ISO Compliance Training That Goes Beyond the Standard: Learn from David S. Marshall’s Deep Audit, Security and Internal Control Experience
- John C. Blackshire, Jr.

- 1 day ago
- 9 min read
ISO Compliance Is Not About Memorizing Clauses
Organizations often approach ISO standards as documentation exercises.
They assemble policies. They prepare procedures. They build registers. They create checklists. They get ready for an audit.
But an effective ISO management system should do much more than produce documentation for a certification auditor.
It should help the organization:
Define its objectives.
Identify the risks that could prevent those objectives from being achieved.
Establish controls to address those risks.
Monitor whether those controls are working.
Correct weaknesses.
Continually improve the organization.
That is why the instructor matters.
Corporate Compliance Seminars’ ISO Compliance CPE training programs are taught from the perspective of someone who has spent decades working with auditing, information technology, cybersecurity, risk management, regulatory compliance and internal controls—not simply teaching the text of an ISO standard.
David S. Marshall, MBA, CISA, CFE, CFS, co-founder of Corporate Compliance Seminars and Founder and CEO of Infotech Global Audit and Security, brings more than 40 years of hands-on professional experience to these programs. He has managed and performed hundreds of audits, security assessments, fraud investigations and Sarbanes-Oxley compliance activities and has trained thousands of professionals.
That practical background changes how ISO is taught.
The objective is not simply:
“What does the standard require?”
The more useful question is:
“How do we design, implement, operate and audit a management system that actually helps the organization control risk and achieve its objectives?”
Why David Marshall’s Background Is Particularly Relevant to ISO
ISO management-system standards are fundamentally about systems, risk, controls, evidence and continual improvement.
Those disciplines align closely with David Marshall’s professional background.
Through Infotech Global Audit and Security, David’s work has focused on internal auditing, physical and cybersecurity, regulatory compliance, risk management, fraud prevention and detection, project management and professional training. His firm’s audit methodology maps organizational objectives, the risks or problems that can impede those objectives, and the internal controls designed to mitigate the risks.
That is remarkably close to the logic behind modern ISO management systems:
Objectives
↓
Risks and Opportunities
↓
Processes
↓
Controls
↓
Performance Measurement
↓
Corrective Action
↓
Continual Improvement
This means ISO is not taught as a separate compliance universe.
It is connected to the same risk-and-control principles professionals already use in auditing, governance, cybersecurity and compliance.
Experience Across Audit, IT and Compliance Matters
David’s career has crossed several professional disciplines.
Before founding Infotech Global and co-founding CCS, he led an internal auditing, IT and compliance practice within a worldwide U.S. aerospace and defense corporation and previously served as a Senior Manager in the Management Consulting and Auditing practices of a Big Four CPA firm.
He has also worked as a:
Business auditor
IT auditor
Consultant
Financial systems analyst
Enterprise software implementer
Business owner
Trainer
That breadth is particularly valuable when teaching ISO because ISO management systems do not operate inside one department.
An effective management system crosses:
Executive management
Operations
Quality
Information Technology
Cybersecurity
Human Resources
Compliance
Risk management
Internal Audit
Procurement
Third-party management
ISO implementation therefore requires people who can understand how controls and processes interact across the organization.
ISO 9001 Is Really About Managing Processes and Quality Risk
Consider ISO 9001 Quality Management Systems.
Organizations sometimes assume that ISO 9001 is principally for manufacturers.
That is too narrow.
A quality management system can be valuable for virtually any organization that relies on repeatable processes to deliver products or services.
The relevant questions include:
What does the customer require?
What is the organization trying to accomplish?
Which processes produce the product or service?
Who owns those processes?
What could cause the process to fail?
How is performance measured?
What happens when the process produces an exception?
How does management know corrective action worked?
Those are management questions.
They are also audit questions.
David’s experience designing, implementing and assessing internal controls provides a natural foundation for evaluating whether quality processes are not only documented but actually capable of producing consistent results. His professional philosophy emphasizes practical, cost-effective controls rather than controls that outweigh the risks they are intended to address.
That philosophy fits ISO implementation particularly well.
A quality management system should help the organization perform better.
It should not become bureaucracy for the sake of certification.
ISO 27001 Requires More Than Cybersecurity Technology
The same principle applies to ISO/IEC 27001 Information Security Management Systems (ISMS).
Cybersecurity is frequently treated as a technical problem:
Firewalls
Endpoint security
Encryption
Passwords
Vulnerability scanning
Network monitoring
Those technologies matter.
But ISO 27001 takes a broader management-system approach.
CCS’s Managing Information Security (ISO 27001) program addresses understanding ISO 27001, taking a risk-based approach to information security, implementing an effective ISMS and addressing incident management and compliance.
David’s professional background is particularly relevant here because Infotech Global specializes in both physical and cybersecurity as well as internal controls, audit and compliance. His experience includes cybersecurity, ISO and NIST 800 audits.
That allows the discussion to move beyond:
“Do we have a cybersecurity policy?”
toward:
“How does management know that information-security risks have been identified, appropriate controls have been implemented, those controls are operating and deficiencies are being corrected?”
That is the difference between a security document and an effective Information Security Management System.
ISO and Internal Controls Belong Together
One of the strongest reasons audit and compliance professionals should understand ISO is that ISO management systems and internal control frameworks share common concepts.
Both require organizations to understand:
Objectives
Risks
Responsibility
Processes
Controls
Information
Monitoring
Corrective action
David has extensive experience designing, implementing and assessing internal controls and helping organizations with COSO, Sarbanes-Oxley, Enterprise Risk Management, SOC assessments, cybersecurity, ISO and NIST-related work.
That allows participants to see relationships among:
ISO management systems
COSO
SOX
Enterprise Risk Management
Cybersecurity frameworks
Internal Audit
These frameworks are not identical.
But organizations frequently make the mistake of implementing them in separate silos.
A mature organization asks:
How can we build one effective system of governance, risk management and internal control that satisfies multiple requirements?
That is a far more valuable question.
The Auditor’s Perspective Changes ISO Compliance
A consultant may help an organization write an ISO procedure.
An experienced auditor asks a different series of questions.
For example:
What objective is this procedure supposed to achieve?
What risk does it address?
Who owns the process?
How do we know the process operates?
What evidence exists?
What happens when it fails?
Who reviews the exceptions?
How does management determine whether corrective action worked?
Those questions make ISO implementation stronger.
They also prepare the organization for both internal and external audits.
David’s experience includes conducting consultations, walkthroughs and document inspections to evaluate objectives, risks and internal controls. Infotech Global’s assessment approach emphasizes identifying practical, risk-ranked control improvements and corrective actions.
That audit discipline is incorporated into the way ISO concepts are taught.
Walkthroughs Reveal Whether the Management System Really Works
An organization may have an excellent written procedure.
The auditor still needs to determine whether employees actually follow it.
Suppose a quality procedure states:
All customer complaints are logged, categorized, investigated and reviewed for corrective action.
A meaningful ISO audit would ask:
Show me the complaint log.
Select the most recent significant complaint.
Who received it?
How was it classified?
Who investigated it?
What caused the problem?
Was corrective action required?
Who approved the corrective action?
How did management determine that the corrective action was effective?
Did similar complaints occur later?
The procedure tells the auditor what should happen.
The walkthrough and evidence tell the auditor what did happen.
That distinction is central to both internal auditing and effective ISO auditing.
Corrective Action Is More Than Fixing the Immediate Problem
One of the most valuable aspects of ISO management systems is the emphasis on improvement.
But many organizations confuse correcting an exception with correcting its cause.
Suppose a customer receives an incorrect product.
Management sends the right product the next day.
The customer problem has been corrected.
But the management-system problem may remain.
The organization should ask:
Why was the wrong product shipped?
Was the order entered incorrectly?
Did labeling fail?
Was inventory stored incorrectly?
Was employee training inadequate?
Did the system allow an inappropriate substitution?
Could the same failure affect other customers?
That moves the organization toward root-cause analysis.
David’s internal control background supports this type of thinking because control recommendations should address sustainable corrective actions rather than simply repairing isolated exceptions. Infotech Global describes its approach as developing pragmatic, risk-ranked recommendations with corrective actions, accountabilities and implementation considerations.
ISO Should Improve the Business Even When Certification Is Not Required
This may be one of the most important messages in the CCS ISO Compliance programs.
Organizations do not need to pursue formal ISO certification to benefit from ISO principles.
The standards can provide useful management disciplines for organizations that simply want to:
Improve processes.
Reduce errors.
Strengthen cybersecurity.
Clarify accountability.
Manage risk.
Improve customer satisfaction.
Strengthen vendor management.
Improve performance measurement.
Create better corrective-action systems.
That makes ISO relevant to:
Public companies
Private businesses
Government agencies
Nonprofits
Healthcare organizations
Financial institutions
Professional service firms
Manufacturers
Technology companies
Infotech Global reports experience across financial services, aerospace and defense, IT, manufacturing, distribution, retail, healthcare and service industries, giving David a broad base of examples for demonstrating how risk and control concepts apply differently across organizations.
A Practical Philosophy: Controls Should Balance Risk
ISO programs can become overengineered.
Organizations sometimes react to an audit finding by adding:
Another approval
Another form
Another signature
Another review
Another policy
Eventually, employees spend more time administering the controls than managing the process.
David’s stated philosophy is that internal controls should balance risks rather than outweigh them, and that organizations should measure performance if they expect to improve it.
That provides a useful perspective for ISO compliance.
An effective management system should be:
Risk-based
Practical
Scalable
Measurable
Sustainable
Cost-effective
The objective is not the largest ISO manual.
The objective is a management system that works.
David Brings Fraud and Ethics Experience Into the Discussion
Quality and information-security failures are not always accidental.
Organizations must also consider:
Intentional circumvention
Vendor misconduct
Data theft
False certifications
Fraudulent documentation
Management override
David is a Certified Fraud Examiner and Certified Fraud Specialist, has conducted fraud investigations, formerly served for six years as President and Chair of the Greater Chicago Chapter of the Association of Certified Fraud Examiners, and serves on the ACFE Worldwide Advisory Council.
That background adds another dimension to ISO compliance.
A control should not only work when everyone follows the rules.
A mature control environment should consider what happens when someone deliberately tries to defeat the process.
Government and Defense Experience Adds Another Dimension
David has also worked with government organizations and the U.S. defense industry. His professional background includes classified government work under a U.S. Department of Defense security clearance, and he continues consulting within the defense industry.
That experience is relevant for organizations dealing with:
Government contracts
Sensitive information
Cybersecurity
Security controls
Supplier management
Regulatory compliance
Controlled environments
These organizations often need to understand how ISO fits alongside other frameworks and requirements rather than treating ISO as a stand-alone certification effort.
An Instructor Should Be Able to Answer “What Happens in the Real World?”
ISO training should generate questions.
Participants may ask:
What if management refuses to perform the required review?
How much documentation is enough?
How do we audit a process that is mostly automated?
What if the organization outsources the process?
How should we document a risk assessment?
When does an exception become a systemic problem?
How do we determine root cause?
How do ISO controls align with COSO?
How do ISO 27001 and NIST work together?
How should Internal Audit approach an ISO management system?
How can we make ISO cost-effective?
These questions cannot always be answered by repeating language from a standard.
They require experience.
David’s 40-plus years conducting audits, compliance activities, security assessments and training provide the practical context necessary for those discussions.
CCS ISO Compliance Training Is Designed for Practitioners
Corporate Compliance Seminars emphasizes training taught by practitioners rather than salespeople, with content designed around real audit, risk and compliance problems. CCS is a NASBA-registered CPE sponsor and offers both live webinars and in-person training.
The ISO Compliance category is intended for professionals responsible for areas such as:
Quality management
Information security
Internal Audit
Compliance
Risk management
Operations
Cybersecurity
Governance
The objective is not merely to introduce ISO terminology.
It is to help attendees understand how management systems are designed, implemented, operated, measured and audited.
Why Learn ISO from David S. Marshall?
David brings a combination of experience that is difficult to replicate in a traditional standards-only course:
More than 25 years of professional experience.
Hundreds of audits, security assessments and fraud investigations.
Big Four auditing and consulting experience.
Leadership of an internal audit, IT and compliance practice within a global aerospace and defense company.
Extensive SOX and COSO implementation experience.
Cybersecurity, ISO and NIST audit experience.
CISA, CFE and CFS professional credentials.
Experience training thousands of professionals.
Global experience across numerous industries.
Most importantly, he approaches ISO from the perspective of someone who has had to determine whether controls work in real organizations.
That matters.
The Bottom Line: ISO Should Make the Organization Better
The value of ISO is not the certificate hanging in the lobby.
The value is what happens inside the organization.
Does management understand its objectives?
Are important risks identified?
Are processes clearly defined?
Are responsibilities assigned?
Are controls appropriately designed?
Do employees perform them?
Is performance measured?
Are failures identified?
Are root causes corrected?
Does the organization continually improve?
If the answer to those questions is yes, the organization has something much more valuable than a compliance program.
It has a management system.
Corporate Compliance Seminars’ ISO Compliance training is designed to help professionals reach that level of understanding, and David S. Marshall brings the audit, cybersecurity, risk, compliance and internal-control experience needed to connect ISO requirements with the realities of running and improving an organization.
Comments