Skip to content

ISO STANDARDS · 30 JULY 2026 · 1 MIN READ

Five mistakes companies make during ISO certification

Treating it as a document project, over-scoping, outsourcing ownership, gold-plating controls and stopping at the certificate, and what to do instead.

1. Treating it as a document project

The first instinct is to buy or write the documents. Documents are necessary and they are the easy part. The auditor certifies a running system: records of audits, reviews, actions and evidence over time. Start the system on day one; the documents fall out of it.

2. Scoping everything

An ISMS that covers every entity, site and system in a group is three times the work and no more convincing to a client. Scope to what the client or tender actually asks about. You can extend at surveillance.

3. Outsourcing ownership

A consultant can build the system. They cannot own it. When they leave, the system leaves with them unless every requirement has an internal owner who understands why it exists. Insist on owners from week one; the auditor will interview them, not the consultant.

4. Gold-plating controls

Not every Annex A control needs to be implemented at enterprise grade. The standard asks for controls proportionate to your risk assessment, justified in the Statement of Applicability. A well-argued "not applicable" is fine. A half-implemented "applicable" is a finding.

5. Stopping at the certificate

Surveillance audits come every year. Systems that were built for Stage 2 and then abandoned fail in year two, and the recovery costs more than keeping the ledger true would have. Cadences, expiry dates and reassessment schedules are not admin, they are the system.

By ISO Assist. Tagged CERTIFICATION · PROGRAMME · LESSONS.

More in ISO standards

Reading about it is the slow way.

Book a demo and see the standard adopted in a workspace.