The Trustworthy Accountability Group is a non-profit certification body for the digital advertising supply chain. It writes voluntary compliance standards, verifies that companies meet them, awards seals to those that pass, and assigns each registered company a persistent identifier that travels through programmatic bid requests. It exists because digital advertising has no licensing regime. Anyone can register a domain, list inventory and collect money from an exchange, and buyers long had no dependable way to establish who sat on the other side of a transaction. TAG, as it is universally known, was built to supply that missing vetting layer.

Membership is commercial rather than regulatory. No law obliges a company to hold a seal, and nothing stops an uncertified firm from trading. The seals work as a purchasing signal, useful only to the extent that buyers ask.

How certification works

Everything begins with TAG Registration. A company submits to a background check, historically powered by Dun and Bradstreet, and on approval is listed in the TAG Registry and issued a sixteen-digit TAG-ID. Certification then applies at the entity level, not the product level: all material ad monetisation operations within a given market must comply, and any display of a seal must state which markets it covers.

The guidelines split the supply chain into four covered party categories: Direct Buyers, meaning advertisers and their agencies; Direct Sellers, meaning publishers, their sales agents and podcast creators; Intermediaries, covering any technology layer connecting the two; and Anti-Fraud and Measurement Services, which do not transact inventory but detect or filter invalid traffic. A company operating in several must satisfy all of them.

Two routes exist. Self-attestation rests on binding declarations from a compliance officer and a business executive; independent validation adds an outside auditor. The choice is not always free, since certification covering global operations, any European country, the United Kingdom or China requires independent validation. In the 2026 cycle, 74% of seals were independently audited. Certified companies must also appoint a compliance officer whose reporting lines sit outside the operations being tested, run quarterly internal reviews, and reapply by January 31 each year.

What the requirements actually specify

The Certified Against Fraud guidelines read as a checklist of supply chain plumbing. Every participant must filter 100% of monetisable transactions for both general and sophisticated invalid traffic, compliant with one of two recognised standards: the Media Rating Council's Invalid Traffic Detection and Filtration Guidelines Addendum, or China's T/CAAD 002-2020. Domain, app and data centre IP threat filtering apply to all parties, pre-bid or post-bid. TAG distributes its own Data Center IP List, though the guidelines state plainly that using it alone does not satisfy the requirement.

Role-specific rules follow. Intermediaries must implement the TAG Payment ID System across all OpenRTB transactions. Direct Sellers must publish ads.txt on every monetised domain and app-ads.txt for every monetised app, populating the Certification Authority field with the TAG ID of each intermediary holding a DIRECT or RESELLER relationship; buyers and intermediaries must honour those files. Server-side ad insertion vendors must pass X-Forwarded-For or X-Device-IP and X-Device-User-Agent headers with tracking requests, per the IAB Tech Lab VAST spec.

Version 11.0, released in July 2026, added three requirements showing where the fraud problem has moved. Direct Sellers monetising owned apps in Apple's App Store or Amazon's Fire TV App Store must support device attestation through the Privacy Pass protocol and Open Measurement SDK 1.6 or higher. Intermediaries running search, artificial intelligence or large language model services must disclose crawler user agent metadata, distinguish indexing from query response and model training, and honour robots.txt. They must also publish a sellers.json or buyers.json file carrying "TAG-ID" as an identifier name.

Origin and evolution

The 4A's, the ANA and the IAB announced the organisation jointly at the IAB MIXX Conference on September 30, 2014, building on the earlier IAB Trustworthy Digital Supply Chain Initiative. Linda Woolley became its first chief executive that November. Mike Zaneis succeeded her in 2015 and remains in post as of September 2026.

The first programme was anti-piracy, launched in February 2015 as the Brand Integrity Program Against Piracy. Certified Against Fraud followed in 2016, with more than thirty companies signing up before any seal existed, and Certified Against Malware launched on November 15, 2016 alongside a Malware Threat Sharing Hub. The original four programmes were fraud, piracy, malware and Inventory Quality Guidelines; Brand Safety Certified replaced part of that lineup in September 2020 and Certified for Transparency followed in November 2022.

Requirements tightened alongside the wider standards effort. In January 2018, TAG made ads.txt adoption mandatory for publishers seeking the fraud seal, giving the IAB Tech Lab specification its first hard enforcement mechanism. Version 4.0, in January 2019, made independent validation compulsory for European and global certification, and version 9.0, in July 2023, required TAG-ID in sellers.json and ads.txt files. Since 2017 the organisation has also held a US Department of Homeland Security designation as the Information Sharing and Analysis Organization for digital advertising, the basis of its AdSec Threat Exchange.

Why it matters for the marketing community

The commercial case rests on studies the organisation commissions. Research with the 4A's, ANA and IAB, released on October 9, 2024, estimated that industry anti-fraud efforts saved US advertisers $10.8 billion in 2023, a 92% reduction against the roughly $11.78 billion that would have been lost at an unfiltered invalid traffic rate of 9.96%. A European study published on June 17, 2025 found that anti-fraud programmes prevented €3.45 billion in losses across a €48.3 billion display and video market, with a further €1.075 billion recoverable by extending the standards to the 24% of channels lacking them.

Those figures rest on a unit of analysis that matters more than the seals themselves. A TAG Certified Channel is a transaction in which three or more entities hold the fraud seal; one certified party does not qualify a path. TAG's February 2025 impact report recorded invalid traffic below 1% in certified channels for four consecutive years in the United States and six in Europe.

Adoption peaked in 2025. TAG awarded 321 seals in 2024, a record 326 in 2025 across 207 companies, then 307 seals to 196 companies in 2026, with 32 reaching Platinum status by holding three or more.

Criticisms and the 2026 rupture

The structural objections are long-standing. Certification covers a legal entity rather than a product, so a seal says little about any individual integration. Self-attestation remains available outside the mandatory-audit markets. And participation is paid, with fees folded into membership dues that are not published.

They became a rupture in June 2026. An Adweek investigation by Kendra Barnett, published on June 11, found that Google and The Trade Desk had both let their certifications lapse without intending to renew. Google had held three of the four seals, The Trade Desk all four; both remain members. Zaneis confirmed their reasoning, that Media Rating Council accreditations backed by EY audits now cover much of the same ground, and said Google's assessment was correct. Procter and Gamble, whose 2017 mandate under chief brand officer Marc Pritchard had driven adoption across the ecosystem, confirmed it now encourages certification rather than requiring it. Dailymotion's certifications disappeared from the registry while its website continued to display TAG seals. PPC Land's coverage recorded the first net decline in certifications and participating companies since 2018 and quoted anonymous executives calling the seals performative. Zaneis put the departures at ordinary attrition of 5% to 10%.

A sharper argument came from the buy side: that the registry's original value, a verified directory of counterparties, was largely made redundant once the IAB Tech Lab shipped sellers.json, ads.txt and the SupplyChain object as free alternatives. Membership figures are themselves inconsistent: TAG boilerplate cited more than 600 companies in 2020, reporting in late 2024 put the figure above 700, and Zaneis gave 500 in 2026.

A separate challenge concerns what certification can detect at all. On July 28, 2026, TAG published an analysis with the ANA and the technology firm Fiducia finding that AI slop inventory graded as premium more than 70% of the time, taking between 1.3% and 2.4% of open web programmatic spend while recording an invalid traffic rate of 0.05% against 0.32% for clean supply. Machine-generated inventory passes the quality checks the apparatus is built around.

Distinguishing TAG from adjacent bodies

The Media Rating Council accredits measurement methodology and audits specific vendor products; TAG certifies whole companies against process standards. The overlap is now the crux of the departures.

The IAB Tech Lab authors the technical specifications, including ads.txt, sellers.json and the SupplyChain object. TAG mandates their adoption but does not write them; the two are frequently conflated because TAG's requirements are expressed in Tech Lab terms.

Regional schemes cover comparable ground under separate governance. Japan's JICDAQ, which certified Magnite in July 2026, audits through the Japan Audit Bureau of Circulations rather than by internal review, while the IAB UK Gold Standard ties its brand safety pillar to TAG seals.

A TAG-ID is also not a seller ID, which identifies a selling entity within one exchange's inventory and can be blocked individually, as in DV360's seller ID blocklist. Neither should be confused with an ad tag, the snippet of markup that calls a creative into a page.

Recent developments

Enforcement work has continued independently of the certification troubles. TAG launched its Pirate Domain Exclusion List in 2024, and on June 30, 2026 it demonetised 1,376 domains streaming stolen World Cup content, identifying a further 176 already listed. That ran alongside the US Department of Justice's Operation Offsides, which seized roughly 400 domains outright four days earlier, though TAG did not disclose what revenue the excluded domains had collected.

The July 2026 guidelines revision points the programme at connected television fraud and at AI systems monetising scraped content. Whether that repositioning arrests the decline in participation is the open question going into the 2027 recertification cycle.

Timeline

  • September 30, 2014: 4A's, ANA and IAB announce the organisation at the IAB MIXX Conference
  • November 3, 2014: Linda Woolley named first president and chief executive
  • February 2015: Brand Integrity Program Against Piracy launched
  • 2015: Mike Zaneis becomes chief executive
  • May 2016: Certified Against Fraud programme launched with more than thirty participants
  • November 15, 2016: Certified Against Malware programme and Malware Threat Sharing Hub launched
  • April 11, 2017: More than 200 companies from over twenty countries registered
  • July 31, 2017: First nine Certified Against Malware seals awarded
  • 2017: US Department of Homeland Security ISAO designation granted
  • January 18, 2018: ads.txt adoption made mandatory for the fraud seal
  • January 2019: Version 4.0 requires independent validation for European and global certification
  • September 2020: Brand Safety Certified programme launched
  • February 2021: TAG TrustNet formally launched with technology partner Fiducia
  • November 2022: Certified for Transparency programme announced
  • July 2023: Version 9.0 requires TAG-ID in sellers.json and ads.txt files
  • 2024: Pirate Domain Exclusion List launched
  • October 9, 2024: US Ad Fraud Savings Report estimates $10.8 billion saved in 2023
  • June 17, 2025: European Ad Fraud Savings Report estimates €3.45 billion saved in 2023
  • March 6, 2025: Record 326 seals awarded to 207 companies
  • March 5, 2026: 307 seals awarded to 196 companies, the first net decline since 2018
  • June 11, 2026: Adweek reports Google and The Trade Desk certifications lapsed
  • June 30, 2026: 1,376 pirate domains demonetised over World Cup streaming
  • July 2026: Version 11.0 adds device attestation, crawler transparency and demand and supply transparency requirements
  • July 28, 2026: Analysis with ANA and Fiducia finds AI slop grading premium more than 70% of the time

Summary

Who: A non-profit created by the American Association of Advertising Agencies, the Association of National Advertisers and the Interactive Advertising Bureau, led by chief executive Mike Zaneis since 2015. Its certified companies span advertisers, agencies, publishers, demand-side and sell-side platforms and verification vendors.

What: A voluntary certification and threat intelligence body operating four seals - Certified Against Fraud, Certified Against Malvertising, Brand Safety Certified and Certified for Transparency - plus a company registry issuing sixteen-digit TAG-IDs, the Data Center IP List, the Pirate Domain Exclusion List and the AdSec Threat Exchange.

When: Announced September 30, 2014 and operating since 2015. The fraud seal launched in 2016 and reached its widest adoption in 2025, before recording its first net decline in 2026.

Where: Headquartered in Washington, DC, with seals scoped by country, region or globally. Certification covering Europe, the United Kingdom, China and global operations requires independent audit rather than self-attestation.

Why: Programmatic advertising created a market in which buyers routinely transact with counterparties they cannot identify. TAG supplies vetting, a persistent identifier and process standards that fill the gap left by the absence of any licensing requirement for participating in the supply chain.