When Meridian Trust Bank asked us to take them to ISO 27001, their previous consultants had estimated 24 months. We signed for 14 and delivered in 11. Nothing about that timeline required heroics; it required removing the three delays that quietly consume most certification programmes.
Decision one: the risk register got an owner with budget
Most ISMS programmes stall in committee. Risks are identified, logged, discussed, and reassigned — a carousel that produces minutes instead of mitigations. Meridian's CIO broke the pattern by giving the risk register a single owner with delegated spend authority up to a defined threshold. Mitigation decisions that previously waited six weeks for a steering committee happened in six days. Auditors later cited the decision log as evidence of management commitment — the hardest clause to fake.
Decision two: evidence became a by-product, not a project
The month before an audit is traditionally a scramble of screenshot archaeology. We refused to run it that way. Every control was wired to produce its own evidence continuously: access reviews exported automatically on completion, patch compliance snapshotted weekly, incident tickets templated with the fields Annex A asks about. By audit week, the evidence pack was an export, not an expedition. This is also why the certificate survives surveillance audits without the annual panic — the system documents itself.
Decision three: scope discipline
The single biggest schedule killer in certification is scope creep dressed as thoroughness. Meridian certified its core banking environment and the SOC that protects it — not the staff canteen WiFi. A tight, defensible scope statement cut the control population by a third without weakening the security story the certificate tells regulators and correspondent banks.
What it cost, honestly
Eleven months, a programme team of four (two ours, two theirs), and tooling the bank largely already owned. The expensive part was attention: a fortnightly management review that started on time and ended with decisions. If your organisation cannot sustain that meeting, no consultant can certify you — and one that promises otherwise is selling you a plaque, not a posture.
Run our eight-question readiness checker for a blunt first answer. It maps to the same domains an auditor samples first, and it will tell you which of these three decisions your organisation has actually made.
Talk to the team behind this.
Route your enquiry directly to the IT desk.