Troy, Michigan — serving the US / (248) 890-9283
Wilkshire Consulting logo WILKSHIREMANAGEMENT SYSTEMS

ISO certification consulting

Which ISO standard do you actually need?

Four standards, and most organizations only need one or two. This page helps you work out which, then shows you what certification actually takes.

  • 3–6Months to certify
  • 100+ISO certifications
  • 8Common finding areas
  • 2015Doing this since

Start here

Pick the standard that matches your problem

Each of these solves something different. Read the "choose this if" lines rather than the titles. Most people arrive knowing their problem but not which standard addresses it.

Both standards were revised in 2026

ISO 14001:2026 published on 15 April 2026 and the transition clock is running. ISO 9001:2026 is targeted for September 2026 and cannot be certified to yet. ISO 14001:2026 transition →   ISO 9001:2026 transition →

  • ISO 9001

    Quality management

    The most widely held management system standard, and usually the first one an organization certifies.

    Choose this if

    • A customer or tender asked for it
    • Defects, rework or inconsistency are costing you
    • Processes live in people's heads rather than on paper
    • You need a QMS underneath R2v3 Appendix C or F
    ISO 9001 in detail →
  • ISO 14001

    Environmental management

    Controls environmental impact and demonstrates regulatory compliance.

    Choose this if

    • Customers are asking about sustainability credentials
    • You hold environmental permits or handle regulated waste
    • You want to reduce waste and disposal costs systematically
    • Supply-chain questionnaires keep raising it
    ISO 14001 in detail →
  • ISO 45001

    Occupational health & safety

    Manages workplace risk and demonstrates a systematic approach to safety.

    Choose this if

    • Incident rates or insurance premiums are a problem
    • You're being prequalified as a contractor
    • Safety is managed reactively rather than by system
    • You need to show due diligence after an incident
    ISO 45001 in detail →
  • ISO 27001

    Information security

    Protects information you hold, and increasingly demanded in procurement.

    Choose this if

    • A customer or tender is asking for it
    • You hold data that isn't yours to lose
    • You're an ITAD and customers ask beyond device sanitization
    • Your certificate still says 2013 — that deadline has passed
    ISO 27001 in detail →
  • Integrated

    QEHS — all three together

    ISO 9001, 14001 and 45001 run as one system rather than three.

    Choose this if

    • You need more than one and want a single set of documents
    • You'd rather have one internal audit programme than three
    • A customer or tender asks for quality, environmental and safety together
    • You already hold one and are adding others
    What integration saves you →
  • ISO 50001

    Energy management

    Improves energy performance and supports energy reporting obligations.

    Choose this if

    • Energy is a material line on your P&L
    • You have energy reporting or reduction commitments
    • You want measurable efficiency gains, not one-off projects
    • Incentive programs in your state require it
    ISO 50001 in detail →

Still not sure? Ten minutes on the phone usually settles it.

Reference

What the clauses actually require

ISO 9001, 14001 and 45001 share the same ten-clause structure. Clauses 1 to 3 — scope, normative references and terms — contain no auditable requirements, so an audit starts at clause 4. Everything below is where findings come from.

R2v3 is organised differently, around ten Core Requirements rather than clauses. If that's your standard, the R2 requirements table is the equivalent.

Clauses 4 to 10 — ISO 9001, 14001 and 45001
ClauseWhat it requires
4 — Context Determine what affects your organization internally and externally, identify interested parties and their requirements, define the scope of the system, and establish the processes that make it up. Climate change has been a mandatory consideration here since February 2024.
5 — Leadership Top management must demonstrate commitment, not delegate it. A policy, assigned roles and authorities, and evidence that leadership is actually engaged. ISO 45001 adds worker consultation and participation, which is where most 45001 audits come unstuck.
6 — Planning Address risks and opportunities, set measurable objectives with plans to achieve them, and plan changes rather than absorbing them. ISO 14001:2026 adds a dedicated change management clause at 6.3.
7 — Support Resources, competence, awareness, communication and documented information. This is the clause that catches the most organizations, because competence and awareness are tested by interviewing your staff rather than by reading your records.
8 — Operation Operational planning and control, requirements for products and services, design and development, control of external providers, production and service provision, release, and control of nonconforming outputs. The largest clause by some distance.
9 — Performance evaluation Monitoring, measurement, analysis and evaluation; internal audit; management review. Auditors look for two to three months of real data against measurable targets, not a spreadsheet assembled the week before.
10 — Improvement Nonconformity and corrective action, and continual improvement. The common finding is corrective action that fixes the symptom without root cause or an effectiveness review.

Clause numbering reflects the harmonized structure used by ISO 9001:2015, ISO 14001:2026 and ISO 45001:2018. ISO 50001 and ISO 27001 follow the same shape with discipline-specific requirements. Confirm against your own copy of the standard before using these references in documentation.

If you need more than one

They're built to work together, but you don't have to take all of them

ISO management system standards share a common clause structure. Context, leadership, planning, support, operation, performance evaluation and improvement follow the same shape in each one, which is why a single system can satisfy several standards at once.

That's an option, not an obligation. Plenty of our clients certify to one standard and stop, and that's often the right answer.

What integrating actually saves you

  • One document control system, not three
  • One internal audit programme covering all standards
  • One management review meeting
  • One set of corrective actions and objectives
  • One audit visit instead of separate audits

Because the shared clauses are written once and serve every standard, adding 14001 or 45001 to a 9001 build is far less work than doing them separately later. Our timeline stays in the same three-to-six month range whether you're certifying to one standard or three.

When not to integrate Separate systems can be the better call. Where sites operate very differently, where one standard is driven by a single customer and the others aren't, or where you simply don't have the internal capacity to build everything at once. We'll say so if that's your situation.

Where ISO audits actually generate findings

These come from reviewed audit nonconformities across client audit reports. The pattern is consistent: findings are rarely technical product failures. They're management system maintenance failures. The work was done, but it can't be evidenced.

  • Clause 9.2

    Internal audit process issues

    Records missing, incomplete or not retained, or auditor objectivity not maintained because the person auditing owns the process.

  • Clause 9.3

    Management review not effective

    Late, reused from a prior year, or missing required inputs and outputs.

  • Clause 6.1

    Risk and opportunity actions not tracked

    Risks identified, but actions never assigned, tracked, or reviewed for effectiveness.

  • Clause 7.5

    Documented information gaps

    Outdated master document list, uncontrolled forms, or records that can't be located during the audit.

  • Clause 8.4

    Supplier control issues

    Evaluations or re-evaluations out of date, or approval and monitoring criteria never defined in the first place.

  • Clause 8.2.3

    Contract review records missing

    Customer requirements genuinely reviewed, but informally, so no evidence is retained that the review happened.

  • Clause 6.2 & 9.1

    Objectives and KPIs not maintained

    Objectives exist, but current data, trend analysis and follow-up evidence are incomplete.

  • Clause 7.2 & 7.3

    Competence and awareness not evidenced

    Training records exist but competence was never defined per role, or nobody verified the training worked. Auditors test this by interviewing whoever is doing the job, not by reading your matrix.

The top four apply whichever standard you're certifying

Internal audit, management review, documented information and corrective action come from the shared clause structure, so they read almost identically in ISO 9001, 14001 and 45001. If those four are solid, you're in good shape across all three, and if they're weak, adding standards multiplies the problem rather than spreading it.

How we work

Three to six months, start to certificate

For a single-site organization starting from scratch. Multi-site operations take longer; organizations with most of a system already in place move faster.

  1. Free readiness call

    Which standard fits, what your customers are actually asking for, realistic timeline.

  2. Gap analysis and plan

    Clause by clause against your operation, with owners and effort estimates per finding.

  3. Build and document

    Procedures, records and controls matched to how you work, not a template pack.

  4. Internal audit and management review

    Run properly, findings closed, before Stage 1. Open internal findings become the registrar's findings.

From ISO clients

What organizations say

  • Tony was a great partner through the whole ISO experience. He helped us build our QMS system from the ground up. Tony took the time to understand our business, and help mold the QMS system to what would work best for us while also aligning with the ISO standard. 100% would recommend to anyone looking for guidance with the ISO process.
    Jenna WierGoogle review
  • Tony at Wilkshire Consulting has been an unbelievable asset helping us to achieve and maintain ISO certification for our machine shop. While we understood ISO from our former careers, we critically needed help meeting standards and requirements. I have recommended Tony to other small shops like ours many times and will continue to do so.
    Sean MotylGoogle review

ISO questions we get asked

How long does ISO certification take?

Three to six months for a single-site organization starting from scratch, assuming documentation work stays on schedule. Multi-site operations take longer. Adding a second or third standard doesn't extend it much, because the shared clauses are written once.

Do we have to certify to all three standards?

No. Many organizations certify to one and stop, and that's frequently the right decision. The standards are designed to work together, so integrating is efficient when you genuinely need more than one, but it isn't mandatory, and the right answer depends on your goals, industry and what your customers are actually asking for.

Which standard should we start with?

Usually ISO 9001, because it's the most widely recognized, most often requested by customers, and gives you the document control and audit habits the others build on. The exception is when a specific pressure points elsewhere — an environmental permit issue, a contractor prequalification, or a customer explicitly asking for 14001.

Can you be our certification body as well?

No, and neither can anyone else who builds your system. A consultant cannot audit their own work for certification. We stay independent of all registrars, which also means we've no incentive to steer you toward a particular one.

We're already certified — can you help maintain it?

Yes. A good share of our work is surveillance audit preparation, internal auditing, closing findings, and taking over maintenance when the person who ran the system leaves. Certification is the start of the obligation, not the end.

Do you work outside Michigan?

Yes, across the United States. Most implementation work runs remotely, with on-site visits for internal audits, training, and pre-audit walkthroughs.

Part of the work

We help you pick the registrar

Your audit will only be as good as your auditor. Two registrars quoting the same scope can produce very different experiences — one sends someone who knows your sector and finds real problems, the other sends someone learning your business on your time.

So choosing one isn't administrative. We go through it with you: which bodies are accredited for your standards and scope, who has auditors with relevant sector experience, what the three-year cost actually looks like, and what their lead times mean for your deadline.

We have no preferred registrar. We recommend whoever fits your scope, your sites and your timeline, and we give you the questions to ask so you can check the reasoning yourself.

  • Accreditation, checked

    Accreditation is scope-specific. A body accredited for ISO 9001 is not automatically accredited for 45001 or 27001.

  • The auditor, not just the firm

    Ask about the specific auditor's sector experience. The brochure tells you about the company; you're getting a person.

  • The whole cycle costed

    Stage 1, Stage 2, two surveillance audits and recertification — plus travel, and a follow-up audit if you pick up majors.

  • Lead times against your deadline

    Auditor availability, not your readiness, frequently sets your certification date.

One thing no consultant can do

Certify you. A body accredited to ISO/IEC 17021-1 must protect its impartiality, which means it cannot consult for an organization it audits. Anyone offering both is worth a hard question.

Next step

Find out where you stand

Score yourself in three minutes, or book a free call and we'll tell you which standard you need and what it'll take.

Call Book free call