Good ISO 27001 consulting is not a document-pack delivery exercise. The goal is to help the company operate a risk-based ISMS that its own control owners can sustain and evidence.
What an ISO 27001 consultant should do
- Clarify scope: Which products, systems, locations, and teams are in the ISMS?
- Assess current state: Does the control exist, operate, and produce evidence?
- Operate risk methodology: Make risk owners, treatment, and acceptance decisions visible.
- Support the SoA and control map: Explain applicability and connect controls to accountable owners.
- Adapt policies: Avoid context-free copy/paste policy packs.
- Build the evidence system: Define what is evidenced, by whom, how often, and in which format.
- Prepare internal validation: Mature internal audit, management review, and corrective-action workflows.
- Transfer knowledge: The system should continue after the consultant leaves.
What the consultant should not do
- Guarantee certification
- Represent the independent decision of a certification body
- Claim controls operate when they do not
- Make all risk-acceptance decisions on behalf of management
- Leave generic templates disconnected from real operations
Which outputs should you ask for?
Request concrete deliverables such as a gap register, risk register, SoA support, control-owner matrix, evidence calendar, policy backlog, internal-audit readiness list, management-review pack, and 90-day action plan.
Use the ISO 27001 Readiness Assessment to create your own gap view and review the ISO 27001 consulting model.
Next step
Instead of only reading, run the related free assessment, identify missing evidence, and then scope advisory work around the decision that is actually required.
Frequently asked questions
Does this guide replace company-specific advisory?
No. It provides a general decision framework; scope, regulatory, contractual, and risk context should be evaluated for the company.
What should the first step be?
Write down the current pressure, decision owner, evidence gap, and the output that should exist in the next 30–90 days.
Sources
This content is educational. It is not legal advice, an audit opinion, or a compliance guarantee.