ISO management systems

ISO Consultant vs Certification Body: What Is the Difference?

Organisations working towards ISO 45001 or ISO 14001 usually deal with two quite different kinds of organisation: a consultant and a certification body. Their roles are often confused, and some marketing blurs them deliberately. Understanding the difference protects the value of the certificate you end up with.

What an ISO consultant does

A consultant helps you develop, implement, maintain and improve a management system. Depending on what you need, that can include a gap assessment, planning, designing processes with you, coaching the people who will run the system, supporting internal audits and preparing for the certification audit. A consultant does not decide whether you meet the standard, and cannot issue a certificate.

What a certification body does

A certification body is an independent third party. It audits your management system against the standard and decides whether to certify it. For an initial certification that means a two-stage audit: the first stage reviews whether the system is ready, and the second assesses whether it has been implemented effectively. After certification it carries out surveillance audits during the three-year certificate cycle, followed by a recertification audit.

Why the two roles are kept separate

Accredited certification bodies work to an international standard for bodies that audit and certify management systems, ISO/IEC 17021-1. Its central principle is impartiality. A certification body must not provide management system consultancy to an organisation it certifies, and it has to manage any risk to impartiality arising from relationships with consultancies.

That separation is what gives an accredited certificate its value. The auditor has no stake in a system they helped to build, so a client reading your certificate can trust that someone independent has examined it.

What accreditation means

Accreditation is the check on the checkers. In the UK the national accreditation body is UKAS, which assesses whether certification bodies are competent and impartial for the standards they certify. A certificate issued under UKAS accreditation can carry the UKAS mark for that scope.

Certificates from bodies operating outside recognised accreditation are not subject to the same oversight, and some clients and tenders specifically require accredited certification. You can check a certification body's accreditation on the UKAS website, and many accredited certificates can be verified through IAF CertSearch.

Warning signs

  • A certificate that is guaranteed before any audit has taken place
  • One organisation offering to write your system and certify it
  • Very short timescales with no evidence that the system has actually operated
  • A certification body that cannot show accreditation for the standard you need
  • A pack of template documents presented as a finished management system

How the two work together on a project

  1. The consultant assesses your current arrangements and agrees a plan with you.
  2. You implement the system, with as much or as little consultancy support as you need.
  3. Internal audits and a management review are completed, so the system has been through a full check cycle.
  4. You choose an accredited certification body and book the audits.
  5. The certification body carries out the two-stage initial audit and makes its certification decision.
  6. Surveillance audits follow, and you maintain and improve the system between them.

Some organisations ask their consultant to be available during the certification audit. Practice varies between certification bodies, and the consultant cannot take part in the audit itself.

Where Featherstone Safety fits

Featherstone Safety is a consultancy. We are not a certification body, we do not issue certificates and we have no commercial tie to any certification body. We help organisations build and run ISO 45001 and ISO 14001 systems that reflect how they actually work, and we help them prepare for an independent audit. See our ISO 45001 consultancy and integrated management system support.

Frequently asked questions

Can my ISO consultant certify my organisation?

No. Certification is decided and issued by an independent certification body. Accredited certification bodies are not allowed to certify a management system they have provided consultancy on, which is why the two roles are kept separate.

Should we appoint a consultant or a certification body first?

Usually a consultant or internal lead first, to assess readiness and plan the work. It is still worth getting certification body quotes early, because their fees are a separate budget and audit dates can affect your timetable.

Does an ISO certificate mean we are legally compliant?

No. Certification shows that, at the time of audit, your management system was found to conform to the standard. It does not transfer your legal duties or prove compliance with every legal requirement, although a good system should help you identify and meet them.

How can we check a certificate is genuine?

Ask the certification body to confirm it, check the body is accredited for that standard on the UKAS website, and look the certificate up on IAF CertSearch where it is listed.

This guide gives general information about UK health and safety law. It is not legal advice, and duties remain with the employer and other dutyholders.

Planning an ISO 45001 or ISO 14001 project?

Featherstone Safety is an independent consultancy supporting organisations in London and across the UK to implement and maintain ISO management systems. We scope every project before quoting, and we do not issue certificates.

Try the ISO 45001 readiness checklist