A compliance consulting practice lives or dies on six structural decisions, and
most of them get made by accident. The first client sets the pricing model, the first framework sets
the positioning, and three years later the firm is shaped by choices nobody remembers making.

Decision one: how many frameworks you cover
The instinct is to specialise, and for the first year it is usually right — being the ISO
27001 person is easier to sell than being the compliance person. The problem arrives later, when
existing clients start asking for the next thing.
A client certified to ISO 27001 will shortly be asked by a customer for SOC 2. A medical device
manufacturer on ISO 13485 will need EU MDR. A supplier winning automotive work needs IATF 16949. Each
of those requests goes to somebody, and if it is not you it is a competitor with a foot in your
account.
The economics favour breadth more than most practitioners expect, because the expensive part of an
engagement is understanding the client — their scope, their systems, their people, their
appetite. That knowledge is already paid for. Adding a second framework for an existing client is
mostly incremental, which is why a multi-framework
approach tends to raise revenue per client faster than winning new logos does.
Decision two: your delivery model
Three models dominate, and mixing them without noticing is a common source of unprofitable work.
| Model | What you sell | Where it breaks |
|---|---|---|
| Project | Certification readiness, fixed scope and end date | Revenue restarts at zero after every engagement |
| Retained | Ongoing management of the system, monthly | Scope creeps quietly until the day rate is halved |
| Productised | A defined package at a defined price | Only works if the scope genuinely repeats |
The productised model is the one worth building toward, because it is the only one where doing the
work twice is cheaper than doing it once. It also demands the most discipline: a fixed price against
an unfixed scope is how consultancies lose money politely.
Decision three: how your compliance consulting practice handles documentation
Every compliance consulting practice reaches the same fork. Drafting policy sets from scratch for
each client is defensible, slow, and almost impossible to price competitively. Reusing your own
accumulated material is faster but drifts — the ISO 27001 pack you wrote in 2022 quietly stops
matching the 2022 Annex A structure you are now auditing against.
Buying a maintained library solves the drift and the speed together, provided the licence permits
client work. That is a real caveat rather than a formality: most template packs are licensed to a
single organisation, which does not cover deploying them across engagements. Our guide to
white label compliance
templates covers the five licence terms to check.
71 frameworks, licensed to your firm.
The Consultant Package covers all 71 toolkits — 6,000+ documents — including the sector frameworks most template libraries skip: IATF 16949, AS9100, ISO 13485, EU MDR and IVDR, ISO 17025, PCI DSS, HIPAA, CMMC, FedRAMP, TISAX, SWIFT CSP and SOX. Firm-wide licence, unlimited client engagements, clients keep what you hand them. One-time $1,399, perpetual, 12 months of updates.
Decision four: where the independence line sits
This one is not a preference. A consultant who designs and implements a management system cannot
then audit or certify it, and certification bodies operate under accreditation rules that keep
consultancy and certification apart. Our guides to
choosing a certification body
and ISO 27001 consultant costs set out
how that separation works from the client’s side.
The practice-level question is what you offer as a result. Internal audit delivered by someone
independent of the implementation is a legitimate and useful service — but if your firm built
the system, that independence has to come from a different person, and for smaller practices often a
different firm. Reciprocal arrangements with a peer consultancy are common and work well, provided
both sides document the independence.
Decision five: how you price
Day rates are simple, defensible and cap your income at your available hours. Fixed-fee packages
break that link but transfer delivery risk to you, which is only survivable if the scope is genuinely
controlled.
Whichever you choose, the mechanics matter more than the number. Tie payment to accepted
deliverables rather than elapsed time. State assumptions explicitly — environment access,
subject matter expert availability, review turnaround — and make it clear what happens when one
fails. Almost every unprofitable engagement in this field traces back to an unstated assumption about
how quickly the client would do their part.
Decision six: how you scale beyond yourself
The ceiling on a solo practice is arithmetic. Getting past it means either associates or
productisation, and both depend on the same thing: work that is repeatable enough for somebody else to
deliver to your standard.
That is where a documented method and a consistent document set stop being conveniences and become
the asset. An associate handed a maintained library and a defined delivery approach can be productive
in weeks. An associate handed a folder of previous clients’ documents and a verbal explanation cannot,
and every engagement they run will look different from yours.
What actually transfers
- The document library — maintained, current, and licensed for the whole firm
rather than for you personally. - The delivery method — the sequence of an engagement, written down, with the
checkpoints named. - The scoping conversation — the questions you ask before quoting, which is
usually the hardest thing to teach and the most expensive to get wrong. - The client-facing artefacts — proposal, statement of work, status report
format, so a client cannot tell who is delivering.
What does not transfer is judgement, which is why the first associate is always harder than the
third.
What a compliance consulting practice sells that software does not
Compliance platforms have taken a large share of the market a consulting practice used to own, and
pretending otherwise is a poor sales strategy. It is worth being clear about where each actually wins.
Software is strong at continuous evidence collection, control monitoring and keeping an audit trail
current. It is weak at everything requiring judgement: deciding scope, deciding what is genuinely a
risk to this business, negotiating with an auditor, and telling a founder that the thing they want to
do will cost them the certificate.
A compliance consulting practice competes badly on the first list and cannot be replaced on the
second. Positioning against a platform on evidence automation is a losing argument; positioning as
the judgement layer — often alongside a platform the client already bought — is a winning
one, and it is increasingly how engagements are structured.
The two questions that decide every engagement
Whatever the framework, two questions do most of the work and neither is answerable by a tool.
What is the scope? — which entities, systems, sites and people are in, which
are out, and can that boundary be defended to an auditor. Scope set badly is the single most expensive
error in certification work, and it is set in the first fortnight.
And what is this organisation actually willing to operate? A control set the client
will not sustain past the certificate is worse than a smaller one they will, because the surveillance
audit arrives twelve months later and finds an ISMS nobody has touched.
Frequently asked questions
How many frameworks should a compliance consulting practice cover?
Start with one you can sell, then add the frameworks your existing clients ask for. Breadth added in
response to real demand is far safer than breadth chosen speculatively.
Can I audit a management system I helped implement?
No. The independence requirement is the point of the audit. Internal audit by someone independent of
the implementation is fine; by the implementer it is not.
Is it acceptable to use bought templates on client work?
Yes, if the licence permits it. Check whether you are licensed as an individual, an organisation or a
firm, and whether client engagements are covered at all.
Should I specialise by framework or by sector?
Sector specialisation usually travels further. A consultant who understands medical device
manufacturing can learn ISO 13485, EU MDR and ISO 14971; a consultant who only knows one standard
cannot easily learn the sector.
What is the most common cause of unprofitable engagements?
Unstated assumptions about client availability, followed closely by fixed prices agreed against scopes
that were never written down.
Where this leaves your practice
None of these six decisions has a universally right answer, and a compliance consulting practice
can be built successfully on almost any combination of them. What does not work is leaving them
implicit. Decide how many frameworks you cover and why, which delivery model you are actually selling,
where your documentation comes from and whether it is licensed for the use you are putting it to,
where the independence line sits, how you price, and what would have to be true for somebody other
than you to deliver the work.
Write the answers down. The firms that struggle are rarely the ones that chose badly — they
are the ones that never chose, and discovered three years in that the practice had been shaped by its
first three clients.
References
- ISO/IEC 17021-1:2015 — requirements for bodies providing audit and certification of management systems.
- ISO/IEC 27001:2022 — information security management systems, on the ISO catalogue.
More for compliance consultants
- Building a compliance consulting practice — you are here
- White label compliance templates
- Multi-framework compliance
- The virtual CISO model
- The statement of work
- Choosing a certification body
All 71 toolkits are licensed for client work in the Consultant Package, or start with the free ISO templates.