Article
Choosing a consultant: five questions that reveal the answer
Every consultancy claims experience and success rates. These five questions produce answers that are hard to fake, including from us.
Prem Kumar Dvivedi · 12. September 2026
Consultancy proposals look alike. They claim experience, list logos and quote a success rate that nobody audits. Here are five questions whose answers are hard to manufacture — including for us, which is the point of publishing them.
1. Will you audit us as well?
The answer must be no. A body that certifies the system it built is prohibited by accreditation rules, and an organisation offering both is either misunderstanding the rules or expecting you to. Ask it first; it settles a great deal.
2. Who will actually be on site, and what have they audited?
Proposals are written by principals and delivered by juniors. Ask for the name of the consultant who will do the work, their sector experience, and whether they have audited in your industry rather than only consulted in it. Somebody who has sat on the other side of the table asks better questions and wastes less of your time.
3. What documentation will you write, and what will we write?
A consultancy that writes everything leaves you with a system nobody in the building recognises, which fails at the first surveillance audit after they leave. A consultancy that writes nothing has sold you a checklist. The honest answer is a split: they draft the structural documents, your people write the ones describing work they do.
4. What happens between certification and the first surveillance audit?
This is where most engagements quietly end and most systems quietly fail. Ask what the contract covers after the certificate arrives. If the answer is nothing, price that in — you will need internal auditors who can run the programme themselves, and that capability has to be built before the consultant leaves.
5. What will you tell us we do not want to hear?
A consultant who has never delivered bad news to a client has not been doing the job. The useful answer names something specific: a scope that is too wide for the budget, a timeline that assumes people will be released who will not be, a standard the buyer asked for that is not the one they actually need.
One more, for the certification body
Ask for audit days rather than a price. Days are comparable between quotes; prices are not. A quote well below the others usually has fewer days in it, and fewer days means a shorter audit, which sounds like a saving until the surveillance audit finds what the initial one did not.
See how this looks as a working system
Reading about a requirement and seeing the documentation that satisfies it are different things. In a short demo we open the actual manual, procedures and records set for ISO 9001, show you how each clause is answered and where your existing way of working already fits. You will know what implementation involves before you commit to it.
More reading
- Automotive Suppliers Face Stricter Cybersecurity Assessments
Cybersecurity is becoming a key part of supplier evaluations in the automotive industry. Vehicle manufacturers now check how suppliers protect data and systems alongside quality, cost, and delivery.
13. September 2026
- Automotive OEM Vendor Cybersecurity Assessment: Controls, Scoring and ISO Standards Mapping
What does an automotive vendor cybersecurity assessment cover?
13. September 2026
- Inside an Automotive OEM Vendor Cybersecurity Assessment: The 19 Control Families and What They Actually Ask For
The nineteen control families in an automotive vendor cybersecurity assessment, where the structure came from, and why good controls still score zero.
13. September 2026
