ISO Certification Body vs ISO Consultant: Who Does What?
Data checked:
TL;DR
An ISO certification body is an independent, accredited organisation that audits your management system and issues the ISO certificate. An ISO consultant is an adviser who helps you build and prepare that system but cannot certify it. Impartiality rules mean the same organisation cannot both design and certify the same management system.

Most organisations approaching ISO 9001, ISO 27001, ISO 14001 or ISO 45001 for the first time meet two very different kinds of provider in the same week, and the sales language often sounds identical. One of them helps you build a management system. The other decides, independently, whether that system meets the standard. Confusing the two is the single most common reason an ISO project stalls, costs more than expected, or produces a certificate that a customer later refuses to accept.
This guide sets out exactly who does what, why the separation exists, when you genuinely need each provider, and how to check that a certificate means what it claims to mean.
Who does what
Consultant
helps you prepare
Internal auditor
checks your system from inside the organisation
Certification body
independently audits and certifies
Accreditation body
evaluates the certification body
ISO
develops and publishes the standards
Your organisation
owns and operates the management system
The simplest distinction is that a consultant can advise, but the certification body must independently judge.
Who does what, and who can actually certify you
| Dimension | Certification body | ISO consultant |
|---|---|---|
| Core role | Independent audit and certification decision | Advice, preparation and implementation support |
| Can issue an ISO certificate | Yes | No |
| Independence requirement | Mandatory; governed by ISO/IEC 17021-1 | None; commercial relationship with you |
| Typical accreditation | Accredited by a national accreditation body | Not accredited; may hold personal qualifications |
| Engaged when | You are ready to be audited, and for each cycle thereafter | Before certification, or to fix capability gaps |
| Tells you how to fix a problem | No, states the requirement and the finding | Yes, that is the service |
| Relationship length | Multi-year certification cycle | Project-based, ideally time-limited |
| Who owns the outcome | Your organisation | Your organisation |
What an ISO certification body does
A certification body is an independent third party that audits your management system against a published standard and makes the certification decision.
In practice, a certification body will:
- agree the certification scope, the sites covered and the audit duration with you;
- carry out a Stage 1 audit, which typically reviews documented information, scope, context, internal audits and management review, and confirms readiness for the next stage;
- carry out a Stage 2 audit, which evaluates the implementation and effectiveness of the management system against the standard through sampling, interviews and evidence;
- raise findings, usually classified as nonconformities or opportunities for improvement, and evaluate your corrective actions;
- make an independent certification decision, taken by people who did not carry out the audit;
- issue a certificate with a defined scope and validity, then run surveillance audits during the cycle and a recertification audit at the end of it, commonly a three-year cycle.
What a certification body will not do is design your processes, write your procedures, run your internal audits or tell you exactly how to fix a nonconformity. It can explain what the requirement is; it cannot supply the solution and then judge it.
Certification bodies that operate under accreditation are themselves assessed against ISO/IEC 17021-1, the international requirements for bodies providing audit and certification of management systems, by a national accreditation body such as UKAS in the United Kingdom or ANAB in the United States.
What an ISO consultant does
A consultant is an adviser you hire. There is no accreditation of consultants in the way certification bodies are accredited, and no licence is required to describe yourself as one, which is precisely why due diligence matters.
A competent consultant typically:
- runs a gap analysis against the chosen standard and translates it into a realistic project plan;
- helps you define scope, context, interested parties and risks in a way that will survive an audit;
- drafts or restructures documented information so it reflects how the business actually works;
- coaches process owners, trains internal auditors and prepares people for audit interviews;
- helps you set up internal audit and management review so the system produces its own evidence;
- supports you through findings after Stage 1 or Stage 2, and helps design corrective actions.
The distinction that matters is ownership. A consultant can build the scaffolding, but your management team has to own the system, run it and be able to explain it without the consultant in the room. Auditors notice very quickly when a management system belongs to a departed contractor rather than to the business.
Where the internal auditor fits
There is a third role that is neither of the above and is frequently under-resourced: the internal auditor. Management system standards expect the organisation itself to audit its own system at planned intervals and to feed the results into management review. This is a first-party audit, and it belongs to you.
An internal auditor can be an employee, a contractor or a consultant, provided they do not audit their own work. In small organisations this usually means auditing across departments, the operations lead audits the quality processes, and vice versa, or bringing in an external internal auditor for objectivity. What you cannot do is skip the exercise and expect a Stage 2 audit to go well, because a missing or superficial internal audit programme is one of the most common findings raised at certification.
Why the same organisation usually cannot do both
Impartiality is not a matter of professional courtesy; it is written into the rules certification bodies are accredited against. ISO/IEC 17021-1 requires certification bodies to identify, analyse and manage threats to impartiality, including self-interest, self-review and familiarity threats. A body that designed your management system would be reviewing its own work when it audited it.
The most cited practical consequence is the separation period: a certification body shall not certify a management system on which it has provided management system consultancy, and the standard sets a minimum period of two years after the end of that consultancy before certification can proceed. Accreditation bodies such as UKAS publish their own impartiality policies on the same basis.
That does not mean a certification body may tell you nothing. Explaining the requirements of a standard, describing the audit process, answering questions about the meaning of a clause, and providing generic training that is publicly available are normally acceptable. Specifying, developing or implementing your management system is not.
It also does not mean you must choose one provider or the other. Many organisations engage a consultant for preparation and, separately, an accredited certification body for the audit. The arrangement is entirely legitimate provided the two are genuinely independent of one another.
How to work with a consultant without becoming dependent
The failure mode is not a bad consultant; it is a good one whose departure takes the management system with them. Three habits prevent it.
First, insist that documented information is written in your own systems and in your own language, not delivered as a branded template pack that nobody internally recognises. Second, make process owners, not the consultant, present their own processes during internal audits and, later, to the certification body's auditor. Third, agree a defined handover at the outset, including who runs the internal audit programme and the management review after the project closes. A consultant who welcomes that conversation is usually the right one.
Do you actually need a consultant?
A consultant is optional. Certification is not gated on having used one, and some organisations certify successfully with no external help at all. The honest test is capability and time, not company size.
You probably do not need one when:
- someone internally has taken a management system through certification before;
- your processes are already documented and genuinely followed;
- the standard is a familiar one for your sector and the scope is a single site;
- you have the internal audit capability the standard expects.
External support usually pays for itself when:
- nobody internally has worked with the standard end to end;
- the scope is multi-site, multi-standard or heavily regulated;
- a tender or customer deadline makes lost months expensive;
- a previous audit produced major nonconformities you have not been able to close.
Who should you contact next?
The tool below is a starting point rather than a recommendation of any named provider. It runs entirely in your browser.
Who should you contact next?
Answer four questions to see which type of provider usually fits your situation.
Suggested next contacts
Accreditation directory or certificate-verification service
Check the certificate against the certification body's own verification service and, where relevant, the accreditation body's directory of accredited bodies.
See how certification is structuredConsultant and certification body, with the roles kept separate
You can prepare with an adviser and collect certification quotations in parallel, provided the body that audits you did not design or implement your management system.
Compare independent providersPlan the full cost of the cycle
Certification is not a one-off fee: budget for Stage 1, Stage 2, surveillance audits and recertification alongside any implementation support.
Read the ISO cost breakdownYour answers stay in this browser tab. Nothing is collected, transmitted or stored. This tool provides general guidance, not legal, regulatory or certification advice.
What to ask each provider before signing
Ask a certification body: which accreditation body accredits you for this standard; how many audit days are you proposing and on what basis; what is the total cost across the full cycle, including surveillance and recertification; who makes the certification decision; and what happens if we do not close a major nonconformity in time.
Ask a consultant: who will actually do the work and what is their experience of this standard; what is out of scope; what will be handed over and in what format; how will our own people be trained to run the system; and what commercial relationship, if any, do you have with certification bodies. That last question is fair, and the answer should be a straightforward one.
What each one costs, and what drives the price
Prices vary widely by country, standard, scope and risk, so treat the pattern rather than any single figure as the useful part. Our separate analysis of ISO certification costs for small businesses breaks the numbers down in detail.
| Cost element | Charged by | What drives it |
|---|---|---|
| Stage 1 and Stage 2 audit | Certification body | Audit days, headcount, number of sites, standard, risk category |
| Surveillance audits | Certification body | Usually annual, at a fraction of the initial audit duration |
| Recertification | Certification body | End of each cycle, commonly every three years |
| Travel and expenses | Certification body | Site locations and whether remote auditing is permitted |
| Gap analysis | Consultant | Scope, number of processes, existing documentation |
| Implementation support | Consultant | Day rate or fixed project fee; length of the project |
| Internal audit and training | Consultant or internal | Number of auditors and processes to cover |
| Software and tooling | Third-party vendors | Optional; helpful for evidence collection at scale |
Two budgeting mistakes recur. The first is treating certification as a one-off fee rather than a multi-year cycle. The second is comparing a consultant's fixed project price with a certification body's initial audit price as if they were alternatives, they are different purchases.
Red flags when choosing either provider
Red flags
- “Guaranteed ISO certification”
- A certificate offered without a meaningful audit
- A consultant claiming to issue an accredited ISO certificate
- A provider implying that ISO itself approved or certified the company
- Use of the ISO logo to imply certification
- No identifiable certification body or accreditation body
- An accreditation claim that cannot be verified
- A vague certificate scope
- No Stage 1 or Stage 2 process where these are applicable
- The same individual designing the system and independently auditing it for certification
- A very low initial price that omits surveillance or recertification costs
- The consultant retaining control of essential processes after the project ends
None of these on its own proves bad faith, but each is worth a direct question before you sign anything.
How to verify a certification body and a certificate
Verification is quick, and it is the step most often skipped.
- Ask which accreditation body the certification body holds accreditation from, and for which standards and scopes. Accreditation is granted scheme by scheme, not as a general status.
- Check the accreditation body's own directory. ANAB, for example, publishes a searchable directory of accredited certification bodies, and other accreditation bodies maintain equivalents.
- Confirm the accreditation body is internationally recognised through the IAF Multilateral Recognition Arrangement, which is what makes a certificate meaningful across borders.
- Verify the certificate itself. Many certificates can be checked through IAF CertSearch or the issuing body's own verification service. Read the scope statement and the validity dates, not just the standard number.
- Read the scope carefully. A certificate covering one site or one product line does not cover the whole organisation, and a mismatch between the scope and what a supplier claims is a legitimate reason to query it.
- Confirm who audited and who decided. Under ISO/IEC 17021-1 the certification decision is taken independently of the audit team.
If a supplier cannot answer the first question, everything after it is guesswork.
Frequently asked questions
Can a consultant issue an ISO certificate?
No. Only a certification body can issue an ISO management system certificate. A consultant may issue a training certificate or a completion letter, but that is not certification against the standard and should not be presented as such.
Does ISO certify companies directly?
No. ISO develops and publishes the standards; it does not perform certification. Certification is carried out by independent certification bodies, which are separate organisations from ISO.
Can the same firm consult and then certify us?
Not for accredited certification. ISO/IEC 17021-1 prohibits a certification body from certifying a management system on which it provided management system consultancy, subject to a minimum two-year separation after the consultancy ends. Some groups offer both services through separate legal entities, so ask specifically which entity will audit you.
Is accredited certification always required?
No. Certification itself is voluntary, and you can conform to a standard without being certified. Accredited certification becomes effectively mandatory when a customer, tender or regulator asks for it, which, for ISO 27001 and ISO 9001 in particular, is increasingly common.
How long does certification usually take?
For a small organisation starting from a reasonable base, three to nine months from decision to Stage 2 is a common range. Starting from scratch, with new processes to embed and evidence to accumulate, twelve months is more realistic. The constraint is rarely the audit; it is having enough operating history to audit.
Can a certification body recommend a consultant?
Accredited bodies are generally careful here, because directing work to a specific adviser creates the appearance of a financial interest in a client they will later audit. Many will point you to a directory or decline to recommend anyone. Treat a strong push towards one named consultant as a question worth asking about.
What happens if we fail the Stage 2 audit?
A failed Stage 2 is usually a set of major nonconformities rather than a refusal. You are given a defined period to implement corrective actions, and the certification body verifies them, sometimes remotely, sometimes through a short follow-up visit, before the certification decision is made.
“ISO does not perform certification.”
Compare independent ISO certification and preparation providers
ContinueSources and methodology
This article is based on the published requirements for certification bodies in ISO/IEC 17021-1, ISO's own published guidance on certification and conformity assessment, and the public policies and directories of national accreditation bodies (UKAS and ANAB) and the International Accreditation Forum. Cost and duration statements describe commonly observed patterns rather than quoted prices, because both vary by country, standard, scope and risk category. No provider paid for inclusion, and no provider is named in any negative example. All sources were checked on 14 August 2026.
- ISO. Certification - checked 14 August 2026
- ISO. Conformity assessment - checked 14 August 2026
- ISO. ISO/IEC 17021-1:2015 — Requirements for bodies providing audit and certification of management systems - checked 14 August 2026
- ISO. Management system standards - checked 14 August 2026
- UKAS. Impartiality - checked 14 August 2026
- ANAB. Management systems accreditation - checked 14 August 2026
- ANAB. Directory of accredited certification bodies - checked 14 August 2026
- International Accreditation Forum. IAF CertSearch — global database of accredited certifications - checked 14 August 2026
- International Accreditation Forum. IAF Multilateral Recognition Arrangement (MLA) - checked 14 August 2026
- International Accreditation Forum. About IAF - checked 14 August 2026
About the author
General information articles from the StandardsDesk editorial team.
Editorial note: StandardsDesk is an independent educational and referral service. It is not an LEI issuing organisation, a Local Operating Unit, a GLEIF Registration Agent, a certification body, or a legal, tax or investment adviser. Services are delivered by independent third-party providers, which may pay StandardsDesk a referral fee. Read the affiliate disclosure.


