Streamline ISO Consultants

  • Home
  • Security & AI
    • ISO 27001 Information Security
    • ISO 42001 AI Management
    • Cyber & Information Security Advisory
    • Essential Eight
    • SOC 2
    • TISAX
  • ISO Consulting Services
    • ISO Consultants Australia
    • ISO 9001 for US Companies
    • ISO Mentoring
    • Independent ISO Internal Audit Services Australia (Clause 9.2)
    • ISO Gap Analysis Audits: Know Where You Stand Before Stage 1
    • ISO Certification Auditors
    • ISO System Development
    • ISO Management System Maintenance & Ongoing Support
  • ISO Standards
    • ISO 9001 Quality Management
    • ISO 45001 Occupational Health and Safety
    • ISO 14001 Environmental Management
    • ISO 17025 Testing and Calibration
    • HACCP Food Safety
    • ISO 19443 Nuclear Supply Chain
  • Resources
    • All Articles
    • ISO Clause Guides
    • Quality Quotes
  • About
    • ISO FAQs
    • Quality Policy
    • Client Testimonials
    • ISO 9001 Certificate
  • Contact
    • Business Info
    • Privacy Policy

Frequently Asked Questions: ISO FAQs

Short, plain English answers to the questions we are asked most often about ISO certification in Australia. Each answer is deliberately brief and links to the full guide on that topic, so use this page to find your starting point rather than as the whole explanation. Figures are Australian dollars and apply to Australian organisations.

On this page

  • Getting started
  • Cost and funding
  • Timelines and validity
  • The standards
  • Integrated management systems
  • Certification bodies and certificates
  • Audits
  • Consultants and how we work

Getting started

What is ISO certification?

An independent audit confirming your management system meets a published standard. You build and run the system, an accredited certification body audits it and issues the certificate. See the ISO standards we work with.

Which ISO standard do I need?

Usually whichever your customers or tenders ask for. Quality is ISO 9001, safety ISO 45001, environment ISO 14001, information security ISO 27001. If a tender prompted the question, send us the wording and we will tell you what it requires.

Is ISO certification a legal requirement in Australia?

No. It is voluntary. It becomes a commercial requirement when a client, principal contractor or tender makes it a condition of supply, which is how most organisations end up needing it. See ISO 9001 for tenders.

Do we need certification, or just a system that works?

Both are legitimate. If nobody is asking for the certificate, building to the standard without certifying gives you the operational benefit at lower cost. If a tender needs the certificate, the system alone will not satisfy it.

Is our business too small for ISO certification?

No. A small organisation usually has fewer processes and fewer significant risks, so there is less to control. Size changes the effort, not the eligibility.

What is the difference between accreditation and certification?

You are certified. Certification bodies are accredited. An accreditation body such as JAS-ANZ audits the certification body, which is what makes the certificate mean something. See ISO certification bodies in Australia.

Cost and funding

How much does ISO certification cost in Australia?

For ISO 9001, 45001 or 14001, most small to medium organisations land between $7,000 and $25,000 in the first year, covering both consulting support and the certification body audit fees. See the ISO 9001 certification cost guide.

What does ISO 27001 cost?

More than the others, typically $15,000 to $30,000 in the first year, because the risk assessment, Statement of Applicability and Annex A controls carry more work. See the ISO 27001 certification cost guide.

Why do quotes vary so much?

Because they are pricing different things. Some cover only the certification audit, some only consulting, some both. Scope, number of sites, headcount and how much work you do yourself all move the number. Ask what is included before comparing.

Is it cheaper to certify several standards at once?

Yes, substantially. The management clauses are shared, so a standard built as part of an integrated system generally runs 50% to 75% of its standalone cost, and the more you build at once the further toward the lower end it goes.

Are there government grants or funding for ISO certification?

Sometimes. Funding usually arrives through broader business capability or industry programs where certification counts as eligible expenditure, rather than as an ISO specific grant. See government funding and grants.

What are the ongoing costs after the first year?

A surveillance audit in years two and three, then a recertification audit. Surveillance audits are shorter and cheaper than the initial certification audit. Budget for internal audit and management review time as well.

Timelines and validity

How long does ISO certification take?

Three to six months for most small and medium organisations. Shorter is usually rushed, because the system has to run long enough to produce records worth auditing. Longer and projects lose momentum. Larger, multi-site and multinational organisations run longer.

Can we get certified faster?

Rarely, and not well. The constraint is not how fast a consultant works, it is that a certification body needs evidence the system has been operating. See ISO 9001 certification in 10 days.

How long is an ISO certificate valid for?

Three years, with a surveillance audit each year and a recertification audit before it expires.

What happens if we miss a surveillance audit?

The certification body can suspend and eventually withdraw the certificate. Suspension is usually recoverable, withdrawal means starting again. Tell them early if a date is a problem rather than letting it pass.

The standards

What is ISO 9001?

The international standard for a quality management system: a documented, working way of running the business so it consistently meets customer and regulatory requirements. See ISO 9001 quality management systems.

What is ISO 45001?

The standard for an occupational health and safety management system, built around hazard identification, worker consultation and controlling risk to health and safety. See ISO 45001 safety consulting.

What is ISO 14001?

The standard for an environmental management system: identifying where your operation affects the environment, controlling what matters, and meeting your compliance obligations. See ISO 14001 consulting.

What is ISO 27001?

The standard for an information security management system, built on a risk assessment, a Statement of Applicability and the Annex A controls. See ISO 27001 information security.

What is ISO 42001?

The standard for an artificial intelligence management system, covering governance of AI you build or use. See ISO 42001 AI management.

What is ISO 17025?

The standard for testing and calibration laboratories, covering technical competence and valid results rather than management system conformity alone. See ISO 17025 for laboratories.

What is HACCP?

A food safety approach based on identifying hazards and controlling them at critical points in the process. See HACCP food safety systems.

What changed in the 2026 editions?

ISO 14001:2026 was published on 15 April 2026 and replaces both the 2015 edition and the 2024 climate change amendment. The clause structure is retained, so existing systems transition without a rebuild. See the ISO 14001:2026 transition guide and the ISO 9001 equivalent.

Do the standards require us to consider climate change?

Yes, as a context issue. Clause 4.1 requires you to determine whether climate change is a relevant issue for your organisation, and clause 4.2 notes interested parties may have climate related requirements. It is not a requirement to measure emissions or set targets. See climate risk assessment.

Integrated management systems

What is an integrated management system?

One management system meeting several standards at once, with a single set of processes, internal audits and management reviews rather than running them in parallel.

Can ISO 9001, 45001 and 14001 be combined?

Yes, and we usually recommend it. They share the same high level structure, so context, leadership, competence, document control, internal audit, management review and improvement are run once rather than three times.

Does an integrated system cost less?

Yes. Expect a standard built as part of an integrated system to run 50% to 75% of its standalone cost, and the certification body audits them together, which costs less than separate audits.

Certification bodies and certificates

Who issues ISO certificates?

An accredited certification body, independent of any consultant. In Australia most are accredited by JAS-ANZ. See ISO certification bodies in Australia.

How do I choose a certification body?

Check the accreditation covers the standard and the scope you need, confirm they have auditors competent in your industry, and compare the full three year cost rather than the first year alone. See how to choose a certification body.

Are there fake ISO certificates?

Yes. Forgeries are now visually convincing, so the document itself proves nothing. See how to tell if an ISO certificate is real or fake.

How do I check a certificate is genuine?

Look the certification body up on the accreditation body register for the region where it was accredited, then confirm the certificate and its scope with that body directly. Do not rely on a logo or a PDF.

Can we change certification bodies?

Yes. A transfer is a defined process and does not mean starting again, provided your current certificate is valid and in good standing. Timing it with a surveillance or recertification audit is usually cleanest.

Audits

What happens in a Stage 1 and Stage 2 audit?

Stage 1 reviews the documented system and readiness. Stage 2 tests whether you do what the system says, by sampling records and interviewing people. Both are carried out by the certification body.

How do you pass an ISO audit?

By being able to show objective evidence against each clause. The auditor is not looking for perfection, they are looking for a system that operates and that finds its own problems. See the ISO 9001 audit process.

What is a nonconformity?

A failure to meet a requirement of the standard or of your own system. Major nonconformities must be closed before certification, minor ones with an agreed corrective action. Finding your own is a sign the system works.

What is an internal audit?

Your own check that the system is working and being followed, required by clause 9.2 of every management system standard, done before the certification body arrives. See internal auditing.

Who can carry out our internal audit?

Anyone competent and independent of the area being audited. In a small organisation nobody is independent enough, which is when an external internal auditor is used. See independent internal audits.

What is a gap analysis audit?

A review of what you already have against the requirements of the standard, so you know what is missing before committing to a project. See gap analysis audits.

Consultants and how we work

What does an ISO consultant do?

Helps you design, build and implement the management system, and prepares you for the certification audit. See how an ISO consultant can help.

Can the consultant also be the certification auditor?

No. ISO 19011 requires audits to be independent, so the person who built the system cannot certify it. That independence is what makes the certificate credible.

Can we build the system ourselves?

Yes, and if you have a capable operations or HSE person it is often better value. See ISO mentoring, where your team builds it with an experienced auditor alongside.

What is an outsourced ISO manager?

Ongoing support where we run the management system routines with you, for organisations that need the system maintained without hiring for it. See outsourced ISO manager.

We already have a system. Can you check it?

Yes. A gap analysis or a certification readiness review tells you where it would fail before a certification body finds it.

Do you work outside Brisbane, Sydney and Melbourne?

Yes, across Australia, on site and remotely. See ISO consultants Australia.

Still have a question?

Streamline designs, audits and mentors management systems across ISO 9001, 45001, 14001, 27001, 42001, 17025 and HACCP, standalone or integrated. You work directly with a qualified ISO Lead Auditor from the first conversation through to your certification audit. If a tender or a customer has asked you for certification, send us the wording and we will tell you what it actually requires.

Email hello@streamline.business, or call Brisbane 07 3667 8280, Sydney 02 8315 7780 or Melbourne 03 9034 3990.

Book a free consultation →

More ISO Certification Information

  • ISO certification bodies in Australia
    How to Choose an ISO Certification Body in Australia
  • ISO 45001 workplace safety inspection
    ISO 45001 Consulting, Safety Audits and Mentoring
  • ISO 14001 environmental management
    ISO 14001 Consulting, Environmental Audits and Mentoring
  • Consultant guiding a business owner through their ISO management system at a laptop
    ISO Mentoring: Expert Guidance for DIY ISO Systems
  • ISO 27001 information security risk analysis
    ISO 27001 Consulting, Internal Audits & Mentoring
  • Quality inspector in an Australian machining workshop checking a machined aluminium component against a tablet record, with CNC machines and Australian flags behind
    How Much Does ISO 9001 Certification Cost in…
  • Tilt-shift miniature of an AI data centre and microchip: AI tools and ISO 42001
    ISO 42001 AI Management Consulting, Audits & Mentoring
  • Tilt-shift miniature naval shipyard inspection bay with a submarine hull section on keel blocks and workers in hi-vis checking tagged components in a parts quarantine area
    ISO 19443: The Nuclear Supply Chain Standard, and…
  • Manager reviewing a budget spreadsheet
    ISO 27001 Certification Cost & Timeline in Australia…

Quick Information Request

Brisbane ISO Consultants

Level 14, 167 Eagle St
Brisbane Queensland 4000
Phone: 07 3667 8280
Email: hello@streamline.business

Sydney ISO Consultants

Level 5, 20 Bond Street,
Sydney NSW 2000
Phone: 02 8315 7780
Email: hello@streamline.business

Melbourne ISO Consultants

Level 8, 350 Collins Street
Melbourne, Victoria 3000
Phone: 03 9034 3990
Email: hello@streamline.business

Client and partner logos

KEY ISO ARTICLES

Articles, Deep Dives & More
Frequently Asked Questions
Quality Quotes
Funding Grants for ISO Certification
ISO Consultants
Strategic Planning - Mystical Art?
ISO Certification Auditors
How to get ISO 9001 Certification
ISO Certification Cost
How to tell if your ISO Cert is fake
4-year-olds and Root Cause Analysis
Fast ISO 9001 Certification
The Ultimate Guide to ISO 9001 Audit
ISO 45001 Certification Cost
Who's Interested in a Party?
How to use Smartsheet for ISO
Smarter Quality Objectives
Local Government QMS
Quality Assurance, Quality Control or QMS
ISO Certification in Sydney
ISO Certification in Melbourne
ISO Certification in Brisbane
SAI Global Consultant Affiliate Program

QUICKLINKS TO ISO INFO

ISO Consultants Australia
ISO Mentoring
ISO 27001 Certification Cost
ISO 9001 Quality Management
ISO 45001 Health & Safety
ISO 14001 Environment
ISO 17025 Testing & Calibration
ISO 27001 Information Security
ISO 42001 AI Management
ISO 22000 HACCP Food Safety

Search

FOLLOW OR GET IN TOUCH

linkedinmail
Smartsheet Platinum Partner

Copyright © 2026 Streamline · Log in

Privacy Policy · Terms of Use · Disclaimer

Call us Enquire