ISO 27001 for consulting firms: what to certify and how

How consultancies get ISO 27001 certified when their assets are people, laptops and client system access. Scoping by service line, the people and supplier controls auditors sample, and whether you need a consultant.

The short answer: ISO 27001 for consulting firms is about proving you can hold other people's information as carefully as they do. A consultancy rarely runs much infrastructure, so the risk sits in laptops, client system logins, shared drives and associates rather than data centres. That makes scope definition and people controls the hard part of ISO 27001, and it is why most consultancies can reach audit readiness in around two to three months of focused work.

Consultancies get handed the crown jewels early. Board packs, restructuring plans, payroll files, source code, patient data, tender pricing. Then procurement runs its supplier due diligence and discovers that the firm holding all of it has a two-page security policy written in 2019. Certification has quietly become the price of entry for framework agreements, public-sector tenders and any master services agreement with a security schedule attached.

{{snapshot}}

ISO 27001 for consultancies at a glance

  • Client data is your main asset, and almost none of it belongs to you, which changes how you write your risk register.
  • Scope by service line, not by office, because your people work from homes, client sites, trains and co-working desks.
  • People controls carry the weight: screening, confidentiality terms, awareness training and offboarding that actually revokes client access.
  • Associates and subcontractors are suppliers and auditors will ask how you assure work delivered by people who are not on your payroll.
  • One certificate serves every tender, so the effort is repaid each time a client sends a 120-question security questionnaire.

{{/snapshot}}

Why clients started asking consultancies for a certificate

Three things changed. Enterprise security teams extended supplier assurance beyond software vendors to anyone with access, and advisers usually have more access than the software. Public buyers standardised their questions, so tender portals now ask for certification status as a yes or no field rather than an essay. And breach reporting made procurement nervous about the small firm with the big access.

Consultancies also sit in an awkward spot under data protection law. You are often a processor acting on client instructions, sometimes a controller for your own candidate and contact data, and occasionally both inside the same engagement. The ICO's guidance for organisations is clear that processors carry their own obligations. An ISMS is the cheapest way to evidence them consistently instead of renegotiating each contract from scratch.

There is a commercial argument too. A certificate shortens the sales cycle. Instead of a security questionnaire ping-pong lasting six weeks, you send a scope statement, a certificate and a Statement of Applicability, and the conversation moves on. Firms selling to regulated buyers find this is the difference between being shortlisted and being asked to partner with someone larger.

The scoping problem: your assets walk out of the building every morning

Manufacturers scope a factory. SaaS companies scope a product and its cloud. A consultancy has neither. What you have is people, laptops, a handful of SaaS tools, and logins to systems you do not own. Clause 4.3 asks you to define boundaries and interfaces, and this is where most consultancy projects stall for a fortnight.

The workable answer is to scope by service line and information type. Something like: "the provision of advisory and delivery services to clients, including all information received from or created for clients, across all UK personnel and company-managed devices." That covers the way you work rather than the place you sit. It also survives a new office, a new remote hire or a client asking you to work from their site for six months.

Be deliberate about client-owned environments. When your consultants log into a client's tenant, that system stays inside the client's ISMS, but your access to it belongs in yours. Describe it as an interface: how access is requested, approved, reviewed and removed. Auditors accept that boundary readily. What they do not accept is a scope statement that quietly omits the half of your work performed on other people's kit.

Resist the temptation to carve out a "secure team" and certify only that. It looks tidy on paper and falls apart the first time a client reads the scope on your certificate and notices their engagement sits outside it. Small firms in particular are usually better off certifying the whole company. The same logic applies to any lean organisation, which we cover in more detail in ISO 27001 for small businesses.

Once scope is settled, the Statement of Applicability becomes the document that keeps every engagement consistent. Build it from your actual risks rather than copying a template from a firm with a server room, and use the Statement of Applicability builder to work through the 93 Annex A controls without losing a week to formatting.

Do you need an ISO 27001 consultant to get certified?

No. Plenty of consultancies find it faintly absurd to hire a consultant, which is fair. But the honest version of the answer has conditions attached. You need someone who has read the standard properly, who can chair a management review without it turning into a status meeting, and who can run an internal audit that finds something. That person can be external, or internal, or a platform plus one determined operations lead.

Where consultants earn their fee is speed and translation: turning Clause 6.1 into a risk methodology your team will actually follow, and telling you which of the auditor's questions matter. Where they cost you money is dependency. One of our customers, access-control provider CloudPass, was paying around £5,000 a year for external consultants who visited twice a year, and still kept its evidence in OneDrive folders. The consultants were not the problem. The absence of a system between visits was.

One rule is not negotiable. Your certification body must be independent of whoever implemented your ISMS. If you use a consultancy to implement, they cannot certify you, and a firm offering both in one package is telling you something about their accreditation.

The controls that carry weight in a people business

ISO 27001:2022 lists 93 Annex A controls across four themes: organisational, people, physical and technological. Consultancies find the people and organisational themes disproportionately heavy, and the physical theme unusually light, which is the opposite of the standard implementation guides written for firms with a building to protect. The full set is broken down in our guide to Annex A controls.

Here is the mapping that tends to hold for advisory firms.

Common consultancy riskAnnex A themeWhat evidence looks like
An associate joins mid-engagement and needs client system access on day onePeopleScreening record, signed confidentiality terms, role-specific induction, dated access approval
Consultants working from client sites, homes and co-working spacesPeople and physicalRemote working policy, device encryption reports, MDM enrolment list, clear-screen rules for client premises
Client files scattered across email, personal drives and messaging appsOrganisational and technologicalClassification scheme, approved transfer channels, external sharing restrictions, logged exceptions
Access to a client tenant that nobody revoked when the project closedTechnologicalAccess review per engagement, closure checklist tied to project sign-off, revocation timestamps
A subcontractor delivering part of a client engagementOrganisationalSupplier register entry, security clauses in the subcontract, due diligence record, monitoring notes
One expert holds the client relationship and all the working papersOrganisationalContinuity plan naming deputies, tested restore of the document repository, handover records

Two of these fail more often than the rest. Offboarding is the first: firms remove the leaver from their own Microsoft tenant and forget the four client systems the person had accounts in. Information transfer is the second: a partner emails a valuation model to a personal address because the client's file share is slow. Both are cultural problems with technical fixes, and both are exactly what an auditor samples.

Associates and subcontractors: the supply chain you forgot you were part of

Most consultancies flex through associates. That model is efficient and it is the single most common gap in consultancy ISMSs. If an associate does client work in your name, the client holds you responsible, and so does the auditor.

Treat associates as both people and suppliers. On the people side, apply equivalent screening and confidentiality obligations, and record them. On the supplier side, keep them in the supplier register with the same due diligence you would apply to a software vendor, sized to the risk. A two-day training associate with no data access does not need the same file as a subcontractor rebuilding a client's network.

Then look upstream. You are somebody else's supplier, and your clients will start asking you the questions you are now asking your associates. Firms that deliver technical services alongside advisory work often end up somewhere between the two models, which is why the overlap with ISO 27001 for managed service providers is worth reading if you run any managed or hosted element.

If you implement ISO 27001 for clients, stop running it on spreadsheets

A specific group of readers here sells ISO 27001 rather than just holding it. Security and risk consultancies spend their days building ISMSs for other people, usually in a folder structure per client, with a risk register in Excel and a version control policy that consists of putting the date in the filename.

Infosec Consulting, a cyber-security consultancy with fifteen years behind it, moved its clients onto Hicomply as the platform their ISMSs run on: one repository for documents, policies and procedures rather than a different arrangement per client. You can read how Infosec Consulting runs client ISMSs on one platform, and if that is your model, the partner programme is where the commercial side lives.

The same logic applies to your own certification. A centralised risk register that auto-populates from your asset list saves the annual ritual of rebuilding the spreadsheet from memory. HR software firm HealthBoxHR started with nothing in place and, in the words of CTO Paul Clulow, "we were able to achieve ISO/IEC 27001:2022 certification in 12 weeks" using policy templates mapped to controls, as covered in the HealthBoxHR case study. IT and comms integrator Advantex cut its audit preparation time by 30 to 40 per cent after moving off manual tracking.

One more thing worth flagging. Consultancies have been the fastest adopters of AI tools, and client data is going into them. Summarising a client's board pack in a general-purpose model is a processing decision with contractual consequences. Run it through a proper AI risk assessment before a client asks you to describe your AI usage in an assurance questionnaire, because that question is now arriving in tenders.

{{snapshot}}

Hicomply's take

We see the same two mistakes in consultancy implementations. The first is scoping around a team or an office when the real boundary is the information, which produces a certificate clients read once and query immediately. The second is treating associates as a contracting detail rather than part of the ISMS, then scrambling during the audit to find screening records for someone who left in March. Fix both early and a consultancy implementation is genuinely light work. Your controls live in policies, contracts and access reviews, not in expensive infrastructure you would have to buy first.

{{/snapshot}}

Get your consultancy certified without slowing client work

The work is not complicated for an advisory firm. It is a scope statement that reflects how you actually deliver, a risk register built from your real assets, a set of policies people can follow on a client site, and evidence that keeps collecting itself while you are busy billing. What you build for ISO 27001 also powers SOC 2 and whatever the next tender asks for.

Start with the ISO 27001 readiness assessment to see where your firm actually sits, then book a demo and we will walk through what a consultancy scope looks like on the platform, including how associates and client access get evidenced.

Ready to Take Control of Your Privacy Compliance?

Hicomply’s platform provides an all-in-one solution to streamline, automate, and centralise your compliance activities, ensuring complete control and efficiency.

Book a demo
Last updated
August 17, 2026
Category
ISO 27001 by Industry
Topics
No items found.
Lucy Murphy
Head of Customer Success

Lucy works closely with customers to help them get the most out of the Hicomply platform, from onboarding to audit success. She brings a user-focused mindset to everything she does, making her well-placed to write about day-to-day challenges, shortcuts, and success strategies. Her content is grounded in what real InfoSec and compliance teams need to know — and how to get there faster.Expect helpful walkthroughs, product tips, and practical insights.

Popular ISO 27001 for Consulting Firms queries, answered!

Do consulting firms actually need ISO 27001?

Nothing in law requires it. Commercially it is close to mandatory once you sell to enterprise or public-sector buyers, because supplier due diligence, framework agreements and master services agreements increasingly ask for it as a yes or no field. If your tenders keep stalling at the security questionnaire stage, that is your answer.

What should be in scope for a consulting firm's ISMS?

Scope by service line and information type rather than by location. A workable statement covers advisory and delivery services, all client information received or created, all personnel and all company-managed devices. Client-owned systems stay in the client's ISMS, but your access to them belongs in yours and should be described as an interface.

Do you need to hire a consultant to get ISO 27001 certified?

No. You need someone who has read the standard, can run a real internal audit and can chair a management review. That can be an external consultant, an internal lead, or a platform plus a determined operations manager. One rule is fixed: your certification body must be independent of whoever implemented the ISMS.

Do associates and subcontractors have to be covered by our ISMS?

Yes, if they do client work in your name. Treat them twice over: as people, with equivalent screening and confidentiality obligations on record, and as suppliers, with an entry in the supplier register, security clauses in the subcontract and due diligence proportionate to their access. Missing associate records is the most common consultancy audit finding.

How long does ISO 27001 certification take for a consultancy?

Typically two to three months to reach audit readiness for a firm with clean processes and management support, then the Stage 1 and Stage 2 audits with your certification body. HealthBoxHR started with nothing in place and certified in 12 weeks. Delays usually come from unresolved scope, not from the controls themselves.

Unlock Your Path to ISO 27001 Success

Download our Ultimate ISO 27001 Compliance Checklist for clear, step-by-step guidance to fast-track your certification.

End to end ISO 27001 compliance documentation

Your hub for the fundamentals of ISO 27001 compliance, curated best practices, and resources for GRC professionals.

ISO 27001 Overview

Achieve ISO 27001 Certification

ISO 27001 is the globally recognised standard for building a structured Information Security Management System (ISMS) that protects the confidentiality, integrity and availability of information. This article explains what ISO 27001 is, how it works, the core principles behind it, and what organisations must do to achieve certification. You’ll learn the standard’s structure, its key requirements, how the certification process unfolds, and the practical steps needed to implement an ISMS that is both compliant and effective.

Learn more about Achieve ISO 27001 Certification

Benefits Of ISO 27001 For Businesses

ISO 27001 certification is one of the most credible ways for businesses to prove they protect sensitive information with structure, consistency, and internationally recognised best practice. This guide explains what ISO 27001 certification is, why companies pursue it, the core business benefits, the costs involved, and how organisations of any size can achieve and maintain certification. Whether you're preparing for your first audit or strengthening your security posture, this article gives you the clarity, detail, and practical steps to move forward with confidence.

Learn more about Benefits Of ISO 27001 For Businesses

History And Evolution Of ISO 27001

ISO 27001 is now recognised as the world’s leading standard for managing information security, but its journey spans decades of technological change, emerging cyber threats, and global collaboration. This article traces the origins of ISO 27001, from its earliest foundations to the modern 2022 revision. You’ll learn how the framework developed, why it became globally adopted, how ISO 27002 fits into the picture, and how ISO standards evolved more broadly over time.

Learn more about History And Evolution Of ISO 27001
ISO 27001:2022 Requirements

Actions To Address Risks And Opportunities | Clause 6.1

Clause 6.1 of ISO 27001 defines how organisations must identify, assess, and treat information security risks — and how they must uncover opportunities to strengthen their Information Security Management System (ISMS). This clause acts as the engine of the ISO framework: it drives risk-based thinking, aligns controls to real-world threats, and ensures continual improvement. In this guide, we break down Clause 6.1 line by line, explain its relationship with Annex A, show you what documentation is required, and provide examples and best practices to help you implement it correctly and confidently.

Learn more about Actions To Address Risks And Opportunities | Clause 6.1

ISO27001 Awareness | Clause 7.3

In this article, we explore everything you need to know about ISO 27001 Clause 7.3—its purpose, what the standard requires, how awareness strengthens your ISMS, and how to build a practical, auditor-ready awareness program that supports continuous security improvement.

Learn more about ISO27001 Awareness | Clause 7.3

ISO 27001 Communication | Clause 7.4

In this guide, we break down exactly what ISO 27001 Clause 7.4 requires, why structured communication is essential to an effective ISMS, and how organisations can build a clear, compliant communication process supported by practical, real-world examples.

Learn more about ISO 27001 Communication | Clause 7.4

Internal Audit | Clause 9.2

Understanding the intricacies of ISO 27001:2022 is crucial for organisations aiming to enhance their information security management systems. Clause 9.2, which focuses on internal audits, plays a pivotal role in this context.

Learn more about Internal Audit | Clause 9.2
Information Security Management System (ISMS)

ISO 27001 ISMS Audit And Review Process

The audit and review process is one of the most important pillars of ISO 27001. It ensures your Information Security Management System (ISMS) is working as intended, risks are managed effectively, controls are operating correctly, and continual improvement is actively taking place. This guide explains every component of the ISO 27001 audit lifecycle — internal audits, external audits, certification audits, surveillance audits, and management reviews — and shows you how to prepare, what evidence auditors expect, and how to maintain long-term compliance.

Learn more about ISO 27001 ISMS Audit And Review Process

ISO 27001 ISMS Continuous Improvement Cycle

In this end-to-end guide, you’ll learn how continual improvement works in ISO 27001, why it’s essential for long-term security maturity, how the PDCA cycle operates inside an ISMS, and what processes, documentation, and actions are required to maintain compliance year after year.

Learn more about ISO 27001 ISMS Continuous Improvement Cycle
Annex A Controls — Organizational

Acceptable Use Of Assets | Annex A 5.10

Information security policies serve as the foundation of any robust cybersecurity program. Without clearly defined rules for acceptable use of information assets, organizations face increased vulnerability to data breaches, compliance violations, and operational disruptions. Control 5.10 of ISO 27001:2022 specifically addresses this critical aspect of information security management, requiring organizations to establish formal guidelines for how information and associated assets should be handled.

Learn more about Acceptable Use Of Assets | Annex A 5.10

Access Control Policies | Annex A 5.14

Information rarely stays still. Every organisation transfers data daily—between teams, systems, partners, customers, cloud platforms, and suppliers. Emails are sent, files are shared, storage media is moved, meetings are held, and conversations take place across calls and video conferences. Each transfer represents a moment of heightened risk.

Learn more about Access Control Policies | Annex A 5.14

Access Rights Management | Annex A 5.16

ISO 27001 Annex A 5.16 focuses on how organisations manage access rights by governing the full lifecycle of identities. This control ensures that only authorised users, systems, and services can access information assets, and that access is removed when no longer required.

Learn more about Access Rights Management | Annex A 5.16
Annex A Controls — People

Confidentiality And NDA Management | Annex A 6.6

Confidentiality obligations sit at the very core of information security. Without enforceable confidentiality controls, even the strongest technical safeguards can be rendered ineffective by human behaviour, contractual gaps, or unclear responsibilities. ISO 27001:2022 Annex A 6.6 formalises this reality by requiring organisations to define, implement, communicate, and enforce confidentiality and non-disclosure obligations across employees, contractors, suppliers, and other relevant parties.

Learn more about Confidentiality And NDA Management | Annex A 6.6

Disciplinary Process And Enforcement | Annex A 6.4

Establishing a fair disciplinary process is essential for organizations that want to effectively manage security violations while maintaining employee trust. When security breaches occur, organizations often struggle to respond consistently, which can lead to resentment, legal complications, or ineffective deterrence. Consequently, ISO 27001 includes specific requirements under Annex A 6.4 to ensure disciplinary processes are both fair and effective.

Learn more about Disciplinary Process And Enforcement | Annex A 6.4

Employee Screening And Background Checks | Annex A 6.1

In this guide, we explain everything organisations need to know about ISO 27001:2022 Annex A 6.1 — Employee Screening and Background Checks. You’ll learn what the control requires, why it exists, how auditors assess compliance, what evidence is expected, and how to design a screening process that is legally compliant, proportionate, and effective across different roles and risk levels.

Learn more about Employee Screening And Background Checks | Annex A 6.1
Annex A Controls — Physical

Access Control To Premises | Annex A 7.2

Physical security remains one of the most underestimated components of information security. While organisations invest heavily in cybersecurity tools, a single uncontrolled door, shared workspace, or unlogged visitor can undermine even the most mature digital controls. ISO 27001 Annex A 7.2 exists to address this exact risk by requiring organisations to establish and maintain effective access control to premises where information and information-processing facilities are located.

Learn more about Access Control To Premises | Annex A 7.2

Cabling And Electrical Security | Annex A 7.12

Modern technologies rely heavily on fiber, network, and power cables to function correctly. When we focus on ISO cyber security, we often overlook these critical components' physical vulnerabilities. Power and information cables face risks of damage and interception. Cyber criminals who gain access to fiber cables can disrupt all network traffic with simple techniques like 'bending the fiber.' This makes data and information unavailable.

Learn more about Cabling And Electrical Security | Annex A 7.12
ISO 27001 by Industry

ISO 27001 for Small Businesses

A practical guide to ISO 27001 for small businesses in the UK: how to scope the ISMS small, what certification really costs, how long it takes, the four mistakes small firms make, and when Cyber Essentials is enough instead.

Learn more about ISO 27001 for Small Businesses

ISO 27001 for Healthcare Companies

How UK health-tech firms, care providers and NHS suppliers use ISO 27001 to answer procurement security questions, and how it sits alongside the NHS DSPT, DTAC and Cyber Essentials Plus without duplicating the work.

Learn more about ISO 27001 for Healthcare Companies

ISO 27001 for Consulting Firms

How consultancies get ISO 27001 certified when their assets are people, laptops and client system access. Scoping by service line, the people and supplier controls auditors sample, and whether you need a consultant.

Learn more about ISO 27001 for Consulting Firms

ISO 27001 for Managed Service Providers

How UK MSPs certify to ISO 27001: what belongs in scope when you hold privileged access to client estates, the Annex A controls auditors focus on, and how CE+, ISO 27001 and SOC 2 fit together.

Learn more about ISO 27001 for Managed Service Providers

Your ISO 27001 Compliance Newsletter

Stay ahead with the latest expert insights, news, and updates on compliance.
Decorative