What ISO certification can and cannot do for your organisation

Over the years, I have received countless calls and emails from CEOs, COOs, quality and compliance managers and generally interested industry professionals who all ask a version of the same question: “What can an ISO certification do for my company?” Inherent in that question is another, but one that doesn’t get asked as often: “Is there something that certification to an ISO standard cannot do for my company?”
Here’s what an ISO certification can do for your organisation:
- Build credibility and trust. Certification to these two specific ISO standards signals to customers, partners and regulators that your organisation meets internationally recognised standards. It is a third-party endorsement of your processes.
- Improve internal processes. The certification process forces organisations to document, standardise and review workflows, which often surfaces inefficiencies and gaps that weren’t visible before – and formal processes create transparency and trust.
- Open market access. Many industries, governments and large corporations require certification to an ISO standard as a prerequisite to doing business.
- Reduce errors and risk. Through the implementation of ISO 20252 and ISO 27001 requirements, these standards help create a transparency of processes so that when failure happens, remediation can be traced to a direct source and corrected.
- Support continuous improvement. These two specific standards include built-in cycles of review and corrective action, through the internal audit process, by pushing organisations to improve over time rather than stall and wait for an annual external audit.
- Provide a common language. Across global supply chains, ISO standards give partners and suppliers a shared framework for quality, safety and compatibility expectations.
Here’s what an ISO certification cannot do for your organisation:
- Guarantee product or service quality. Certification means your processes conform to a standard – not that your client report or project or other output is actually good. A company can be ISO 20252 or ISO 27001 certified and still produce mediocre products if those processes aren’t developed or matured or consistently followed.
- Replace competence or good judgement. No certification substitutes for skilled people making sound decisions. Audits don’t make up for a poorly trained workforce.
- Prevent all failures or incidents. ISO 20252 doesn’t provide 100% data quality, and ISO 27001 doesn’t make your company unhackable. The goal is a notable reduction in fraud and/or data breaches.
- Automatically satisfy legal or regulatory compliance. Certification to these ISO standards and legal requirements can often overlap, but certification to a standard is not the same as legal compliance.
- Sustain itself without ongoing commitment. Certification becomes hollow without genuine, continual process improvement, and ongoing annual internal and external audits.
- Cure organisational culture problems. Leadership support and buy-in is critical to ongoing success because adoption of an ISO standard is effectively a cultural shift for an organisation.
- Apply uniformly across all contexts. Standards are generic by design. They require interpretation and adaptation, and both ISO 20252 and ISO 27001 can be scaled to fit a two-person research firm to a global and diverse full-service organisation.
Remember…
Certification to industry-relevant standards like ISO 20252 and ISO 27001 are tools. Implemented thoughtfully and adopted seriously, they can drive real improvements and open doors to new opportunities and new business.
Juliana Wood is managing director at CIRQ, (the Certification Institute for Research Quality), a subsidiary of the Insights Association that provides audit and certification services for ISO 20252 and ISO 27001.
We hope you enjoyed this article.
Research Live is published by MRS.
The Market Research Society (MRS) exists to promote and protect the research sector, showcasing how research delivers impact for businesses and government.
Members of MRS enjoy many benefits including tailoured policy guidance, discounts on training and conferences, and access to member-only content.
For example, there's an archive of winning case studies from over a decade of MRS Awards.
Find out more about the benefits of joining MRS here.







