Article

Management system consulting across six markets

The clauses do not change between India, Mongolia, Australia, Nigeria, South Africa and the United States. Almost everything around them does.

Prem Kumar Dvivedi · 30 August 2026

MSCi is Management System Compliance Incorporation, a management system consultancy. The initials are shared with unrelated organisations elsewhere; the work described here is ours.

We are concentrating on six markets: India, Mongolia, Australia, Nigeria, South Africa and the United States. A reasonable question from anybody buying consulting is what actually differs between them, given that ISO 9001 is the same document in all six.

What does not change

The standard. Clause for clause, ISO 9001, ISO 14001, ISO 45001 and ISO/IEC 27001 ask the same things in Lagos as in Ulaanbaatar. So does the audit structure: a stage 1 that checks whether you are ready, a stage 2 that tests whether the system runs, and surveillance afterwards. Anybody who tells you a standard is softer in one country has misunderstood either the standard or the country.

The sequence of work does not change either — gap assessment, documentation, training, implementation, internal audit, management review, then the certification body.

What changes: who is asking

This is the largest difference, and it is not regulatory.

India

Certification is very often driven by a tender. Public procurement — including through GeM — and large private buyers frequently name ISO 9001 as a qualification condition, which sets the deadline before anybody has looked at the gap. Sector regulators sit alongside it rather than replacing it: BIS for product conformity, CDSCO for medical devices, and the DPDP Act for personal data, which has pushed a number of organisations towards ISO/IEC 27001 and 27701 as the practical way to demonstrate a position.

Mongolia

Mining and the businesses supplying it dominate, and with them health and safety. ISO 45001 is frequently the first standard rather than the second, and the buyer asking for it is often an international operator applying its own group requirements to local suppliers. MASM, the national standards body, is the reference point for national adoptions. Documentation has to work in Mongolian for the people who use it, whatever language the audit is conducted in.

Australia

Safety is statutory. The model Work Health and Safety laws place duties on officers personally, which changes the conversation about ISO 45001 entirely: it is not only a customer requirement but a defensible demonstration of due diligence. Australian buyers also tend to arrive with a clear idea of what they want and to ask harder questions about how much of the system is genuinely used.

Nigeria

Oil, gas and their supply chains set the tone, and the standards asked for are often bundled with client-specific requirements that go beyond ISO. The Standards Organisation of Nigeria and, for food and drugs, NAFDAC form the regulatory backdrop. Multi-site operations and a wide spread of literacy and turnover across sites make training and competence records the part that needs the most attention.

South Africa

Certification is usually customer-driven, often by the requirements of larger corporates and by tender conditions in mining, manufacturing and services. Organisations here tend to have a good deal of the system already in place informally, which makes the documentation-versus-substance distinction particularly sharp — and the gap smaller than the first conversation suggests.

United States

ISO certification is rarely a legal requirement and almost always a commercial one. Customers ask, and increasingly they ask for information security assurance in particular — SOC 2 alongside or instead of ISO/IEC 27001, and often both, because different customers ask for different things. In medical devices, the FDA's quality system regulation has been aligned with ISO 13485, which makes a single system serve both purposes where it did not before.

What changes: how the work is delivered

  • Language. The audit may be in English; the system has to be usable by the people who operate it. Documentation in a language the shop floor does not read is a finding waiting to happen.
  • Time zones and site visits. Onsite, remote and hybrid delivery are genuinely different products, and which one fits depends on how many sites you run and how far apart they are.
  • The certification body. Which bodies are accredited, recognised and accepted by your particular buyer varies by market, and choosing badly is an expensive mistake to unwind.
  • What "normal" looks like. An auditor's expectations of documentation density differ. So do the informal norms about what is written down and what is understood.

Starting from the same place

Whichever of the six you are in, the first useful step is the same: find out where you stand against the standard before anybody quotes you for anything. The free readiness checklist on this site does that for each standard we work on, scores it out of 100 and sends you the full answered checklist with recommendations. It takes about fifteen minutes and commits you to nothing.

About the author

Prem Kumar Dvivedi is an auditor with more than forty years in this industry. He has spent that time on both sides of the table — building management systems and auditing them — across quality, environment, health and safety, food safety and information security.

See how this looks as a working system

Reading about a requirement and seeing the documentation that satisfies it are different things. In a short demo we open the actual manual, procedures and records set for ISO 9001, show you how each clause is answered and where your existing way of working already fits. You will know what implementation involves before you commit to it.

Ask us about this

Tell us what is being asked of you and by whom.

What are you looking for?

We reply within one working day. Your details stay with our consultants.

More reading

All articles