You do realise, “validating” a certificate for authcl.com only proves that it was issued to authcl.com?
If that happens to be a phishing site, “you are liable for damages” is a bit of a stretch. You could get an EV certificate for a malware site with any supplier anywhere if you used a legitimate business name to do so.