Conformity Group
Please note that this specification is suitable for pre-production pilot implementations.
Mailing List
A group mailing list is maintained and can be used by any list member to post messages to the group. The list also maintains an archive of all messages sent to the group.
- To join the mailing list - your request will be reviewed by a list administrator.
Meetings
Group meetings are held approximately fortnightly. To attend, please join the mailing list above.
Each meeting will generally work through open issues and pull requests.
Previous meeting dates, recordings, transcripts, and minutes are summarised below with the most recent meeting at the top.
Previous Meetings
Click a date to jump to the detailed summary below.
| Meeting | Summary | Materials |
|---|---|---|
| 2026-08-12 | Worked through a circulated definitions document, aligning UNTP terms (conformity assessment, attestation, profile, scheme, topic, endorsement) with ISO-CASCO vocabulary in response to ISEAL's comments; agreed to retain "conformity assessment" as a clarification of CASCO, confirmed persons out of scope, and declined to elevate "process" to a standalone object of conformity for v1.0. | — |
| 2026-08-04 | Under deadline pressure to finalise the review this month, the group confirmed scheme declaration is mandatory under v0.7, heard Phil Archer's update on parallel W3C verifiable-credentials work enabling out-of-the-box recognition-chain verification, reviewed comments from Trust Layer Foundation, a UNIDO/GQSP commenter and ISEAL, and again declined to grade intermediate trust levels between self-declaration and a verifiable authority pathway. | — |
| 2026-07-28 | The chair presented revised conformity trust pathways — dropping the ambiguous "endorsement" in favour of "authority endorsement" and restructuring scheme- and CAB-level assurance into small mutually exclusive choices with mandatory aligned evidence — debated the value of self-declaration and how UNTP conformance is enforced, and reviewed fresh comments from ISOA and Microsoft, with volunteers to produce worked examples. | — |
| 2026-07-21 | The group confirmed positions reached over the previous two sessions on the European Risk Policy Institute (Ivan Savov) submission — reaffirming credential-status modelling, folding ISO-CASCO definitions into the UNTP vocabulary, and declining to build scheme-governance metadata or assurance-maturity gates — and took as homework Kylie Sheehan's (ISOA) comment on the problematic term "endorsement". | — |
| 2026-07-09 | Revisiting an EPRI comment on modelling a conformity credential's life cycle, the group debated a single enduring credential whose status rotates versus issuing a fresh standalone credential on each change; broad support emerged for the standalone approach after Zach clarified that revocation flags a credential invalid without deleting its still-discoverable data. | — |
| 2026-06-23 | The CASCO-alignment subgroup confirmed UNTP should restore explicit ISO-CASCO alignment; the group agreed to revert the assessor-level code list to standard first/second/third-party definitions plus "unspecified", worked through strengthening the endorsement/trust-chain concept in response to ERPI's comments, and broadly accepted the ERPI submission. | — |
| 2026-06-09 | The group reaffirmed removing "Hybrid" from the Assessor Level code list, debated reducing it to four items aligned to ISO/IEC 17000 definitions, raised data-modelling questions on how endorsement evidence relates to the assessor/assessment code lists, and formed a terms-and-definitions sub-group; the meeting closed with tributes to the retiring Reinaldo Figueiredo. | — |
| 2026-05-26 | Resuming the review series after the March pause, the group worked through the chair's own public comments — adopting Global ACI (ILAC/IAF merger) terminology, dropping the overlapping "hybrid" assessor level, and proposing a mandatory-criteria transparency field on conformity profiles — while reaffirming it requires scheme transparency rather than imposing scheme rules. | — |
| 2026-02-10 | Prepared the Conformity Credential web page for public comment, reviewed and submitted the Assessment Assurance documentation, and reactivated the Scheme Vocabulary subgroup to consider Issue #590. | Meeting Materials and Slides |
| 2026-01-20 | No written summary — see meeting materials. | Meeting Materials |
| 2025-12-16 | No written summary — see meeting materials. | Meeting Materials |
| 2025-12-03 | Broad support for the draft Assessment Assurance guide, with agreement to socialise it externally and to raise a GitLab issue (#563) to incorporate it as a normative part of UNTP. | Meeting Materials |
| 2025-11-25 | Reviewed and carried forward outstanding actions — CEFACT expert registration, SDO standards referencing, Conformity Topic Classification ownership, and scheme-endorsement structure; see transcript and slides. | Meeting Materials and Slides |
| 2025-11-05 | Continued discussion of establishing trust in UNTP conformity credentials, carrying forward the standing action list; see transcript and slides. | Meeting Materials and Slides |
| 2025-10-14 | Agreed that establishing trust in UNTP conformity credentials is essential to the protocol's credibility, and carried forward the outstanding action items; see transcript. | Meeting Materials |
| 2025-09-30 | Reviewed outstanding actions on the SVC page, SDO standards referencing, Conformity Topic Classification, and issue #79 on where observation ends and conformity assessment begins; see transcript. | Meeting Materials |
| 2025-09-02 | Agreed to form a conformity-examples subgroup and discussed cross-scheme comparability and MRA/MLA recognition, flat-versus-hierarchical criteria (issue #344), and the long-standing issue #79. | Meeting Materials |
| 2025-08-13 | First meeting after the move to UNICC GitLab, focused on the value of detailed worked examples and edge cases for DPP/DCC/SVC — including criterion nesting and reuse of criteria across multiple schemes. | Meeting Materials |
| 2025-07-15 | Kick-off of the Conformity working group — terms of reference and Rec 49, a GitHub walk-through, and scoping the Sustainability Vocabulary (SVC) as the major new work item, including globally unique identifiers for conformity criteria. | Meeting Materials |
Terms of Reference
Abbreviations used
- DCC - Digital Conformity Credential
- CVC - Conformity Vocabulary Catalogue
Purpose & functions
The purpose of the Group is to coordinate UNTP aspects relating to conformity credentials, under the direction of the UNTP Steering Committee. Specific functions are as follows:
- To maintain, subject to oversight from the Steering Committee, the UNTP Core DCC specification, including definitions and vocabulary
- To develop and maintain the SVC specification, including Conformity Topic Classification and the Conformity Vocabulary Schema.
- To maintain the UNTP Certifier Implementation Register
- To maintain the UNTP Conformity Scheme Register
- To maintain the DCC Test harness
- To provide advice to the UNTP Adoption subcommittee regarding conformity-related issues arising in relation to UNTP adoption
- To provide technical advice, as required, to Industry Extension Groups
- To liaise with UN/CEFACT to ensure continuing compatibility with applicable CEFACT standards, including the Digital Product Conformity Certificate Exchange standard.
- To maintain awareness of developments within ISO CASCO and other relevant global conformity assessment institutions to facilitate alignment with international practices
- To liaise with other UNTP sub-committees to ensure that compatibility between UNTP elements is maintained.
- To maintain the Group mailing list
Roles & Responsibilities
Group Lead
- Arrange and Chair Group meetings
- Provide updates as required to the UNTP Steering Committee
- Attend UNTP Steering Committee meetings
- Act as liaison point for identified global conformity assessment institutions
- Provide recommendations to the Steering Committee on matters having potential to affect other UNTP sub-committee activities
- To cooperate with the Steering Committee in handling complaints and disputes relating to the DCC or SVC
- To provide advice and to participate when appropriate in Suspension proceedings and Appeal proceedings relating to DCC or SVC
- Maintain mailing list specific to Sub-committee participation
- Delegate duties to other Group members as applicable
Group Technical Editor
- Maintain relevant Github repository pages
- Maintain Pull Requests relating to the DCC and SVC specifications
- Maintain classification lists, implementation registers
- Maintain DCC Test Harness
Operation
- The Group is open to anyone to participate as an observer.
- Contributors to specifications and content maintained by the group must be registered UN/CEFACT experts.
- The Group will meet monthly, or more frequently.
- Where deemed necessary by the Group Lead, working groups may be established for dealing with specialized matters
- While consensus among group participants is always desirable, decisions affecting the UNTP Core DCC Specification are taken by the Group Lead and are subject to oversight by the Steering Committee.
2026-08-12 Meeting Summary
UNTP Conformity Public Comment Review Meeting #8 - 12 August 2026
Attendance
- Brett Hyland (Chair)
- Neil Savery
- Gideon Richards
- Adrienna Zsakay
- Dr Easter Huang
- Matthias Glauss
Quick recap
The group worked through a circulated definitions document, aligning UNTP terminology with ISO-CASCO vocabulary and explaining any deviations. The bulk of the meeting reviewed the definitions of conformity assessment, conformity attestation, conformity profile, conformity scheme, conformity topic and endorsement, incorporating public comments from ISEAL. The group agreed that UNTP's "conformity assessment" (really a conformity assessment activity in CASCO terms) should keep its name, framed as a clarification rather than a departure from ISO. It then examined ISEAL's comment that UNTP covers only product, facility and organisation whereas ISEAL also covers processes, persons, systems and entities. Persons were confirmed as out of scope; process was debated at length but not elevated to a standalone object of conformity for v1.0. The chair noted the group would meet again in a fortnight.
Discussion topics
Conformity assessment definition
Brett proposed either renaming UNTP's "conformity assessment" to "conformity activity" (an abbreviation of CASCO's "conformity assessment activity") or simply defining precisely what UNTP means. Neil and Gideon argued that "conformity assessment" is the universally accepted term across ISO/IEC/CASCO and should be retained. The group acknowledged UNTP is more granular than CASCO (multiple conformity assessments contributing to an attestation) and restricts objects of conformity to products, facilities and organisations. Gideon noted CASCO's "specified requirements" (clause 5.1 of ISO 17000) is itself loose, so UNTP's framing is a reasonable clarification. Decision: keep the name and definition, framed as a clarification (restricting objects, adding "or contributes to") rather than a deviation.
Object of conformity terminology
Gideon flagged that "object of conformity" needs a plain-English note, ideally linked to the "specified requirements" in ISO. Brett confirmed UNTP has a term (a data field spun out of the core terms) and acknowledged ISO 17000 defines "object of conformity assessment," not "object of conformity." Neil and Gideon confirmed objects of conformity vary between schemes and relate to a scheme's criteria, illustrated by an Australian off-site construction scheme (quality manual, factory production control, personnel competence, etc.).
Conformity attestation definition
This was identified as a potential genuine deviation from ISO, where attestation is a process leading to a statement of conformity. UNTP wants to allow attestations (e.g. a carbon emission value) without a pass/fail compliance decision. Neil noted most current ESG legislation sets reporting rather than quantified-threshold requirements. Brett proposed the wording "for the purpose of demonstrating that specified requirements are fulfilled" so an attestation need not itself demonstrate fulfilment. The group accepted this wording and agreed to leave it and see what feedback arises.
Conformity profile, scheme and topic definitions
ISEAL had called the Conformity Profile definition garbled and noted it sounded like a standard; Brett presented a revised definition adding one hierarchical layer between scheme and criteria. Gideon suggested adding examples and replacing "auditable criteria" (queried, to be highlighted purple) given the audit/evaluation debate. The Conformity Scheme definition was taken directly from ISO CASCO; Gideon queried whether it came from 17000 or the newly revised 17067, to be checked. For Conformity Topic, "determinable" was replaced with "specified attributes" per Gideon's suggestion.
Endorsement definition
Endorsement was reframed to apply to the conformity credential/attestation itself, not the scheme: a credential is either backed by a scheme or carries an authority endorsement. The group was comfortable with the updated definition.
ISEAL comment on objects of conformity (persons and process)
ISEAL noted UNTP covers product, facility and organisation, while ISEAL covers products, processes, systems, persons and entities. Persons were confirmed out of scope (reaffirming a pre-v0.7 decision); Dr Easter Huang (from IPC/personnel certification, ISO 17024) argued for retaining the wording so persons could be reintroduced later, but Matthias agreed persons are poorly defined for a product passport. Process was debated extensively: Matthias raised Industry 4.0 / intangible products (e.g. selling measurement values) and future process/cryptography certifications; Gideon cited factory production control as an object of conformity. Brett argued process can be treated as part of the scope of a product, facility or organisation certification, noting a process lacks a verifiable unique identifier. The 2021 replacement of ISO 18001 by 45001 was noted in passing.
Decisions
- Retain the name and definition of "conformity assessment," framed as a clarification of ISO CASCO (restricting objects to product/facility/organisation and adding "or contributes to"), not a rename to "conformity activity."
- Adopt the conformity attestation wording "for the purpose of demonstrating that specified requirements are fulfilled"; leave as-is pending feedback.
- Replace "determinable" with "specified attributes" in the Conformity Topic definition.
- Confirm persons remain out of scope for UNTP.
- Do not elevate process to a standalone object of conformity assessment for v1.0; treat process as part of the scope of product/facility/organisation certification. The framework allows future iterations or industry extensions (e.g. metrology) to add it.
Action items
- Add a plain-English note defining "object of conformity," ideally linking to ISO's "specified requirements" (Brett).
- Add examples to the Conformity Profile note and revisit/highlight "auditable criteria" (marked purple with a query) (Brett).
- Confirm whether the Conformity Scheme definition derives from ISO 17000 or the revised 17067, and note any differences (Brett / Gideon).
- Go back to ISEAL to confirm the group is minded not to elevate process, and ask for specifics on what they need it to cover and how it would differ (Brett).
2026-08-04 Meeting Summary
UNTP Conformity Public Comment Review Meeting #7 - 4 August 2026
Attendance
- Brett Hyland (Chair)
- Phil Archer
- Zach (Zachary)
- Gideon Richards
- Adrienna Zsakay
- Anish Karmarkar (Microsoft) — first meeting
- Roberto Perez-Franco
- Andrew Wheeler
Quick recap
The group pressed on with the public comment review despite the usual August pause, working under pressure to finalise the review this month ahead of a UNTP v1.0 release. Brett confirmed that scheme declaration is clearly mandatory under the UNTP v0.7 specification and flagged that it should probably become a standardised digital object, to be worked through with Zachary. Phil reported on parallel W3C verifiable credentials work (with Steve and John Phillips, plus GS1) that will let generic verification software follow recognition/authority chains out of the box, with candidate recommendation expected end of October. The group agreed alignment can be handled via UNTP's extensions model rather than lockstep timing. New comments from Trust Layer Foundation, a UNIDO/GQSP-related commenter, and ISEAL were reviewed, with the group repeatedly declining to grade intermediate levels of trust between self-declaration and a verifiable authority pathway. A new attendee, Anish Karmarkar of Microsoft, introduced himself. The meeting ran out of time on the large ISEAL submission and agreed to reconvene the following week.
Discussion topics
Scheme declaration as a mandatory, standardised object
Brett confirmed with Zach during the week that scheme declaration is clearly mandatory in the UNTP v0.7 spec. This raised the question of whether it should become a standardised digital object; the likely answer was yes, to be worked out with Zachary.
CAB attestation options and alignment with W3C / GS1 work
The group revisited the options for a CAB to declare it is the scheme (self-declaration), is licensed/recognised by the scheme, or uses an authority pathway. Phil described two W3C worked examples (linking to the grid, and GS1 recognition) that align with UNTP's trust anchor concept, noting GS1 may make small adjustments and UNTP might follow. Zach said UNTP need not be in lockstep: any divergence at 1.0 can be treated as a UNTP extension and folded back into a 1.1 or 2.0 release. Phil noted W3C candidate recommendation is expected end of October, with formal standard status about a year out, and stressed the hard part has been governance (signing authority, revocation), not technology.
Scheme recognition and confidence (Gideon's ongoing concern)
Gideon reiterated that self-declared scheme information is only hearsay unless verified or recognised, and that a UNTP recognition process is the key open question. Brett acknowledged UNCEFACT is unlikely to audit schemes, but noted self-declared lies could be exposed and UNTP-conformant status revoked. Zach described emerging algorithmic validation of UNTP conformance as a first tier, with the extensions model encouraging communities to extend the test suite for domain-specific needs (discussed with Harley of the technical group).
Trust Layer Foundation comment
The group agreed with the commenter that most trade runs on supplier self-declarations, which UNTP does not seek to prevent, and that schemes of varying integrity are welcome provided the basis for trust is made clear. There was no appetite to grade intermediate levels of trust between self-declaration and a verifiable authority pathway. Gideon agreed, noting the difficulty of determining trust without an agreed criterion.
UNIDO/GQSP-related comment (aggregated batch-level DCCs)
The commenter raised aggregator/cooperative-issued batch-level DCCs, minimum necessary disclosure, and cherry-picking of results. The group agreed the fundamental architecture cannot change but that this is valuable adoption information from the field. Zach proposed responding that this is important, pointing the commenter to the Community Activation Program, suggesting an extension exploring a reference architecture for aggregated cooperative batch-level DCCs, and asking for learnings to feed a post-1.0 (1.2 or 2.0) release. On minimum necessary disclosure, Zach cautioned against presupposing credential value (pass/fail only may suit some schemes) and suggested instead making the minimum required conformity credential fields more visible, e.g. a "required yes/no" column in the field table generated by a script.
ISEAL submission
The group began the large ISEAL submission. Points on UNTP-introduced risks and CAB-vs-scheme-owner benefits were judged to belong to the steering committee / business case / adoption groups rather than conformity; Phil linked the risks point to W3C threat modelling, and Adrienna suggested UNTP add balancing content on risks. On the conformity profile, the group agreed the concept and language need clarifying and that "standard" vs "conformity profile" should be reconciled, though Zach noted the commenter may be reading the core vocabulary page out of context. The core vocabulary also needs revisiting for ISO alignment (deferred to next time). On certificate/credential dates, Phil noted (via GS1 legal experience) that credential validity periods need not match certification periods; the specific date instances referenced need checking. On assessment assurance, Brett disagreed that the accredited-CAB pathway and the peer-assessment pathway are functionally equivalent, since they involve different issuing parties and trust chains, and suggested UNTP should state who issues the endorsement. It was noted there is no current approval process against the UNIDO Guide — understood as a placeholder pending such a process from UNIDO, UNCEFACT, or another body. The group also discussed whether ISEAL "credibility principles" (generic, non-normative) should be differentiated from verifiable reference points; Gideon argued principles and requirements layer together and are hard to separate.
Website vs identifier requirement
Responding to a comment that not everyone has a website (disadvantaging small participants), Roberto noted websites are easier than ever to create. Zach clarified there is no core requirement for a website — only for an identifier — which could come from, e.g., a signed mobile app, though that is not yet supported. Andrew suggested this is an opportunity for a third-party service. The group did not see this as a major issue.
Decisions
- The group will not attempt to grade intermediate levels of trust between self-declaration and a verifiable authority pathway.
- Divergence between UNTP 1.0 and ongoing W3C/GS1 recognition work will be handled via the extensions model and reconciled in a later (1.1/2.0) release, rather than delaying UNTP.
- The accredited-CAB pathway and the peer-assessment (scheme benchmarking) pathway are not functionally equivalent and should be distinguished, including by stating who issues the endorsement.
- A further review meeting will be held the following week.
Action items
- Brett to work with Zachary on making scheme declaration a standardised digital object.
- Brett to craft the UNIDO/GQSP comment response (point to Community Activation Program, suggest an extension for aggregated batch-level DCCs, request learnings for a post-1.0 release).
- Zach to make the minimum required conformity credential fields more visible (e.g. a "required" column in the field table, produced by a script).
- Conformity credential/scheme vocabulary spec to be clarified re: conformity profile vs "standard" and certificate/credential date instances (dates to be checked against the credential vs attestation/assessment subunits).
- Core vocabulary to be revisited for ISO alignment (deferred to a future meeting).
- Brett to recirculate the ISEAL submission to attendees for continued review next week.
2026-07-28 Meeting Summary
UNTP Conformity Public Comment Review Meeting #6 - 28 July 2026
Attendance
- Brett Hyland (Chair)
- Gideon Richards
- Andrew Wheeler
- Zach
- David McNeil
- Neil Savery
Quick recap
The chair presented revised proposals for the conformity trust pathways, aimed at addressing public-comment feedback about mismatched evidence and the ambiguous use of the word "endorsement". The word "endorsement" has been dropped in favour of "authority endorsement", and the scheme-level and CAB-level assurance selections were restructured to give a small set of mutually exclusive choices with mandatory, aligned evidence. A significant portion of the meeting explored whether a scheme's self-declaration carries real value, and how UNTP conformance could be assured and enforced. The group also reviewed fresh public comments from the International Scheme Owners Association (ISOA) and from Microsoft. Several participants agreed worked examples would help validate the proposals, and volunteers were identified to produce them. The chair scheduled the next meeting for the following week.
Discussion topics
Restructured scheme endorsement and evidence alignment
The chair described a redesign to prevent mismatches where a scheme owner claims one form of endorsement but links unrelated evidence. Self-endorsement was removed as a distinct endorsement option; instead the scheme's alignment with international standards is treated as a given self-declaration, and any additional claim of external authority evaluation becomes an optional pathway requiring matching authority evidence. The aim is better matching between the authority claimed and the evidence provided, consistent with Recommendation 49's focus on the conformity assessment process rather than ranking schemes.
Conformity credential trust pathways ("canonical trust")
Responding to a public comment calling for stronger "canonical trust" (a single defined pathway), the chair proposed reducing the mandatory CAB assessment-level code list to three mutually exclusive choices: assurance derived from an authority, derived from the scheme, or nothing stated. A CAB must select exactly one. Scheme-derived claims reference the scheme declaration or evidence of registration under the scheme; authority-derived claims require an "authority endorsement" credential in which all fields (endorsement type from the authority-only code list, plus authority evidence) are mandatory. Authority evidence today is typically a PDF or web link, but is expected to increasingly take the form of a Digital Identity Anchor, enabling a machine-verifiable trust graph.
Value and enforcement of scheme self-declaration
Gideon Richards questioned the value of self-declaration since anyone can assert alignment. The chair argued it is better than nothing because schemes must publicly state which international standards they align with (for governance, standards development, personnel competency and conformity assessment), exposing themselves to reputational risk. He proposed embedding a mandatory self-declaration template as part of the scheme/conformity vocabulary catalogue. Gideon pressed for a mechanism confirming a scheme has actually followed UNTP guidance ("yes/no" compliance), and the chair suggested the appropriate place for such an attestation is the conformity attestation itself.
Regulatory interface
Neil Savery noted the proposals must consider how UNTP interfaces with non-uniform government regulations, where regulators expect claims to be verifiable and testable. He suggested the declaration template would help regulators check how it had been completed and test it, and cautioned against treating this piece as fully self-contained. The chair asked the group to reserve the word "claims" for manufacturer claims to avoid confusion with scheme declarations.
UNTP conformance testing and assurance
Zach outlined existing reference-implementation tooling: a playground validates that a credential passes the rules for its type, so a conformity credential lacking one of the three mandatory assessment fields would fail. A less mature conformity-vocabulary test environment can validate a scheme by URL. A "tier 3" test checks the full accreditor-to-global-MRA path (illustrated by the Australian accredited-steel example). A model is also being explored whereby UNTP issues a "UNTP conformant" credential, potentially underpinning an ongoing funding model. Gideon flagged the discussion feels Western-centric and volunteered to help develop a UNTP conformant route.
ISOA (Kylie) public comments
Three points were reviewed: the term "endorsement" (partly addressed by relabelling to "authority endorsement"); concern that some competency-of-personnel standards listed in the guidance table relate to CABs rather than scheme owners; and that "assessed performance" (numeric measure or categorical score) does not cover all outcome types. The group discussed whether personnel-competency belongs on the conformity credential page or the conformity vocabulary page, agreeing to separate assessor competency from scheme-definition competency and take it offline.
Microsoft public comment (evidence in credentials)
The chair judged this comment, assigned to the conformity group, appears to concern evidence linked directly in a digital product passport rather than via a conformity credential. Since mandatory fields already provide a structured trust pathway, the chair saw no need to structure the optional human-readable evidence file. Zach noted the comment looks like a copy-paste of DPP/DFR comments and suggested closing it as a possible duplicate or deferring beyond version 1.0.
Decisions
- The word "endorsement" is dropped; the relevant field is relabelled "authority endorsement", removing self-endorsement as an authority option.
- The mandatory CAB assessment-level code list will be reduced to three mutually exclusive choices (authority-derived, scheme-derived, or none stated).
- A mandatory scheme self-declaration of international-standards alignment is to be embedded in the conformity vocabulary catalogue schema.
- The single normative reference (e.g. ISO 17021-1) that others already normatively reference will be removed from the guidance table as redundant.
- The placement of personnel-competency guidance (credential page vs vocabulary page) and the assessed-performance data type issue to be worked offline.
Action items
- Andrew Wheeler to prepare worked examples for his scheme/CAB certificate, including a self-declaration example, with Zach assisting to ensure it happens.
- David McNeil to contribute an "as-is / could-be" example (accredited test laboratory, potentially with a Digital Identity Anchor), working with Andrew.
- Zach and the chair to take offline the personnel-competency placement and its relation to Kylie's comment.
- Zach to review the related Microsoft DPP/DFR comments to confirm whether the conformity-group comment is a duplicate / candidate for deferral beyond 1.0.
- Gideon Richards to participate in developing a "UNTP conformant" route.
- Chair to schedule the next meeting weekly (following week).
2026-07-21 Meeting Summary
UNTP Conformity Public Comment Review Meeting #5 - 21 July 2026
Attendance
- Brett Hyland (Chair)
- Phil Archer
- Gideon Richards
- Adrienna Zsakay
Quick recap
The group continued its review of public comments, spending the first part of the meeting confirming the positions reached over the previous two sessions on the submission from the European Risk Policy Institute (Ivan Savov). Most of Ivan's remaining points were discussed and largely settled: the group reaffirmed its position on credential status modelling, agreed to fold ISO-CASCO definitions into the UNTP vocabulary, and declined to build scheme governance metadata or assurance-maturity gates. Phil Archer explained how W3C verifiable credential status lists actually work, which reassured but did not change the group's earlier position. A recurring theme was the distinction between the verifiable credential and the underlying CAB certificate, and the importance of the data carrier identifying the product rather than any certificate or passport. The meeting closed with a homework question on the new comment from Kylie Sheehan (International Scheme Owners Association) about the problematic term "endorsement". Brett flagged that meetings may move from fortnightly to weekly given the volume of outstanding issues.
Discussion topics
Canonical trust chain and machine-readable linkage
The group supported the ERPI request for a canonical (defined, unambiguous) trust chain from CAB identity through accreditation, recognised scope and scheme profile mapping, noting much of the visibility depends on software tooling. Phil linked "canonical" to ongoing W3C VC working group efforts. Gideon cautioned against over-engineering ("too much ones and zeros") given UNTP's voluntary nature, risking missing the real issues. Accreditation-scope matching was set aside as unlikely to be achievable.
Credential status states (suspended, withdrawn, expired)
Reaffirming the previous meeting's conclusion, the group held that continually updating a single issued credential overwrites history, whereas VCs are durable and can be copied and live on. The preferred approach is to revoke or expire a credential and issue a new one if status later becomes current again. Phil explained VC status lists (fixed-length arrays of ones and noughts, with each credential locked to an index position pointing at an external, updatable list; separate lists for revoked vs suspended). This confirmed flexibility exists but did not sway the group. The credential status must be crystal clear for machine verifiability; deeper detail belongs in the certificate. Gideon raised the need to record which standard version was verified against, and questioned how traceability between suspend/unsuspend states is maintained — Phil noted retaining that history is an implementation choice, not part of the spec.
ISO-CASCO term definitions and CAB/scheme competence hooks
Ivan requested clarification of ISO-CASCO terms; Brett will extract the ISO-CASCO definitions into the UNTP vocabulary. Requests for hooks on CAB/assessor competence and impartiality safeguards were viewed as breadcrumb trails rather than UNTP obligations, since these requirements already sit within CASCO standards (e.g. 17065, 17067) and are incumbent on the CAB.
Scheme governance metadata
The group agreed weak schemes should not gain artificial legitimacy but concluded UNTP should not prescribe deterministic governance metadata. Assurance derives either from the scheme's self-declaration against a standard (via its published vocabulary) or from a defined authority pathway, leaving the user to judge adequacy. Phil noted GS1's experience that defining internal governance, not technology, is the hard part. A separate list of "governance data" from Ivan (namespace, version identifier, stable URI, mapping relationships) was considered unrelated conformity-vocabulary material the group was broadly comfortable with, though it was not submitted as public feedback.
Release status and implementation vs assurance maturity
The group believed UNTP release status (normative vs work-in-progress) is already addressed. On distinguishing implementation progress from assurance maturity, Brett noted the Technical group is building conformance test suites; mere commitments to implement are no longer acknowledged. The group rejected any approach that penalised newcomers for short market history, flagging it as a potential barrier to trade / TBT issue.
QR codes, data carriers and fraud vectors
Phil stressed a QR code is neither trustworthy nor untrustworthy — trust comes from the verifying software; "secure QR code" is a misnomer. Low-cost QR verification and SME onboarding were deemed outside the conformity group's remit. On visibly distinguishing a natively signed credential from, e.g., a JPEG of the human-readable version, Phil noted W3C now requires threat-modelling documents; reliance on a visual logo is meaningless, and checking the signature is the relying party's responsibility. The key architectural principle reaffirmed: the data carrier must identify the product, then route (e.g. via a link resolver) to one or more sources of data, enabling suspended/revoked status to surface. If a product is upgraded it becomes a different identity, so verification against a new passport would correctly fail.
Selective disclosure and confidential data
Implementation guidance on personal data, confidential evidence and trade secrets was seen as largely a CAB-client matter; most conformity model fields are optional. Phil confirmed selective disclosure is a built-in VC feature but is driven mainly by personal-identification use cases rather than conformity, so the group need not prioritise it.
"Endorsement" terminology (homework)
Kylie Sheehan (International Scheme Owners Association) noted "endorsement" is problematic as it usually implies benchmarking/evaluation of a scheme, suggesting "authorization" or "approval". Brett agreed "endorsement" is imperfect but considered the alternatives no better, viewing it as the least-bad term for a reusable unit applied across very different contexts (scheme endorsement, credential endorsement, scheme self-declaration, CAB recognition). Phil noted the W3C VC working group uses "recognised". The group was asked to consider whether to keep one reusable unit or split it into several objects.
Decisions
- Retain the previous meeting's position on status: do not overwrite a single credential's history; revoke or expire and issue a new verifiable credential when certification status changes.
- Keep the verifiable credential conceptually distinct from the underlying CAB certificate; credential status must be unambiguous for machine verification.
- Do not prescribe mandatory scheme governance metadata or assurance-maturity gating; assurance comes from scheme self-declaration or a defined authority pathway.
- Treat QR verification, SME onboarding, and selective disclosure as outside the conformity group's scope.
- Adopt "data carrier" rather than "QR code" in group terminology (per Adrienna Zsakay's suggestion).
Action items
- Brett Hyland to extract ISO-CASCO term definitions and add them to the UNTP vocabulary.
- Brett Hyland to respond in detail to each of Ivan Savov's public comments via the GitLab issues; contributions from members welcome.
- Brett Hyland to seek John Phillips' permission to share his credential lifecycle treatise with interested members.
- All members to consider, as homework, a better term than "endorsement" (or whether to split the reusable unit) ahead of the next meeting.
2026-07-09 Meeting Summary
UNTP Conformity Public Comment Review Meeting #4 - 9 July 2026
Attendance
- Brett Hyland (Chair)
- Neil Savery
- Martina Paul
- Reinaldo Figueiredo
- Etty Feller
- Zach
Quick recap
Brett opened with the standard UN intellectual property reminder and then revisited an EPRI (European Policy Risk Institute) comment asking UNTP to model the life cycle of a conformity credential. He presented a schematic of the UNTP architecture — product passport, conformity credential, UNTP attestation, and linked CAB certificate — to expose the constraints of a digitally verifiable design. The core debate was whether to follow EPRI's suggestion of a single enduring credential whose status rotates over time (active, suspended, reissued), or to issue a new standalone credential on each change. Brett argued against the enduring-credential approach because it overwrites history and makes the "valid from" date ambiguous, recommending instead that the CAB expire or revoke the credential and issue a fresh one when validity is re-established. Zach clarified an important technical point that revocation does not delete a credential's data — it flags it as invalid while the data remains discoverable — which softened several of Brett's stated concerns. The group also discussed terminology, data-governance roles, scheme-owner transparency obligations, and how to communicate all this to regulators without exposing verifiable-credential mechanics. No formal resolution was reached, but there was broad support for the standalone-credential approach.
Discussion topics
Certificate status use cases (present vs historical)
Brett distinguished two requirements: establishing a certificate's status at the time of inquiry (the common case), and establishing its status at a historical point in time (harder, and poorly served by the paper world). He noted the digital approach might do better than paper on the historical case, even if not perfectly.
UNTP architecture schematic and constraints
Brett walked through the architecture: the product passport (a W3C VC) links to a conformity credential (also a W3C VC) with issuer-selectable valid-from/valid-to dates and a status (active or revoked by default in the W3C bitstring). The credential wraps an immutable UNTP attestation, which may link to or embed (as an evidence file) an externally hosted CAB certificate. Because VC content is fixed, a changed certificate URL cannot be reached from the original credential — a key constraint for life-cycle modelling. Neil Savery asked whether "CAB" was generic or referred to the accreditation framework; Brett confirmed today's focus was deliberately limited to the CAB certificate, not endorsements.
Enduring credential vs reissuing new credentials (the EPRI comment)
Brett recommended against EPRI's enduring-credential-with-rotating-status model, arguing it overwrites history, makes validity dates ambiguous, and improperly shifts to the user/machine the burden of interpreting statuses like "suspended" or "under appeal" — a judgement that should belong to the CAB and scheme. His preferred approach: the CAB closes the valid period on a status change, and issues a new standalone credential when validity is re-established. Zach and Brett noted new credentials are cheap and fast to generate in an automated system.
Suspension, revocation and expiry semantics
Etty Feller and Reinaldo Figueiredo pushed back on the idea that a reissued certificate after a suspension can hide that a suspension occurred — a reissue must carry a new date and reason, and schemes/CABs keep records. Brett drew a distinction between reissuing a certificate (a CAB/ISO CASCO process) and reissuing a credential (a digital envelope), noting the credential's validity date restarts and does not reach back over the suspended period; history lives inside the certificate. He suggested CABs will generally prefer to expire rather than revoke, so the certificate can "tell its own story," and that expiry better signals a voluntary withdrawal versus an adversarial revocation.
Data persistence on revocation
Zach clarified that revocation does not remove a credential — the data persists and is flagged as invalid by the issuer, so a verifier can still see that a passport's claim is no longer backed by a third-party attestation. He also noted receivers can download and self-host credentials, but issuer revocation carries through on status check. This led Brett to acknowledge some options on his slides were wrong because the trail persists. Neil Savery added that reputable schemes maintain the certificate history (with revoked/suspended status) on their own public-facing databases, and that transparency is an accreditation requirement.
Data governance roles and ownership
Martina Paul raised who bears the risk and who "owns" the data, suggesting UNTP adopt formal data-governance terminology (owner, provider, steward). Brett recalled the BRS position that the commissioning company might be seen as owner but the CAB is termed the "custodian" as the only party able to change the data. Both agreed data-governance terms would bring precision.
Communicating to regulators / mixed-integrity data
Etty Feller stressed that regulators know nothing of envelopes and credentials and need plain definitions, especially around why multiple certificate versions exist and scope of accreditation. Zach agreed verifiable-credential mechanics should stay in technical rooms: to regulators, the message is simply that there is one active certificate plus a discoverable history. Brett closed by flashing the specification's "mixed integrity UNTP data" example (upstream PDF sources transformed via a language model and marked lower integrity), addressing a separate EPRI concern about distinguishing low- from high-integrity verifications.
Decisions
- No formal decision was taken; the group reached a broad but non-binding consensus favouring Brett's approach (issue a new standalone credential per certification iteration, rather than EPRI's enduring rotating-status credential).
- Agreement that history should not be overwritten and that revocation/expiry semantics leave data discoverable.
Action items
- Brett to draft a detailed response to EPRI explaining why UNTP will not adopt the enduring-credential model.
- Zach and Brett to schedule time to work the certificate life-cycle approach to the next level of detail and bring it back to the group.
- Consider adopting formal data-governance role terminology (owner, provider, steward, custodian) across UNTP concepts (raised by Martina Paul).
- Clarify on the relevant slide that expire-vs-revoke is at the CAB's discretion within the constraints of the scheme rules (noted by Neil Savery).
Note: This was Reinaldo Figueiredo's final meeting before retirement; the group recorded its thanks and best wishes.
2026-06-23 Meeting Summary
UNTP Conformity Public Comment Review Meeting #3 - 23 June 2026
Attendance
- Brett Hyland (Chair)
- Jiangyun LI (China Quality Certificate Center, a CAB affiliated with CNAS) — first-time attendee
- Gideon Richards
- Neil Savery
- Etty Feller
- Reinaldo Figueiredo
- Zach
- Phil Archer (W3C Verifiable Credentials Working Group co-chair)
- Matthias Glauss
- Roberto Perez-Franco
Quick recap
The group welcomed a new attendee and reviewed two items carried over from the previous meeting alongside the public comment submission from the European Risk Policy Institute (ERPI). The CASCO alignment subgroup had met and confirmed that UNTP should restore explicit alignment with ISO CASCO terminology; the chair will supply alignment data to the technical team. Consensus held on reverting the assessor-level code list from the UN/CEFACT BRS code list to standard CASCO first/second/third-party definitions plus an "unspecified" option, supplemented by plain-English explanations. Much of the meeting addressed strengthening the endorsement/trust-chain concept in response to ERPI's comments, with debate over self-declaration, non-accredited but market-recognised bodies, and the group's firm preference for transparency over hierarchy. The group also discussed credential status lists (active/suspended/revoked), deprecated-certificate pointers, and the limits of UNTP's role in attesting CAB competence. The group broadly agreed with ERPI's submission and deferred remaining points to the next meeting.
Discussion topics
CASCO alignment and assessor-level code list
The subgroup (which included ISEAL) confirmed that UNTP had drifted from its intended ISO CASCO alignment and should restore it explicitly. The chair will provide alignment data to the technical team, with results expected within a week or so. Consensus was reaffirmed to move the assessor-level code list back to standard CASCO first/second/third-party audit definitions, with an "unspecified" fallback. Gideon Richards proposed adding a plain-English explanatory column so non-CASCO audiences can understand the terms. Etty Feller and Reinaldo Figueiredo cautioned against reinterpreting or altering ISO terminology (which is fixed in standards and referenced by the WTO TBT conformity assessment guidance), recommending explanatory notes rather than changes to defined terms.
Trust chain and canonical traversal (ERPI feedback)
Responding to ERPI's call for a canonical trust chain from CAB identity through accreditation or competent-authority evidence, Brett Hyland reported the technical team believes this is achievable. Zach framed it as an opportunity for the conformity group to define a best-practice profile for traversing the trust graph (implemented technically as "tier 3" linked-data testing). Phil Archer noted the mechanisms already exist or are in active development, citing the UN GRID register and the W3C "recognized entities" work, and explained connections can be made either credential-to-credential or via the issuer's resolved DID document.
Self-declaration and scheme authority
Reinaldo Figueiredo stressed that trust chains increasingly include self-declared and first-party steps, and that full third-party assessment is not always feasible. The group agreed the scheme itself defines what activities may be self-declared and the rules governing them. Brett Hyland and Zach noted UNTP already accommodates this: schemes can approve parties to issue attestations, and the market can evaluate the density of linked evidence. Zach emphasised enabling both self-attestation and dense graph validation, leaving evaluation to the marketplace.
Transparency versus hierarchy
Reinaldo Figueiredo raised non-accredited but market-recognised bodies (e.g. ASME, ANAB for general accreditation) that derive authority from market acceptance rather than government or accreditation endorsement. The group agreed UNTP must not penalise such bodies and should present facts transparently without imposing a hierarchy, since UNTP is voluntary and the UN lacks authority to rank bodies. Etty Feller noted the model must also reflect regions where governments approve schemes or require accreditation.
UNTP conformance and status/revocation of credentials
Zach raised that, as a voluntary standard, there is no mandate to publish linked machine-readable data, but the group can define what "UNTP conformant" means and UN/CEFACT is considering issuing an algorithmic conformity credential (a possible funding model). Gideon Richards questioned how suspension or withdrawal would be surfaced. Phil Archer explained credentials can link to multiple binary status lists (active/suspended/revoked). Brett Hyland described the identity-resolver approach of keeping a binary active/inactive flag while allowing discovery of historical credentials, and raised the tension that manufacturers (CAB clients) may not want suspension history broadcast. Neil Savery argued accredited CABs are already obligated to disclose such status publicly, so no special mechanism is needed. Matthias Glauss argued a status mechanism is essential to prevent the trust graph asserting untruths. The group leaned toward agreement.
Deprecated certificate pointers and CAB competence hooks
Roberto Perez-Franco suggested a mechanism for a deprecated/superseded certificate to point to its current version, referencing ConformityID user research in the building sector. On ERPI's request for hooks covering CAB/assessor competence, impartiality, and appeals, the group (Brett Hyland, Etty Feller, Gideon Richards, Zach, Roberto Perez-Franco) agreed this is not UNTP's role and risks breaching CAB confidentiality; at most a link field for more information would be offered, not a detailed tick-box menu. The chair also intends to clarify with ERPI the point on certification/inspection/testing/calibration, noting the existing code list may not have been visible to commenters.
Decisions
- Restore explicit alignment with ISO CASCO terminology; the chair will provide alignment data to the technical team.
- Revert the assessor-level code list from the BRS code list to standard CASCO first/second/third-party definitions plus an "unspecified" option, supplemented by plain-English explanations (not changes to the ISO terms themselves).
- Adopt transparency rather than hierarchy: present facts about any basis for assurance without ranking schemes or bodies.
- Broadly agree with the ERPI public comment submission, with no opposition raised.
Action items
- Brett Hyland to prepare and supply the CASCO alignment data to the technical team (results expected within about a week).
- Brett Hyland to annotate the relevant public-comment issues in GitLab and seek clarification from the ERPI commenter on the certification/inspection/testing/calibration point.
- Conformity group to define the best-practice trust-graph traversal profile for conformity attestation (with technical implementation handled by the technical working group).
- Circulate the revised vocabulary to the group for expert review once reshaped.
- Continue discussion of the remaining ERPI points (CAB competence hooks) at the next meeting.
2026-06-09 Meeting Summary
UNTP Conformity Public Comment Review Meeting #2 - 9 June 2026
Attendance
- Brett H (Chair)
- Etty F
- Roberto P
- Easter H
- Gideon R
- Matthias G
- Reinaldo F
- Neil S
- Zach Z
- Martina P
- Adrian von M
- Phil A
Quick recap
The second meeting in the public-comment review series opened with a welcome, rules of the road, and introductions, including new member Matthias G, who is affiliated with a measuring-equipment manufacturer interested in links to the Digital Calibration Certificate model developed by PTB. The group reaffirmed the removal of "Hybrid" from the Assessor Level code list and debated reducing the list to four items and adopting ISO/IEC 17000 definitions, stressing alignment with existing standards for semantic interoperability. Discussion then turned to the relationship between linked "endorsement" evidence and the AssessorLevel / AssessmentLevel code lists, raising several data-modelling questions to be weighed against acceptable levels of change at v0.7. The group also agreed to form a sub-group on alignment and cross-referencing of terms and definitions, and reaffirmed that no decisions are final while public comment remains open. The meeting closed with tributes to Reinaldo F, who retires next month.
Discussion topics
Assessor Level code list
The group reaffirmed the position from the previous meeting to remove "Hybrid". Discussion followed on whether to reduce the code list to four items (1st, 2nd, 3rd party plus "Not Specified") and whether to shift to adoption of ISO/IEC 17000 definitions in the code list. The question was raised as to whether an assessing organisation having an interest (e.g. financial) but not a "user interest" needed to be addressed, as had been attempted in the original BRS work. Views expressed indicated this should not be necessary, provided that relevant interpretive notes were available. The point was strongly made that sticking with the 17000 definitions aligned with the desire for semantic interoperability with other emerging systems, and that in general UNTP should exercise care if seeking to create any term or definition for which there is already an analogue in an existing standard. ISO 17067 (FDIS stage) was identified as another important reference for terms and definitions.
Relation between linked "endorsement" evidence and the AssessorLevel / AssessmentLevel code lists
While usage seems self-consistent for the Scheme Vocabulary logical model, it is less so for the Conformity Credential logical model, noting that the latter emerged from the original BRS, prior to the development of the "assurance" categories by the UNTP Conformity Group. The discussion led to reflections on several aspects:
- Independence of the code lists from linked endorsement evidence. Whether it is logically correct to have the code lists independent from the linked endorsement evidence. This was identified as a data-modelling question to be considered in terms of the extent of change acceptable at v0.7.
- Cryptographic verification and the Digital Identity Anchor. Whether the structure of the "Endorsement" data object is amenable to cryptographic verification of the issuing party and whether it reflects the more recent development within UNTP of the "Digital Identity Anchor" concept. This is likewise a data-modelling question to be considered in the context of acceptable levels of change at v0.7, noting that the process needs to handle present-day practices, which generally take the form of website linkages or PDF certificates.
- Alignment of terms and definitions with applicable standards. The opportunity should be taken to review terms and definitions appearing in logical models or code lists for alignment with applicable standards (such as 17067) and other norms. While the only external definitions currently being considered by the group are those for 1st, 2nd and 3rd party conformity assessment, other terms such as "benchmarking" and "scheme owner" appear in descriptions within code lists, so some form of cross-referencing or a general glossary would be a good idea. Clarification may also be needed on the need for permission to reference ISO terms. Prior work published in the UN/CEFACT DPCCE BRS should also be given due weight and consideration (this tended to strictly follow ISO CASCO). A call was made for a sub-group to consider the matter, with Gideon R, Zach Z and Phil A indicating willingness to assist. It was further suggested that ISEAL be approached, possibly Josh T., who has attended previous UNTP Conformity Group meetings.
- Non-final status of decisions during public comment. Recognition that public comment is ongoing means that decisions on changes should not be regarded as final until all comments have been reviewed, including any arriving in the next five weeks.
Tribute to Reinaldo F
The meeting ended with general tributes for Reinaldo F, who retires next month. His impressive contributions to conformity assessment over several decades were applauded, including his longstanding and selfless support for the work of UN/CEFACT and the UNTP programme.
Decisions
- Reaffirmed the position from the previous meeting to remove "Hybrid" from the Assessor Level code list.
Action items
- Revisit the Assessor Level code list topic next meeting, for potential decision.
- Consider the independence of the code lists from linked endorsement evidence as a data-modelling question, in terms of the extent of change acceptable at v0.7 — Brett to follow up and advise.
- Consider the "Endorsement" data object questions (cryptographic verification of the issuing party and reflection of the Digital Identity Anchor concept) as data-modelling questions in the context of acceptable levels of change at v0.7, noting the need to handle present-day website-linkage and PDF-certificate processes — Brett to follow up and advise.
- Assemble a sub-group to consider the alignment and cross-referencing of terms and definitions — Gideon R, Zach Z and Phil A to assist; ISEAL (possibly Josh T.) to be approached.
- Add resolutions to the relevant GitHub issue, but do not close them until public comment has concluded.
2026-05-26 Meeting Summary
UNTP Conformity Public Comment Review Meeting #1 - 26 May 2026
Attendance
(from transcript speaker labels)
- Brett Hyland (Chair)
- Gideon Richards
- Phil Archer (GS1; also co-chair of the relevant W3C working group)
- Marc Boissonnet (TIC Council)
- Neil Savery
- Zach
- Georgia Alsop (UKAS, Chief Financial and Digitalization Officer)
Quick recap
This was the first meeting of the public-comment review series, resuming after a pause since 10 March 2026. The Chair recapped the group's purpose and its two delivered specification outputs (the Digital Conformity Credential page and the Scheme Vocabulary page), both anchored in UNCEFACT Recommendation 49. Public comment had opened roughly a week and a half earlier; no external comments touching the group's work had arrived, so the meeting worked through the Chair's own submitted comments. Members first shared regulatory and legal developments (a German palm-oil/RSPO judgment, the EU ECGT directive, and the new W3C credentials working group). The bulk of the meeting covered five of the Chair's issues: terminology updates for Global ACI, the "hybrid" assessor-level term, the "requirements" heading, a proposed mandatory-criteria field on conformity profiles, and (deferred as homework) the dual use of the UNTP-Endorsement object. Overall direction favoured keeping the framework simple, pushing scheme transparency rather than imposing rules, and possibly adding implementation guidance explaining author intent.
Discussion topics
Regulatory and legal developments
Gideon Richards reported a German court judgment on a "responsible palm oil" claim, where merely linking to the RSPO website was found insufficiently detailed and not in the local marketing language, signalling regulators clamping down on vague claims. Marc Boissonnet described the EU ECGT directive (Empowering Consumers for the Green Transition), which defines greenwashing and introduces an independence requirement for scheme owners, traders and verifiers that member states are struggling to transpose; the meaning of "independence" remains unclear pending EU Commission clarification, with hopes that ISO 17065 accreditation will be deemed sufficient. Marc argued the focus should be on conflict of interest rather than independence. The Chair noted the group deliberately uses "impartiality" over "independence."
W3C working group update
Phil Archer, switching from his GS1 role to his co-chair role for the W3C working group, reported that group is now fully active with multiple task forces, including confidence methods, render methods, authority-to-issue / linking credentials ("recognized entity"), and vocabularies for business wallets and digital product passports. A face-to-face meeting was planned in Brussels the following week. The Chair emphasised this work is central to UNTP's direction and noted his own accreditation authority intends to issue digital credentials anchored in its Global ACI MRA signatory status, using a did:web identifier.
Global ACI terminology update (Issue: naming/tidy-up)
ILAC and IAF merged in 2026 to form Global ACI, replacing prior "Mutual Recognition Arrangement" / "multilateral arrangement" terminology with a single "multilateral recognition arrangement." The conformity credential page needs updating. Zach and Gideon Richards raised the need to accommodate legacy terminology during the transition (IAF MD25 still current). Consensus formed around adopting the modern terminology with an explanatory note and a link back to Global ACI, rather than cluttering the page with three equivalent terms.
Assessor-level vocabulary and the "hybrid" term (Item 5 area)
The assessor-level code list, inherited from the earlier Digital Product Conformity Certificate Exchange BRS, splits second-party into membership, buyer and commercial arrangements. A "hybrid" term (suggested by Reinaldo) had been added for assessments that analyse client-provided data without independent scrutiny, but it overlaps with the first/second/third-party categories, breaking mutual exclusivity. Gideon Richards and Neil Savery argued against embedding "hybrid" into the recognised first/second/third-party framework, preferring to describe it in a note. Zach argued algorithmic validation of claims (per Rec 49) is coming and "hybrid" may not go far enough, possibly needing a separate categorisation. Discussion linked this to how forcefully schemes must disclose the nature of their assessments in the scheme vocabulary, and to future "UNTP conformity" recognition requirements around disclosure granularity.
"Requirements" heading and numbering (Items 3 and 4)
The Chair noted the "requirements" heading on each specification page reads as implementer obligations but actually lists design requirements, and questioned the elaborate requirement-numbering scheme in favour of simple sequential numbering. These were flagged to the steering committee as not requiring group discussion.
Mandatory-criteria field on conformity profiles (Gideon's earlier issue)
A buyer could review profile criteria without realising a scoring framework may require, e.g., only 50% of criteria to be met. The Chair proposed adding a mandatory field to the conformity profile indicating whether all linked criteria are mandatory, prompting buyers to consult the scoring framework. Gideon Richards cautioned against making partial passes look deficient (citing B Corp, ISeal, IFRS/ESRS base-plus-additional models). Neil Savery reframed the field wording toward "is there a minimum level that must be achieved in all criteria?", which the group liked. Georgia Alsop (UKAS) cautioned the group against straying into defining scheme rules, and the Chair reaffirmed the group only requires transparency, leaving decisions to the buyer. Gideon and Neil advocated producing guidance documentation expressing the authors' "intent."
UNTP-Endorsement dual usage (homework item)
The Chair explained the term "endorsement" originated as a statement of credibility linked to a CAB-issued conformity credential (e.g. an accreditation), but the same UNTP-Endorsement object was later reused for scheme-vocabulary credibility statements (self-declaration, benchmarking credential, accreditation-body suitability assessment). The two usages do not share the same logical connections. This was deferred as homework for the next meeting.
Decisions
- Adopt modern Global ACI terminology on the conformity credential page, with an explanatory note and link back to Global ACI to cover legacy terms.
- Drop the "hybrid" assessor-level term from the recognised first/second/third-party framework (noting this leaves algorithmic verification less visible, to be addressed separately).
- Favourable consensus to add a conformity-profile field along the lines of "is there a minimum level that must be achieved in all criteria?" (exact wording to be refined).
Action items
- BH to reflect on Marc Boissonnet's certification-vs-ratings distinction and return with more coherent thoughts next meeting.
- BH / group to consider whether and how to populate the "implementation guidance" section to explain author intent.
- Gideon Richards to post a link to the German palm-oil/RSPO judgment in the chat if he can locate it.
- All members to review the UNTP-Endorsement dual-usage issue as homework ahead of the next meeting.
2026-02-10 Meeting Summary
UNTP Conformity Meeting #11 - 10 February 2026
Agenda
- Welcome & Rules of the Road
- New member intros
- Conformity Credential webpage prep for Public Comment
- UNTP Digital Identity Anchor in our work
- UNIDO publication update
Key Outcomes
- The Assessment Assurance documentation was reviewed and has now been submitted for processing.
- The subgroup on Scheme Vocab will be reactivated to consider Issue #590
2025-12-03 Meeting Summary
UNTP Conformity Meeting #8 - 03 December 2025
Attendance
Brett Hyland Etty Feller Reinaldo Figueiredo Gideon Richards Ulas Nalbantoglu Zach Zeus Neil Savery Georgia Alsop Adrienna Zsakay Phil Archer Anil Jauhri Rama Ha Alison Jose
Welcome & Rules of participation (BH)
New participant intro - Rama Ha
Discussion topic:
Decide if the draft Conformity Assurance Guide is ready to be socialised beyond our own group
Discussion indicated broad support for the Assessment Assurance approach that was circulated ahead of the meeting. A number of upcoming external stakeholder mtgs were identified that would provide opportunities for socialising the concepts.
New action : Write intro for the UNTP Assessment Assurance doc to provide context and then get Steering Committee permission to commence preliminary consultancy. Updated doc sent to group on 5/12 with approval to socialise within our networks - Action to be closed
New action: Raise Gitlab issue for incorporating UNTP Assessment Assurance as a normative part of UNTP. Issue #563 raised and Updated document linked on 5/12 - Action to be closed
Previous action items completed:
• Problem with selecting national delegation for CEFACT Expert registration - Zach advises this interface is now stable - Action closed
• Gitlab Issue #79 (open) has been discussed in terms of credible processes for gathering human observations to form conclusions (such as human welfare). It was agreed that work just completed by the UNTP-Conformity group in defining credible scheme evaluation represents a possible resolution of this issue - Action closed
Note: Gitlab Item #79 has since been annotated as follows:
The UNTP-Conformity group has been discussing closely related matters to Issue#79 over the past few months. In relation to 'accumulating evidence of ethical participation' through mechanisms other than formal audits, this does seem a worthy goal and yet to be packaged as a conformity credential it would still need to be structured and managed through some set of processes (let's call this a 'scheme', which is the formal term in ISO CASCO). The UNTP-Conformity group has been working hard on describing what a credible scheme should look like, in terms of: scheme development/management, governance, standards development, competency of personnel and oversight of conformity assessment (refer to Issue #563 for more detail). While the UN wouldn't wish to be involved in judging schemes, there are classes of organisations who carry out this exactly this function.
So, such a human welfare scheme has the option of issuing conclusions that depend on a user's own belief in the value of the scheme (ie, does not align with UNECE Rec49 principles), or the scheme could submit to an evaluation of their scheme by a recognised authority such that there is alignment with REC49 principles.
In terms of the other matter raised in the thread above, that of an isolated, stand-alone, human observation, this doesn't really sound like the subject of a conformity credential. Perhaps a record of such an observation could be used as one form of 'evidence' which might be linked directly from a claim that is contained in a DPP or DFR.
Outstanding action item list:
- (Updated) Scope the terms of engagement with the conformity credential implementors previously nominated by the subgroup and have Zach approach those groups - BH & ZZ to draft ToR
- (Updated) Articulate a framework for referencing SDO-published standards such that everyone can digitally reference these in the same way, regardless of who's doing the implementation - PA to liaise with BH
- (Updated) Seek advice on whether the Conformity Topic Classification can be moved to its own Gitlab page as it isn’t exclusive to the Scheme Vocab subject and also note that the Waste Framework Directive is missing from the list of references (ZZ action)
- (Updated) If a particular scheme requires all CABs assessing to their scheme to use a hierarchical structure for criteria then should this be accommodated as an extension (Gitlab open issue #344) or must we update the Core conformity credential structure (Subgroup action)
- (Update) Establish whether the scheme header/vocab structure allows reference to scheme assurance pathways and seek to have the Logical Model updated in not (BH & ZZ action)
- Steve Capell is to investigate any implications for UNTP information security in light of the EU CapGemini initiative (SC action)
2025-11-25 Meeting Summary
UNTP Conformity Meeting #7 - 25 November 2025
Attendance
- See Transcript
Welcome & Rules of participation
Participant intro (All)
Item Discussion
- See Slides
Outstanding Action items:
Not reviewed so carried forward: 1 - Problem with nominating national delegation for CEFACT Expert registration interface has been fixed, but instabilities in the platform remain, Zach to continue to monitor and advise group (ZZ action)
2 - Worked Example subgroup to scope the terms of engagement with the conformity credential implementors previously nominated by the subgroup and have Zach approach those groups (Subgroup action)
3 - Articulate a framework for referencing SDO-published standards such that everyone can digitally reference these in the same way, regardless of who's doing the implementation (BH action in conjunction with PA)
4 - Seek advice on which UNTP group is tasked with maintenance of the Conformity Topic Classification, move it to the appropriate Gitlab page and also advice the owner that the Waste Framework Directive is missing from the references (ZZ action)
5 - If a particular scheme requires all CABs assessing to their scheme to use a hierarchical structure for criteria then should this be accommodated as an extension (Gitlab open issue #344) or must we update the Core conformity credential structure (Subgroup action)
6 - Gitlab open issue #79 has implications for defining where observations finish and CA begins, so BH to draft response based on insights from Mtg#4 and circulate for feedback before annotating the Gitlab issue log.
7 - Confirm whether the scheme header/vocab structure allows reference to scheme endorsements (BH action)
8 - Steve Capell is to investigate any implications for UNTP information security in light of the EU CapGemini initiative
2025-11-05 Meeting Summary
UNTP Conformity Meeting #6 - 05 November 2025
Attendance
- See Transcript
Welcome & Rules of participation
Participant intro (All)
Item Discussion
- See Slides
Outstanding Action items:
Not reviewed so carried forward: 1 - Problem with nominating national delegation for CEFACT Expert registration interface has been fixed, but instabilities in the platform remain, Zach to continue to monitor and advise group (ZZ action)
2 - Worked Example subgroup to scope the terms of engagement with the conformity credential implementors previously nominated by the subgroup and have Zach approach those groups (Subgroup action)
3 - Articulate a framework for referencing SDO-published standards such that everyone can digitally reference these in the same way, regardless of who's doing the implementation (BH action in conjunction with PA)
4 - Seek advice on which UNTP group is tasked with maintenance of the Conformity Topic Classification, move it to the appropriate Gitlab page and also advice the owner that the Waste Framework Directive is missing from the references (ZZ action)
5 - If a particular scheme requires all CABs assessing to their scheme to use a hierarchical structure for criteria then should this be accommodated as an extension (Gitlab open issue #344) or must we update the Core conformity credential structure (Subgroup action)
6 - Gitlab open issue #79 has implications for defining where observations finish and CA begins, so BH to draft response based on insights from Mtg#4 and circulate for feedback before annotating the Gitlab issue log.
7 - Confirm whether the scheme header/vocab structure allows reference to scheme endorsements (BH action)
8 - Steve Capell is to investigate any implications for UNTP information security in light of the EU CapGemini initiative
Close -
2025-10-14 Meeting Summary
UNTP Conformity Meeting #5 - 14 October 2025
Attendance
- See Transcript
Participant intro (All)
Outstanding Action items:
Agreement was reached that we need to find ways to establish trust in UNTP conformity credentials. if the protocol is to become credible.
1 - Problem with nominating national delegation for CEFACT Expert registration interface has been fixed, but instabilities in the platform remain, Zach to continue to monitor and advise group (ZZ action)
2 - Worked Example subgroup to scope the terms of engagement with the conformity credential implementors previously nominated by the subgroup and have Zach approach those groups (Subgroup action)
3 - Articulate a framework for referencing SDO-published standards such that everyone can digitally reference these in the same way, regardless of who's doing the implementation (BH action in conjunction with PA)
4 - Seek advice on which UNTP group is tasked with maintenance of the Conformity Topic Classification, move it to the appropriate Gitlab page and also advice the owner that the Waste Framework Directive is missing from the references (ZZ action)
5 - If a particular scheme requires all CABs assessing to their scheme to use a hierarchical structure for criteria then should this be accommodated as an extension (Gitlab open issue #344) or must we update the Core conformity credential structure (Subgroup action)
6 - Gitlab open issue #79 has implications for defining where observations finish and CA begins, so BH to draft response based on insights from Mtg#4 and circulate for feedback before annotating the Gitlab issue log.
7 - Confirm whether the scheme header/vocab structure allows reference to scheme endorsements (BH action)
8 - Steve Capell is to investigate any implications for UNTP information security in light of the EU CapGemini initiative
Close -
2025-09-30 Meeting Summary
UNTP Conformity Meeting #4 - 30 September 2025
Attendance
- See Transcript
Item Discussion
Welcome & Rules of participation (BH)
Participant intro (All)
Outstanding Action items:
1 - Problem with nominating national delegation for CEFACT Expert registration interface has been fixed, but instabilities in the platform remain, Zach to continue to monitor and advise group (ZZ action)
2 - Worked Example subgroup to scope the terms of engagement with the conformity credential implementors previously nominated by the subgroup and have Zach approach those groups (Subgroup action)
3 - Articulate a framework for referencing SDO-published standards such that everyone can digitally reference these in the same way, regardless of who's doing the implementation (BH action in conjunction with PA)
4 - Prepare version 4 of the Gitlab SVC page incorporating the various insights from Mtg#4 and circulate to UNTP-Conformity for feedback (BH Action)
5 - Seek advice on which UNTP group is tasked with maintenance of the Conformity Topic Classification, move it to the appropriate Gitlab page and also advice the owner that the Waste Framework Directive is missing from the references (ZZ action)
6 - If a particular scheme requires all CABs assessing to their scheme to use a hierarchical structure for criteria then should this be accommodated as an extension (Gitlab open issue #344) or must we update the Core conformity credential structure (Subgroup to action as part of engagement with implementors)
7 - Gitlab open issue #79 has implications for defining where observations finish and CA begins, so BH to draft response based on insights from Mtg#4 and circulate for feedback before annotating the Gitlab issue log.
8 - Confirm whether the scheme header/vocab structure allows reference to scheme endorsements (BH action)
9 - Steve Capell is to investigate any implications for UNTP information security in light of the EU CapGemini initiative
Close -
2025-09-02 Meeting Summary
UNTP Conformity Meeting #3 - 2 September 2025
Attendance
Brett Hyland Phil Archer Gideon Richards Zach Zeus Steve Capell Ulas Nalbantoglu Ladin Camci Neil Savery Alison Jose David McNeil
Item Discussion
Welcome & Rules of participation (BH) Per slides.
Participant intro (All)
Outstanding Action items:
-
CEFACT Expert registration interface - Problem acknowledged, fix requested, Zach to chase up - New Action 1 (ZZ)
-
Edit of SVC Gitlab page - Circulate again for further review after Eurozone holiday - New Action 2 (BH)
-
Conformity examples - agreed on the need for a new Sub-group to be formed - volunteers requested New Action 3 (BH)
Discussion: Steve: Concentrate not just on edge cases but also formalise some routine examples and highlight any progress towards comparability of conformity outcomes across different schemes
Gideon: we have a baseline MRA/MLA but this will be tested when different scheme types both fall under a MLAMRA
Steve: Maybe schemes can recognise each other under mutual acceptability
Gideon: We must recognise the commercial nature of Schemes and rely on objective information
Open issues assigned to group (ZZ)
Open Issue # 344: https://opensource.unicc.org/un/unece/uncefact/spec-untp/-/issues/344
Discussion
Gideon: need to be clear on what is a Scheme (eg, contract between a CAB and a Client)
Phil: can have a flat list that is mapped to a hierarchy using a schema
Gideon: cognizant of ‘pick&choose’ standards like IFRS
Steve: a question would be - has anyone ever seen a certificate of conformity issued by a CAB that had anything other than a flat list of assessments?
BH: flat list would obviously be the current norm, so if someone can help express the idea of a schema for mapping such to a hierarchy in terms that non-IT folk can understand - Phil Archer? New Action 4 (BH)
Open Issue # 343: https://opensource.unicc.org/un/unece/uncefact/spec-untp/-/issues/343
Incorrectly assigned ! Organise transfer to Tech group New Action 5 (ZZ)
Open Issue #79: https://opensource.unicc.org/un/unece/uncefact/spec-untp/-/issues/79
Discussion
Complex question - raises issues of reliability (objective evidence), the need for an incentive in place for providing factual outcomes and consideration of varying local legislative compliance rules. All to give consideration to this complex issue to help clear this longstanding open issue New Action 6 (All)
Alison queried information security issues in light of CapGgemini https://www.capgemini.com/solutions/eu-ai-act-compliance
Steve will investigate implications New Action 7 (SC)
Close -
2025-08-13 Meeting Summary
Meeting 13 August 2025 11pm CEST
Attendance:
Roger Meikle Ulas Nalbantoglu Brett Hyland Zach Zeus Andrew Wheeler Adrienna Zsakay Emiliano Sune Gideon Richards Jose Saiz de Oneñaca Rembrandt Koppelaar Todd Taylor Ryan Colker Ladin Camci Matthias Prellwitz Martin Pompéry Leslie Lopez Aria
Item Discussion
Welcome & Rules of participation (BH) Per slides.
Per slides. Action 1: Participants encouraged to register as CEFACT experts.
https://uncefact.unece.org/display/uncefactpublic/UNCEFACT+Expert+Registration
Participant intro (All) -
Outstanding Action item: Presentation from SVC ad hoc sub-group (BH)
Per slides
Open issues assigned to group (ZZ)
Open Issue #344: https://opensource.unicc.org/un/unece/uncefact/spec-untp/-/issues/344 Open Issue #343: https://opensource.unicc.org/un/unece/uncefact/spec-untp/-/issues/343 Open Issue #79: https://opensource.unicc.org/un/unece/uncefact/spec-untp/-/issues/79
Action 2: Group to consider the above and to either directly comment in GitLab or notify BH of interest in contributing to offline work on these issues
Gitlab changeover
GitHub now moved to UNICC GitLab Updated links: UNTP Conformity Credential page: https://untp.unece.org/docs/specification/ConformityCredential UNTP Conformity Vocabulary page: https://untp.unece.org/docs/specification/ConformityVocabularyCatalog Issues list: https://opensource.unicc.org/un/unece/uncefact/spec-untp/-/issues
Action 3: BH to circulate a MS Word edited version of the Gitlab SVC page for review/comment
Technical discussion (ALL)
Group sees value in a set of detailed worked examples, to highlight possible edge cases.
Chat comments from RK:
What nesting types and degrees of nesting are allowed. Few cases that may be useful (perhaps not clear enough yet)
- Example 1 - can a criterion be nested to multiple scheme credentials - Company A needs to provide data under Sustainability Scheme AA, Scheme BB, Scheme CC, Scheme DD, all because each brand mandates a different sustainability schemes.. Each of these have the same criterion (ID=URI...)
- Example 2 - can a sub-criterion link to a criterion that links to multiple sustainability schemes ; and can a sub-criterion also a be a criterion in another scheme - Company A measures sub-criterion Water consumption which is a criterion for resource consumption, which is part of a circular economy sustainability scheme credential (for example WBCSD circular economy measurement scheme). Company A has the same data but as a criterion Water consumption under an ESG sustainability scheme Example 3 - can part of a Scheme conformity vocabulary be linked to another scheme - Scheme AA has Criteria 1 to 15, Scheme BB has criteria 7 to 15, Is there a 'smart way' to re-use these in the vocabularies.
Action 4: Ideas sought on how to convincingly demonstrate the power and/or limitations of the various combinations of DPP, DCC and SVC to address a realistic range of conformity examples (CAB & Scheme volunteers?)
Close -
2025-07-15 Meeting Summary
UNTP Conformity Group Meeting minutes
Meeting 15 July 2025 10am CEST
Attendance:
Roger Meikle Ulas Nalbantoglu Kylie Sheehan Alison Jose Roberto Perez-Franco Brett Hyland Zach Zeus Alex Lubbock David McNeil Andrew Wheeler Jeff Ruddle Kris Tucker Lalit Mehta Adrienna Zsakay Emiliano Sune Ann Dao Brad Moore Martin Michelot Phil Archer Neil Savery Gideon Richards Christof Ameye Jose Saiz de Oneñaca Anil Jauhri Rembrandt Koppelaar Alice Paisley-Carruthers Richard Kubwalo Michael Shea
Item Discussion
Welcome & Rules of participation (BH) Per slides.
Action 1: Participants encouraged to register as CEFACT experts. https://uncefact.unece.org/display/uncefactpublic/UNCEFACT+Expert+Registration
Participant intro (All) -
Existing UNTP Conformity Implementations (ZZ) For information
Terms of reference & Rec 49 (BH) Per slides
Github walk-through (ZZ)
Links:
- http://untp.unece.org/docs/specification/ConformityCredential
- http://untp.unece.org/docs/specification/ConformityVocabularyCatalog
- https://opensource.unicc.org/un/unece/uncefact/spec-untp/-/issues
Technical discussion (ALL)
Focus on Sustainability Vocabulary as the major new work item. Some lack of clarity identified as to the nature and granularity of information in attestations that will be required to “unambiguously reference conformity criteria (from standards or regulations) they are based on, requiring each criterion to have a globally unique identifier”.
Action 2: To translate this expectation into language actionable by CA professionals, initial scoping to be provided ahead of the August meeting by a volunteer group [Ulas, Gideon, Jeff, Brett]