ISO Certification FAQs | ISO 9001, 14001, 27001 & 45001 Explained | Goldenpath
● Help Centre

Frequently Asked Questions

Plain-English answers to the questions UK SMEs ask most about ISO certification — cost, timelines, audits, requirements and what happens when something doesn't go to plan. Can't find what you need? Call us on 01553 341004.

5.0 Google rating ★★★★★
50+ Years' combined
ISO experience
4 ISO standards covered
end-to-end
UKAS Accredited certification
pathway
Cost depends on the standard, your staff numbers, turnover, complexity, and which accreditation body you choose. As a guide, accreditation body fees typically start around £2,000 + VAT and travel, with Goldenpath's implementation and consultancy fee starting at £3,500 + VAT and travel. ISO 27001 and ISO 45001 can run higher than ISO 9001 due to the extra scope of risk assessment work (information assets for 27001, physical health and safety risks for 45001). Ask us for a bespoke quotation for your specific standard and business.
Be wary of claims about getting ISO certification in 30–45 days. Technically it's possible — and we can fast-track ISO 9001 — but it's unlikely unless you can devote a staff member to the implementation alongside the consultant. Allow 3–5 months, which is a more comfortable timeline.

Each standard manages a different type of risk, but they share the same high-level structure:

ISO 9001 — quality management. Focuses on consistently meeting customer and regulatory requirements through documented processes and continuous improvement.

ISO 14001 — environmental management. Focuses on reducing environmental impact: waste, emissions, energy use and resource efficiency.

ISO 27001 — information security management. Focuses on protecting the confidentiality, integrity and availability of business information and data.

ISO 45001 — occupational health and safety. Focuses on preventing workplace injury and ill health.

There are two types of audit, and the process is the same whether you're certifying to ISO 9001, ISO 14001, ISO 27001 or ISO 45001. The mandatory internal audit is where your consultant checks that all the information needed for compliance is in place — a company can audit its own work, but this isn't considered good practice and can lead to costly non-conformances, or even a rescinded certificate. The annual external audit is where the accreditation body examines all the evidence. This is normally face-to-face and can take up most of a day.
All ISO management system standards (9001, 14001, 27001, 45001) require a documented system including defined processes, performance monitoring, and continuous improvement practices, plus leadership commitment, risk-based thinking, and compliance with applicable legal and regulatory requirements. The specific risks you assess differ by standard — for example ISO 27001 focuses on information security risks, ISO 45001 on health and safety risks, and ISO 14001 on environmental risks. Call us for a detailed breakdown for the standard you're working towards.
A certified company benefits from improved efficiency, more consistent outcomes, and increased stakeholder confidence through standardising processes and continual improvement. Certification also enhances credibility, opens up new market opportunities (many tenders and enterprise clients require it), and helps meet regulatory or contractual requirements — whether that's quality (ISO 9001), environmental performance (ISO 14001), information security (ISO 27001), or health and safety (ISO 45001).
Most likely not. Your business is running, you and your staff know how to do things, you're successful, and customers wouldn't keep coming back if they weren't satisfied. ISO puts a system around the running of your business so that your current standards are maintained and improved as the business grows.

Maintaining records is a requirement for ISO compliance, but it's far from burdensome — chances are you already have many of them in place.

With today's electronic systems, record-keeping is simpler and more efficient than ever. These tools not only make transactions easily traceable but also allow you to extract valuable data for analysis and continuous improvement.

There are two main types of audit involved in ISO compliance: internal and external. Internal audits are carried out by your own team or trusted advisors like Goldenpath, while external audits are conducted by an independent, accredited certification body.

The duration depends on the size and complexity of your business. Internal audits can often be broken into manageable sections, minimising disruption to your daily operations. In most cases, audits take just one day, though larger organisations may require two or three days to complete the process thoroughly.

And don't worry — auditors aren't here to catch you out. Their role is to verify that your processes align with the standard and to help you demonstrate conformance with confidence. Read more about how Goldenpath supports every audit through our ongoing compliance support.

"Non-conformance" — it's the term that often causes the most concern when it comes to ISO certification.

But whether it's a mistake, a complaint, an error, or simply a misunderstanding, the reality is that things sometimes go wrong. And that's okay — we're all human.

What matters is how you respond. ISO provides a clear framework to help you identify and analyse the root cause of the issue, which often turns out to be different from what you first expected. From there, it guides you toward practical solutions to prevent it from happening again — turning problems into opportunities for continuous improvement. Our Managed Compliance service handles non-conformance tracking and corrective actions for you on an ongoing basis.

Certification & standards questions

ISO certificates are valid for 3 years. Annual surveillance audits are required in years 1 and 2 to maintain certification, followed by a full recertification audit in year 3. This applies across ISO 9001, ISO 14001, ISO 27001 and ISO 45001. Goldenpath's Managed Compliance retainer handles surveillance audit preparation so your certificate stays active without extra admin on your end.
Yes. A certificate can be suspended or withdrawn if your business fails a surveillance audit, doesn't resolve a major non-conformance within the required timeframe, or stops operating the management system as documented. Staying on top of internal audits and corrective actions is the best way to protect your certification long-term.
ISO certification is voluntary in the UK — there's no legal requirement to hold it. However, many tenders, contracts, and enterprise clients require it as a condition of doing business, which is why most SMEs pursue it for commercial rather than legal reasons.
A consultant like Goldenpath helps you build, implement, and prepare your management system. A certification body — which must be UKAS-accredited to be recognised in the UK — independently audits your system and issues the certificate. A consultant cannot certify you; the two roles are kept separate to ensure impartiality.
Yes. ISO 9001, ISO 14001, ISO 27001 and ISO 45001 share a common high-level structure, making it straightforward to combine them into a single Integrated Management System (IMS). This avoids duplicate documentation and is usually more cost-effective than certifying each standard separately.
You won't simply "fail" — auditors raise non-conformances rather than pass/fail verdicts. A minor non-conformance gives you time to submit a corrective action plan. A major non-conformance must be resolved, often within 90 days, before certification can be granted or maintained. Your consultant and certification body will guide you through the process.

Ongoing compliance & support questions

Certification is the beginning, not the end. ISO certificates require annual surveillance audits in years 1 and 2 and a full recertification audit in year 3. Your management system also needs to be actively maintained between audits — updating documents, completing internal audits, managing non-conformances, and reviewing objectives. Without this, you risk failing a surveillance audit and losing your certificate. Goldenpath's Managed Compliance retainer takes all of that off your desk completely.

Managed Compliance is Goldenpath's recommended monthly retainer for businesses that want to stay certified without adding to their management workload. It includes ongoing internal audits, system updates, corrective action management, regular check-ins, and full audit-day support — so your certificate stays active year after year with no last-minute panic.

On average, clients using Managed Compliance save 6–12 hours per month across their leadership and operations team compared to managing it themselves.

A Readiness Sprint is a fixed-fee project designed to get you certified as efficiently as possible — gap analysis, system build, documentation, and pre-audit preparation. It's ideal if you're working towards a tender deadline or want to achieve certification for the first time. Managed Compliance is the monthly retainer that takes over once you're certified, handling all the ongoing maintenance, audits and updates so your certificate stays valid. Many clients start with a Readiness Sprint and roll straight into Managed Compliance.
Yes. Goldenpath offers add-on support for EcoVadis, Constructionline, Achilles, and EN 1090 accreditations, which can be integrated into your existing ISO management system. These are particularly useful for companies strengthening their tender submissions and supply chain credibility. They're designed to expand your compliance without creating duplicate documentation or extra overhead.
Yes — this is something we do regularly. If you're already certified but your current management system has become a burden, your previous consultant has moved on, or you simply want more reliable ongoing support, Goldenpath can step in and take over. We'll carry out a review of your existing system, identify any gaps, and transition you into our Managed Compliance retainer with minimal disruption. Call us on 01553 341004 to discuss.

From question to certified

Most clients follow the same three-step path — here's what it looks like end to end.

1

Discovery Call

A free, no-pressure 15-minute call to understand your business, timeline, and which standard fits. You'll leave with a clear, fixed-fee proposal.

2

Readiness Sprint

A fixed-fee project to get you certified — gap analysis, system build, documentation, and pre-audit preparation, done alongside your team.

3

Managed Compliance

Once certified, our monthly retainer keeps you audit-ready — internal audits, updates, and full support at every surveillance and recertification audit.

★★★★★ 5.0 Google Rating
★★★★★

"Have been working alongside Rowland to secure ISO 9001 & ISO 14001. Great consultant with excellent knowledge. Rowland is very helpful and goes the extra mile to help you. Would definitely recommend the services of Goldenpath Process Management!"

Nathan Oates — Director, Orvarto
★★★★★

"Professional and excellent service throughout. Would 100% recommend reaching out to Goldenpath for any help with ISO certifications."

Jessie Heath — General Manager, Walther Strong & Company Ltd
★★★★★

"We had previously tried to achieve this in-house by employing someone which didn't work. Using Goldenpath did work — fully recommend their services."

Riley Mytton — General Manager, Atlantis Tanks Group Ltd

Still have questions?

Book a free, no-pressure 15-minute discovery call. We'll answer your questions and provide a clear fixed-fee proposal — no obligation.

No spam. No obligation. We respond within 1 business day.

5.0