What you actually receive.
A certification body is judged on its documents, so here is every one an SCL assessment produces: what it is for, what it states, when it is issued, and how long it stays true. The certificate is the shortest document on this list and the least informative. The Certification Determination Document is the one that matters.
The documents, at a glance
An assessment runs in four phases and each phase closes with a document. Three of them exist before anyone knows the outcome, which is the point: the scope is fixed in writing before the evidence is read, so it cannot be adjusted afterwards to fit a result.
| Document | Phase | Issued when | What it settles |
|---|---|---|---|
| Applicability Determination Record | 1 | Always, and signed | Scope, classification, tailoring |
| Evidence Review Report | 2 | Always | Preliminary findings, open items |
| Technical Assessment Report | 3 | Always | Final findings and the risk score |
| Certification Determination Document | 4 | Always, certified or not | The determination, and the authoritative certified scope |
| Certificate | 4 | Only on a Certified determination | A short public summary of the above |
A separate product, the Readiness Report, is described at section 08. It is not part of a certification assessment and produces no determination.
Applicability Determination Record
The first document, and the one that decides what the assessment is. It records which requirement sets apply to this system, the classification tier it falls in, the Operational Claim, the Operational Design Domain and its Exclusions, and any tailoring.
It is signed before any evidence is reviewed. That sequence is deliberate. Scope agreed in advance cannot be quietly widened to manufacture a pass, or narrowed to avoid a failure.
If the Operational Design Domain is revised during the assessment and the client accepts the revision, an amended record supersedes the original and governs the certified scope. If the client declines the revision, the original governs and the mismatch is recorded as a finding.
Evidence Review Report
The result of reviewing the client's documentation against the applicable requirements, before anyone looks at the running system. It records preliminary findings and open items.
It is not a determination and carries no status. Findings in it are explicitly preliminary and may change once the technical assessment is done. A client may not describe an Evidence Review Report as a certification result, and may not use any SCL mark in connection with it. See the mark rules.
Technical Assessment Report
The record of the technical assessment itself: findings against each applicable requirement, with the evidence each finding rests on, and the quantified risk score with its per dimension scores and the rationale for aggregating them.
It is the last word on findings. No determination is issued at the closing meeting, and findings communicated during the assessment are preliminary until this report is issued.
This is an assessment record rather than a client-facing summary. The determination in section 05 is what states the outcome, and it is the document written to be read by the client and, in part, by third parties.
Certification Determination Document
This is the important document, and it is issued whether the determination is Certified or Not Certified. A client who does not certify still receives a complete account of what was assessed and why the answer was no. There is no outcome in which an assessment simply produces nothing.
It states:
- The system assessed, and the framework version it was assessed against
- The classification tier and the requirement sets that applied
- The Operational Claim and the Operational Design Domain, both as originally declared and as certified
- A summary of findings
- The quantified risk score, with the rationale for how it was scored
- The determination itself: Certified or Not Certified
- For Certified: the validity period and the surveillance schedule
- For Not Certified: the findings that require remediation before re-assessment, including any scope reconciliation the client declined
It governs. Where the certificate face and this document appear to disagree about what was certified, this document is the authoritative record of the complete certified scope. The certificate is a summary of it, not a substitute for it.
The determination logic is not discretionary: any Major finding means Not Certified. No Major findings means Certified. Observations do not affect the determination.
The certificate
The certificate face carries the certificate number, the system name and version, the client organization, the framework version, the classification tier, the requirement sets assessed, the Operational Claim in a single sentence, the notable Exclusions, the quantified risk score, the issue date, the validity period, the surveillance due date, the Lead Assessor's name and the SCL Principal's signature.
Where the full Exclusions list is too long for the certificate face, the notable Exclusions summary omits no material exclusion that a third party would need in order to spot a mismatch with their own intended use. The complete list lives in the Certification Determination Document.
The certificate does not say the system is safe. It says the system was assessed against a defined standard, met the applicable requirements within the certified Operational Claim and Operational Design Domain, and carried a documented risk score at the time of assessment. What a certificate does and does not say is set out at /disclaimer.
Every certificate is checkable by anyone at /verify, without contacting SCL.
The certification badge
The badge is the artwork a certificate holder may display. It is issued with the certificate, and it is the only SCL mark a party outside SCL is ever authorized to use.
It is not a free-standing document and it carries no information the certificate does not. A badge displayed without the certificate number and a working verification link is not an authorized use. The rules are at /mark.
Readiness Report
A Readiness Assessment reviews available documentation against the applicable requirements and produces a Readiness Report: a gap analysis for each requirement reviewed, a finding summary, and one follow-up meeting to go through it.
It produces no certificate and no determination, and confers no status. Its fee is not credited toward a certification assessment fee; they are separate engagements. SCL does not consult on how to remediate what it finds. If a client goes on to a certification assessment, that assessment is conducted independently against the standard. See /impartiality for the constraints that apply when the same body does both.
Distinct again from the self-service readiness check at /assess, which is a tool the operator runs themselves. That is not an assessment by SCL at all.
The framework itself
The AI Requirements Framework is the standard every assessment runs against, and it is free. Every requirement is readable at /requirements and every defined term at /glossary, without contacting SCL and without payment.
Cite it at the concept DOI, 10.5281/zenodo.19024420, which always resolves to the current version.
A certificate does the opposite. It names the specific version DOI of the framework release it was issued against, never the concept DOI. If a certificate cited the concept DOI, the conformity basis under an issued certificate would change silently every time the framework was revised. A determination has to stay pinned to the standard as it read on the day it was made.
How long any of it lasts
A certificate is a point in time determination. It carries a validity period and a surveillance due date, both stated on its face, and the surveillance cadence is set by classification tier:
| Classification | Surveillance |
|---|---|
| Safety Critical | Annual surveillance audit |
| Mission Critical | Biennial surveillance audit |
| Operational Support | Triennial surveillance audit |
A surveillance audit is an abbreviated assessment. It confirms there have been no material changes to the system, that continuous validation requirements are being met, that logged out-of-distribution events, hallucination events and bias threshold exceedances have been reviewed, that operational use is still inside the certified Operational Design Domain and Exclusions, and that the system's actual use still matches its classification.
Any expansion of use beyond the certified scope requires re-assessment before operation continues in the expanded scope. That is not a recommendation.
The register at /verify is the authority on current status, and reports each certificate as Valid, Expired, Suspended or Withdrawn. A certificate that has lapsed is not a weaker certificate; the right to display the mark ends with it.
Records, and how long SCL keeps them
SCL retains the full assessment record, the Applicability Determination Record, the evidence package, the Evidence Review Report, the assessment plan, the Technical Assessment Report and the Certification Determination Document, for a minimum of 10 years, or the life of the certified system, whichever is longer. Records are access controlled.
This matters for a reason beyond tidiness. A determination that cannot be reconstructed years later cannot be defended years later, and a certification body that cannot defend an old determination is not much use to anyone relying on one.
Records relating to complaints and appeals are retained on the same basis. See /complaints.
Related pages. The certification process. Verify a certificate. What a certificate says, and what it does not. The SCL name and mark. Impartiality. Every requirement.