LinkTree

ISO 27566-1 Certification

ISO 27566-1 Certification is the new international gold standard for age assurance systems. Developed through the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC), it provides a comprehensive framework for assessing whether an age assurance service is safe, effective, privacy-preserving, and interoperable.
Make an EnquiryApply now
Home » ISO 27566-1 Certification
Age Assurance - Age Check Certification Scheme (ACCS)

ISO 27566-1 is the new international gold standard for age assurance systems. Developed through the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC), it provides a comprehensive framework for assessing whether an age assurance service is safe, effective, privacy-preserving, and interoperable.

Certification to ISO 27566-1 by ACCS demonstrates that your solution is independently audited and internationally recognised, giving regulators, clients, and users confidence that your system meets the highest benchmark of trust and compliance.

Who Can Apply?

ISO 27566-1 certification applies across the age assurance ecosystem:

  • Age Verification (AV) Providers
    Services that directly check or estimate a user’s age (e.g., via document checks, biometrics, or databases).
  • Intermediaries
    Entities that act as a secure bridge between users, AV providers, and relying parties — ensuring age proofs can be reused safely across services.
  • Relying Parties
    Online platforms, content providers, or service operators that depend on AV to manage user access and comply with regulation.
  • Hybrid Services
    Organisations that perform more than one of these roles (e.g., a provider that both verifies ages and acts as an intermediary).

What Does the Certification Cover?

ACCS audits solutions against five core characteristics that regulators expect to see in effective age assurance:

  1. Functionality – Does the system accurately assess or verify age at the required assurance level?
  2. Privacy – Are personal data minimised, protected, and used lawfully, with clear user rights?
  3. Accessibility – Is the service inclusive and usable across demographics, abilities, and devices?
  4. Security – Are systems resilient to fraud, attacks, and misuse?
  5. Performance – We look at measurable outcomes i.e. performance targets vs. achieved metrics.

Together, these criteria ensure a balanced, trustworthy, and regulator-ready solution.

The Age Check Practice Statement

At the heart of ISO 27566-1 certification is your Age Check Practice Statement (ACPS). This is a structured document that sets out:

  • Your service’s scope, purpose, and role(s) (AV, intermediary, relying party, or hybrid)
  • Your Technical Architecture and methods you use to check or estimate age.
  • Your policies for data handling, user rights, and consent
  • Your approach to accessibility, inclusion, and user support
  • Your security and fraud prevention measures

The ACPS provides the foundation for the audit. It defines how your system operates in theory, and ACCS then evaluates whether your practice matches your promise.

What the Audit Involves

Our audit follows a rigorous, multi-layered approach:

  • Policy & Documentation Review – Analysis of your ACPS, governance policies, and compliance framework.
  • Component Testing – Assessment of the effectiveness and accuracy of the technology components (e.g., biometric age estimation, document checks).
  • Context-of-Use Evaluation – Verification of how your service performs in real-world conditions, including accessibility and user experience.
  • Risk & Security Analysis – Checks against vulnerabilities, attack vectors, and data protection standards.

Only services that pass across all these layers can achieve ISO 27566-1 certification.

Why It Matters

ISO 27566-1 is increasingly referenced as the benchmark by regulators worldwide:

  • Ofcom (UK) – Recognises ISO 27566-1 as part of its Online Safety Act compliance pathways.
  • European Union (DSA & AVMSD) – Alignment with harmonised standards underpins regulatory expectations for “highly effective” age verification.
  • Australia (eSafety Commissioner) – Standards-based assurance is required for safety tech providers.
  • United States (COPPA & state-level laws) – Independent validation of AV solutions strengthens compliance with child-safety mandates.
  • Brazil (Law 15,211/2024) – Growing emphasis on certified age assurance providers in LATAM markets.

Achieving ISO 27566-1 certification positions your organisation as a trusted, regulator-ready provider able to serve global markets.

Choosing Your Certification Pathway

Choosing the right certification depends on your state of readiness, target markets, and whether you need component-level or system-level assurance. Many providers progress to a dual path, combining technical credibility with the global compliance signal increasingly expected by regulators.

  • IEEE 2089.1 → technical performance badge (accuracy, robustness, fairness).
  • ISO/IEC 27566-1 → holistic certification (privacy, security, accessibility, performance, functionality).
  • Dual Path → technical credibility plus global compliance signal.

Download: PAS → IEEE → ISO Comparison Guide (Link) or view it online.
Take: “Which pathway fits us?” 2-minute quiz (Link )
Assess your organisation’s ISO/IEC 27566-1:2025 age assurance compliance maturity, click here.

Certification Process

  1. Application & Scoping – Define your role(s), service boundaries, and intended level of certification.
  2. Develop Your ACPS – With ACCS guidance, prepare your Age Checking Practice Statement.
  3. Pre-Audit Review – We identify gaps and advise on remediation before the main audit.
  4. Formal Audit – Policy review, component testing, and context-of-use evaluation.
  5. Certification Decision – Successful applicants are awarded the ISO 27566-1 certificate and listed on the ACCS public register.
  6. Surveillance & Renewal – Ongoing oversight to maintain certification validity.

Is ISO-27566-1 the same as other age verification standards?

No. ISO-27566-1 is the first full international standard that looks at age assurance systems as a whole — not just at individual technologies. It brings together requirements for effectiveness, privacy, accessibility, security, and interoperability. Other standards (such as IEEE 2089.1) test specific components like biometric age estimation. ISO-27566-1 certification shows your entire service meets the highest system-level benchmark.

Does this cover data protection / GDPR / privacy law?

Yes, but in a standards-based way. ISO-27566-1 requires services to handle data responsibly, minimise collection, protect user privacy, and support user rights. It is designed to be compatible with frameworks such as GDPR and other global privacy laws, but certification is not the same as full legal compliance — it provides independent assurance that your age assurance system aligns with recognised privacy principles.

What if I already have an ACCS certification — do I need a full new audit or can it be partial?

If you already hold an ACCS certification (e.g. to IEEE 2089.1, PAD, etc.), some of your previous audit evidence can be re-used. However, ISO-27566-1 is a broader system-level standard, so a full certification audit is still required. We streamline the process for existing clients, so you won’t need to duplicate work unnecessarily.

What kinds of verification methods are acceptable under this standard (document checks, biometric, etc.)?

ISO-27566-1 is technology-neutral. It does not prescribe one method over another. Services can use document checks, biometric estimation, database lookups, third-party verification, or hybrid approaches, provided they can demonstrate effectiveness, privacy, security, accessibility, and interoperability. Certification focuses on whether your chosen methods meet the requirements, not which method you choose.

What happens if I fail the audit? Am I rejected or given opportunity to remediate?

If gaps or non-conformances are found, you will receive a report. You will normally be given a defined timeframe to address these issues and resubmit evidence. Only if critical issues remain unresolved after remediation would certification be denied. The goal is to help you meet the standard, not to exclude you unnecessarily.

Will certification protect me legally, or am I still liable?

Certification is not a legal shield. You remain responsible for complying with applicable laws and regulations. However, ISO-27566-1 certification provides strong evidence of due diligence. It shows regulators, partners, and customers that you follow international best practice and have been independently audited, which significantly strengthens your position in demonstrating compliance.

How long does certification take?

The timeline depends on the size and complexity of your service. For most providers, certification takes 4–12 weeks from application to decision, including time for documentation, audit activities, and any remediation. If you already have an ACCS certification, this may be shorter as some evidence can be re-used.

How much does it cost?

Costs vary depending on scope, service role (AV, intermediary, relying party, or hybrid), and the level of testing required. Fees are quoted during the application stage once we understand your service in detail.

What do I receive once certified?

Successful providers receive:

  • An official ISO-27566-1 Certificate of Conformity issued by ACCS
  • Permission to display the ACCS certification badge on your website and digital materials.
  • Listing on the ACCS public register of certified providers
  • A detailed audit report with findings and recommendations

This gives you both the recognition and the evidence you need to demonstrate compliance to regulators, partners, and customers.

Explore other services in Age Assurance

Age Check Certification Scheme
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.