NEW — The ISO 14001:2026, ISO/IEC 17020:2026 and FSSC 22000 V7 documentation kits are now available.
ISO/IEC 17065

65% of a Nation’s Building Certificates, One Certifier: The CertMark Single-Point-of-Failure in CodeMark

Published on August 20, 2026
9 min read
By Hafsa J.

Last Updated on August 20, 2026 by Hafsa J.

65% of a Nation’s Building Certificates, One Certifier: The CertMark Single-Point-of-Failure in CodeMark

If you specify building products, or you run a certification body, the CertMark case is the cleanest warning you will find about a risk most procurement teams never price in: concentration. CertMark International (CMI) had issued roughly 65% of all CodeMark certificates, the product certificates that let builders use a material as deemed-to-comply across Australia and New Zealand, when JAS-ANZ suspended its accreditation on 10 July 2019. One certifier. Two national construction markets. A single suspension.

The lesson is not that CMI was uniquely bad. It is structural. When one accredited body holds the majority of a scheme’s certificates and the chain that produces those certificates breaks, the failure does not stay contained at the certifier. It propagates into every building that relied on the mark. That is certifier-concentration risk, and ISO/IEC 17065 is the standard whose machinery is supposed to keep it from happening.

Here is the short version of what follows. The suspension flowed from a documented break in the “chain of evidence” behind CMI’s certificates, the accreditation system caught it late, and the cleanup crossed the Tasman because the same body anchored both countries’ confidence in the same marks. For a specifier, the takeaway is immediate. Before you rely on a product certificate, look at who carries the scheme, not just whether the certificate is valid today.

What actually happened to CMI and CodeMark

CodeMark is the product certification scheme that sits underneath the building codes of Australia and New Zealand. A CodeMark certificate is meant to give a building surveyor or a consenting authority a shortcut: if a product carries one, it is treated as evidence the product meets the relevant code requirements, so it can be signed off without re-litigating the technical case on every job. That shortcut only works if the certificate behind it is sound.

The unwinding started with cladding. In February 2019, nine CodeMark cladding certificates were withdrawn. Cladding was already the most scrutinized product category in the region after the combustible-cladding crisis, so withdrawals there were not a quiet administrative event. They were a signal that the evidence supporting certificates issued by CMI did not hold up.

On 10 July 2019, JAS-ANZ, the body that accredits CodeMark certifiers in Australia and New Zealand, suspended CertMark International’s accreditation. The stated basis was a broken “chain of evidence”: the documented line from a product’s requirements, through the testing and evaluation, to the certification decision, could not be reconstructed to the standard the scheme demanded. In plain terms, the paper trail that is supposed to justify each certificate had gaps. The JAS-ANZ accreditation register is where these certifier sanctions are recorded.

Because CMI’s reach was not confined to one country, the consequences were not either. New Zealand’s regulator, the Ministry of Business, Innovation and Employment (MBIE), ran a parallel suspension on its side of the scheme. The same certifier, the same questions about evidence, two regulators acting in tandem. That cross-border symmetry is exactly what you would expect when one body underwrites the majority of a trans-Tasman scheme: when it is suspended, both markets feel it at once.

Why one certifier holding 65% is a structural problem, not a CMI problem

Most buyers treat a product certificate as a binary: it is valid, or it is not. The CertMark case shows why that framing is too thin. The real exposure is not whether a single certificate is live. It is how much of a scheme depends on the judgment, the records, and the continued accreditation of one organization.

Run the math on 65%. If a single body issued roughly two-thirds of every CodeMark certificate, then a single accreditation suspension puts a question mark over two-thirds of the scheme’s certificates at once. The specifier who chose products certified by smaller, independent bodies absorbed a far smaller shock than the specifier whose entire portfolio happened to run through CMI. Same scheme, very different risk, and almost nobody was measuring it.

This is where accreditation is supposed to earn its keep. Accreditation is the layer above the certifier: an accreditation body such as JAS-ANZ assesses, surveils, and, when necessary, suspends the certification bodies operating a scheme. It is the mechanism that is meant to catch a failing certifier before the failure reaches the market. The uncomfortable read on CMI is that the system worked, but late. By the time the cladding certificates were withdrawn and the accreditation pulled, the certificates were already in the field, on real buildings, doing the job a sound certificate was supposed to do. If you want the full picture of how accreditation, assessment, and surveillance are meant to function, our guide to ISO/IEC 17065 accreditation walks through the machinery in detail.

Concentration also defeats one of the quiet assumptions buyers make about accredited schemes: that mutual recognition and a shared rulebook make certifiers interchangeable. On paper, any accredited CodeMark certifier follows the same standard. In practice, when two-thirds of the certificates trace back to one decision-making chain, that chain becomes the scheme’s single point of failure. Diversity of certifiers is not bureaucratic redundancy. It is how a scheme stays standing when one body falls.

The clause 7 chain that is supposed to hold, and where it broke

The phrase JAS-ANZ used, a broken “chain of evidence”, is not vague regulator-speak. It points straight at the operational core of ISO/IEC 17065: clause 7, the process requirements. A sound product certificate is the output of a specific, segregated sequence, and each link is a separate clause.

It runs like this. Evaluation (clause 7.4) is where competent, independent personnel test, inspect, or audit the product against the scheme and write it up, with traceability from the product’s requirements, to the methods used, to the results obtained (clause 7.4.7 spells out that requirements-to-methods-to-results trace explicitly). Review (clause 7.5) is a second look by people who did not perform the evaluation, ending in a documented recommendation. The certification decision (clause 7.6) is then made by someone who, again, took no part in the evaluation. That separation is deliberate: the person who did the work does not get to bless their own work.

A broken chain of evidence is a 7.4.7 failure that contaminates everything downstream. If the line from requirement to test method to result cannot be reconstructed, then the review in 7.5 had nothing solid to check, and the decision in 7.6 was made on a foundation that could not be verified. The certificate still printed. The evidence underneath it did not exist in the form the scheme required. For a walkthrough of how the evaluate, review, and decide steps are meant to be staffed and separated, see our breakdown of the ISO 17065 evaluation, review, and certification decision chain.

Surveillance (clause 7.9) is the other half of the story, and the one that explains the timing. Surveillance is the ongoing program of checks after a certificate is granted, with a frequency that the standard says must be justified by the scheme, the risk, and the certifier’s performance. When one body is issuing the majority of a scheme’s certificates, the surveillance design has to scale with that load and that risk. A concentration of certificates demands a concentration of oversight. The CMI case is what it looks like when the evaluate-review-decide chain and the surveillance that is supposed to backstop it both come under question at the same body at the same time.

What specifiers and certification bodies should do with this

The CMI episode converts into a short set of checks. None of them require inside information; they all run on public registers and basic diligence.

If you specify or buy certified products:

  • Check who carries the scheme, not just whether the certificate is valid. If one certifier issued most of the certificates in a category, you are carrying that body’s accreditation risk whether you priced it or not.
  • Spread certifier exposure where you can. A portfolio whose certificates trace back to two or three independent bodies survives a single suspension far better than one routed through a dominant CB.
  • Confirm the certificate against the scheme’s public register, and confirm the issuing certifier is currently accredited. A valid certificate from a suspended certifier is the exact gap the CertMark case exposed.
  • For high-consequence product categories such as cladding, ask for the evidence behind the certificate, not just the certificate number.

If you run or are building a certification body, the same case reads as a design brief:

  • Treat traceability (clause 7.4.7) as the certificate’s load-bearing wall. If the line from requirement to method to result cannot be reconstructed on demand, you do not have a defensible certificate, you have a printed one.
  • Keep the evaluate, review, and decide roles genuinely separate (clauses 7.5 and 7.6). The segregation is not a formality; it is the control that catches a weak evaluation before it becomes a granted certificate.
  • Scale surveillance (clause 7.9) to volume and risk. If you hold a large share of a scheme, your surveillance program is also the scheme’s safety margin.

The documentation backbone for all of this, the procedures, the records, the traceability structure that lets you reconstruct any certificate on demand, is exactly what a 17065 management system is built to hold. Our ISO/IEC 17065 documentation toolkit is structured around the clause 7 process chain for that reason.

The number that should change how you read a certificate

65% is the figure worth carrying out of this case. Not because CMI was singular, but because the percentage is the risk. A scheme can be perfectly designed, fully accredited, and internationally recognized, and still wobble if too much of it rests on one certifier’s chain of evidence. The CertMark suspension did not expose a flaw in ISO/IEC 17065. It exposed what happens when the standard’s controls are concentrated into a single point that can fail all at once. The next time you rely on a product certificate, the useful question is not only whether the mark is valid. It is how many other certificates depend on the same body holding the line.

Share on social media
Take the next step

Prepare your ISO/IEC 17065 certification with the complete kit

The complete documentation package to deploy an ISO/IEC 17065:2012-compliant product certification body: ready-to-use document architecture covering scheme management, evaluation, certification decisions, and surveillance.