ISO standards
International management standards that buyers ask for by number.
Please note: This page explains what a term means. It is general information, not legal, financial, tax or investment advice, and it does not know anything about your business. Before you sign, file or commit to anything, check it with an accountant, a solicitor, or the official guidance we link to.
What it means
The ones most often required: ISO 9001 (quality), ISO 14001 (environmental), ISO 27001 (information security), ISO 45001 (health and safety).
Why it matters
They are frequently a gateway to larger contracts, and in tenders they are often a pass/fail requirement rather than a scored one.
What it looks like in practice
Certification is by an accredited body against the standard, with surveillance audits between three-yearly recertifications. Cost scales with the size and complexity of the business.\n\nISO 27001 in particular has become a common requirement for anyone handling customer data.
What to watch out for
Uncertified "compliance". Saying you work to a standard without certification is legitimate and does not satisfy a tender that asks for certification.
Where to get proper advice
UKAS's list of accredited bodies — accreditation matters, because unaccredited certificates are not accepted.
Where to read more
Last reviewed 2026-08-28 by Fiducia Together · Next review due 2027-08-28
Please note: This page explains what a term means. It is general information, not legal, financial, tax or investment advice, and it does not know anything about your business. Before you sign, file or commit to anything, check it with an accountant, a solicitor, or the official guidance we link to.
Fiducia Together