Frequently Asked Questions About ISO standards and Consultancy
An introduction to our FAQ
We know how confusing ISO standards can be, and the world of Consultancy can sometimes feel like a ‘dark art’ (and more than a little bit dull and/or expensive!). We get it… so we created an FAQ that answers the most common questions we get asked about these topics.
But if you’ve still got questions then please contact us and we’ll do what we can to help you… Ok. Ready?
First question is…
What is an ISO standard?
An ISO standard is an internationally recognised set of guidelines, requirements, or best practices developed by the International Organization for Standardization (ISO).
Think of an ISO standard as a proven framework that helps organisations operate more consistently, efficiently, and effectively.
I like to think of them as a ‘recipe’… If you were to bake a cake, you’d want to follow a recipe so that the results were (largely) the same.
It’s the same with ISO standards. Without a recipe you just don’t know where to start, what the ingredients are or when it’s done!
ISO standards cover a wide range of topics, including:
- Information Security (ISO 27001)
- Artifical Intelligence (ISO 42001)
- Business Continuity (ISO 22301)
- Privacy Management (ISO 27701)
- Quality Management (ISO 9001)
- Environmental Management (ISO 14001)
(1 – 4 Are the one’s Consultants Like Us specialise in, but we can help with others too).
The purpose of an ISO standard is to provide organisations with a structured approach to managing specific areas of their business while reducing risks and improving performance.
For example, ISO 27001 helps organisations establish, implement, maintain, and continually improve an Information Security Management System (ISMS), helping protect sensitive information from loss, misuse, or unauthorised access.
Importantly, ISO standards are not just for large organisations. Businesses of all sizes can use them to improve processes, build customer trust, demonstrate good governance, and gain a competitive advantage.
In simple terms:
An ISO standard is a globally recognised blueprint for doing something well, consistently, and with confidence.
Do we need to use Consultants?
Many achieve ISO 27001 without using Consultants, so the short answer is no… you don’t need Consultants.
It really depends on the following;
- Your level of expertise
- Your budget
- Your timescales
If you’re already an expert in any of the ISO standards prevously mentioned, then you might be able to do this yourself – but if you’re busy with everything else, then perhaps you need a Consultant Like Us to help?
The analogy I always give is one of DIY (because I’m terrible at DIY!).
If I wanted some renervation work doing, my options are;
- Do it myself (and be a ‘have a go hero’!)
- Do it with someone (who can teach me)
- Bring in an expert.
It all depends on your level of confidence and how good or how fast you want it built.
It’s the same for an ISO management system.
Consultants Like Us can give you the tools and the training you need, or we can do it for you.
You might not want to use Consultants, but you might need to use Consultants Like Us.
What questions should I ask a Consultant?
Choosing an ISO consultant can have a significant impact on the success of your certification project. The right consultant should simplify the process, provide practical guidance, and help your organisation build a management system that works in the real world – not just for an audit.
Keep in mind that having a certificate on your wall doesn’t mean you’re secure, or you have a quality product.
When looking to engage with a Consultant, do your research. Below are some questions you can ask… but remember that you are going to trust them with the inner workings of your business, so one question you should ask yourself is…
“Can I see myself and my team working with this person?”
Here are some more important questions to ask the Consultant before appointing them:
- What experience do you have with organisations like ours?
- Which ISO standards do you specialise in?
- How many organisations have you helped achieve certification?
- Can you explain your implementation process?
- How much of the work will our team need to do?
- How long is the project likely to take?
- What support will you provide during certification audits?
- Do you provide templates, training, or ongoing support?
- How do you ensure the management system is practical and not just paperwork?
- What are the most common challenges organisations face during implementation?
- How do you help organisations maintain compliance after certification?
- What are your fees and what is included?
- Are there any additional costs we should be aware of?
- Can you provide client testimonials or references?
- What makes your approach different from other consultants?
The most important question, however, may be:
“Will this management system help us run the business better, or is it just designed to pass an audit?”
A good consultant helps you achieve certification.
Consultants Like Us help you improve the business at the same time.
