Newsletter
Issue 01: Following, compliant, certified
The distinction that decides tenders, and what evidence each level actually needs.
This is the first issue of the ComplyTrain newsletter. Every other Thursday: one idea worth your time, and the reading behind it, for the people who have to make a management system work rather than describe it.
We are starting with three words, because they cause more trouble in tender documents than any others.
The three words are not synonyms
A buyer writes "ISO 9001 compliant" into a requirement. A supplier answers "we work to ISO 9001". Both sides leave the meeting believing they agreed, and neither is misrepresenting their own sentence. The gap surfaces months later, when somebody asks for a certificate number.
Following
You have read the standard and you use it as guidance. Your processes resemble what it asks for. There is no external claim, and no evidence obligation beyond your own judgement. This is a legitimate place to be, and it is where most organisations start.
Compliant
You meet the requirements, and you can show it. The second half of that sentence is the load-bearing one. Compliance you cannot evidence is indistinguishable from following, seen from outside - and outside is exactly where your customer is standing.
Certified
An accredited certification body has audited you and issued a certificate. It is the only one of the three a third party will accept without inspecting you themselves, and the only one that arrives with an expiry date and surveillance audits attached.
What this changes in a tender response
If a requirement asks for compliance and you are following, say so plainly and describe your route. Buyers disqualify for the mismatch far more often than for the gap.
- Read what the requirement actually asks for: guidance, evidenced compliance, or a certificate number.
- If you claim compliance, decide in advance which records you would produce - and check that you could produce them this week.
- If certification is the requirement, treat the timeline as evidence accumulation rather than paperwork. That is what sets the calendar.
We have written both sides of this up at more length: following, compliant, certified and how certification works.
Also worth reading
- Following, compliant, certified: what the three words actually mean
“Following”, “compliant with”, and “certified” describe three different levels of commitment, cost, and market value. A detailed guide, with examples, for anyone approaching formal compliance.
- How certification works: the road from decision to certificate, step by step
A first-timer’s walk through the certification process: gap analysis, building the system, Stage 1 and Stage 2 audits, the certificate, and the surveillance cycle that keeps it.
- Internal, external, second-party: the audits that decide compliance - and contracts
The three kinds of compliance audit - internal, certification, and second-party customer audits: what each requires, what auditors look for, and how findings affect contracts and tenders.
