When to Use an ISO Consultant and What Good Support Looks Like

ISO Consultants in Brief

  • Whether you need one depends on the internal time available, not on the standard
  • Good support documents how the business runs, not the clause structure of the standard
  • Help can be bought as defined pieces of work rather than an open-ended engagement

Using an ISO Consultant

Not every organisation needs an ISO consultant. Whether one earns their fee depends far less on which standard is being pursued and much more on who is available internally to lead the work, and how much of that person's time is genuinely free rather than nominally allocated.

An organisation with a capable lead who can give the project steady attention can usually reach certification using a document toolkit and occasional support. An organisation without that person tends to spend more in stalled progress and internal time than a consultant would have cost in the first place.

The choice is not all or nothing. Support can be bought for the whole journey from first review to certificate, or just for the pieces that are hardest to do from a standing start.

Do You Need an ISO Consultant?

A handful of questions usually settle it. Is there a named person who will own the project, rather than a committee who will discuss it? How many hours a week can they actually give it? Is there a customer deadline or tender date driving the timetable? How many standards are in scope, and does any documented system already exist?

Where there is a willing owner, a realistic deadline and one standard in scope, a toolkit and a little guidance normally does the job. Where the deadline is tight, several standards are in play, or the person nominated to lead has a full-time job already, external help stops being a luxury.

The failure mode nobody plans for is the slow one. A project that drifts across eighteen months quietly consumes far more management time than a short piece of paid support, and the business often has little to show for it beyond a folder of half-finished documents.

What a Good ISO Consultant Does Differently

The clearest marker of quality is what the finished management system is built around. A good ISO consultant documents how the organisation actually runs and then demonstrates that this meets the standard. A poor one documents the standard and asks the organisation to fit around it.

ISO 9001 does not require documentation to follow the clause structure of the standard, and Annex A of the standard says so directly. Any consultant producing a manual with a section per clause has made a choice, not met a requirement, and it is a choice that produces systems people avoid using.

The second marker is what happens after they leave. Support that produces certification but leaves nobody in the business able to run an internal audit, complete a management review or respond to a finding has only deferred the problem to the first surveillance visit.

Management System Problems an ISO Consultant Should Prevent

These are the recurring faults in systems that arrive from outside, and in systems built internally without help. They are worth knowing before commissioning either.

  • Jargon over substance - the system is written in the language of the standard rather than the language of the business, and reads as though it were meant for an auditor rather than a colleague.
  • A template with a name on the front - the documents are generic, describe processes the organisation does not operate, and have never been reconciled against what actually happens.
  • Procedures that create work - new forms and approval steps are introduced that serve the paperwork rather than the operation, and quietly compete with the business objectives they were supposed to support.
  • Time that outruns the fee - months of internal effort go into building something a consultant would have set up in a matter of days, and the saving turns out to be imaginary.
  • Attention drawn off the business - the certification project becomes the priority and ordinary operational discipline slips while everyone is busy writing procedures.

A system suffering from the first three of these can be rescued. Converting a clause-based structure into something organised around the business is routine work and is usually quicker than starting again.

Those are the failure modes of doing it alone. Buying help introduces a different set, and which ones apply depends on what is being bought.

What Goes Wrong With Fixed Fee ISO Consultant Packages

Fixed fee packages promise certification for a stated price on a stated timescale, sometimes a very short one. The price can look reasonable until you work out how much consultant time it actually buys. Where that time amounts to a few hours of producing documentation from a generic template, the organisation is paying for a certificate rather than a management system.

  • A template with your name on it - a couple of hours is enough to change a cover page and little else, so the documentation describes a generic organisation rather than yours.
  • A separate manual for every standard - the template approach usually means one document set per standard. An organisation covering three ends up with three overlapping manuals and the duplication that an integrated system exists to avoid.
  • Documentation that does not achieve compliance - the deeper problem. Supplying documents is not the same as implementing a system, and a few hours of input rarely closes the gap between the two.

Documentation produced this way tends not to survive contact with an assessor who asks how the organisation actually works rather than what the manual says. The questions are answered by whoever is in the room, and if nobody recognises the system, that shows.

What Goes Wrong With an Independent ISO Consultant

There are very good independent consultants and there are poor ones, and two types are recognisable early. The jargon merchant makes implementation more complicated than it needs to be and uses the standard to justify activity that serves nobody. The accreditation purist insists on UKAS accredited certification in every case, including for organisations whose customers have never asked for it, which adds cost without adding value.

  • A system only they understand - documentation complex enough that maintaining it needs their input, so the engagement never really ends and the retainer becomes permanent.
  • Locked or licensed files - third party software carrying ongoing licence costs, or documents supplied in a format the organisation cannot edit. Either way the organisation does not control its own management system.
  • Attendance at every audit - a consultant who advises they should be present for all audits adds a cost to every year of the certification cycle.
  • A favoured certification body - a consultant with a comfortable relationship with one certifier may recommend them rather than comparing what is available.

The common thread is dependency. An arrangement that leaves the organisation unable to run, explain or change its own system without picking up the phone has not finished the job, whatever the documentation looks like.

Buying ISO Consultant Support in Defined Pieces

Open-ended consultancy is not the only option, and for an organisation doing most of the work itself it is rarely the best value. Buying a defined piece of work with a stated output makes the cost predictable and keeps the system in the hands of the people who will have to live with it.

The pieces most worth paying for are the ones where inexperience costs the most time: an initial review against the standard, converting an unusable existing system, the first internal audit, and a readiness check before the certification audit. Internal auditor training pays for itself quickly, because it removes the need to buy the audit in every year.

The pieces least worth paying for are the ones templates already solve. Forms, policies and registers can be adapted in-house in far less time than it takes to brief someone else on them.

When I audit a management system I have no interest in who wrote it, and it makes no difference to the outcome whether a consultant was involved. What I do notice is whether the people in front of me recognise their own system. If I ask about a procedure and the response is that the consultant set that up, the system is not being used and that will show up in the findings regardless of how well the document is written.

We brought someone in for two days when we added ISO 14001 to what we already had for quality.

The useful part was not the documents. It was having someone walk the site with me and tell me which of our existing controls already counted as evidence, because we had assumed we were starting from nothing and we were not. Half the aspects register wrote itself once we knew what we were looking at.

The rest we did ourselves over the following six weeks. If I had handed the whole thing over I would not know the system half as well as I do, and I am the one sat in the audit answering for it. Two days was about right. Ten would have meant somebody else building our system for us.

Practical Compliance Guidance

Section 1 of the IMS1 manual covers the management system itself, setting out its scope, what is included within it and how the documented information is managed and controlled. It is the section that shows an assessor how the system is put together, and the one that most clearly reveals whether a system was built around the business or around the standard.

An alphaZ toolkit works either way round. Used on its own it gives an organisation doing the work itself a far more advanced starting point than a blank page, with the structure, policies, procedures and registers already in place and needing tailoring rather than writing. Handed to a consultant it does exactly the same for them, so the time being paid for goes on fitting the system to the business instead of rebuilding documentation that already exists, which cuts the number of days needed and the cost with it. The library also includes defined blocks of remote support for the parts most often bought on their own, covering review, conversion, audit and training work.

alphaZ document How to use it
ISO 9001 / 14001 / 45001 IMS Toolkit The full integrated document set for quality, environmental and health and safety management. The starting point for an organisation building its own system.
I-C IMS Gap Analysis Checklists Work through these to establish where the organisation already meets the standard before deciding what help is actually needed.
Remote Support - Project A defined day of remote consultancy time that can be booked in one go or used by the hour, for setup, review or training.
Remote Support - Full Clause Conversion Service For organisations saddled with a clause-based system, this converts existing documentation into a structure organised around the business.
Document Preparation Supply of the document set with company name and logo applied, for organisations wanting the templates ready to use without full consultancy.
Internal Audit Training Course Toolkit Training material and certification for bringing internal auditing in-house rather than buying the audit in each year.
Remote Support - Ongoing A fixed monthly allocation of support time for organisations that want help available after certification without a long contract.

Note - all the above files can be downloaded with an alphaZ subscription.

Frequently Asked Questions

No. A certification body assesses the management system against the standard and has no interest in who prepared it. Plenty of organisations certify using a document toolkit and their own people. The practical question is whether the internal time is available, not whether external help is permitted.
It depends on headcount, number of sites, how many standards are in scope and how much documented process already exists. A single site organisation of under fifty people pursuing one standard, with support in place, is commonly looking at a couple of months to being audit ready. Multiple standards, several sites or a system built from nothing will take longer.
A management system the organisation recognises and can operate without them, together with completed internal audit and management review records and someone in the business trained to repeat both. Documentation alone is not a finished handover.

Further Resources

payment logos