Choosing an ISO consultant is one of the most consequential decisions a Malaysian SME makes in its certification journey. The right consultant builds a management system that improves your operations, passes audits smoothly, and pays for itself through better processes and new business opportunities. The wrong one delivers a pile of documentation that looks good on paper, fails its first surveillance audit, and leaves you worse off than before.
After guiding over 200 organisations through ISO certification, we have seen both sides. This guide shares the criteria that actually matter — and the red flags that should make you walk away.
1. Industry experience — not just ISO experience
ISO knowledge is table stakes. What separates good consultants from average ones is whether they understand your industry. A consultant who has implemented ISO 9001 for 50 IT companies may struggle with a manufacturing environment where the processes, risks, and regulatory requirements are fundamentally different.
Ask specifically: "Have you worked with companies in our industry?" and "Can you share references from similar organisations?" A consultant who has worked with manufacturing, construction, food production, or medical devices will understand the operational realities — not just the standard's requirements.
At Cari Consultancy, our team has hands-on experience across manufacturing, construction, food and beverage, oil and gas, medical devices, and professional services — which is why our systems are built around how businesses actually operate, not how a textbook says they should.
2. Methodology — how will they actually do the work?
A credible consultant should be able to walk you through their methodology clearly before you sign anything. Ask for a project plan or at minimum an outline of the phases involved.
A solid ISO consultancy engagement typically follows this structure:
- Gap analysis — Assess current practices against the standard's requirements
- System design — Define the scope, processes, and documentation structure
- Documentation development — Policies, procedures, work instructions, forms
- Implementation support — Roll out the system on the ground, not just on paper
- Training — Awareness training for all staff, internal auditor training for audit team
- Internal audit — Verify the system works before the certification body arrives
- Management review — Ensure leadership engagement and direction
- Certification support — Guide you through Stage 1 and Stage 2 audits
If a consultant's proposal skips the gap analysis and jumps straight to "we will provide documentation templates," be cautious. Template-based approaches produce systems that look identical across different companies — and external auditors can spot them immediately. Your management system should reflect how your business operates, not a generic template.
3. On-site presence vs remote-only
ISO implementation is not a desktop exercise. Your consultant needs to walk your production floor, observe your processes, talk to your operators, and understand how work actually gets done — not just how it is described in a meeting room.
Be wary of consultants who propose a fully remote engagement for initial certification. Remote support works well for ongoing maintenance and surveillance audit preparation, but the initial implementation requires physical presence to understand your operations, identify risks, and build a system that your team can actually use.
Ask how many on-site visits are included in the proposal and what the consultant will be doing during each visit.
4. Training and knowledge transfer
The best consultants work themselves out of a job. After certification, your team should be able to maintain and improve the system independently — or at least with minimal external support. This means genuine knowledge transfer, not dependency.
Check whether the proposal includes internal auditor training (your team needs to conduct internal audits independently), management system awareness training (staff understanding their roles), and practical coaching on document control, corrective actions, and management review.
If the consultant's model requires you to call them for every internal audit and management review indefinitely, you are paying for dependency — not capability. Cari Consultancy's training programmes are designed to make your team self-sufficient.
5. Transparent pricing — no hidden costs
A reputable consultant provides a clear breakdown of what is included in their fee and what is not. Watch for proposals that look cheap upfront but exclude critical elements.
| Should Be Included | Watch for These Extras |
|---|---|
| Gap analysis | "Gap analysis is a separate engagement" |
| Documentation development | "Documentation review is additional" |
| Implementation support (on-site) | "On-site visits charged separately per day" |
| Internal auditor training | "Training is optional and costs extra" |
| Internal audit conduct | "Internal audit is a separate service" |
| Pre-certification review | "Mock audit available at additional cost" |
| Stage 1 & 2 audit support | "Audit attendance is additional" |
For reference, ISO consultancy fees in Malaysia typically range from RM 8,000–RM 25,000 for a single standard (SME) and RM 25,000–RM 55,000 for an IMS. Certification body audit fees are always separate. See our ISO Certification Cost Guide for a full breakdown.
6. Track record and references
Ask for specific numbers and verifiable references. A good consultant should be able to tell you how many organisations they have guided to certification, their success rate, and provide contact details for past clients willing to speak with you.
Questions to ask references: Did the system pass the certification audit on the first attempt? Was the consultant responsive and accessible during implementation? Does the system still work 12 months after certification — or did it collapse at the first surveillance audit? Would you hire them again?
7. Post-certification support
Certification is not the finish line — it is the starting point. Your management system needs to be maintained, your surveillance audits need preparation, and your team may need ongoing support as they encounter new situations.
Ask what post-certification support is available: surveillance audit preparation, system updates when processes change, and ongoing advisory services. The best consultants offer flexible maintenance retainers that keep your system healthy without requiring a full re-engagement each year.
Red flags: when to walk away
- "We guarantee certification" — No ethical consultant can guarantee a certification body's decision. They can guarantee thorough preparation, but the audit outcome is the certification body's call
- "We can do it in 4 weeks" — Rushed implementations produce systems that fail surveillance audits. A minimum of 4 months is realistic for most SMEs
- "We also do the certification audit" — Consultancy and certification must be independent. If the same company offers both, this violates accreditation rules
- No references or vague client claims — A consultant with genuine experience will happily connect you with past clients
- Template-only approach — If they hand you a USB drive of generic documents and call it "implementation," you are paying for paper, not a system
- No on-site visits proposed — A management system built entirely from a desk will not reflect your actual operations
Frequently Asked Questions
Consultancy fees typically range from RM 8,000–RM 25,000 for a single standard (ISO 9001) for an SME, and RM 25,000–RM 55,000 for an Integrated Management System. Certification body audit fees (RM 5,000–RM 15,000) are separate. See our full cost breakdown.
Self-implementation is possible but typically takes 2–3 times longer, carries higher audit risk, and often produces a system that works on paper but not in practice. A good consultant brings experience from hundreds of implementations and builds a system that actually improves your operations.
Ask for client references in your industry, a sample project plan, and consultant qualifications (Lead Auditor certificates, industry experience). Ask how many organisations they have guided to certification. Be wary of consultants who cannot provide references or who guarantee certification outcomes.
No. This is a conflict of interest prohibited by accreditation rules. The consultant who builds your system must be independent from the organisation that audits and certifies it.
For a cost breakdown, see our ISO Certification Cost Guide. For a step-by-step certification walkthrough, read our ISO 9001 Malaysia Guide. Preparing for an audit? See 10 Common ISO Audit Findings.
See How Cari Consultancy Measures Up
200+ organisations guided to certification since 2009. Industry-specific experience across manufacturing, construction, food safety, and medical devices. Transparent pricing, on-site implementation, and a team that builds systems your people can actually use.
Get a Free Consultation About Our Team