What each document proves, and for how long
Direct answer
A certificate proves the thing it was issued for and nothing more. This page states, per document type, what was assessed, who issued it, how long it stays valid, and how to check it with the issuing body.
Key facts
- A certificate proves the thing it was issued for and nothing more.
- The certificates published on this site are the operator's own documents, supplied as scans and published without alteration.
- That distinction matters more than it sounds.
- Two rows deserve a second look.
- Validity is where a genuine certificate becomes a stale one, and the intervals differ by document type rather than by issuer preference.
A certificate proves the thing it was issued for and nothing more. Read that way, a document is a useful object: it names a scope, an issuer, a holder and a validity period, and each of those can be checked. Read as a general verdict on a product, it becomes the most common source of misplaced confidence in sourcing.
Whose certificates these are
The certificates published on this site are the operator's own documents, supplied as scans and published without alteration. The holder name printed on each scan governs: where a scan names a legal entity, that entity is the one the certificate belongs to, and a document naming a different company is not evidence about the company you are dealing with.
That distinction matters more than it sounds. Certificates travel between related companies, and a group of factories under one sales entity will often hold documents that name only one of them. A buyer who reads a scan as evidence about the entity on the invoice is one step ahead of a buyer who reads it as evidence about a brand.
What each document type actually proves
| Document | What it proves | Where it stops |
|---|---|---|
| Management system certificate | A documented quality system is in place and has been audited by the issuing body | It says nothing about any specific product, batch or shipment |
| Social compliance audit | The site was assessed against a named standard on a stated date, with a rating | Ratings expire, and a rating is a snapshot of a site rather than a condition |
| Supplier assessment report | An assessor visited and recorded what they found, under a stated scope | The scope decides the value; a narrow scope can be misleading if read broadly |
| Product test report | A stated method was applied to stated samples with a stated result | It is evidence about those samples, not about a production run |
| Authorisation to apply a mark | The holder is authorised by the mark owner to apply it to specified products | Authorisation to mark is not a test result, and it is not a safety finding |
Two rows deserve a second look. A product test report is the strongest document in the list and the easiest to overstate: it is only as good as its sample selection, and a report on a unit the factory chose is weaker evidence than one on units drawn at random from a lot. And an authorisation to apply a mark establishes a commercial relationship with the mark owner rather than a technical result — useful, checkable, and not a substitute for a test.
How long each type stays valid
Validity is where a genuine certificate becomes a stale one, and the intervals differ by document type rather than by issuer preference.
| Document | Typical validity | At expiry |
|---|---|---|
| ISO 9001 quality system | 3 years, with surveillance audits at 12 and 24 months | A certificate past its surveillance audit is not a live certificate |
| Social compliance audit (amfori BSCI) | Up to 24 months for a high rating, shorter for a lower one | A fresh audit is required; the old rating does not carry forward |
| Social compliance audit (SMETA) | Commonly treated as robust for up to 24 months | High-risk sites are re-audited annually in practice |
| Product test report | No fixed term, but the method and the rule it references both move | A report against a superseded method is a historical document |
One pattern runs through the table and catches buyers regularly. A document can be genuine, unexpired and still not describe the thing you are buying, because a specification change moves the product. A new colourway moves the finish, a finish change can move the assessed material, and a hardware part change moves the component that gets tested. A certificate that covers a product you no longer order is not evidence about the product you do.
How to check that a certificate is genuine
Read the certificate number and the issuing body off the scan, then verify it with that body's own registry rather than with the supplier. This is the step most buyers skip, and it is the one that separates a document from a claim about a document.
Three checks in order. The issuing body's registry should return the certificate number with the same holder name and the same validity dates as the scan — a registry lookup is usually public and takes minutes. The holder name should match the entity you are contracting with, or you should know why it does not. And the scope should cover the product or process you care about; a certificate for a different site, a different product line or a different process is genuine and irrelevant at the same time.
Two failure modes are worth naming because both look like success. A registry entry that exists but has expired is often reported as "found" by a cursory check, so compare the dates rather than the number. And a scan that has been altered is usually altered in the scope or the dates rather than in the certificate number, because the number is the part that gets checked — which is why the registry comparison has to cover all three fields rather than one.
What does each document actually prove?
A certificate is evidence of one thing, checked on one date. Read it as such, and it becomes useful; read it as a guarantee, and it becomes a risk.
| Document type | What it covers | What it does not cover |
|---|---|---|
| UL authorisation to apply the UL Mark | Authorisation for the holder to apply the mark to products within the scope listed by UL | Any product outside that scope, and any claim that everything a factory makes is listed |
| amfori BSCI audit summary | Social compliance at a site on a stated audit date, with a grade | Product safety, material specification or capacity |
| Supplier assessment report (SGS) | An assessment of the supplier as an organisation at a point in time | Whether a specific order will be made to your specification |
| Product test report (SGS) | The sample tested, against the standards named on the report | The rest of the production run — testing a sample is not certifying a batch |
| ISO 9001:2015 certificate | A quality management system, audited by a certification body | A product's specification, tolerance or colour consistency |
How long does each type stay valid?
| Scheme | Validity | What it means for your order |
|---|---|---|
| ISO 9001 | 3 years, with surveillance audits at 12 and 24 months | A valid certificate is a live system, not a one-off result |
| amfori BSCI | 24 months for an A or B rating | A grade from a year ago describes a site a year ago |
| SMETA (Sedex) | Not accepted as robust after 24 months | Risk-based: yearly for high-risk sites, every 2 years otherwise |
| Platform licence badge | Point in time | Confirms the licence matched the registry when checked, not that it still does |
Where this sits in the process
This page is one topic out of the verification standard. The overview is Credentials and certificates.
Sources
- Scans supplied by the operator; published without alteration
- Validity windows per scheme, and what each verification type covers, are stated at /verification/
- Compliance duties per market are set out at /compliance/
