- Home
- /
- ISO
ISO certification consulting
Which ISO standard do you actually need?
Four standards, and most organizations only need one or two. This page helps you work out which, then shows you what certification actually takes.
- 3–6Months to certify
- 100+ISO certifications
- 8Common finding areas
- 2015Doing this since
Start here
Pick the standard that matches your problem
Each of these solves something different. Read the "choose this if" lines rather than the titles. Most people arrive knowing their problem but not which standard addresses it.
ISO 14001:2026 published on 15 April 2026 and the transition clock is running. ISO 9001:2026 is targeted for September 2026 and cannot be certified to yet. ISO 14001:2026 transition → ISO 9001:2026 transition →
-
ISO 9001
Quality management
The most widely held management system standard, and usually the first one an organization certifies.
Choose this if
- A customer or tender asked for it
- Defects, rework or inconsistency are costing you
- Processes live in people's heads rather than on paper
- You need a QMS underneath R2v3 Appendix C or F
-
ISO 14001
Environmental management
Controls environmental impact and demonstrates regulatory compliance.
Choose this if
- Customers are asking about sustainability credentials
- You hold environmental permits or handle regulated waste
- You want to reduce waste and disposal costs systematically
- Supply-chain questionnaires keep raising it
-
ISO 45001
Occupational health & safety
Manages workplace risk and demonstrates a systematic approach to safety.
Choose this if
- Incident rates or insurance premiums are a problem
- You're being prequalified as a contractor
- Safety is managed reactively rather than by system
- You need to show due diligence after an incident
-
ISO 27001
Information security
Protects information you hold, and increasingly demanded in procurement.
Choose this if
- A customer or tender is asking for it
- You hold data that isn't yours to lose
- You're an ITAD and customers ask beyond device sanitization
- Your certificate still says 2013 — that deadline has passed
-
Integrated
QEHS — all three together
ISO 9001, 14001 and 45001 run as one system rather than three.
Choose this if
- You need more than one and want a single set of documents
- You'd rather have one internal audit programme than three
- A customer or tender asks for quality, environmental and safety together
- You already hold one and are adding others
-
ISO 50001
Energy management
Improves energy performance and supports energy reporting obligations.
Choose this if
- Energy is a material line on your P&L
- You have energy reporting or reduction commitments
- You want measurable efficiency gains, not one-off projects
- Incentive programs in your state require it
Still not sure? Ten minutes on the phone usually settles it.
Reference
What the clauses actually require
ISO 9001, 14001 and 45001 share the same ten-clause structure. Clauses 1 to 3 — scope, normative references and terms — contain no auditable requirements, so an audit starts at clause 4. Everything below is where findings come from.
R2v3 is organised differently, around ten Core Requirements rather than clauses. If that's your standard, the R2 requirements table is the equivalent.
| Clause | What it requires |
|---|---|
| 4 — Context | Determine what affects your organization internally and externally, identify interested parties and their requirements, define the scope of the system, and establish the processes that make it up. Climate change has been a mandatory consideration here since February 2024. |
| 5 — Leadership | Top management must demonstrate commitment, not delegate it. A policy, assigned roles and authorities, and evidence that leadership is actually engaged. ISO 45001 adds worker consultation and participation, which is where most 45001 audits come unstuck. |
| 6 — Planning | Address risks and opportunities, set measurable objectives with plans to achieve them, and plan changes rather than absorbing them. ISO 14001:2026 adds a dedicated change management clause at 6.3. |
| 7 — Support | Resources, competence, awareness, communication and documented information. This is the clause that catches the most organizations, because competence and awareness are tested by interviewing your staff rather than by reading your records. |
| 8 — Operation | Operational planning and control, requirements for products and services, design and development, control of external providers, production and service provision, release, and control of nonconforming outputs. The largest clause by some distance. |
| 9 — Performance evaluation | Monitoring, measurement, analysis and evaluation; internal audit; management review. Auditors look for two to three months of real data against measurable targets, not a spreadsheet assembled the week before. |
| 10 — Improvement | Nonconformity and corrective action, and continual improvement. The common finding is corrective action that fixes the symptom without root cause or an effectiveness review. |
Clause numbering reflects the harmonized structure used by ISO 9001:2015, ISO 14001:2026 and ISO 45001:2018. ISO 50001 and ISO 27001 follow the same shape with discipline-specific requirements. Confirm against your own copy of the standard before using these references in documentation.
If you need more than one
They're built to work together, but you don't have to take all of them
ISO management system standards share a common clause structure. Context, leadership, planning, support, operation, performance evaluation and improvement follow the same shape in each one, which is why a single system can satisfy several standards at once.
That's an option, not an obligation. Plenty of our clients certify to one standard and stop, and that's often the right answer.
What integrating actually saves you
Because the shared clauses are written once and serve every standard, adding 14001 or 45001 to a 9001 build is far less work than doing them separately later. Our timeline stays in the same three-to-six month range whether you're certifying to one standard or three.
Where ISO audits actually generate findings
These come from reviewed audit nonconformities across client audit reports. The pattern is consistent: findings are rarely technical product failures. They're management system maintenance failures. The work was done, but it can't be evidenced.
Clause 9.2
Internal audit process issues
Records missing, incomplete or not retained, or auditor objectivity not maintained because the person auditing owns the process.
Clause 9.3
Management review not effective
Late, reused from a prior year, or missing required inputs and outputs.
Clause 6.1
Risk and opportunity actions not tracked
Risks identified, but actions never assigned, tracked, or reviewed for effectiveness.
Clause 7.5
Documented information gaps
Outdated master document list, uncontrolled forms, or records that can't be located during the audit.
Clause 8.4
Supplier control issues
Evaluations or re-evaluations out of date, or approval and monitoring criteria never defined in the first place.
Clause 8.2.3
Contract review records missing
Customer requirements genuinely reviewed, but informally, so no evidence is retained that the review happened.
Clause 6.2 & 9.1
Objectives and KPIs not maintained
Objectives exist, but current data, trend analysis and follow-up evidence are incomplete.
Clause 7.2 & 7.3
Competence and awareness not evidenced
Training records exist but competence was never defined per role, or nobody verified the training worked. Auditors test this by interviewing whoever is doing the job, not by reading your matrix.
The top four apply whichever standard you're certifying
Internal audit, management review, documented information and corrective action come from the shared clause structure, so they read almost identically in ISO 9001, 14001 and 45001. If those four are solid, you're in good shape across all three, and if they're weak, adding standards multiplies the problem rather than spreading it.
How we work
Three to six months, start to certificate
For a single-site organization starting from scratch. Multi-site operations take longer; organizations with most of a system already in place move faster.
Free readiness call
Which standard fits, what your customers are actually asking for, realistic timeline.
Gap analysis and plan
Clause by clause against your operation, with owners and effort estimates per finding.
Build and document
Procedures, records and controls matched to how you work, not a template pack.
Internal audit and management review
Run properly, findings closed, before Stage 1. Open internal findings become the registrar's findings.
From ISO clients
What organizations say
-
Tony was a great partner through the whole ISO experience. He helped us build our QMS system from the ground up. Tony took the time to understand our business, and help mold the QMS system to what would work best for us while also aligning with the ISO standard. 100% would recommend to anyone looking for guidance with the ISO process.
Jenna WierGoogle review -
Tony at Wilkshire Consulting has been an unbelievable asset helping us to achieve and maintain ISO certification for our machine shop. While we understood ISO from our former careers, we critically needed help meeting standards and requirements. I have recommended Tony to other small shops like ours many times and will continue to do so.
Sean MotylGoogle review
ISO questions we get asked
How long does ISO certification take?
Three to six months for a single-site organization starting from scratch, assuming documentation work stays on schedule. Multi-site operations take longer. Adding a second or third standard doesn't extend it much, because the shared clauses are written once.
Do we have to certify to all three standards?
No. Many organizations certify to one and stop, and that's frequently the right decision. The standards are designed to work together, so integrating is efficient when you genuinely need more than one, but it isn't mandatory, and the right answer depends on your goals, industry and what your customers are actually asking for.
Which standard should we start with?
Usually ISO 9001, because it's the most widely recognized, most often requested by customers, and gives you the document control and audit habits the others build on. The exception is when a specific pressure points elsewhere — an environmental permit issue, a contractor prequalification, or a customer explicitly asking for 14001.
Can you be our certification body as well?
No, and neither can anyone else who builds your system. A consultant cannot audit their own work for certification. We stay independent of all registrars, which also means we've no incentive to steer you toward a particular one.
We're already certified — can you help maintain it?
Yes. A good share of our work is surveillance audit preparation, internal auditing, closing findings, and taking over maintenance when the person who ran the system leaves. Certification is the start of the obligation, not the end.
Do you work outside Michigan?
Yes, across the United States. Most implementation work runs remotely, with on-site visits for internal audits, training, and pre-audit walkthroughs.
Part of the work
We help you pick the registrar
Your audit will only be as good as your auditor. Two registrars quoting the same scope can produce very different experiences — one sends someone who knows your sector and finds real problems, the other sends someone learning your business on your time.
So choosing one isn't administrative. We go through it with you: which bodies are accredited for your standards and scope, who has auditors with relevant sector experience, what the three-year cost actually looks like, and what their lead times mean for your deadline.
We have no preferred registrar. We recommend whoever fits your scope, your sites and your timeline, and we give you the questions to ask so you can check the reasoning yourself.
- Accreditation, checked
Accreditation is scope-specific. A body accredited for ISO 9001 is not automatically accredited for 45001 or 27001.
- The auditor, not just the firm
Ask about the specific auditor's sector experience. The brochure tells you about the company; you're getting a person.
- The whole cycle costed
Stage 1, Stage 2, two surveillance audits and recertification — plus travel, and a follow-up audit if you pick up majors.
- Lead times against your deadline
Auditor availability, not your readiness, frequently sets your certification date.
Certify you. A body accredited to ISO/IEC 17021-1 must protect its impartiality, which means it cannot consult for an organization it audits. Anyone offering both is worth a hard question.
Next step
Find out where you stand
Score yourself in three minutes, or book a free call and we'll tell you which standard you need and what it'll take.