Skip to content
LokalMatch

ISO Consultants

ISO Consultants near you

An ISO consultant helps an organisation build a management system that meets the requirements of a published standard, and prepares it for the audit that leads to certification. The standards most often involved are ISO 9001 for quality management, ISO 14001 for environmental management, ISO 45001 for occupational health and safety management, and ISO/IEC 27001 for information security management. The work usually means turning things a business already does informally into defined processes, with records that demonstrate the processes are followed and improved.

Tell us what you need and we’ll help you find ISO consultants who serve your area.

Free for homeowners · No obligation to hire

On this page

One structural fact matters more than anything else when hiring. A consultant cannot certify you. Certification is issued by a certification body, and in Canada those bodies are accredited by the Standards Council of Canada, which runs its management systems accreditation programme on the basis of ISO/IEC 17021-1, the international standard for management systems audit and certification. The Council accredits the certification bodies; it does not certify the organisations that seek certification. So a firm offering to both prepare you and certify you is describing something that accredited certification does not permit, and that is a warning sign rather than a convenience. This guide is general information, not legal or financial advice.

The management system standards most often certified

  • ISO 9001: quality management systems, the most widely held of the management system standards.
  • ISO 14001: environmental management systems, covering how an organisation manages its environmental responsibilities.
  • ISO 45001: occupational health and safety management systems.
  • ISO/IEC 27001: information security management systems, frequently requested by enterprise and public-sector customers.
  • ISO 22301: business continuity management systems, for organisations that need certified continuity arrangements.
  • ISO 50001: energy management systems, one of the further sub-programmes covered by Canadian accreditation.

The route from first meeting to certificate

Most engagements begin with a gap analysis: comparing what the organisation already does against the requirements of the standard. Well-run businesses usually find they satisfy more of it than expected, but informally, without the documented processes and records an auditor can examine. The consultant's real job is to close those gaps without burying the operation in paperwork it will abandon within a year.

Building the system follows. Scope is defined, processes are documented, responsibilities are assigned and the records that evidence conformity start being kept. Two internal steps then have to happen before any external audit is worth booking: an internal audit, in which the organisation checks itself against the standard and records what it finds, and a management review, in which leadership formally considers whether the system is working and what needs to change. Standards expect both, and auditors look for them early.

External certification audit is generally carried out in two stages by the certification body: a first stage reviewing documentation and readiness, and a second examining implementation in practice. Findings are raised, the organisation corrects them, and a certificate is issued by the certification body if the outcome is satisfactory. The consultant can prepare you for all of this and can be present, but the audit decision belongs to the certification body alone.

Accreditation: who is entitled to certify you

ISO develops and publishes the standards. It does not audit organisations or issue certificates against them; that is done by certification bodies, which are separate commercial organisations. The credibility question is therefore not whether a certification body exists but whether it is accredited, and by whom.

In Canada, the Standards Council of Canada is the accreditation body, and it describes itself as the only internationally recognised accreditation body in the country offering a management systems accreditation programme. That programme is based on ISO/IEC 17021-1, the international standard for bodies providing management systems audit and certification, with sub-programmes covering quality, environmental, occupational health and safety, information security and energy management systems among others. The Council evaluates and accredits certification bodies to confirm their competence to audit and certify organisations; accreditation is not granted to the organisations seeking certification themselves.

Recognition travels through the International Accreditation Forum. The Council is a signatory to the Forum's Multilateral Recognition Arrangement for most of its management systems sub-programmes, which is why a certificate from a body it accredits is accepted internationally. That is the practical reason to care about accreditation: an unaccredited certificate may satisfy nobody outside the room it was printed in. Ask a certification body which accreditation it holds and for which sub-programme, and check it against the accreditation body's own records rather than a logo on a website.

Warning signs when hiring an ISO consultant

  • Any offer to both prepare your management system and certify it, which accredited certification does not allow.
  • A guaranteed certificate, when the decision rests with an independent certification body after an audit.
  • A promised certification date that leaves no time for an internal audit and management review beforehand.
  • Generic templates with another company's processes lightly renamed, which auditors recognise immediately.
  • A documentation set so heavy that nobody in the business will maintain it after the auditor leaves.
  • Vagueness about which accreditation the proposed certification body holds, or for which standard.
  • No plan for who runs the system internally once the consultant's engagement ends.

What happens after the certificate is issued

Certification is not a one-off event. Certification bodies carry out periodic surveillance audits during the life of a certificate to confirm the system is still operating, and recertification is required at the end of the cycle rather than the certificate simply continuing. A system that is assembled for the initial audit and then quietly abandoned tends to be found out at the first surveillance visit.

The organisations that get value from certification treat the system as the way the work is done rather than as a parallel set of records. Internal audits continue on a schedule, management review happens as a real meeting with decisions attached, nonconformities are recorded and closed out, and improvements are documented as they happen. The measure of a good consulting engagement is whether the system is still running, and still useful, at the first recertification.

Consultant, certification body or doing it in-house

These are three distinct roles and the boundary between the first two is enforced by the accreditation rules. A consultant helps you design, document and implement the system. A certification body audits it independently and issues the certificate. Keeping those separate is the whole basis of the certificate being worth anything to a customer, since impartiality is what accreditation under ISO/IEC 17021-1 is built around.

Doing it in-house is entirely possible, and organisations with an existing quality or safety function often should. The standards are published documents, and nothing requires an external consultant. What in-house work needs is genuine time from someone who understands both the standard and the operation. Where consultants earn their fee is in speed, in knowing what auditors actually look for, and in avoiding the over-documentation that first-timers reliably produce. A sensible middle path is to use a consultant for the gap analysis and system design, then run the internal audits and management review yourself, so the capability stays in the building.

How ISO projects are scoped, and how LokalMatch requests reach consultants

Scope depends on the standard, the number of sites and employees in scope, the complexity of the processes being certified, and how much of a documented system already exists. An organisation with mature procedures and existing audit records needs much less help than one starting from nothing. Remember that a consultant's fee and the certification body's audit charges are separate arrangements with separate organisations, and that the certification body is engaged by you rather than by the consultant. Ask for both to be set out clearly before committing.

On LokalMatch you describe which standard you are pursuing, what prompted it, the size and structure of your operation and your target timeframe, and ISO consultants working in your area get in touch. LokalMatch is not a certification body, does not audit or certify anyone and does not screen, rank or recommend the consultants who respond; consultants pay for the requests they receive, so speaking to several costs you nothing. Ask each consultant which accredited certification bodies their clients have used, and treat an offer to handle the certification itself as a reason to look elsewhere.

ISO Consultants: frequently asked questions

Can the consultant who builds my system also certify it?

No, and an offer to do both should end the conversation. Certification is issued by a certification body accredited under ISO/IEC 17021-1, a standard built around the impartiality of the certifying organisation. The firm that helps you design and implement the system cannot also provide the independent audit that gives the certificate its value.

Does ISO itself certify companies?

No. ISO develops and publishes the standards. Audits and certificates come from certification bodies, which are separate organisations, and in Canada those bodies are accredited by the Standards Council of Canada under its management systems accreditation programme. A claim to be certified by ISO directly misdescribes how the system works.

How do I check that a certification body is legitimate?

Ask which accreditation body has accredited it and for which sub-programme, then verify that with the accreditation body rather than relying on logos. In Canada the Standards Council of Canada accredits certification bodies for management systems and is a signatory to the International Accreditation Forum's Multilateral Recognition Arrangement for most of those sub-programmes, which is what gives certificates international acceptance.

Which ISO standard does my business actually need?

It depends on what you are being asked for. ISO 9001 covers quality management, ISO 14001 environmental management, ISO 45001 occupational health and safety, and ISO/IEC 27001 information security. Most organisations pursue certification because a customer, a tender or a sector expectation requires a specific one, so establish which is being asked for before scoping any work.

Do I need a consultant at all?

No. The standards are published and an organisation can implement one itself, particularly where a quality or safety function already exists. A consultant mainly buys speed and familiarity with what auditors look for. Whichever route you take, someone internal has to understand and own the system, because it has to keep running after certification.

What happens after we are certified?

The certification body conducts periodic surveillance audits to confirm the system is still operating, and recertification is required at the end of the cycle. Internal audits, management reviews and the closing out of nonconformities continue throughout. Certification records how the organisation works, so it only holds up if the organisation keeps working that way.

Sources

  1. Standards Council of Canada: Management Systems accreditation programme
  2. Standards Council of Canada: Quality Management Systems accreditation
  3. Standards Council of Canada: Information Security Management Systems accreditation
  4. ISO: Certification
  5. ISO: Management system standards
  6. ISO 14001:2015 Environmental management systems

Written by the LokalMatch editorial team. Last reviewed September 14, 2026. How we write and check our guides

Find ISO consultants by city

Nunavut

Show 1 cities

Ontario

Show 71 cities

Quebec

Show 74 cities

Yukon

Show 1 cities

What affects the fees ISO consultants charge

Fees depend on the work involved and how the professional bills. We only publish fee ranges when they’re backed by real LokalMatch data or reliable sources. Until then, here’s what usually changes the fee:

  • Scope and complexity of the work
  • How the firm bills: hourly, per project or on a monthly retainer
  • Experience of the team
  • Timeline and how urgent the work is
  • Ongoing support after the work is delivered

How to compare ISO consultants before you hire

  • Ask for examples of similar work for clients like you.
  • Read reviews and ask for references you can contact.
  • Make sure the scope, deliverables and timeline are written down before work starts.
  • Ask who will do the work: an in-house team, freelancers or subcontractors.
  • Compare two or three proposals before you decide.

Questions to ask ISO consultants before you hire

  • Have you done work like this before, and can I see examples?
  • Who will work on this, and who is my main contact?
  • How do you charge: hourly, per project or monthly?
  • What is included, and what costs extra?
  • How long is the contract, and how can either side end it?
  • How will you report on progress?
  • Who owns the work, files and accounts you set up for me?

Licences and registration

This kind of work is often limited to licensed or registered professionals, and the rules depend on where you are. Ask which body they’re registered with, and check their status on that body’s public register before you hire.

Ready to contact ISO consultants?

Tell us what you need in a few sentences.