Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

Compliance consulting statement of work: scope, deliverables, assumptions, client duties and change control

Compliance Consulting Statement of Work: The Essential 2026 Guide for Consultants

A compliance consulting statement of work is the document that decides whether a management system engagement ends with a certified client and a fair fee, or with a disputed scope and unpaid hours. It defines what you will deliver, what the client must provide, how changes are handled and where your responsibility stops. Consultants who implement ISO standards, privacy programs or sector frameworks for a living usually learn this the hard way, on the engagement where the client expected certification and the contract only promised documents.

This guide lists the sections a compliance consulting statement of work should contain, explains how to write each one so it holds up under pressure, and covers independence, template licensing and the common mistakes that cost consultants money.

Why a compliance consulting statement of work matters

Compliance projects are unusually exposed to scope disputes. The finish line, such as an audit outcome, depends on people and decisions you do not control. Timelines depend on client staff who have day jobs. And the client often assumes that “help with the standard” means “do everything.” A written compliance consulting statement of work turns those assumptions into agreed terms before work starts.

It also protects the client. A clear document lets them compare proposals, budget accurately and hold you to defined deliverables. Treat it as a shared plan, not a defensive legal instrument. Have a lawyer review your master agreement and template for the jurisdictions in which you work, because this guide is practical advice and not legal advice.

SectionWhat it settlesTypical problem if missing
Objective and scopeStandard, sites, functions and systems coveredClient adds a second site mid-project
DeliverablesNamed documents, workshops and reportsDisagreement over what “complete” means
AssumptionsConditions the plan relies onDelays blamed on the consultant
Client responsibilitiesAccess, decisions, evidence, staff timeWaiting weeks for approvals
Timeline and milestonesSequence and dependenciesUnrealistic audit date promised
Fees and expensesPrice, payment terms, travelUnbillable overruns
Change controlHow new requests are pricedUnpaid scope creep
ExclusionsWhat is deliberately not includedAssumed audit representation

Objective and scope

State the goal in terms you can influence. “Prepare the organization for certification against the named standard” is a controllable objective. “Achieve certification” is not, because the certification body makes that decision. Name the standard and edition, list the sites, business units, products and processes in scope, and name the systems and locations excluded. If the standard is being revised, say which edition you are working to and what happens if the client’s audit falls under a different one.

Deliverables in a compliance consulting statement of work

List each deliverable so that someone could check whether it was done. Compare “policy documents” with “information security policy, access control policy and supplier policy, drafted for client review, two revision rounds.” The second is checkable. Typical items include a gap assessment, a risk assessment, policy and procedure sets, training sessions, an internal audit, a management review facilitation and a readiness review before the certification audit. See our guide on the gap analysis remediation plan for how to turn assessment findings into a delivery plan.

Define what a completed deliverable is

Say who reviews each deliverable, how long they have, and what happens if they do not respond. A common clause treats a deliverable as accepted if the client does not comment within an agreed number of working days. That keeps projects moving when reviewers go quiet.

Assumptions and client responsibilities

Consultants write documents; clients run the management system. That difference should be visible in the statement of work. List what the client will supply and decide: a named project sponsor, a day-to-day contact, access to staff and records, timely decisions, resources to implement controls and attendance at workshops. Put dates on the important ones. If your plan assumes that the client’s IT team will implement technical controls, say so, so that a delay in the client’s own work does not become your problem.

Timeline, milestones and the audit date

Build the timeline from realistic effort, and do not promise an audit date you cannot control. A management system needs to operate long enough to produce records, such as internal audit results and a management review, before a certification audit can be meaningful. Set milestones around your own deliverables and around client dependencies. Our guide to IMS implementation gives a sense of the sequence and the effort involved in a multi-standard project.

Fees, expenses and payment

There are three common structures. Fixed price by phase suits well-defined work. Time and materials suits uncertain scope. A retainer suits ongoing support after certification. Whichever you choose, tie invoices to milestones or to calendar dates, state how expenses are billed, and say what happens if the client pauses the project. Avoid contingent fees based on certification success, since they can create pressure to overstate the position, and check the rules of any professional body you belong to.

Change control in the compliance consulting statement of work

Every engagement has requests that were not in the plan: another site, an extra standard, a rewritten procedure after the client reorganizes. A change control clause says that such requests are raised in writing, estimated, agreed by both parties, and only then started. Use a one-page change request form and a running log, so that the effect on cost and timeline is visible.

Independence from the certification body

ISO/IEC 17021-1 sets the requirements for bodies that audit and certify management systems, and it puts weight on their impartiality. European Accreditation guidance on the standard says that where a client has received management system consultancy from a body that has a relationship with a certification body, this is a significant threat to impartiality. The ISO/IEC 17021-1 listing describes the standard’s scope. In practice, keep your consulting separate from any certification body you have a relationship with, do not take part in the client’s certification audit as an auditor, and check the client’s certification body rules before you sign. State your position on independence in the statement of work.

Templates and licensing

If you reuse document templates across clients, check the licence terms before you commit to reusing them. Many document packs are licensed to one organization, and using them for a second client can put you outside the terms. Use materials that are licensed for consulting use, and say in the statement of work who owns the deliverables: usually the client owns the tailored documents you deliver, while you keep your methods, tools and pre-existing materials. The Consultant Package is a catalogue of editable toolkits licensed for use across unlimited client engagements, which removes the per-client licence question for firms that implement management systems regularly.

Adapting the statement of work by engagement type

The structure stays the same, but the detail shifts with the work. A readiness assessment for one standard, such as an ISO 27001 readiness assessment, is short and fixed in price, with a report as the main deliverable. A full implementation is longer and phased, with documents, training and internal audit. A multi-standard program, like one built around an integrated management system manual, needs extra clarity about shared documents and who approves them. Adjust the deliverables and assumptions to the engagement, and reuse the rest. Keep a library of approved clauses, such as confidentiality, data handling and acceptance, so each new proposal starts from wording your lawyer has already reviewed, and only the parts that differ need fresh attention. That saves time and reduces the risk of errors.

Common compliance consulting statement of work mistakes

  1. Promising certification. Outcomes controlled by an independent body should not be a deliverable.
  2. Vague deliverables. Words such as “support” and “assist” hide scope. Name the work product.
  3. No client obligations. Delays caused by the client become your cost.
  4. Silent on maintenance. The client may expect you to keep the system running after go-live. Say whether you will.
  5. No change process. Small additions accumulate into a large unpaid workload.
  6. Ignoring data handling. You will see policies, risks and possibly personal data. State how you handle and return confidential material.

Compliance consulting statement of work FAQ

How long should a statement of work be?

Most run between three and eight pages. Clarity matters more than length. Put the commercial terms in the master agreement and keep the statement of work focused on scope, deliverables and responsibilities.

Should I guarantee certification?

No. Certification is decided by an independent body, and your work is preparation. Promise defined deliverables and support, and describe the client’s responsibilities for operating the system.

Who owns the documents I create?

That is a contract term to agree in advance. A common approach is that the client owns the tailored deliverables while the consultant retains its pre-existing templates and methods. Have your lawyer review the clause.

How do I handle scope creep?

Use a change control clause and a simple request form. Estimate the impact, agree it in writing, and log every change so the project record matches the invoices.

Do I need professional indemnity insurance?

Many consulting clients ask for it, and it is sensible for advisory work. Confirm the cover and limits with your broker and reflect any liability cap in your master agreement.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.