An online ISO consultant, with the platform included

Remote ISO 27001, ISO 9001, ISO 42001 and ISO 20000-1 implementation led by a practitioner with 20+ years in governance, risk and compliance — delivered in scheduled sessions inside a shared workspace, so you finish with a live management system instead of a document pack.

What remote delivery looks like

Gap analysis in week one

Scope, context, interested parties and a clause-by-clause gap assessment against the standard, with a phased plan and named owners.

Risk assessment done with you

A working ISO 31000-aligned register built in session — not handed over as a template you have to interpret alone.

Policies drafted in your context

AI-assisted drafting reviewed line by line by the consultant, so wording reflects how your organisation actually operates.

Internal audit and management review

Clause 9.2 and 9.3 run properly before the certification body sees them, with findings closed and evidence verified.

Stage 1 and stage 2 support

Preparation sessions, evidence rehearsal and attendance alongside your team during the certification assessment.

Handover you can maintain

Everything lives in your own workspace with owners and review dates, so surveillance year one is not another project.

Standards we support remotely

Who this service is for

Good fit
  • 5–500 people, certifying for the first time or recovering a lapsed system.
  • A named internal owner able to give a few hours a week.
  • A customer, tender or investor deadline driving the timeline.
  • Teams that already work remotely and prefer scheduled sessions to site visits.
  • Groups or consultancies needing several entities certified on one methodology.
Not a fit
  • Buying a document pack with no internal participation.
  • Wanting the consultant to also act as your certification body — that is prohibited.
  • Certification required in under six weeks with nothing in place.
  • Sites requiring physical inspection as the core of the engagement.

How engagements are structured

  1. Discovery call — scope, standard, timeline and existing maturity. No charge.
  2. Gap analysis — clause-by-clause assessment and a phased plan with effort estimates.
  3. Implementation sprints — fortnightly sessions building risk, controls, policies and evidence in your workspace.
  4. Assurance phase — internal audit, corrective actions and management review.
  5. Certification support — stage 1 and stage 2 preparation and attendance.
  6. Handover and surveillance — owners, review dates and an optional fractional retainer.

Prefer ongoing expertise to a fixed project? See consultancy and fractional leadership, or get in touch to book the discovery call.

Answers buyers, procurement and auditors want

What does an online ISO consultant actually do?+

The same work as an on-site consultant, delivered remotely: gap analysis against the standard, scope and context definition, risk assessment, policy and procedure drafting, Statement of Applicability, internal audit, management review and support through your certification body's stage 1 and stage 2 assessments. The difference is delivery — scheduled video sessions and shared workspace access instead of billed site days.

Is remote ISO consultancy accepted by certification bodies?+

Yes. Certification bodies assess your management system, not how you built it. Remote audits themselves are routine under IAF MD 4, and consultancy has no bearing on eligibility — the only rule is that your certification body cannot also consult on the system it certifies.

How much does an online ISO consultant cost?+

Remote delivery removes travel and site-day costs, which is usually where fixed-price ISO projects inflate. We quote per phase rather than per day so you can see what implementation, internal audit and certification support each cost. See the ISO 27001 certification cost guide for a full line-by-line breakdown.

How long does ISO 27001 take with remote support?+

For a team under 50 people with reasonable existing practice, 3–4 months from kick-off to stage 1 is realistic; 6 months is typical where policies, risk management and evidence all need building from scratch. The variable is your availability for evidence collection, not the consultant's.

Do we need the software as well as the consultancy?+

No, but they work better together. The platform holds the risk register, controls, policies, evidence and audit records the consultant produces, so when the engagement ends you own a live management system rather than a folder of documents that ages immediately.

Can you support multiple standards at once?+

Yes. An integrated management system covering, for example, ISO 27001 and ISO 9001, or ISO 27001 and ISO 42001, shares context, leadership, internal audit and management review clauses. Running them together is materially cheaper than sequential projects.

Who is not a good fit for this service?+

Organisations wanting a document pack with no internal involvement. Certification bodies interview your staff, and a system nobody in the business recognises fails stage 2. If you cannot commit a named internal owner for a few hours a week, remote delivery will struggle.

Which regions do you work with?+

Primarily the UK, with clients across the EU and North America. Remote delivery means timezone, not geography, is the only real constraint — we schedule around UK business hours with flexibility for US and EU teams.

Book a discovery call with an online ISO consultant

Thirty minutes, no charge: we will tell you the realistic timeline, the effort your team needs to commit, and whether you need consultancy at all or just the platform.

Prefer a conversation? Email hello@iso-standard.app — a practitioner responds within one business day.

AI-enabled — privacy-respecting

AI does the drafting. You keep the control — and the data.

How we handle data →
  • AI that assists — not replaces

    Assisted drafting for policies, risks, controls and buyer questionnaires. Every AI suggestion is reviewed and approved by you before it lands in the record.

  • Opt-in, workspace-scoped

    AI features run only when you invoke them, only against the workspace you're in. We never mine your data to answer someone else's prompt.

  • Your data stays yours

    Prompts routed via the AI Gateway to model providers whose API terms exclude your content from model training. Nothing is sold or shared for advertising.

  • Isolated by design

    Row-level security enforces workspace boundaries at the database. MFA, SSO, audit logs and least-privilege roles govern who sees what.

We never sell personal information, never share it for advertising, and never use your workspace content to train third-party models. Full sub-processor list and Acceptable Use Policy on the Trust page.

MM
Michael McCarroll
Founder · 25+ years
IT governance · Information security · AI
Why this platform exists

Enterprise-grade governance — built for the SMEs and consultants enterprise GRC forgets.

I've spent 25 years in corporate governance — aligning technology, controls and compliance with what the business is actually trying to do. Time and again, the same pattern: the organisations that win new clients aren't the ones with the biggest GRC budget. They're the ones who can demonstrate trust on demand. This platform is the tool I wanted for the SMEs and consultants I've worked with — institutional-grade governance without an institutional price tag, built on the way audits and buyer reviews actually happen.