Frequently asked questions
Answers before you ask
Common questions about working with ABS — the process, timelines, recognition and the standards we work with. Don't see yours? Ask us.
Getting started
ABS is a consulting and advisory firm. We take you through five steps — discovery and scope definition, gap assessment and roadmap, implementation, audit readiness, and support through the independent audit — guiding you through to successful certification. See our process page for the detail of each step.
Tell us your scope — the standard you want, your organisation size, number of sites and any existing certifications — and we send a fixed-price proposal within 24 hours. You can use the Request-a-quote form or the contact page.
It depends on what your customers, contracts or regulators ask for, and what you want to improve. Common starting points are ISO 9001 for quality, ISO 27001 for information security (or SOC 2 where your customers are mainly US enterprises), ISO 14001 for environmental management and ISO 45001 for health and safety, and many sectors have their own schemes, such as FSSC 22000 for food or IATF 16949 for automotive. If you are unsure, tell us who is asking and why, and we will recommend the right standard at the scoping call.
No. If you already have policies and controls in place, we assess what exists against the standard. Where there are gaps, our gap assessment tells you exactly what to close before the audit — you are never left guessing.
Costs & timelines
There is no fixed timeline. It depends on the standard, the scope you certify, the size of your organisation, how many sites you operate and how many shifts they run. Each service page gives an indicative range for that standard, and you receive a firm timeline with your fixed-price quote.
Our consulting fees depend on the standard, organisation size, number of sites and complexity of scope, and every engagement starts with a fixed-price scoping call and a proposal within 24 hours. Note that the independent certification body charges its own separate audit, surveillance and recertification fees, which we identify clearly so there are no surprises.
Yes, for on-site work. Much of our work is delivered remotely, so many engagements need no travel at all. Where on-site work is needed, our consultants travel to you and the travel costs are set out upfront in your proposal — so there are no surprises.
Working with ABS
Most of it, yes. Our team is based in India, and gap analysis, documentation review, training and audit preparation are routinely delivered fully remotely to clients worldwide. Some standards — for example ISO 45001, where site safety must be observed — involve an on-site element, and your certification body may require an on-site audit. We confirm the approach for your scope upfront.
Our team is based in New Delhi, India, and works with clients worldwide. Office hours are Monday to Friday, 9:00–18:00 IST.
We invoice in your currency: GBP for clients in the UK, EUR in Europe, AED or USD in the Middle East, and USD in North America.
You choose and contract the certification body. We help you shortlist bodies accredited for your scope by an IAF MLA-signatory accreditation body, compare their proposals, and prepare for their audit.
Yes. Confidentiality is part of every engagement agreement, and we sign a separate NDA on request, including before the scoping call if you need one.
Yes. We support certified organisations through surveillance and recertification audits, and through the move to a new edition of a standard, such as ISO 9001:2026.
The certification journey
Stage 1 reviews whether your management system is documented and ready — checking policies, scope and readiness, and surfacing any gaps early. Stage 2 assesses whether the system is genuinely implemented and effective, through interviews, records and observation. See our full process page for the five steps.
A non-conformity is a finding to be addressed, not a failure. You implement corrective action within an agreed timeframe and your certification body verifies it. Certification proceeds once findings are closed. Our approach is to surface gaps during our gap analysis, so material issues rarely appear for the first time at Stage 2.
Certification is maintained through regular surveillance audits — typically annual — and renewed through a recertification audit at the end of the three-year cycle for most ISO standards. If your organisation changes materially, scope changes can be assessed and added at the appropriate point. We can support you through each surveillance and recertification audit, helping you keep the system maintained and close any findings.
Once any Stage 2 findings are closed and the independent certification decision is made, the certificate is issued. How long the whole journey takes depends on your scope, organisation size, sites and shifts, so you receive a firm timeline with your fixed-price quote.
Yes. We prepare you for certification against internationally recognised standards such as ISO 9001 and ISO 27001, and help you select an appropriately accredited certification body. Recognition depends on that body, its accreditation and the relevant accreditation scope — choosing well is what makes the certificate carry weight with customers and regulators wherever you operate.
IAF does not directly accredit certification bodies. Certification bodies are accredited by accreditation bodies that may be members of the IAF Multilateral Recognition Arrangement. Accreditation and scope should be verified directly through the relevant accreditation body or IAF CertSearch, where applicable.
Choosing a standard
ISO 27001 is the international standard for a risk-based information security management system; SOC 2 is an AICPA attestation focused on whether your controls meet specific trust criteria. ISO 27001 is more widely recognised internationally; SOC 2 is the default in US enterprise and SaaS. Many organisations hold both.
Not every Annex A control is automatically mandatory. The organisation determines applicable controls based on its information security risks, legal obligations and business requirements, and records the justification for inclusion or exclusion in the Statement of Applicability.
No. ISO/IEC 27017 (current edition 2026) and ISO/IEC 27018 (current edition 2025) are codes of practice used alongside ISO/IEC 27001. Neither is certified on its own: where you want the controls independently assessed, they are assessed within an ISO 27001 certification scope.
HACCP is the method for identifying and controlling food safety hazards; ISO 22000 wraps those principles inside a full, certifiable management system. FSSC 22000 builds further on ISO 22000 to become GFSI-recognised.
No — CMMI maturity is confirmed through an appraisal (the current CMMI Appraisal Method) led by a Certified Lead Appraiser, not a certificate. Organisations are "appraised at" a maturity level, and the result is typically valid for three years.
No. SMETA is an ethical audit developed by Sedex; the deliverable is an audit report shared on the Sedex platform, not a certificate. Buyers request it for responsible-sourcing due diligence.
Yes. Many organisations pursue integrated management systems — for example ISO 9001, ISO 14001 and ISO 45001 together, or ISO 27001 with ISO 27701. Shared structure means evidence can be reused across standards, reducing effort and cost.
ISO 9001:2026 is the new edition of the quality management standard, published on 16 September 2026 to replace ISO 9001:2015. It builds on the 2015 edition: top management is expected to promote a quality culture and ethical behaviour, risks and opportunities are addressed more clearly, and the 2024 climate change amendment is now part of the standard. Certified organisations need to transition to keep their certification, but there is time to plan: there is a three-year transition period, and 2015 certificates are expected to remain valid until September 2029, subject to final confirmation by the accreditation bodies.
In February 2024, ISO amended 31 of its management system standards, including ISO 9001, ISO 14001, ISO 45001, ISO 27001, ISO 22000, ISO 22301 and ISO 50001. Each now requires the organisation to determine whether climate change is a relevant issue for it, and notes that interested parties can have climate-related requirements. Certification audits include it. Editions published since then, such as ISO 9001:2026, build the same requirement in.
Partnerships & training
Tell us a little about yourself and the partnership you have in mind through our , and our team will be in touch.
Yes. Training can be part of your engagement, and ABS Academy also runs standalone management system courses, including awareness, internal auditor and lead auditor training. See Training & Professional Development for the courses.