The short answer: ISO 27001 for consulting firms is about proving you can hold other people's information as carefully as they do. A consultancy rarely runs much infrastructure, so the risk sits in laptops, client system logins, shared drives and associates rather than data centres. That makes scope definition and people controls the hard part of ISO 27001, and it is why most consultancies can reach audit readiness in around two to three months of focused work.
Consultancies get handed the crown jewels early. Board packs, restructuring plans, payroll files, source code, patient data, tender pricing. Then procurement runs its supplier due diligence and discovers that the firm holding all of it has a two-page security policy written in 2019. Certification has quietly become the price of entry for framework agreements, public-sector tenders and any master services agreement with a security schedule attached.
{{snapshot}}
ISO 27001 for consultancies at a glance
- Client data is your main asset, and almost none of it belongs to you, which changes how you write your risk register.
- Scope by service line, not by office, because your people work from homes, client sites, trains and co-working desks.
- People controls carry the weight: screening, confidentiality terms, awareness training and offboarding that actually revokes client access.
- Associates and subcontractors are suppliers and auditors will ask how you assure work delivered by people who are not on your payroll.
- One certificate serves every tender, so the effort is repaid each time a client sends a 120-question security questionnaire.
{{/snapshot}}
Why clients started asking consultancies for a certificate
Three things changed. Enterprise security teams extended supplier assurance beyond software vendors to anyone with access, and advisers usually have more access than the software. Public buyers standardised their questions, so tender portals now ask for certification status as a yes or no field rather than an essay. And breach reporting made procurement nervous about the small firm with the big access.
Consultancies also sit in an awkward spot under data protection law. You are often a processor acting on client instructions, sometimes a controller for your own candidate and contact data, and occasionally both inside the same engagement. The ICO's guidance for organisations is clear that processors carry their own obligations. An ISMS is the cheapest way to evidence them consistently instead of renegotiating each contract from scratch.
There is a commercial argument too. A certificate shortens the sales cycle. Instead of a security questionnaire ping-pong lasting six weeks, you send a scope statement, a certificate and a Statement of Applicability, and the conversation moves on. Firms selling to regulated buyers find this is the difference between being shortlisted and being asked to partner with someone larger.
The scoping problem: your assets walk out of the building every morning
Manufacturers scope a factory. SaaS companies scope a product and its cloud. A consultancy has neither. What you have is people, laptops, a handful of SaaS tools, and logins to systems you do not own. Clause 4.3 asks you to define boundaries and interfaces, and this is where most consultancy projects stall for a fortnight.
The workable answer is to scope by service line and information type. Something like: "the provision of advisory and delivery services to clients, including all information received from or created for clients, across all UK personnel and company-managed devices." That covers the way you work rather than the place you sit. It also survives a new office, a new remote hire or a client asking you to work from their site for six months.
Be deliberate about client-owned environments. When your consultants log into a client's tenant, that system stays inside the client's ISMS, but your access to it belongs in yours. Describe it as an interface: how access is requested, approved, reviewed and removed. Auditors accept that boundary readily. What they do not accept is a scope statement that quietly omits the half of your work performed on other people's kit.
Resist the temptation to carve out a "secure team" and certify only that. It looks tidy on paper and falls apart the first time a client reads the scope on your certificate and notices their engagement sits outside it. Small firms in particular are usually better off certifying the whole company. The same logic applies to any lean organisation, which we cover in more detail in ISO 27001 for small businesses.
Once scope is settled, the Statement of Applicability becomes the document that keeps every engagement consistent. Build it from your actual risks rather than copying a template from a firm with a server room, and use the Statement of Applicability builder to work through the 93 Annex A controls without losing a week to formatting.
Do you need an ISO 27001 consultant to get certified?
No. Plenty of consultancies find it faintly absurd to hire a consultant, which is fair. But the honest version of the answer has conditions attached. You need someone who has read the standard properly, who can chair a management review without it turning into a status meeting, and who can run an internal audit that finds something. That person can be external, or internal, or a platform plus one determined operations lead.
Where consultants earn their fee is speed and translation: turning Clause 6.1 into a risk methodology your team will actually follow, and telling you which of the auditor's questions matter. Where they cost you money is dependency. One of our customers, access-control provider CloudPass, was paying around £5,000 a year for external consultants who visited twice a year, and still kept its evidence in OneDrive folders. The consultants were not the problem. The absence of a system between visits was.
One rule is not negotiable. Your certification body must be independent of whoever implemented your ISMS. If you use a consultancy to implement, they cannot certify you, and a firm offering both in one package is telling you something about their accreditation.
The controls that carry weight in a people business
ISO 27001:2022 lists 93 Annex A controls across four themes: organisational, people, physical and technological. Consultancies find the people and organisational themes disproportionately heavy, and the physical theme unusually light, which is the opposite of the standard implementation guides written for firms with a building to protect. The full set is broken down in our guide to Annex A controls.
Here is the mapping that tends to hold for advisory firms.
| Common consultancy risk | Annex A theme | What evidence looks like |
|---|---|---|
| An associate joins mid-engagement and needs client system access on day one | People | Screening record, signed confidentiality terms, role-specific induction, dated access approval |
| Consultants working from client sites, homes and co-working spaces | People and physical | Remote working policy, device encryption reports, MDM enrolment list, clear-screen rules for client premises |
| Client files scattered across email, personal drives and messaging apps | Organisational and technological | Classification scheme, approved transfer channels, external sharing restrictions, logged exceptions |
| Access to a client tenant that nobody revoked when the project closed | Technological | Access review per engagement, closure checklist tied to project sign-off, revocation timestamps |
| A subcontractor delivering part of a client engagement | Organisational | Supplier register entry, security clauses in the subcontract, due diligence record, monitoring notes |
| One expert holds the client relationship and all the working papers | Organisational | Continuity plan naming deputies, tested restore of the document repository, handover records |
Two of these fail more often than the rest. Offboarding is the first: firms remove the leaver from their own Microsoft tenant and forget the four client systems the person had accounts in. Information transfer is the second: a partner emails a valuation model to a personal address because the client's file share is slow. Both are cultural problems with technical fixes, and both are exactly what an auditor samples.
Associates and subcontractors: the supply chain you forgot you were part of
Most consultancies flex through associates. That model is efficient and it is the single most common gap in consultancy ISMSs. If an associate does client work in your name, the client holds you responsible, and so does the auditor.
Treat associates as both people and suppliers. On the people side, apply equivalent screening and confidentiality obligations, and record them. On the supplier side, keep them in the supplier register with the same due diligence you would apply to a software vendor, sized to the risk. A two-day training associate with no data access does not need the same file as a subcontractor rebuilding a client's network.
Then look upstream. You are somebody else's supplier, and your clients will start asking you the questions you are now asking your associates. Firms that deliver technical services alongside advisory work often end up somewhere between the two models, which is why the overlap with ISO 27001 for managed service providers is worth reading if you run any managed or hosted element.
If you implement ISO 27001 for clients, stop running it on spreadsheets
A specific group of readers here sells ISO 27001 rather than just holding it. Security and risk consultancies spend their days building ISMSs for other people, usually in a folder structure per client, with a risk register in Excel and a version control policy that consists of putting the date in the filename.
Infosec Consulting, a cyber-security consultancy with fifteen years behind it, moved its clients onto Hicomply as the platform their ISMSs run on: one repository for documents, policies and procedures rather than a different arrangement per client. You can read how Infosec Consulting runs client ISMSs on one platform, and if that is your model, the partner programme is where the commercial side lives.
The same logic applies to your own certification. A centralised risk register that auto-populates from your asset list saves the annual ritual of rebuilding the spreadsheet from memory. HR software firm HealthBoxHR started with nothing in place and, in the words of CTO Paul Clulow, "we were able to achieve ISO/IEC 27001:2022 certification in 12 weeks" using policy templates mapped to controls, as covered in the HealthBoxHR case study. IT and comms integrator Advantex cut its audit preparation time by 30 to 40 per cent after moving off manual tracking.
One more thing worth flagging. Consultancies have been the fastest adopters of AI tools, and client data is going into them. Summarising a client's board pack in a general-purpose model is a processing decision with contractual consequences. Run it through a proper AI risk assessment before a client asks you to describe your AI usage in an assurance questionnaire, because that question is now arriving in tenders.
{{snapshot}}
Hicomply's take
We see the same two mistakes in consultancy implementations. The first is scoping around a team or an office when the real boundary is the information, which produces a certificate clients read once and query immediately. The second is treating associates as a contracting detail rather than part of the ISMS, then scrambling during the audit to find screening records for someone who left in March. Fix both early and a consultancy implementation is genuinely light work. Your controls live in policies, contracts and access reviews, not in expensive infrastructure you would have to buy first.
{{/snapshot}}
Get your consultancy certified without slowing client work
The work is not complicated for an advisory firm. It is a scope statement that reflects how you actually deliver, a risk register built from your real assets, a set of policies people can follow on a client site, and evidence that keeps collecting itself while you are busy billing. What you build for ISO 27001 also powers SOC 2 and whatever the next tender asks for.
Start with the ISO 27001 readiness assessment to see where your firm actually sits, then book a demo and we will walk through what a consultancy scope looks like on the platform, including how associates and client access get evidenced.


.avif)























