Chapter 11: Compliance Declaration and Certification
ICO Std 2002:2026 — Chapter 11
This chapter specifies the mechanisms for declaring compliance with ICO Std 2002, defines three compliance levels, establishes the processes for self-assessment and third-party certification, and addresses the relationship between ICO Std 2002 and ICO Std 2001 (Digital Product Passport — Credibility & Quality, DPP-CQ). It provides a structured framework through which ranking entities can demonstrate their adherence to the methodological, transparency, and audit requirements of this standard.
11.1 Compliance Declaration
A ranking entity that applies the provisions of ICO Std 2002 may issue a compliance declaration indicating the extent to which its ranking system conforms to this standard. The compliance declaration shall be prepared in accordance with the requirements specified in 11.1.1 through 11.1.4.
11.1.1 Self-Declaration Template
A self-declaration of compliance shall be prepared using the standard template specified below. The template shall be completed in full and made publicly accessible.
a) Header information:
1) The declaration title: “Compliance Declaration — ICO Std 2002:2026”;
2) The name and identifier of the ranking entity;
3) The name and version of the ranking system;
4) The date of the declaration;
5) the compliance level being declared (see 11.1.4).
b) Conformance statement: A statement of the form:
“[Name of ranking entity] declares that the ranking system [name and version] conforms to ICO Std 2002:2026 at compliance level [Level], as demonstrated by the conformance checklist attached hereto.”
c) Scope of declaration: A specification of the scope of the declaration, including:
1) the chapters and provisions of ICO Std 2002 to which the declaration applies;
2) any provisions that are excluded from the declaration, with justification;
3) the ranking cycle(s) covered by the declaration.
d) Evidence reference: References to the evidence supporting the compliance declaration, which may include:
1) the methodology documentation (see 9.1.2);
2) the internal audit report(s) (see 10.1.1);
3) the external audit report(s), if any (see 10.1.2);
4) the certification certificate, if any (see 11.2).
e) Attestation: The name, title, and signature of the authorised representative of the ranking entity making the declaration.
11.1.2 Conformance Checklist
The compliance declaration shall be accompanied by a conformance checklist that maps each provision of ICO Std 2002 to the ranking entity’s compliance status. The conformance checklist shall:
a) list each chapter and sub-clause of ICO Std 2002;
b) for each provision, indicate one of the following compliance statuses:
1) Conformant: The ranking system fully complies with the provision.
2) Partially conformant: The ranking system complies with some but not all aspects of the provision, with the areas of non-conformance documented.
3) Not conformant: The ranking system does not comply with the provision, with the reason for non-conformance documented.
4) Not applicable: The provision does not apply to the ranking system, with the justification for inapplicability documented.
c) include, for each provision marked as “Partially conformant” or “Not conformant,” a description of:
1) the specific aspect of non-conformance;
2) the reason for the non-conformance;
3) any planned corrective actions and timelines.
11.1.3 Partial Conformance Declaration
A ranking entity may issue a partial conformance declaration where it does not fully comply with all provisions of this standard. A partial conformance declaration shall:
a) clearly identify the provisions with which the ranking entity does not conform;
b) for each non-conforming provision, document:
1) the nature and extent of the non-conformance;
2) the reason for the non-conformance, including whether it is due to:
i) technical limitations that prevent compliance;
ii) resource constraints;
iii) deliberate methodological choices that diverge from the standard.
3) any mitigating measures implemented to address the impact of the non-conformance.
c) not claim a compliance level higher than that justified by the conformance checklist (see 11.1.4).
11.1.4 Compliance Levels
Compliance with ICO Std 2002 is classified into three levels. The compliance level is determined by the extent of conformance with the provisions of this standard, as assessed through the conformance checklist (see 11.1.2).
a) Level 1 — Foundational Compliance:
A ranking system achieves Level 1 compliance when it conforms to all of the following provisions:
1) Chapter 4 (Principles): all provisions;
2) Chapter 5 (Indicator System Design): 5.1, 5.2, 5.3;
3) Chapter 7 (Data Collection): 7.1, 7.2, 7.3;
4) Chapter 8 (Scoring and Ranking): 8.1, 8.2, 8.3;
5) Chapter 9 (Publication and Transparency): 9.1.1, 9.1.2, 9.3.1;
6) no more than 3 provisions marked as “Partially conformant” across all chapters;
7) no provisions marked as “Not conformant” in the mandatory provisions listed above.
b) Level 2 — Advanced Compliance:
A ranking system achieves Level 2 compliance when it meets all Level 1 requirements and additionally conforms to:
1) Chapter 5 (Indicator System Design): 5.4, 5.5;
2) Chapter 6 (Weighting Rules): all provisions;
3) Chapter 7 (Data Collection): 7.4;
4) Chapter 8 (Scoring and Ranking): 8.4, 8.5;
5) Chapter 9 (Publication and Transparency): 9.1.3, 9.1.4, 9.2.2, 9.3.2, 9.4;
6) Chapter 10 (Audit and Traceability): 10.1.1, 10.2;
7) no more than 3 provisions marked as “Partially conformant” across all chapters;
8) at least one internal audit completed (see 10.1.1).
c) Level 3 — Full Compliance:
A ranking system achieves Level 3 compliance when it meets all Level 2 requirements and additionally conforms to:
1) Chapter 9 (Publication and Transparency): 9.2.3 or 9.2.4, 9.5;
2) Chapter 10 (Audit and Traceability): 10.1.2, 10.3;
3) all provisions marked as “Conformant” or “Not applicable” with no “Partially conformant” or “Not conformant” provisions;
4) at least one external audit completed with an unqualified opinion (see 10.1.2).
Note: The compliance levels are cumulative: each higher level requires full compliance with the requirements of all lower levels. The provisions required at each level are based on a risk-based approach, where Level 1 covers the minimum requirements for a defensible ranking, Level 2 adds the methodological rigour and quality assurance requirements, and Level 3 adds the transparency, audit, and accountability requirements for rankings that are used in high-stakes contexts.
11.2 Certification Process
A ranking entity may seek third-party certification of its compliance with ICO Std 2002. The certification process shall be conducted in accordance with the requirements specified in 11.2.1 through 11.2.4.
11.2.1 Application Requirements
A ranking entity applying for certification shall:
a) submit a formal application to a conformity assessment body (CAB) that meets the requirements specified in 10.3.1;
b) provide the self-declaration of compliance (see 11.1.1) and the conformance checklist (see 11.1.2);
c) provide access to all methodology documentation, data, computation logs, and audit records necessary for the certification assessment;
d) declare the compliance level for which certification is sought;
e) agree to the terms of the certification agreement, including the scope, timeline, and cost of the assessment.
11.2.2 Assessment Procedure
The certification assessment shall be conducted in accordance with the following procedure:
a) Document review: The CAB shall review the methodology documentation, conformance checklist, and supporting evidence submitted by the ranking entity. The document review shall verify:
1) the completeness and accuracy of the conformance checklist;
2) the consistency between the self-declaration and the supporting evidence;
3) the adequacy of the methodology documentation relative to the requirements of this standard.
b) On-site or remote assessment: The CAB shall conduct an assessment of the ranking entity’s processes, which may include:
1) interviews with ranking entity personnel;
2) inspection of computational systems and data repositories;
3) observation of data collection and processing procedures;
4) verification of computation logs and traceability records.
c) Re-computation test: The CAB shall independently re-compute the ranking for a sample of entities and verify the results against the published ranking. The sample shall be selected in accordance with 10.3.3.
d) Findings and recommendation: The CAB shall document all findings from the assessment and prepare a recommendation regarding the certification decision. The recommendation shall include:
1) the assessed compliance level;
2) any nonconformities identified;
3) any observations or opportunities for improvement.
11.2.3 Certification Decision
The certification decision shall be based on the assessment findings and shall result in one of the following outcomes:
a) Certification granted: The ranking system is certified as conforming to ICO Std 2002 at the declared compliance level. A certificate shall be issued that includes:
1) the name and identifier of the ranking entity;
2) the name and version of the ranking system;
3) the certified compliance level;
4) the scope of certification;
5) the date of issue and the date of expiry;
6) the name and accreditation identifier of the CAB.
b) Certification granted with conditions: The ranking system is certified subject to the resolution of identified minor nonconformities within a specified timeframe. The certificate shall not be issued until all conditions are met.
c) Certification denied: The ranking system does not meet the requirements for the declared compliance level. The CAB shall provide a detailed explanation of the reasons for denial.
The certificate validity period shall not exceed three years from the date of issue.
11.2.4 Certificate Maintenance
To maintain a valid certificate, the ranking entity shall:
a) notify the CAB of any significant changes to the ranking methodology, data sources, or processes that could affect compliance within 30 calendar days of the change;
b) undergo surveillance assessments at intervals determined by the CAB, which shall be at least annual;
c) address any nonconformities identified during surveillance assessments within the timeframe specified by the CAB;
d) apply for recertification before the certificate expiry date.
Failure to meet any of the above requirements may result in suspension or withdrawal of the certificate, as specified in 11.5.3.
11.3 Compliance Mark
A ranking entity that has been certified as conforming to ICO Std 2002 may use the compliance mark in accordance with the rules specified in 11.3.1 through 11.3.3.
11.3.1 Mark Usage Rules
a) The compliance mark may only be used by ranking entities that hold a valid certificate issued in accordance with 11.2.
b) The compliance mark shall clearly indicate the certified compliance level (Level 1, Level 2, or Level 3).
c) The compliance mark shall be displayed:
1) the ranking publication (see 9.1);
2) the methodology documentation;
3) the ranking entity’s official website and promotional materials, where the ranking system is referenced.
d) The compliance mark shall not be used:
1) in a manner that implies endorsement by ICO or the CAB beyond the scope of the certification;
2) in connection with ranking systems that are not covered by the certificate;
3) after the certificate has expired, been suspended, or been withdrawn.
11.3.2 Mark Design Specification
The compliance mark shall consist of:
a) the ICO logo or identifier;
b) the text “ICO Std 2002” and the compliance level designation;
c) the certificate number;
d) the year of certification.
The visual design of the compliance mark shall ensure legibility at common display sizes and shall not be altered from the standard design without written permission from ICO.
11.3.3 Misuse Prevention
a) The CAB shall monitor the use of compliance marks by certified entities and shall take appropriate action where misuse is identified.
b) Where a ranking entity uses the compliance mark in a manner that violates 11.3.1, the CAB shall:
1) issue a written warning specifying the nature of the misuse;
2) require corrective action within 30 calendar days;
3) suspend the certificate if the misuse is not corrected within the specified timeframe.
c) Any person or organisation may report suspected misuse of the compliance mark to ICO or the CAB. ICO or the CAB shall investigate all credible reports and take appropriate action.
11.4 Dispute Resolution
This section specifies the mechanisms for resolving disputes arising from compliance declarations, certification decisions, and the use of compliance marks.
11.4.1 Formal Objection Process
Any stakeholder may file a formal objection regarding:
a) a compliance declaration that the objector believes to be inaccurate or misleading;
b) a certification decision that the objector believes to be unjustified;
c) the use of a compliance mark that the objector believes to be in violation of 11.3.1.
The formal objection shall:
1) be submitted in writing to ICO or the CAB, as appropriate;
2) identify the specific provision(s) of this standard that are alleged to be violated;
3) provide evidence or reasoning supporting the objection;
4) be submitted within 90 calendar days of the publication or decision giving rise to the objection.
11.4.2 Mediation
Where a formal objection is filed, ICO shall attempt to resolve the dispute through mediation before proceeding to arbitration. The mediation process shall:
a) appoint a mediator who is independent of all parties to the dispute;
b) provide all parties with the opportunity to present their positions;
c) aim to reach a mutually acceptable resolution within 60 calendar days of the appointment of the mediator;
d) produce a written mediation agreement if the dispute is resolved, which shall be binding on all parties.
11.4.3 Arbitration (Final Resort)
Where mediation fails to resolve the dispute, either party may request arbitration. Arbitration shall be conducted in accordance with the following rules:
a) The arbitration panel shall consist of three members: one selected by each party and one selected by the two appointed arbitrators or, failing agreement, by ICO.
b) The arbitration proceedings shall be conducted in accordance with the rules of an internationally recognised arbitration institution (e.g., ICC International Court of Arbitration).
c) The arbitration decision shall be final and binding on all parties.
d) The costs of arbitration shall be borne by the parties as determined by the arbitration panel.
11.5 Continuous Compliance Monitoring
A ranking entity that has issued a compliance declaration or obtained certification shall maintain ongoing compliance with the provisions of ICO Std 2002 throughout the validity period of the declaration or certificate.
11.5.1 Monitoring Mechanisms
The ranking entity shall implement the following monitoring mechanisms to ensure continued compliance:
a) Periodic self-assessment: The ranking entity shall conduct a self-assessment against the conformance checklist (see 11.1.2) at least once per ranking cycle and whenever a significant change is made to the ranking system.
b) Change impact assessment: Before implementing any change to the ranking methodology, data sources, or processes, the ranking entity shall assess the impact of the change on compliance and update the conformance checklist accordingly.
c) Incident monitoring: The ranking entity shall monitor for incidents that could affect compliance, including:
1) data quality incidents (see 7.3);
2) correction or retraction events (see 9.3);
3) stakeholder appeals or objections (see 9.4.3 and 11.4);
4) changes in applicable regulatory requirements.
d) Compliance reporting: The ranking entity shall produce an annual compliance report that summarises:
1) the current compliance level and any changes from the previous report;
2) any nonconformities identified and the corrective actions taken;
3) any changes to the ranking system and their impact on compliance;
4) the status of any ongoing audits, appeals, or disputes.
11.5.2 Compliance Drift
Where a ranking entity’s compliance with this standard deteriorates over time (compliance drift), the entity shall:
a) identify the cause of the compliance drift;
b) assess the impact of the drift on the ranking results and stakeholders;
c) develop and implement a remediation plan with defined timelines;
d) update the compliance declaration and conformance checklist to reflect the current compliance status.
If the compliance drift results in a downgrade of the compliance level, the ranking entity shall:
1) publicly disclose the downgrade and the reasons for it within 30 calendar days;
2) update the compliance mark usage to reflect the new compliance level (see 11.3.1);
3) notify the CAB, if certified, within 14 calendar days.
11.5.3 Non-Compliance Handling
Where a ranking entity is found to be non-compliant with the provisions of this standard, the following procedures shall apply:
a) Self-identified non-compliance: Where the ranking entity identifies its own non-compliance through self-assessment or monitoring, it shall:
1) document the non-compliance and its impact;
2) develop a corrective action plan with defined timelines;
3) implement the corrective action within the agreed timeframe;
4) update the compliance declaration and conformance checklist;
5) notify the CAB, if certified.
b) Externally identified non-compliance: Where non-compliance is identified through external audit, stakeholder objection, or other external means, the ranking entity shall:
1) acknowledge the non-compliance within 14 calendar days of notification;
2) investigate the non-compliance and document its root cause and impact;
3) develop and implement a corrective action plan;
4) report the corrective action and its effectiveness to the identifying party and the CAB, if certified.
c) Certificate suspension: The CAB may suspend a certificate when:
1) a major nonconformity is identified and the ranking entity fails to implement corrective action within the specified timeframe;
2) the ranking entity fails to cooperate with a surveillance assessment;
3) the ranking entity provides false or misleading information in connection with the certification.
A suspended certificate shall be reinstated only when the CAB verifies that all nonconformities have been effectively corrected.
d) Certificate withdrawal: The CAB shall withdraw a certificate when:
1) a suspended certificate is not reinstated within 6 months of suspension;
2) the ranking entity ceases to operate the ranking system;
3) the ranking entity engages in fraud or intentional misrepresentation in connection with the certification.
Upon withdrawal, the ranking entity shall immediately cease using the compliance mark and shall publicly disclose the withdrawal.
11.6 Relationship with ICO Std 2001 (DPP-CQ)
This section specifies the relationship between ICO Std 2002 (Tianji Ranking Methodology Standard) and ICO Std 2001 (Digital Product Passport — Credibility & Quality, DPP-CQ). The two standards are complementary and are designed to be used together to provide a comprehensive framework for the quality, transparency, and verifiability of ranking systems.
11.6.1 Complementary Scope
a) ICO Std 2002 specifies the methodological requirements for designing, implementing, and publishing ranking systems, including indicator design, weighting, data collection, scoring, publication, and audit.
b) ICO Std 2001 (DPP-CQ) specifies the requirements for creating and managing digital product passports that document the computational quality and provenance of data-driven products, including ranking results.
c) Together, the two standards provide:
1) ICO Std 2002 defines what a ranking system shall do to be methodologically sound and transparent;
2) ICO Std 2001 defines how the computational quality and provenance of the ranking results shall be documented and verified in a machine-readable, cryptographically secure format.
11.6.2 Cross-Reference Requirements
a) A ranking entity that claims compliance with both ICO Std 2002 and ICO Std 2001 shall:
1) issue a combined compliance declaration that references both standards;
2) ensure that the DPP created in accordance with ICO Std 2001 accurately reflects the methodological provisions applied in accordance with ICO Std 2002;
3) ensure that the traceability records maintained in accordance with 10.2 are consistent with the provenance records required by ICO Std 2001.
b) The compliance level under ICO Std 2002 (see 11.1.4) and the DPP-CQ compliance level under ICO Std 2001 shall be assessed independently, although evidence from one assessment may inform the other.
11.6.3 Integrated Compliance Pathway
For ranking entities seeking integrated compliance with both standards, the following pathway is recommended:
a) Phase 1 — ICO Std 2002 Compliance: Achieve Level 1 compliance with ICO Std 2002, establishing the methodological foundation.
b) Phase 2 — ICO Std 2002 Level 2 + DPP-CQ Basic: Advance to Level 2 compliance with ICO Std 2002 and implement basic DPP-CQ capabilities, including data provenance documentation and hash verification.
c) Phase 3 — ICO Std 2002 Level 3 + DPP-CQ Full: Achieve Level 3 compliance with ICO Std 2002 and implement full DPP-CQ capabilities, including cryptographic verification and, optionally, blockchain anchoring (see 10.4.3).
Note: The integrated compliance pathway is recommended but not mandatory. A ranking entity may comply with ICO Std 2002 independently of ICO Std 2001. However, as the ecosystem of data-driven decision-making evolves, the ability to provide machine-readable, cryptographically verified evidence of computational quality is expected to become increasingly important. Ranking entities that implement DPP-CQ in conjunction with ICO Std 2002 will be better positioned to demonstrate the trustworthiness of their results in automated and cross-jurisdictional contexts.
Note: The compliance and certification framework specified in this chapter provides a structured mechanism for ranking entities to demonstrate and maintain their adherence to this standard. The three-level compliance model (11.1.4) enables a progressive approach to compliance, allowing ranking entities to start with foundational requirements and advance to full compliance as their systems mature. The relationship with ICO Std 2001 (11.6) ensures that this standard is positioned within a broader ecosystem of computational quality assurance, supporting the long-term credibility and interoperability of ranking systems.