
September 2, 2026

In March 2026, a detailed investigation into Delve - a Y Combinator-backed compliance startup that had raised $32 million at a $300 million valuation - alleged that the company had generated auditor conclusions across 494 SOC 2 reports before clients had submitted any evidence. According to the investigation, 493 of those 494 reports were nearly identical, boilerplate language and all. The "US-based" auditors named in those reports traced to shell entities and certification mills with no meaningful independent presence.
Delve has disputed the allegations. But the damage to confidence in compliance documentation has already spread well beyond one company. If a well-funded, high-profile startup could allegedly produce hundreds of certifications with rubber-stamp auditors and pre-written conclusions, the question every procurement team and CIO should now be asking is simple: how do I know a certification means what it claims to mean?
The answer lies in understanding the difference between a certification that reflects genuine embedded practice and one that exists purely to satisfy a checkbox.
ISO 9001 and ISO 27001 are standards maintained by the International Organisation for Standardisation. They are not self-attested. They cannot be purchased, automated, or generated by a platform. Achieving certification under either standard requires a formal audit conducted by an accredited certification body - one that is independently accredited by a national accreditation authority and subject to ongoing surveillance.
ISO 9001 sets requirements for quality management systems. It demands that an organisation define its processes, measure performance against objectives, act on nonconformities, and demonstrate continual improvement. The auditor is not looking for a completed checklist - they are examining whether the processes are real, whether the evidence of operation is genuine, and whether the organisation's leadership is accountable for outcomes.
ISO 27001 sets requirements for information security management systems. It requires organisations to identify and treat information security risks systematically, implement controls proportionate to those risks, and demonstrate that those controls are operating effectively over time. A SOC 2 report describes what controls exist. An ISO 27001 certification attests that a management system governs those controls - and that an independent auditor has tested whether it actually works.
One of the overlooked details in the Delve investigation was the finding that several of the ISO 27001 certificates issued lacked accreditation from government-recognised bodies. This is not a technicality. Accreditation is the mechanism that gives a certification its meaning.
An accredited certification body has been assessed by a national accreditation authority - in Australia, this is the Joint Accreditation System of Australia and New Zealand (JAS-ANZ) - against criteria that cover technical competence, independence, and impartiality. A certificate from an accredited body can be verified. It sits within a chain of accountability that runs from the organisation being certified, through the certification body, to the national accreditation authority.
A certificate from an unaccredited body sits within no such chain. There is no one to hold accountable if the audit was inadequate. There is no public register to verify the certificate against. There is, in effect, no certification - only a document.
The Glue Group holds both ISO 9001 and ISO 27001 certification, audited by BSI Group - one of the world's most recognised accredited certification bodies, operating in over 190 countries and accredited by UKAS in the United Kingdom. Our certifications are not managed by an automation platform, generated from templates, or issued by entities without a verifiable independent presence.
ISO 9001 — Quality Management
Covers our quality management systems across the group. Demonstrates that our processes for delivering products and services are defined, measured, and subject to continual improvement. Audited annually by BSI.
ISO 27001 — Information Security
Covers our information security management system across the group. Demonstrates that information security risks are identified, treated, and governed by a management system that is independently verified. Audited annually by BSI.
Beyond the certifications themselves, the value to our clients and partners is what they reflect: that the processes governing how we work, how we protect information, and how we respond when things go wrong are embedded in our operations - not assembled for audit day and set aside afterwards. BSI auditors do not accept evidence that was created for the audit. They examine whether management systems are genuinely operational.
The Delve situation has made due diligence on compliance documentation more important, not less. When evaluating any technology vendor's certification claims, procurement teams and CIOs should ask:
Who is the certification body, and are they accredited?
Ask for the certificate and look up the certification body on the relevant national accreditation authority register. In Australia, JAS-ANZ publishes a public register of accredited certification bodies. If the body is not on it, the certificate warrants scrutiny.
When was the last surveillance audit, and what did it cover?
ISO certifications require ongoing surveillance audits, not just initial certification. A vendor who cannot provide a recent audit date or scope summary should be asked to explain why.
Can you verify the certificate directly with the certification body?
BSI and other reputable certification bodies maintain public registers of valid certificates. If a certificate cannot be verified through an independent public source, treat it with caution.
Is the certification scope relevant to what you are buying?
Certifications are issued against a defined scope. A certificate that covers administrative operations but excludes product development or customer data handling may not be the assurance you think it is.
The Delve situation is a useful reminder that compliance documentation is only as valuable as the process that produced it. A genuine ISO certification from an accredited body is a meaningful signal - it means an independent expert has tested whether the management system is real and operating effectively. But even a genuine certification is a point-in-time assessment. The quality of the partner you are working with is ultimately demonstrated by how they operate day to day, not just how their documents read.
At The Glue Group, we hold our certifications as a foundation for how we work - not as marketing collateral. If you are in a procurement process involving one of our businesses and want to discuss our certification scope, audit history, or security posture in more detail, we are happy to engage directly.