Recommendations for a Good ISO 27001 Compliance consultant
- Score candidates on seven things: scoping, risk method, written work, internal audit independence, certification body knowledge, honesty about timelines, and independence from commissions.
- Control selection must follow from a real risk assessment. Where it does not, auditors notice.
- Ask for a redacted Statement of Applicability. It shows whether they reason or tick.
- A good consultant raises the internal audit independence problem before you do.
- Insist the fee shows certification body costs as a separate line.
The seven marks
A good ISO 27001 compliance consultant does three things a weaker one does not. They scope from what your buyers actually ask about. They run a real risk assessment and let control selection follow from it. And they raise the internal audit independence problem before you have to.
Everything below tests for those during the selection conversation. Use it as a scorecard across two or three firms.
| Mark | What good looks like | How to test it |
|---|---|---|
| Scoping | Starts from your buyers, your regulator and your actual estate | Ask how they would scope your ISMS, before fees |
| Risk method | A real assessment that drives control selection | Ask which controls they would expect to exclude for you, and why |
| Written work | A Statement of Applicability that reasons | Ask for a redacted example |
| Internal audit independence | Raises it unprompted and proposes a genuine separation | Ask who would audit the system they built |
| Certification body knowledge | Knows accreditation and availability | Ask which bodies they would recommend and why |
| Honesty about timelines | Does the arithmetic out loud | Give a deliberately tight date |
| Independence | No commission from certification bodies or platform vendors | Ask directly, in writing |
1. How they scope
Scope decides the audit fee, the workload, and whether the certificate answers your buyer's question. A good consultant asks who is requiring this, what their vendor process checks, which services and locations are involved, and where information actually lives.
A weak approach applies a standard scope. That produces either a certificate covering more than anyone asked about, at cost, or one so narrow that a buyer reads the scope statement and comes back with questions.
Ask a candidate to sketch your scope in the conversation. Two minutes of reasoning beats any credential.
2. How they run risk
This is the mark most often faked and the one auditors probe hardest.
The standard expects you to identify risks, assess them, treat them, and select controls that follow from that treatment. Many implementations reverse the order: pick the controls, then write a risk register that justifies them. It reads plausibly and falls apart when an auditor asks why a particular control was excluded.
Test it directly. Ask a candidate which of the 93 Annex A controls they would expect to exclude for an organisation like yours, and why. A good answer names two or three with specific reasoning about your circumstances. A weak answer says all 93 apply, which is almost never true and suggests no risk work at all.
3. What they write
Ask for a redacted Statement of Applicability.
It is the auditor's first reference and the spine of the ISMS. A good one records why each control applies or does not, in language specific to the organisation, and describes how the applicable ones are implemented rather than restating the control title.
4. How they handle internal audit independence
The fastest test in the conversation.
Clause 9.2 requires an internal audit before certification and annually after. Your certification body cannot do it. The objectivity and impartiality requirement means whoever built the ISMS should not audit it.
A good consultant raises this before you ask and proposes something concrete: a separate practitioner, a third party, or training someone independent inside your organisation. A weaker one offers to do it themselves without mentioning the issue.
Our approach is a separate practitioner where we built the system, described in ISO 27001 - Internal Audit Consultants.
5. Whether they know the certification market
Ask which certification bodies they would recommend, why, whether those bodies are accredited, and by whom.
Ask about availability too. Audit slots are booked ahead, and a body's earliest Stage 2 date affects your timeline more than any internal delay.
A consultant who treats all certification bodies as interchangeable, or who cannot speak to accreditation, has not been through this recently.
6. Whether they will tell you the date does not work
Give a candidate a deliberately tight target and see what happens.
The sequence is fixed: build the ISMS, operate it long enough to produce records, complete the internal audit, hold the management review, then Stage 1, then Stage 2, subject to the certification body's availability. Three months is the practical floor for an organisation with strong existing security practice; three to six is typical.
A good consultant does that arithmetic on the first call. The alternative is agreeing to a date and revisiting it in month four.
7. Independence
Ask whether the firm takes commission from any certification body, receives referral fees from platform vendors, or has a related entity performing certification. None is improper on its own. You should know before you choose. Our position is on the about page.
What a good proposal contains
Scope stated as organisational units, services and locations, with exclusions named. Deliverables listed individually: gap analysis, policy set, risk method, Statement of Applicability, control implementation, internal audit, certification support. Fees itemised per phase, with certification body costs on a separate line marked as separate. Dated milestones including the earliest defensible Stage 2. A responsibility table with one name per workstream. The named practitioner and committed hours. And whether support continues through surveillance.
Two proposals cannot be compared until both cover the same scope.
What to do next
Draft a provisional scope, give it to two or three firms, and compare their written answers against the seven marks rather than their fees.
Our free readiness diagnostic gives a first view, our readiness and gap assessment gives the full position for a fixed fee, and the ISO 27001 service page sets out how we work.
References
FAQ
What makes a good ISO 27001 consultant?
Scoping from your buyers, a real risk assessment driving control selection, a Statement of Applicability that reasons, honest handling of internal audit independence, current certification market knowledge, realistic timelines, and no commission arrangements.
What is the fastest way to test a consultant?
Ask which Annex A controls they would exclude for your organisation and why. A real answer names a few with specific reasoning.
What document should I ask to see?
A redacted Statement of Applicability they have written.
Should certification fees be in the proposal?
As a separate, clearly marked line. They are always paid to a different organisation.
How quickly can certification realistically happen?
Three months at the fastest with strong existing practice, three to six months typically, and certification body availability can extend it.
About Hael
Hael is an advisory firm specialising in AI governance and security compliance, built on fifteen years of regulatory practice. Every engagement has a named practitioner, a written scope, a responsibility table and a fixed fee, with certification body costs shown separately. We are not a certification body and we take no commission from certification bodies or platform vendors. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on FCA authorisation and compliance since 2013.
This guide is general information and is not professional advice on your particular circumstances.