Hael
Book a meeting
ISO 27001 · Selection

Recommendations for a Good ISO 27001 Compliance consultant

Hael · Published 7 August 2026 · Last reviewed 7 August 2026 · 7 min read
Key takeaways
  • Score candidates on seven things: scoping, risk method, written work, internal audit independence, certification body knowledge, honesty about timelines, and independence from commissions.
  • Control selection must follow from a real risk assessment. Where it does not, auditors notice.
  • Ask for a redacted Statement of Applicability. It shows whether they reason or tick.
  • A good consultant raises the internal audit independence problem before you do.
  • Insist the fee shows certification body costs as a separate line.

The seven marks

A good ISO 27001 compliance consultant does three things a weaker one does not. They scope from what your buyers actually ask about. They run a real risk assessment and let control selection follow from it. And they raise the internal audit independence problem before you have to.

Everything below tests for those during the selection conversation. Use it as a scorecard across two or three firms.

MarkWhat good looks likeHow to test it
ScopingStarts from your buyers, your regulator and your actual estateAsk how they would scope your ISMS, before fees
Risk methodA real assessment that drives control selectionAsk which controls they would expect to exclude for you, and why
Written workA Statement of Applicability that reasonsAsk for a redacted example
Internal audit independenceRaises it unprompted and proposes a genuine separationAsk who would audit the system they built
Certification body knowledgeKnows accreditation and availabilityAsk which bodies they would recommend and why
Honesty about timelinesDoes the arithmetic out loudGive a deliberately tight date
IndependenceNo commission from certification bodies or platform vendorsAsk directly, in writing

1. How they scope

Scope decides the audit fee, the workload, and whether the certificate answers your buyer's question. A good consultant asks who is requiring this, what their vendor process checks, which services and locations are involved, and where information actually lives.

A weak approach applies a standard scope. That produces either a certificate covering more than anyone asked about, at cost, or one so narrow that a buyer reads the scope statement and comes back with questions.

Ask a candidate to sketch your scope in the conversation. Two minutes of reasoning beats any credential.

2. How they run risk

This is the mark most often faked and the one auditors probe hardest.

The standard expects you to identify risks, assess them, treat them, and select controls that follow from that treatment. Many implementations reverse the order: pick the controls, then write a risk register that justifies them. It reads plausibly and falls apart when an auditor asks why a particular control was excluded.

Test it directly. Ask a candidate which of the 93 Annex A controls they would expect to exclude for an organisation like yours, and why. A good answer names two or three with specific reasoning about your circumstances. A weak answer says all 93 apply, which is almost never true and suggests no risk work at all.

3. What they write

Ask for a redacted Statement of Applicability.

It is the auditor's first reference and the spine of the ISMS. A good one records why each control applies or does not, in language specific to the organisation, and describes how the applicable ones are implemented rather than restating the control title.

4. How they handle internal audit independence

The fastest test in the conversation.

Clause 9.2 requires an internal audit before certification and annually after. Your certification body cannot do it. The objectivity and impartiality requirement means whoever built the ISMS should not audit it.

A good consultant raises this before you ask and proposes something concrete: a separate practitioner, a third party, or training someone independent inside your organisation. A weaker one offers to do it themselves without mentioning the issue.

Our approach is a separate practitioner where we built the system, described in ISO 27001 - Internal Audit Consultants.

5. Whether they know the certification market

Ask which certification bodies they would recommend, why, whether those bodies are accredited, and by whom.

Ask about availability too. Audit slots are booked ahead, and a body's earliest Stage 2 date affects your timeline more than any internal delay.

A consultant who treats all certification bodies as interchangeable, or who cannot speak to accreditation, has not been through this recently.

6. Whether they will tell you the date does not work

Give a candidate a deliberately tight target and see what happens.

The sequence is fixed: build the ISMS, operate it long enough to produce records, complete the internal audit, hold the management review, then Stage 1, then Stage 2, subject to the certification body's availability. Three months is the practical floor for an organisation with strong existing security practice; three to six is typical.

A good consultant does that arithmetic on the first call. The alternative is agreeing to a date and revisiting it in month four.

7. Independence

Ask whether the firm takes commission from any certification body, receives referral fees from platform vendors, or has a related entity performing certification. None is improper on its own. You should know before you choose. Our position is on the about page.

What a good proposal contains

Scope stated as organisational units, services and locations, with exclusions named. Deliverables listed individually: gap analysis, policy set, risk method, Statement of Applicability, control implementation, internal audit, certification support. Fees itemised per phase, with certification body costs on a separate line marked as separate. Dated milestones including the earliest defensible Stage 2. A responsibility table with one name per workstream. The named practitioner and committed hours. And whether support continues through surveillance.

Two proposals cannot be compared until both cover the same scope.

What to do next

Draft a provisional scope, give it to two or three firms, and compare their written answers against the seven marks rather than their fees.

Our free readiness diagnostic gives a first view, our readiness and gap assessment gives the full position for a fixed fee, and the ISO 27001 service page sets out how we work.

References

FAQ

What makes a good ISO 27001 consultant?

Scoping from your buyers, a real risk assessment driving control selection, a Statement of Applicability that reasons, honest handling of internal audit independence, current certification market knowledge, realistic timelines, and no commission arrangements.

What is the fastest way to test a consultant?

Ask which Annex A controls they would exclude for your organisation and why. A real answer names a few with specific reasoning.

What document should I ask to see?

A redacted Statement of Applicability they have written.

Should certification fees be in the proposal?

As a separate, clearly marked line. They are always paid to a different organisation.

How quickly can certification realistically happen?

Three months at the fastest with strong existing practice, three to six months typically, and certification body availability can extend it.

About Hael

Hael is an advisory firm specialising in AI governance and security compliance, built on fifteen years of regulatory practice. Every engagement has a named practitioner, a written scope, a responsibility table and a fixed fee, with certification body costs shown separately. We are not a certification body and we take no commission from certification bodies or platform vendors. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on FCA authorisation and compliance since 2013.

This guide is general information and is not professional advice on your particular circumstances.

Free check

See where you stand on ISO 27001, free.

Answer a short set of questions and see what ISO 27001 expects of your AI systems and where you stand today. No sign-up to see your result.

Applicability

Whether ISO 27001 applies to how you use AI, and to which systems.

What is expected

Risk classification, governance, documentation and human oversight.

Where you stand

A banded result, pointed at the gaps that matter most.

What you get

On screen in about five minutes, pre-scoped to ISO 27001.

Or speak to us about your deadline. Book a meeting.