Frequently Asked Questions
Plain-English answers to the questions UK SMEs ask most about ISO certification — cost, timelines, audits, requirements and what happens when something doesn't go to plan. Can't find what you need? Call us on 01553 341004.
ISO experience
end-to-end
pathway
Each standard manages a different type of risk, but they share the same high-level structure:
ISO 9001 — quality management. Focuses on consistently meeting customer and regulatory requirements through documented processes and continuous improvement.
ISO 14001 — environmental management. Focuses on reducing environmental impact: waste, emissions, energy use and resource efficiency.
ISO 27001 — information security management. Focuses on protecting the confidentiality, integrity and availability of business information and data.
ISO 45001 — occupational health and safety. Focuses on preventing workplace injury and ill health.
Maintaining records is a requirement for ISO compliance, but it's far from burdensome — chances are you already have many of them in place.
With today's electronic systems, record-keeping is simpler and more efficient than ever. These tools not only make transactions easily traceable but also allow you to extract valuable data for analysis and continuous improvement.
There are two main types of audit involved in ISO compliance: internal and external. Internal audits are carried out by your own team or trusted advisors like Goldenpath, while external audits are conducted by an independent, accredited certification body.
The duration depends on the size and complexity of your business. Internal audits can often be broken into manageable sections, minimising disruption to your daily operations. In most cases, audits take just one day, though larger organisations may require two or three days to complete the process thoroughly.
And don't worry — auditors aren't here to catch you out. Their role is to verify that your processes align with the standard and to help you demonstrate conformance with confidence. Read more about how Goldenpath supports every audit through our ongoing compliance support.
"Non-conformance" — it's the term that often causes the most concern when it comes to ISO certification.
But whether it's a mistake, a complaint, an error, or simply a misunderstanding, the reality is that things sometimes go wrong. And that's okay — we're all human.
What matters is how you respond. ISO provides a clear framework to help you identify and analyse the root cause of the issue, which often turns out to be different from what you first expected. From there, it guides you toward practical solutions to prevent it from happening again — turning problems into opportunities for continuous improvement. Our Managed Compliance service handles non-conformance tracking and corrective actions for you on an ongoing basis.
Certification & standards questions
Ongoing compliance & support questions
Managed Compliance is Goldenpath's recommended monthly retainer for businesses that want to stay certified without adding to their management workload. It includes ongoing internal audits, system updates, corrective action management, regular check-ins, and full audit-day support — so your certificate stays active year after year with no last-minute panic.
On average, clients using Managed Compliance save 6–12 hours per month across their leadership and operations team compared to managing it themselves.
Still not sure which standard you need?
A quick side-by-side to help you self-select — click a card to see the full requirements for that standard.
ISO 9001
Quality management. Best if you need consistent output, fewer errors, and to win tenders that ask for QMS certification.
See ISO 9001 → 🌱ISO 14001
Environmental management. Best if clients or tenders ask about waste, emissions or energy use, or you want to cut environmental impact.
See ISO 14001 → 🔒ISO 27001
Information security. Best if you handle client data, IT systems, or need to prove information security to enterprise customers.
See ISO 27001 → 🦺ISO 45001
Health & safety. Best if your team works on-site, in manufacturing, construction, or anywhere workplace risk needs managing.
See ISO 45001 →From question to certified
Most clients follow the same three-step path — here's what it looks like end to end.
Discovery Call
A free, no-pressure 15-minute call to understand your business, timeline, and which standard fits. You'll leave with a clear, fixed-fee proposal.
Readiness Sprint
A fixed-fee project to get you certified — gap analysis, system build, documentation, and pre-audit preparation, done alongside your team.
Managed Compliance
Once certified, our monthly retainer keeps you audit-ready — internal audits, updates, and full support at every surveillance and recertification audit.
"Have been working alongside Rowland to secure ISO 9001 & ISO 14001. Great consultant with excellent knowledge. Rowland is very helpful and goes the extra mile to help you. Would definitely recommend the services of Goldenpath Process Management!"
"Professional and excellent service throughout. Would 100% recommend reaching out to Goldenpath for any help with ISO certifications."
"We had previously tried to achieve this in-house by employing someone which didn't work. Using Goldenpath did work — fully recommend their services."
Still have questions?
Book a free, no-pressure 15-minute discovery call. We'll answer your questions and provide a clear fixed-fee proposal — no obligation.
No spam. No obligation. We respond within 1 business day.
