Insights · 6 min read
Why CAS does not provide consultancy
We are asked this most weeks, and usually with an edge of disbelief. You audit management systems. You know exactly what a conforming one looks like.…
Published by CAS — Conformity Assessment Services · 4 September 2026
We are asked this most weeks, and usually with an edge of disbelief. You audit management systems. You know exactly what a conforming one looks like. Why will you not help us build it?
The answer is not commercial reluctance. It is a prohibition in the standard we are accredited against, and it is the single reason our certificate is worth anything to the person reading it.
The rule
ISO/IEC 17021-1 clause 5.2.5 states that the certification body — and any part of the same legal entity, and any entity under its organizational control — shall not offer or provide management system consultancy.
The standard defines what that means at clause 3.3: participation in establishing, implementing or maintaining a management system. Its examples are explicit. Preparing or producing manuals or procedures. Giving specific advice, instructions or solutions towards the development and implementation of a management system.
So the prohibition is not narrow. It is not confined to a formal consulting engagement with a signed scope. It covers the specific advice too.
Why the rule exists
Consider what happens if we design your system and then audit it.
The audit team is examining work done by the organization it belongs to. Every finding is a judgement on a colleague's decision. Every conformity is a confirmation that we were right the first time. ISO/IEC 17021-1 names this at clause 4.2.4 b) — the self-review threat: threats that arise from a person or body reviewing the work done by themselves.
And your buyer, reading the certificate, has no way to see any of it. The document looks identical either way. What they are relying on is that somebody with no stake in the outcome looked and formed an independent judgement.
Break that and the certificate stops carrying information. It becomes a statement by an organization about work it did itself — which is precisely what third-party certification exists to replace.
The constraint is the product. Everything a certification body cannot do is what makes the thing it does do worth something.
How far it reaches
Four extensions of the rule are worth knowing, because organizations meet them unexpectedly.
The whole legal entity. Clause 5.2.5 covers any part of the same legal entity and any entity under the certification body's organizational control. A separate department does not solve it.
Internal audits. Clause 5.2.6 treats a certification body performing internal audits for its certified clients as a significant threat, and bars certifying a system it internally audited for at least two years after that work ends.
Related bodies. Clause 5.2.7: where a client received management system consultancy from a body that has a relationship with the certification body, that is a significant threat — mitigated by not certifying for at least two years after the consultancy ends.
Individuals. Clause 5.2.10: personnel who provided consultancy to a client, including in a managerial capacity, shall not take part in that client's audit or other certification activities — with two years as the recognised mitigation.
This is why our application review asks whether you have worked with a consultant and when that engagement ended. It is not curiosity, and answering it honestly protects you: a certification granted in breach of these clauses is a certification at risk.
And no referral commissions
There is a related practice the standard treats with equal seriousness, and it is common enough in the market to be worth stating plainly.
Clause 5.2.3 lists sources of threats to impartiality, and names among them the payment of a sales commission or other inducement for the referral of new clients.
CAS pays no referral commission to anyone. Not to consultants, not to agents, not to intermediaries.
Clause 5.2.9 goes further: a certification body's activities shall not be marketed or offered as linked with the activities of an organization that provides management system consultancy. And a certification body shall not state or imply that certification would be simpler, easier, faster or less expensive if a specified consultancy organization were used.
If a consultant tells you that working with them makes certification with a particular body smoother, that arrangement is the thing the clause exists to prevent — and the certification body is required to take action to correct such statements.
What we can do
The prohibition is narrower than it first sounds, and the space inside it is genuinely useful.
Explain the requirements. What a clause asks for, what it does not, how conformity is assessed. Everything published in our articles sits here.
Explain the process. Application review, the two stages, how audit duration is calculated, who takes the decision, what happens at surveillance.
Answer technical questions in general terms. What the standard means by a term, how a requirement is typically evidenced, what audit teams commonly look at.
Provide generic training. Clause 3.3 Note 1 is explicit that arranging training and participating as a trainer is not consultancy, provided the course is confined to generic information — the trainer must not provide client-specific solutions.
Tell you plainly when something is outside what we can answer. Which we do, and which is usually more useful than a hedge.
Where the line actually falls
The line is not between "helpful" and "unhelpful". It is between generic and client-specific.
"Clause 6.1 requires risks and opportunities to be determined considering the issues in 4.1" is generic. It is true for every organization holding the standard.
"Here is how your risk process should work given your three sites and your seasonal workforce" is client-specific. It is participation in establishing the system, and it is what we cannot do.
The same distinction governs training. A course on what ISO 9001 requires is generic. A workshop that produces your procedures is not a course.
Choosing a consultant, if you want one
Many organizations use one, and there is nothing wrong with that. The standard anticipates it and simply requires separation.
What we cannot do is recommend one. Not because we lack opinions, but because clause 5.2.9 prohibits exactly that link, and any recommendation from us would compromise the independence you are paying for.
What we can tell you is the structural question worth asking: whoever you engage, their work and our assessment must remain separate, and that separation has a two-year memory in the clauses above.