A fair number of the businesses that contact us for business consulting for ISO standards don’t actually know which standard applies to them. They know a client, a tender, or a regulator has asked for “ISO certification,” but the letters and numbers that follow — 9001, 14001, 45001, 27001, and so on — tend to blur together. That’s a completely reasonable place to start from. The standards weren’t written to be easily told apart by non-specialists, and picking the wrong one wastes time and money.

Start with why you need it, not which standard sounds right
The honest starting point isn’t the standard itself, it’s the reason you’re pursuing certification in the first place. A construction firm chasing a government tender for health and safety compliance needs a different answer than a software company whose client is asking about data security, even though both might casually say “we need ISO.”
Broadly, it breaks down like this:
- If the driver is quality, consistency and customer complaints, you’re likely looking at ISO 9001, the quality management standard.
- If it’s about environmental impact, waste, or a client asking about your sustainability credentials, that points to ISO 14001.
- If health and safety on site or in operations is the concern, particularly relevant to manufacturing and construction, that’s ISO 45001.
- If continuity of operations during disruption matters, whether that’s power outages, supply chain failure, or worse, that’s ISO 22301, business continuity management.
- If it’s IT service delivery and reliability, ISO/IEC 20000-1 is the relevant standard.
| ISO Standard | Focus Area | Best Suited For |
|---|---|---|
| ISO 9001 | Quality management | Businesses focused on consistency and customer satisfaction |
| ISO 14001 | Environmental management | Organisations managing environmental impact or waste |
| ISO 45001 | Occupational health & safety | Manufacturing, construction and industrial operations |
| ISO 22301 | Business continuity | Businesses needing resilience against disruption |
| ISO/IEC 20000-1 | IT service management | IT service providers and technology-driven businesses |
Some organisations end up needing more than one, and there’s a reasonable case for pursuing them together rather than one at a time, since the underlying documentation and audit structure overlap significantly.
Why generic advice doesn’t work here
This is the part where proper consulting earns its keep over simply buying a template online. A template can tell you what a policy should say in general. It can’t tell you whether your organisation’s actual risk profile, client base, or regulatory environment in Kenya or elsewhere in Africa means you need a lighter or heavier version of that policy. We’ve seen businesses spend months implementing a system built for a European manufacturer, only to find half of it doesn’t apply to how they actually operate.
A proper consulting engagement starts by understanding your business — what you do, who you answer to, what’s already working — before it starts talking about clauses and requirements. That’s the approach we take in our management systems consulting work, and it’s also the reasoning behind our wider view on business consulting for ISO standards across Africa, which looks at why a one-size-fits-all approach tends to fail outside the markets these standards were originally written for.

What the first conversation should establish
If you’re speaking to a consultant for the first time, a useful conversation should leave you with three things: which standard, or standards, actually fits your situation; a rough sense of how far your current processes are from meeting it; and an honest estimate of the time and cost involved. Be wary of anyone who skips straight to a quote without asking questions about your operations first. The standard should follow from your business, not the other way round.
Where this fits into the bigger picture
Certification isn’t really the end goal, even though it often gets treated as one. The standards exist to formalise practices that, done well, make an organisation genuinely more resilient and consistent — which is really what most clients and regulators are asking for when they request “ISO” in the first place. Our piece on consistency in growth through business consulting for ISO standards goes into more detail on why that distinction matters for businesses trying to win international contracts.
If you’re still not sure which standard applies to you, that’s a completely normal place to be before a first conversation. It’s usually the first thing we help sort out.
Talk to us about which standard actually fits your business.
