ISO 27001

What does an ISO 27001 consultant do? A practical scope guide

What should an ISO 27001 consultant do across gap assessment, risk, SoA, policy, control ownership, evidence, internal-audit readiness, and management review?

Published2026-08-23Reading time5 min read
Personal credentials
CISSPCISMPMPChief Information Security Officer
Framework expertise areas
ISO 27001ISO 27701SOC 2 readinessDORAGDPR/KVKKAI GovernanceVendor Risk
What does an ISO 27001 consultant do? A practical scope guide — vciso.tr advisory guide cover
What does an ISO 27001 consultant do? A practical scope guide — vciso.tr advisory guide cover

Good ISO 27001 consulting is not a document-pack delivery exercise. The goal is to help the company operate a risk-based ISMS that its own control owners can sustain and evidence.

What an ISO 27001 consultant should do

  1. Clarify scope: Which products, systems, locations, and teams are in the ISMS?
  2. Assess current state: Does the control exist, operate, and produce evidence?
  3. Operate risk methodology: Make risk owners, treatment, and acceptance decisions visible.
  4. Support the SoA and control map: Explain applicability and connect controls to accountable owners.
  5. Adapt policies: Avoid context-free copy/paste policy packs.
  6. Build the evidence system: Define what is evidenced, by whom, how often, and in which format.
  7. Prepare internal validation: Mature internal audit, management review, and corrective-action workflows.
  8. Transfer knowledge: The system should continue after the consultant leaves.

What the consultant should not do

  • Guarantee certification
  • Represent the independent decision of a certification body
  • Claim controls operate when they do not
  • Make all risk-acceptance decisions on behalf of management
  • Leave generic templates disconnected from real operations

Which outputs should you ask for?

Request concrete deliverables such as a gap register, risk register, SoA support, control-owner matrix, evidence calendar, policy backlog, internal-audit readiness list, management-review pack, and 90-day action plan.

Use the ISO 27001 Readiness Assessment to create your own gap view and review the ISO 27001 consulting model.

Next step

Instead of only reading, run the related free assessment, identify missing evidence, and then scope advisory work around the decision that is actually required.

Frequently asked questions

Does this guide replace company-specific advisory?

No. It provides a general decision framework; scope, regulatory, contractual, and risk context should be evaluated for the company.

What should the first step be?

Write down the current pressure, decision owner, evidence gap, and the output that should exist in the next 30–90 days.

Sources

This content is educational. It is not legal advice, an audit opinion, or a compliance guarantee.

Next step

Preparing for SOC 2 or ISO 27001?

Prioritize controls, evidence, policies, and operating rhythms before external review.