Brian Sims
Editor

Speed-focused compliance certification “undermines credibility”

NEW RESEARCH conducted by business resilience specialist IO (formerly ISMS online) suggests growing concern that the rise of accelerated compliance offerings is contributing to a perception that certification alone delivers resilience when, in reality, the greatest business value comes from establishing, embedding and continuously improving the management systems that sit behind it.

The research reveals that 87% of senior cyber security managers in the UK believe the speed at which certification is achieved affects its credibility. The concern is not that speed is inherently dishonest. It’s that compliance done fast, compressed, automated end-to-end and stripped of rigour doesn't deliver what compliance is actually all about. It delivers a certificate. It doesn’t deliver a business that can handle what comes next.

As more providers promise quick and automated routes to compliance, businesses risk mistaking speed for resilience and security.

Chris Newton-Smith, CEO of IO, explained: “Organisations that focus on achieving certification as quickly as possible are at risk of leaving gaps in their security posture. Certification can open doors to new contracts and demonstrate commitment to recognised standards, but treating certification as the end goal rather than the outcome of establishing and embedding effective compliance is, more often than not, at the expense of long-term resilience. Businesses must treat compliance not as a tick-box exercise, but rather as an evolving, iterative and business critical project.”

This sentiment is echoed in the findings with 21% of respondents saying third party certifications may somewhat reflect the real-world effectiveness of an organisation’s security controls at the time of audit, but can quickly become outdated, raising further questions about how much confidence businesses should place in certification achieved through accelerated implementation approaches alone.

Additionally, nearly one-third of those professionals surveyed (31%) cited continuous monitoring of controls as the best indicator of an organisation’s security compliance resilience, not a rapid certification result.

Continuous improvement cycles

ISO standards, including ISO 27001, are all explicitly built on continuous improvement cycles. Software platforms that treat certification as a one-time documentation exercise are structurally at odds with that principle and practitioners appear to know it. Those organisations that treat compliance as a continuous operating discipline rather than a cost to be minimised through speed are the ones that compound their advantage over time.

Newton-Smith continued: “Certification provides valuable independent assurance that an organisation has implemented controls. However, where implementation has been heavily compressed, there may be limited opportunity to demonstrate that those controls have been embedded, monitored and improved over time. Genuine resilience requires that controls are embedded, understood and actively maintained, not just documented for inspection.”

Further, Newton-Smith observed: “The research gives us a clear picture of what practitioners believe genuine compliance resilience looks like, with controls that are monitored continuously, governance with named accountability and human expertise kept in the loop. These are the foundations that allow an organisation to keep operating through disruption, demonstrate its security posture on demand and absorb regulatory change without starting from scratch.”

In addition, Newton-Smith said: “Compliance done rigorously delivers all of this. It’s not just a certification, but the capability to audit faster, absorb new requirements without disruption, face fewer costly surprises, keep the business running and keep earning trust.” 

Essential to credible compliance

The findings also show why human expertise remains essential to credible compliance. While automation can speed up evidence gathering and routine checks, it cannot replace professional judgement when interpreting complex regulatory requirements, assessing context or identifying where an organisation’s documented compliance posture may not fully reflect its day-to-day operational resilience.

45% of respondents believe that human expertise is still essential when evaluating whether the suggested automated compliance processes and actions are relevant or accurate, with 33% saying human expertise is needed to interpret complex regulations. A further 32% said human expertise is key to challenging the credibility or completeness of automated compliance evidence.

“The question to ask of any compliance programme isn’t how long it took,” noted Newton-Smith. “It’s: ‘Do the people in this organisation understand what they’re doing and why?’ Are the controls genuinely embedded? Would this hold if something went wrong tomorrow? If the answer to those questions is ‘Yes’, the certification means something. If the process was too fast for those questions to have been properly answered, the certificate is a risk, not a reassurance.”

Procurement teams and partners are increasingly assessing not just whether an organisation holds certification, but how it manages compliance on an ongoing basis. Certification remains an important signal of trust, but organisations are increasingly expected to demonstrate that compliance is embedded into day-to-day operations through governance, monitoring and continual improvement.

“The ability to demonstrate live and integrated governance is becoming a commercial differentiator for businesses,” concluded Newton-Smith.

*Further information is available online at www.isms.online

Company Info

Western Business Media Limited

Dorset House
64 High Street
East Grinstead
RH19 3DE
UNITED KINGDOM

Login / Sign up