Articles
Longer pieces from MSCi consultants on a single standard, sector or certification question, written for the people who have to implement it.
- September 13, 2026Inside an Automotive OEM Vendor Cybersecurity Assessment: The 19 Control Families and What They Actually Ask ForThe nineteen control families in an automotive vendor cybersecurity assessment, where the structure came from, and why good controls still score zero.Read the article
- September 13, 2026Cybersecurity Across the Automotive Lifecycle: Production, Operational Technology and the Scope GapGovernance, the shop floor and the product in the field: where automotive cyber exposure actually sits, and why an ISO 27001 certificate may not reach it.Read the article
- September 12, 2026What a certification audit actually samplesAuditors do not read your manual cover to cover. They sample, and the sample is predictable. Knowing what gets pulled changes how you prepare.Read the article
- September 12, 2026Why a second standard costs far less than the firstClauses 4 to 10 are shared across the ISO management system standards. That is why the second certificate costs far less than the first.Read the article
- September 12, 2026Certification for Indian exporters: what buyers actually ask forWhich standard an Indian exporter needs is decided by the buyer, the destination market and the sector — not by which certificate is cheapest to obtain.Read the article
- September 12, 2026Mining supply chains and ISO 45001 in MongoliaIn Mongolia, safety certification usually arrives before quality certification, because an international operator asked for it. What that changes about the project.Read the article
- September 12, 2026Information security certification in Nigeria and South AfricaTwo regulators, two statutes, one management system. What NDPA and POPIA ask for, and where ISO 27001 and ISO 27701 do the work.Read the article
- September 12, 2026Food safety: which scheme, and why the buyer decidesISO 22000, FSSC 22000, BRC and HACCP overlap heavily and are not interchangeable. The difference that matters is who recognises which.Read the article
- September 12, 2026Climate disclosure and the management system underneath itAssured emissions reporting asks a question most organisations cannot answer: where did that number come from? ISO 14064 and ISO 50001 are the answer.Read the article
- September 12, 2026What officers owe under work health and safety lawThe due diligence duty is personal, cannot be delegated, and is evidenced by ordinary records. What boards in Australia and New Zealand should keep.Read the article
- September 12, 2026AI governance before the AI strategyMost organisations deploying AI cannot list the systems they already use. ISO 42001 starts there, which is why it is more useful than it sounds.Read the article
- September 12, 2026Choosing a consultant: five questions that reveal the answerEvery consultancy claims experience and success rates. These five questions produce answers that are hard to fake, including from us.Read the article
- August 30, 2026Management system consulting across six marketsThe clauses do not change between India, Mongolia, Australia, Nigeria, South Africa and the United States. Almost everything around them does.Read the article
- August 30, 2026From a self assessment to a certificate: how the work runsThe stages between a fifteen-minute readiness checklist and an accredited certificate, what each one produces, and who does the work at each step.Read the article
Not sure which standard applies to you?
Send us the requirement you have been given. We will tell you which standard satisfies it, what it takes and what it costs, before you commit.
