How to Choose an ISO 27001 Consultant: 10 Questions
Quick answer
The right ISO 27001 consultant will name your lead auditor, give you a written scope and timeline before any payment, and stay involved through post-certification surveillance audits. If they cannot answer these three points clearly, keep looking. The 10 questions and red flags below cover everything else worth checking before you sign.
Choosing the right ISO 27001 consultant comes down to three deal breaker questions. Will they name the lead auditor who will work on your certification. Do they explain a clear scope and timeline before asking for payment. Will they stay involved after the certificate is issued or disappear once the invoice is settled. If a consultant cannot answer all three clearly, treat that as a warning sign before you sign anything.
Most organisations in Australia choosing an ISO 27001 consultant for the first time focus only on price and turnaround time. This is understandable, but it misses the questions that actually predict whether a certification project succeeds. A good consultant should reduce your workload and risk. A poor one can leave you with a rushed audit, unclear documentation, and a certificate that does not hold up under scrutiny from clients or regulators.
- The 3 deal breaker questions
- The 10 questions to ask an ISO 27001 consultant
- 1. Who is the named lead auditor on my engagement?
- 2. What is your exact scope and timeline before I pay a deposit?
- 3. Can I speak to a current or recent client reference?
- 4. What happens if we fail the certification audit?
- 5. Do you provide ongoing support after certification, or just the certificate?
- 6. How many ISO 27001 certifications have you completed in my industry?
- 7. Will you help build the actual ISMS documentation, or just consult?
- 8. What is included and excluded in your fixed fee?
- 9. Which certification body will conduct the final audit, and are they accredited?
- 10. How do you handle scope changes mid-project?
- Red flags to watch for when hiring an ISO 27001 consultant
- Consultant vs DIY vs compliance platform
- Frequently asked questions
- How much does an ISO 27001 consultant cost in Australia?
- How long does it take to get ISO 27001 certified with a consultant?
- Do I need a consultant to get ISO 27001 certified?
- Can the same company act as my consultant and certify me?
- What is the difference between a consultant and a certification body?
- Ketki Tidke
- Not sure which consultant is right for you?
The 3 deal breaker questions
1. Who is the named lead auditor assigned to my certification, and what are their credentials.
2. What is the exact scope, timeline, and cost breakdown before any deposit is paid.
3. What support is included after certification is achieved, and for how long.
In our experience working with Australian SMEs and mid-market organisations, engagements that go wrong almost always trace back to one of these three questions being answered vaguely or not at all during the sales process. The rest of this guide walks through the full set of 10 questions worth asking, the red flags to watch for, and how using a consultant compares with attempting certification in-house or through a software-only platform.
The 10 questions to ask an ISO 27001 consultant
These are the questions we recommend Australian organisations ask before signing with any ISO 27001 consultant. For each one, we have included what a strong, trustworthy answer sounds like and what a weak or evasive answer sounds like, based on patterns we see across genuine client engagements.
1. Who is the named lead auditor on my engagement?
Strong answer: A specific name, their certification number, and a short summary of their audit history in your industry.
Weak answer: A vague reference to “our team of experts” with no individual named.
2. What is your exact scope and timeline before I pay a deposit?
Strong answer: A written scope document listing which sites, systems, and departments are covered, plus a realistic week by week timeline.
Weak answer: A single lump sum quote with no breakdown of what is and is not included.
3. Can I speak to a current or recent client reference?
Strong answer: Willingness to connect you with a client in a similar industry or size, sometimes with a short delay to arrange it.
Weak answer: Refusal, or pointing only to written testimonials on their own website.
4. What happens if we fail the certification audit?
Strong answer: A clear explanation of the corrective action process and whether re-audit support is included in the original fee.
Weak answer: A claim that failure never happens with them, which is not a realistic answer for a genuine audit process.
5. Do you provide ongoing support after certification, or just the certificate?
Strong answer: A defined surveillance audit support package covering the three year certification cycle.
Weak answer: Support ends the moment the certificate is issued, with no mention of annual surveillance audits.
6. How many ISO 27001 certifications have you completed in my industry?
Strong answer: A specific number and examples of comparable projects, with an explanation of industry-specific risks they have handled before.
Weak answer: A generic claim of broad experience with no specifics offered when asked directly.
7. Will you help build the actual ISMS documentation, or just consult?
Strong answer: A clear statement of whether they draft policies and records with you or only review documents you produce yourself.
Weak answer: Ambiguity about who is actually responsible for producing the required ISMS documentation set.
8. What is included and excluded in your fixed fee?
Strong answer: A written list of exclusions, such as certification body fees or tooling costs, disclosed upfront.
Weak answer: Extra costs only surface after the engagement has already started.
9. Which certification body will conduct the final audit, and are they accredited?
Strong answer: A named, independent certification body accredited by a recognised national accreditation body such as JAS-ANZ in Australia. According to the Joint Accreditation System of Australia and New Zealand, only accredited certification bodies can issue certificates recognised internationally.
Weak answer: The consultant is vague about who performs the actual audit, or implies they can issue the certificate themselves. A consultant cannot certify their own client, since certification must come from an independent accredited body.
10. How do you handle scope changes mid-project?
Strong answer: A defined change process with transparent pricing if new systems, sites, or departments are added.
Weak answer: No process at all, leaving pricing and timeline open to dispute later.
In our own engagements, question 9 catches out more prospective clients than any other. It is worth reading our ISO 27001 certification timeline guide to understand how the audit stage fits into the overall process before you commit to a consultant.
Red flags to watch for when hiring an ISO 27001 consultant
Beyond the 10 questions above, certain answers and behaviours are worth treating as immediate warning signs. These are patterns we have seen repeatedly when speaking with Australian organisations who came to us after a previous consultant engagement did not go to plan.
Guaranteed certification
No consultant can guarantee a pass. The certification decision is made independently by the accredited certification body, not the consultant.
No named auditor
If a consultant will not name the individual responsible for your engagement before you sign, treat that as a reason to keep looking.
Consultant and certification body are the same company
Accreditation rules exist specifically to prevent conflicts of interest between the party that helps you prepare and the party that certifies you.
Unusually low fixed price with no scope document
A price that seems too good to be true, without a written scope to back it up, often means costs appear later once you are already committed.
No client references available
Established consultants with a genuine track record can usually connect you with at least one past or current client.
Support ends the moment the certificate is issued
ISO 27001 certification runs on a three year cycle with annual surveillance audits. A consultant who has no plan for this stage is only solving half the problem.
The ISO 27001 standard itself is publicly available and sets out exactly what an information security management system must cover. Any consultant proposing an approach that departs significantly from the standard’s own structure is worth questioning further.
Consultant vs DIY vs compliance platform
A consultant is not the only path to ISO 27001 certification. Some organisations attempt certification in-house, and others use a software-only compliance platform. Here is how the three approaches compare in practice.
| Factor | Consultant | DIY in-house | Compliance platform |
|---|---|---|---|
| Named human expert support | Yes, ongoing | None | Limited, usually ticketed support |
| Typical time to certification | 3 to 6 months | 6 to 18 months, often longer | 4 to 9 months |
| Documentation drafted for you | Usually yes | No, built from scratch internally | Templates provided, you complete them |
| Risk of audit failure | Lower, with an experienced consultant | Higher, especially on first attempt | Moderate, depends on internal effort |
| Ongoing surveillance audit support | Often included | Managed entirely internally | Platform reminders, limited hands-on help |
| Best suited to | Organisations wanting speed and reduced risk | Teams with a dedicated, experienced GRC resource | Organisations comfortable doing most of the work themselves |
In our experience, organisations that attempt certification fully in-house without prior GRC expertise most often underestimate the documentation workload, not the technical controls. That gap is usually where a consultant or platform earns back its cost in time saved alone.
Frequently asked questions
How much does an ISO 27001 consultant cost in Australia?
Costs vary widely based on company size and scope, typically ranging from a few thousand dollars for a small single-site business to well beyond that for larger, multi-site organisations. For a full breakdown, see our ISO 27001 certification cost guide.
How long does it take to get ISO 27001 certified with a consultant?
Most organisations working with an experienced consultant complete certification in 3 to 6 months. Timelines depend on how prepared your existing documentation and controls are before the engagement starts.
Do I need a consultant to get ISO 27001 certified?
No, certification can be pursued in-house or through a compliance platform. A consultant is not mandatory, but it typically reduces the risk of audit failure and the time your internal team needs to spend on documentation.
Can the same company act as my consultant and certify me?
No, this is a conflict of interest under accreditation rules. Your consultant helps you prepare, but the certification decision must come from an independent, accredited certification body.
What is the difference between a consultant and a certification body?
A consultant helps you build the information security management system and get ready for audit. The certification body is an independent, accredited organisation that conducts the actual audit and issues the certificate.
Content Reviewed By
Ketki Tidke
Cyber Security and GRC Lead Auditor
ISO 27001 Lead Auditor
Ketki is a certified ISO 27001 Lead Auditor specialised in Governance, Risk and Compliance, with experience consulting public, private, and government clients. She evaluates threats, risk impacts, and regulatory requirements across multiple industry frameworks.
Not sure which consultant is right for you?
Talk to Ketki and the CyberSapiens team about your ISO 27001 scope, timeline, and budget. No pressure, no obligation, just a clear picture of what certification will actually involve for your organisation.
Book a no-pressure call