive OEM may also require IATF 16949 certification. But until then, managing this internally in such a way that they can gain an acceptable level of confidence in their product quality, given their strategic direction and target market, may be adequate to keep their customers safe and happy.


Going deeper in the market access argument

The history and development of ISO 9001 coincides with the development of the greater supply chain that we know today. Since the 1970s, many large manufacturers have become less vertically integrated, relying more on contract manufacturers, and at the same time quality expectations increased significantly. Likewise, these smaller manufacturers often served a variety of customers, which prompted the need for an international quality standard.


As the ISO 9001 environment matured, the aerospace market saw a similar need, with each of the major OEMs and Primes flowing down their own sets of quality standards, each of which added burden and cost to contract manufacturers. This led to the development of AS9100 (soon to be renamed IA9100), which unified many of these requirements, making individual OEM and Prime quality requirement flow-downs much more manageable.


I once toured a new production facility for a major supplier of premium windows to the construction industry. I saw several of the telltale signs of ISO 9001. The company’s mission, vision, values, and quality policy were posted visibly. I could see process control and traceability in action, verification of inputs, and evidence of continuous improvement. I mentioned this to their quality manager and asked if they were ISO 9001 certified. He told me that at one time they were, however several years ago they chose to quit paying for certification since ISO 9001 certification isn’t really a customer expectation in the construction market. They do see the value of this framework though when it came to ensuring their product quality, so they do maintain compliance internally. To maintain this level of quality throughout their supply chain, they did require ISO 9001 certification of their suppliers. By doing this they are able to gain confidence in their suppliers without having to exert as much effort on second party supplier audits.


Independence and impartiality

The fundamental difference between compliance and certification is the independence of a registrar issuing certification. Independence and impartiality are key quality themes that flow through every level of manufacturing. Operators running the machines that produce product will make every effort to verify product as it is being produced by doing in-process checks, but ultimately a QC inspector provides verification through independent inspection to ensure product meets requirements. This inspector is impartial to the conformance of this product. While it is ideal for operators to take pride in their work, this pride is also an incentive to bias any measurements they take.


Therefore an assessment from an impartial inspector provides a greater level of trust.

Likewise, when a product non-conformance is discovered, an engineer responsible for dispositioning the product must be free from bias. If he or she is in the reporting chain of a manager or director responsible for meeting production targets, this has the potential to influence this engineer in a choice between meeting production targets and meeting quality requirements. The only way to guarantee that quality is not compromised is for this engineer to be free from responsibility for meeting production targets.


Going further, it is stated as preferable (although often difficult for smaller manufacturers) for first party internal auditors to be independent and impartial of the processes they are auditing. Many smaller manufacturers choose to outsource their internal audits to a consultant in order to guarantee independence. An additional benefit of doing this is that consultants typically bring not only a wide variety of experience, but a critical outside perspective not tainted by the norms that people who live in this environment daily can become blind to over time.


At the registrar level, third party auditors are required to disclose any conflicts of interest they may have. A third party auditor is not allowed to perform a third party audit on a company with whom they have recently consulted or worked for. This ensures that auditors do not skip areas where they may know problems exist, or do the opposite by hyper-focusing on areas where they expect to find issues. Either of these practices can bias the outcome of an audit. In these situations an auditor may have either positive or negative allegiances to the people they are auditing. This bias is minimized by intentionally avoiding conflicts of interest to ensure impartiality.


Conclusion

Whether an organization chooses being compliant vs. certified, the underlying goal remains the same: to build and maintain a quality management system that instills confidence in their products and services. Certification provides a level of independence and impartiality that compliance alone cannot fully replicate, and for many organizations operating in competitive supply chains, it serves as a powerful signal of credibility to customers and partners.


However, as the examples above illustrate, certification is not always the right fit for every market or business model. What matters most is that an organization honestly evaluates its strategic direction, its customers' expectations, and the risks associated with its products, and then commits to a framework that genuinely supports quality rather than simply checking a box. In the end, the value of ISO 9001, whether certified or not - lies not in the certificate on the wall, but in the culture of continuous improvement it is designed to build.


What’s next

Stay tuned as we go through the individual clauses and describe what is expected for conformance, some examples of how to meet these requirements, why they are important to customer satisfaction and how they can actually streamline operations. Next week we will begin with an overview of the PDCA cycle and how it applies to ISO 9001 and AS9100, as well as Clause 4, Context of the Organization.

Comments


bottom of page