Can't our registrar just tell us what to fix?
No. ISO/IEC 17021-1 bars your certification body from consulting on the system it certifies and from running your internal audits. That independence is what the certificate is worth.
What to do now
Separate the two jobs in your head, because the standard separates them in writing.
Your registrar tells you what is wrong. It writes the finding, cites the clause, and decides whether your response closes it. That is the whole of what it is allowed to do, and it is genuinely useful. Read the finding text closely: a well-written nonconformity names the requirement, the objective evidence, and the gap between them. That is a specification for the fix even though it is not the fix.
What your registrar cannot do is design your process, write your procedure, sit with your team to build the corrective action, or run your internal audit program. ISO/IEC 17021-1:2015, the standard certification bodies are themselves accredited against, says so in clause 5.2.5: a certification body, any part of the same legal entity, and any entity under its organizational control shall not offer or provide management system consultancy. The definition is broad on purpose and covers establishing, implementing, and maintaining a management system, writing manuals and procedures, and giving specific advice toward certification.
Clause 5.2.6 goes further and bars the certification body from performing your internal audits while it certifies you. Both directions carry a two-year cooling period, so a body that consulted for you cannot audit you for two years afterward, and the reverse holds as well.
So when your auditor closes the meeting with a hint rather than an answer, that is not unhelpfulness. It is a person protecting their accreditation, and yours.
What it costs
The work the registrar cannot do still has to happen, and somebody has to be paid for it.
Published market figures for the prep side cluster in a narrow band. A gap assessment against ISO 9001 runs roughly $2,500 to $5,000 at mid-market size across the sources that publish at all. Outsourced internal audits benchmark at about $2,000 to $6,000 per audit, with one national provider advertising from $1,440 for a remote or on-site audit sized by the IAF MD5 day tables. Independent consultant day rates sit around $800 to $1,250.
That spend is not a workaround for a rule. It is the rule working. Because no certification body can own a consulting arm, the prep market cannot consolidate behind the registrars, and it has not: consulting as a sector averages about 2.6 employees per firm, and the ISO prep field looks the same. You are buying from a fragmented market of small firms and individuals, which is why quality varies so widely and why the question of who exactly will be in your building matters more than the logo on the proposal.
What good looks like
A clean separation, running on a schedule, with nobody confused about their role.
Your registrar audits. It arrives, samples, writes findings against clauses, and makes a certification decision it can defend to its accreditation body. You should be able to read its conflict-of-interest statement and see the same rules described above.
Someone independent of the registrar preps. That may be your own quality manager, a consultant, or a mix. Their job is the part the registrar is barred from: finding the gaps before the audit, designing the fix, building the evidence trail, and running internal audits that are real rather than a signature on a form.
The two sides can talk to each other, and they routinely do. Prep firms refer clients to certification bodies, and several advertise which bodies they work alongside. What cannot happen is one organization doing both for the same client at the same time.
The tell that something is wrong: anyone who offers to both prepare you and certify you, or who implies their relationship with a registrar will smooth your audit. Check that the body is IAF accredited before you sign, because that accreditation is what obliges them to keep the separation at all.
When to bring in outside help
Four situations where the prep side is not a job for your team alone.
The same findings keep coming back. A repeat nonconformity means the corrective action addressed the symptom. Root cause work is hard to do on your own process because you are inside it.
Clause 9.2 is not really running. If internal audits are scheduled and then skipped when the quarter gets busy, you have a finding waiting. It is among the most-cited clauses in the standard for exactly this reason.
Your quality manager left. The knowledge walks out with them, and the audit calendar does not move.
A customer or registrar deadline is fixed and close. Bringing help in three weeks before Stage 2 buys less than bringing it in three months before, and costs more.
How ARG does it
We do the half your registrar is not allowed to do, and we never do the other half.
A gap assessment is an on-site review of your quality system run the way a registrar runs it: clause by clause, evidence first, interviewing the people who do the work rather than reading the binder. You get findings with clause references and a prioritized remediation plan. From there the work splits into fixed-scope projects against named gaps, and a mock audit before your Stage 2, surveillance, or customer audit.
Noah Brown, who leads that work, is a certified ISO 9001 lead auditor and hosts registrar and customer audits from the auditee side inside a working manufacturer. That is the seat we prepare you for.
We prepare clients for certification and we never issue it. Registrar independence is not an inconvenience we work around. It is the reason your certificate persuades your customer.
FAQ
Can our registrar recommend a consultant?
Some will offer a list, some decline entirely. Either way the referral cannot come with influence over your audit result, and a body that steers you hard toward one firm is worth a question about its own independence.
Can the same firm do our internal audits and our certification audit?
No. ISO/IEC 17021-1 clause 5.2.6 bars a certification body from performing internal audits for a client it certifies. A consultant, on the other hand, can run your internal audits. The prohibition binds certification bodies, not consultancies.
Our auditor gave us advice anyway. Is that a problem?
Generic explanation of a requirement is allowed and normal. Designing your process or writing your procedure is not. If an auditor crossed that line, the risk lands on the certification body's accreditation, not on you, but a body that is casual about the rule is a body to reconsider.
If we switch registrars, does the two-year rule apply?
It applies to consultancy relationships, not to switching bodies. A registrar that consulted for you cannot certify you for two years. Switching for price, auditor quality, or scheduling is common and carries no cooling period of its own.
Sources
- ISO/IEC 17021-1:2015 clauses 5.2.5 and 5.2.6 (consultancy prohibition, internal audit prohibition, two-year cooling periods).
- Published prep-side benchmarks, ARG market research 2026, sections 7.1 and 1.2: gap assessment $2,500 to $5,000 typical; outsourced internal audit $2,000 to $6,000, from $1,440; consultant day rate $800 to $1,250.
- Consulting-sector fragmentation figure: IBISWorld, approximately 2.6 employees per firm, not ISO-specific.
Tell us which audit is on your calendar.
A gap assessment is a flat-fee, on-site project led by a certified ISO 9001 lead auditor. Three founding-client spots are open for the quality practice.
We prepare you for certification. We never issue it. Your registrar's independence is the point.