Analyte tiering
Eight priority metals, tested as ten analytes because arsenic and mercury are speciated and chromium is speciated on trigger. Each metal is assigned to a tier by its toxicological profile, and the tier determines whether any exceedance can ever be tolerated.
Carcinogenic with no established safe threshold, neurotoxic with no established safe threshold, or bioaccumulative with long biological half-lives in children. Any confirmed result above 100% of the limit escalates immediately.
Established tolerable daily intakes, shorter biological half-lives, or primarily acute rather than chronic toxicity. Controllable through sourcing and process.
Speciation upgrades chromium to Tier 1 treatment when a credible hexavalent pathway exists. Cr(III) is an essential nutrient and is assumed in food; Cr(VI) is an IARC Group 1 carcinogen by ingestion.
How a limit is set
The default limit for any analyte is the strictest maximum level set by a credible government regulator — the EU, Codex, the FDA, WHO/JECFA, FSANZ, or Health Canada — converted to the row’s native basis. It is a lookup, not a computation: it carries the Tier 2 metals directly, and where the law splits a limit by formulation the standard adopts the law’s own split and cites it. The percentile machinery below runs only where the program sets a number itself — the four Tier 1 toxics, floored against the government maximum so the published value is the stricter of the two, and the cells no government regulates.
For those occurrence-set cells, subcategories are paired. Within a pair, one form carries a structurally higher contamination burden than the other — rice cereal against non-rice, soy formula against cow-milk, root vegetables against above-ground. Pooling the pair would raise the clean limit and flatter the dirty one in the same move, so they are separated.
The lower-burden form within a pair — non-rice cereal, cow-milk formula, above-ground vegetables. Where the program sets this cell from occurrence rather than a government limit, the limit sits at the 97th percentile of the pooled distribution.
The structurally higher-burden form — rice cereal, soy formula, root vegetables, fish-containing. A far tighter percentile, because the point is to separate the better operators within a hard category rather than bless the category.
A subcategory with no within-pair partner defaults to P97.
The percentile is a calibration choice, disclosed as one. A brand certifies a row of ten analytes at once, so per-analyte limits set at a raw P90 would produce a joint pass rate near 35%. For the occurrence-set cells only — the Tier-1 toxics floored against the government maximum, and the cells no government regulates — P97 and P45 are the values that deliver the program’s stated row-level outcomes: roughly 90% of clean-subcategory brands and 40% of dirty-subcategory brands pass, confirmed at 94% and 42% against FDA per-sample lot data. A subcategory whose every published limit binds on a government maximum has no percentile-set cell, and this calibration does not touch it — infant formula powder is one, with all eight of its published values set by government lookup.
We are not aware of another certifier that publishes this number, and disclosing it invites an obvious reading: that the threshold was set to a commercial outcome rather than a health one. The reading is worth answering directly, because the alternative — not saying it — does not make the calibration disappear. It only makes it undiscoverable.
Every percentile-based standard in food safety embeds a pass rate. Codex maximum levels, EU regulation 2023/915 and FDA action levels are all set against achievability, using occurrence data and explicit statements about what industry can meet. The choice is never whether a pass rate exists; it is whether the body setting the limit tells you what it is.
The health-based floor is separate and binds first: no published value ever exceeds the lowest applicable regulatory ceiling in that basis. The calibration operates only in the space beneath that ceiling, where the literature alone does not determine a single number. Where the ceiling binds, the rationale tag reads regulatory-alignment and where an occurrence pool exists beneath a binding ceiling the pooled value is shown so the gap is visible. On infant formula powder no cell is occurrence-set: every published value binds directly on a government maximum — lead on the EU’s 20 ppb.
Native basis
Every standard is published in the form the product is actually sold in: powder as placed on market, ready-to-feed as consumed, dry cereal as sold, purée as consumed. A brand ships and tests in one form, and the mark matches that form.
Sources reporting in another basis are converted inward during pooling, using documented factors — never the reverse. Where a cross-basis equivalent is shown next to a published value it is a reading convenience for audiences working in other units, not a second standard a brand may choose between.
Publication gates
A per-analyte value publishes only when it clears every gate below. A cell that fails any one of them stays unpublished rather than shipping with a caveat.
For a cell the program sets from occurrence — the Tier 1 toxics and the analytes no government regulates — enough contributing sources for the pooled distribution to mean something, with no single survey exceeding 50% relative share.
Every contributing source converted into the row’s native basis using a documented factor, with the conversion recorded.
The strictest applicable government maximum identified and expressed in the row’s basis. For most analytes it is the standard; for a Tier 1 toxic it is the floor the occurrence value is capped against.
The value must be measurable. Where the limit of quantitation binds above the pooled value, the limit is feasibility-driven and says so.
Exactly one of literature-baseline, regulatory-alignment, feasibility-driven or precautionary. An untagged value does not publish.
These are the program’s stated publication conditions, drawn from the manual’s methodology sections. The manual refers to “publication gates” without a single numbered list, so the names here are descriptive rather than quoted. Confirm against the Governance Policy before this ships.
The five statuses
Defined in Program Manual Part 2.3. A status attaches to a product, not to a brand, and it is visible on the certificate.
| Status | Meaning | Mark usable | Condition |
|---|---|---|---|
| A | Certified (Full Compliance) | yes | At or below every value in the Master Limit Table, all ten analytes, native basis. |
| B | Certified (Transitional) | yes, disclosed | A Tier 2 metal up to 150% of limit, under Part 2.3 conditions, with a defined end date and corrective action. |
| C | Probation | suspended | Confirmed Tier 1 exceedance, or transitional conditions unmet. Elevated surveillance applies. |
| D | Suspension | no | Mark usage withdrawn pending remediation. Reinstatement requires a fresh baseline. |
| E | Revocation | no | Certification terminated. Concealment of a known exceedance is grounds. |
Transitional certification is available on Tier 2 metals only, up to 150% of the applicable limit, under the conditions in Part 2.3. No transitional exceedance exists for a Tier 1 metal at any margin.
Lot surveillance
Certification is continuous. Every SKU entering the program is tested across a minimum of three production lots to establish a baseline before any status is assigned at all — a single passing lot certifies nothing.
Surveillance intensity follows status: routine for A, elevated for B, probation protocol for C. Reflex testing triggers add speciation when a result or a formulation change indicates a credible pathway, and sampling follows a documented chain of custody so a result can survive challenge years later.
The Confidential Remediation Track exists so a brand that finds a problem is better off reporting it than concealing it. An item opened and kept on schedule is not published, not disclosed to retailers, and not reflected in the public register. A brand that conceals loses its certificate.
Two remediation pathways
When a lot falls short, a brand chooses how the correction is handled. Both routes require the same corrective action and the same re-testing; what differs is who sees it, and what the brand gets in return for that visibility.
The finding, the affected lots and the corrective action stay between the brand and the program while the item is open and on schedule. Nothing appears in the public register, nothing is disclosed to retailers, and the certificate is unaffected.
The brand elects to publish the finding and its remediation on its own brand page. The record shows what was found, what was done and when it closed — a documented history of catching and fixing a problem rather than an unexplained gap.
Neither route is a way out of the corrective action. The choice is about disclosure, and it exists because a program that punished self-reporting would simply stop being told anything — which would make the mark worth less, not more.
Governance
The program is operated by the Institute of Contaminant Standards (ICS) and governed under the Institute of Contaminant Standards, which sets how limits are established without testing products or selling marks itself.
Governs how limits are set. It does not test products, sell marks, or publish threshold values or brand-level data itself — that separation is what lets it arbitrate.
Toxicology, food-safety and analytical-chemistry experts with documented independence from licensees. Reviews methodology and recommends metal reclassification between tiers. It reports recommendations; it does not render binding decisions.
Holds binding review authority on contested certification decisions. The Program Operator retains final authority on classification and methodology, subject to that review.
Substantive changes to a published limit run through the Standards Ratchet Mechanism, which requires a stated trigger and caps how far a limit may move in a single step. Limits tighten as evidence and analytical feasibility improve.