top of page
Search

ISO Compliance Training That Goes Beyond the Standard: Learn from David S. Marshall’s Deep Audit, Security and Internal Control Experience

ISO Compliance Is Not About Memorizing Clauses

Organizations often approach ISO standards as documentation exercises.


They assemble policies. They prepare procedures. They build registers. They create checklists. They get ready for an audit.


But an effective ISO management system should do much more than produce documentation for a certification auditor.


It should help the organization:

  • Define its objectives.

  • Identify the risks that could prevent those objectives from being achieved.

  • Establish controls to address those risks.

  • Monitor whether those controls are working.

  • Correct weaknesses.

  • Continually improve the organization.


That is why the instructor matters.


Corporate Compliance Seminars’ ISO Compliance CPE training programs are taught from the perspective of someone who has spent decades working with auditing, information technology, cybersecurity, risk management, regulatory compliance and internal controls—not simply teaching the text of an ISO standard.


David S. Marshall, MBA, CISA, CFE, CFS, co-founder of Corporate Compliance Seminars and Founder and CEO of Infotech Global Audit and Security, brings more than 40 years of hands-on professional experience to these programs. He has managed and performed hundreds of audits, security assessments, fraud investigations and Sarbanes-Oxley compliance activities and has trained thousands of professionals.


That practical background changes how ISO is taught.


The objective is not simply:

“What does the standard require?”

The more useful question is:

“How do we design, implement, operate and audit a management system that actually helps the organization control risk and achieve its objectives?”

Why David Marshall’s Background Is Particularly Relevant to ISO

ISO management-system standards are fundamentally about systems, risk, controls, evidence and continual improvement.


Those disciplines align closely with David Marshall’s professional background.


Through Infotech Global Audit and Security, David’s work has focused on internal auditing, physical and cybersecurity, regulatory compliance, risk management, fraud prevention and detection, project management and professional training. His firm’s audit methodology maps organizational objectives, the risks or problems that can impede those objectives, and the internal controls designed to mitigate the risks.


That is remarkably close to the logic behind modern ISO management systems:


Objectives

Risks and Opportunities

Processes

Controls

Performance Measurement

Corrective Action

Continual Improvement


This means ISO is not taught as a separate compliance universe.


It is connected to the same risk-and-control principles professionals already use in auditing, governance, cybersecurity and compliance.


Experience Across Audit, IT and Compliance Matters

David’s career has crossed several professional disciplines.


Before founding Infotech Global and co-founding CCS, he led an internal auditing, IT and compliance practice within a worldwide U.S. aerospace and defense corporation and previously served as a Senior Manager in the Management Consulting and Auditing practices of a Big Four CPA firm.


He has also worked as a:

  • Business auditor

  • IT auditor

  • Consultant

  • Financial systems analyst

  • Enterprise software implementer

  • Business owner

  • Trainer


That breadth is particularly valuable when teaching ISO because ISO management systems do not operate inside one department.


An effective management system crosses:

  • Executive management

  • Operations

  • Quality

  • Information Technology

  • Cybersecurity

  • Human Resources

  • Compliance

  • Risk management

  • Internal Audit

  • Procurement

  • Third-party management


ISO implementation therefore requires people who can understand how controls and processes interact across the organization.


ISO 9001 Is Really About Managing Processes and Quality Risk


Organizations sometimes assume that ISO 9001 is principally for manufacturers.


That is too narrow.


A quality management system can be valuable for virtually any organization that relies on repeatable processes to deliver products or services.


The relevant questions include:

  • What does the customer require?

  • What is the organization trying to accomplish?

  • Which processes produce the product or service?

  • Who owns those processes?

  • What could cause the process to fail?

  • How is performance measured?

  • What happens when the process produces an exception?

  • How does management know corrective action worked?


Those are management questions.


They are also audit questions.


David’s experience designing, implementing and assessing internal controls provides a natural foundation for evaluating whether quality processes are not only documented but actually capable of producing consistent results. His professional philosophy emphasizes practical, cost-effective controls rather than controls that outweigh the risks they are intended to address.


That philosophy fits ISO implementation particularly well.


A quality management system should help the organization perform better.


It should not become bureaucracy for the sake of certification.


ISO 27001 Requires More Than Cybersecurity Technology


Cybersecurity is frequently treated as a technical problem:

  • Firewalls

  • Endpoint security

  • Encryption

  • Passwords

  • Vulnerability scanning

  • Network monitoring

Those technologies matter.


But ISO 27001 takes a broader management-system approach.


CCS’s Managing Information Security (ISO 27001) program addresses understanding ISO 27001, taking a risk-based approach to information security, implementing an effective ISMS and addressing incident management and compliance.


David’s professional background is particularly relevant here because Infotech Global specializes in both physical and cybersecurity as well as internal controls, audit and compliance. His experience includes cybersecurity, ISO and NIST 800 audits.


That allows the discussion to move beyond:

“Do we have a cybersecurity policy?”

toward:

“How does management know that information-security risks have been identified, appropriate controls have been implemented, those controls are operating and deficiencies are being corrected?”

That is the difference between a security document and an effective Information Security Management System.


ISO and Internal Controls Belong Together

One of the strongest reasons audit and compliance professionals should understand ISO is that ISO management systems and internal control frameworks share common concepts.


Both require organizations to understand:

  • Objectives

  • Risks

  • Responsibility

  • Processes

  • Controls

  • Information

  • Monitoring

  • Corrective action


David has extensive experience designing, implementing and assessing internal controls and helping organizations with COSO, Sarbanes-Oxley, Enterprise Risk Management, SOC assessments, cybersecurity, ISO and NIST-related work.


That allows participants to see relationships among:

  • ISO management systems

  • COSO

  • SOX

  • Enterprise Risk Management

  • Cybersecurity frameworks

  • Internal Audit


These frameworks are not identical.


But organizations frequently make the mistake of implementing them in separate silos.


A mature organization asks:

How can we build one effective system of governance, risk management and internal control that satisfies multiple requirements?

That is a far more valuable question.


The Auditor’s Perspective Changes ISO Compliance

A consultant may help an organization write an ISO procedure.


An experienced auditor asks a different series of questions.


For example:

  • What objective is this procedure supposed to achieve?

  • What risk does it address?

  • Who owns the process?

  • How do we know the process operates?

  • What evidence exists?

  • What happens when it fails?

  • Who reviews the exceptions?

  • How does management determine whether corrective action worked?


Those questions make ISO implementation stronger.


They also prepare the organization for both internal and external audits.


David’s experience includes conducting consultations, walkthroughs and document inspections to evaluate objectives, risks and internal controls. Infotech Global’s assessment approach emphasizes identifying practical, risk-ranked control improvements and corrective actions.


That audit discipline is incorporated into the way ISO concepts are taught.


Walkthroughs Reveal Whether the Management System Really Works

An organization may have an excellent written procedure.


The auditor still needs to determine whether employees actually follow it.


Suppose a quality procedure states:

All customer complaints are logged, categorized, investigated and reviewed for corrective action.

A meaningful ISO audit would ask:

  • Show me the complaint log.

  • Select the most recent significant complaint.

  • Who received it?

  • How was it classified?

  • Who investigated it?

  • What caused the problem?

  • Was corrective action required?

  • Who approved the corrective action?

  • How did management determine that the corrective action was effective?

  • Did similar complaints occur later?


The procedure tells the auditor what should happen.


The walkthrough and evidence tell the auditor what did happen.


That distinction is central to both internal auditing and effective ISO auditing.


Corrective Action Is More Than Fixing the Immediate Problem

One of the most valuable aspects of ISO management systems is the emphasis on improvement.


But many organizations confuse correcting an exception with correcting its cause.


Suppose a customer receives an incorrect product.


Management sends the right product the next day.


The customer problem has been corrected.


But the management-system problem may remain.


The organization should ask:

  • Why was the wrong product shipped?

  • Was the order entered incorrectly?

  • Did labeling fail?

  • Was inventory stored incorrectly?

  • Was employee training inadequate?

  • Did the system allow an inappropriate substitution?

  • Could the same failure affect other customers?


That moves the organization toward root-cause analysis.


David’s internal control background supports this type of thinking because control recommendations should address sustainable corrective actions rather than simply repairing isolated exceptions. Infotech Global describes its approach as developing pragmatic, risk-ranked recommendations with corrective actions, accountabilities and implementation considerations.


ISO Should Improve the Business Even When Certification Is Not Required

This may be one of the most important messages in the CCS ISO Compliance programs.

Organizations do not need to pursue formal ISO certification to benefit from ISO principles.


The standards can provide useful management disciplines for organizations that simply want to:

  • Improve processes.

  • Reduce errors.

  • Strengthen cybersecurity.

  • Clarify accountability.

  • Manage risk.

  • Improve customer satisfaction.

  • Strengthen vendor management.

  • Improve performance measurement.

  • Create better corrective-action systems.


That makes ISO relevant to:

  • Public companies

  • Private businesses

  • Government agencies

  • Nonprofits

  • Healthcare organizations

  • Financial institutions

  • Professional service firms

  • Manufacturers

  • Technology companies


Infotech Global reports experience across financial services, aerospace and defense, IT, manufacturing, distribution, retail, healthcare and service industries, giving David a broad base of examples for demonstrating how risk and control concepts apply differently across organizations.


A Practical Philosophy: Controls Should Balance Risk

ISO programs can become overengineered.


Organizations sometimes react to an audit finding by adding:

  • Another approval

  • Another form

  • Another signature

  • Another review

  • Another policy


Eventually, employees spend more time administering the controls than managing the process.


David’s stated philosophy is that internal controls should balance risks rather than outweigh them, and that organizations should measure performance if they expect to improve it.


That provides a useful perspective for ISO compliance.


An effective management system should be:

  • Risk-based

  • Practical

  • Scalable

  • Measurable

  • Sustainable

  • Cost-effective


The objective is not the largest ISO manual.


The objective is a management system that works.


David Brings Fraud and Ethics Experience Into the Discussion

Quality and information-security failures are not always accidental.


Organizations must also consider:

  • Intentional circumvention

  • Vendor misconduct

  • Data theft

  • False certifications

  • Fraudulent documentation

  • Management override


David is a Certified Fraud Examiner and Certified Fraud Specialist, has conducted fraud investigations, formerly served for six years as President and Chair of the Greater Chicago Chapter of the Association of Certified Fraud Examiners, and serves on the ACFE Worldwide Advisory Council.


That background adds another dimension to ISO compliance.


A control should not only work when everyone follows the rules.


A mature control environment should consider what happens when someone deliberately tries to defeat the process.


Government and Defense Experience Adds Another Dimension

David has also worked with government organizations and the U.S. defense industry. His professional background includes classified government work under a U.S. Department of Defense security clearance, and he continues consulting within the defense industry.


That experience is relevant for organizations dealing with:

  • Government contracts

  • Sensitive information

  • Cybersecurity

  • Security controls

  • Supplier management

  • Regulatory compliance

  • Controlled environments


These organizations often need to understand how ISO fits alongside other frameworks and requirements rather than treating ISO as a stand-alone certification effort.


An Instructor Should Be Able to Answer “What Happens in the Real World?”

ISO training should generate questions.


Participants may ask:

  • What if management refuses to perform the required review?

  • How much documentation is enough?

  • How do we audit a process that is mostly automated?

  • What if the organization outsources the process?

  • How should we document a risk assessment?

  • When does an exception become a systemic problem?

  • How do we determine root cause?

  • How do ISO controls align with COSO?

  • How do ISO 27001 and NIST work together?

  • How should Internal Audit approach an ISO management system?

  • How can we make ISO cost-effective?


These questions cannot always be answered by repeating language from a standard.


They require experience.


David’s 40-plus years conducting audits, compliance activities, security assessments and training provide the practical context necessary for those discussions.


CCS ISO Compliance Training Is Designed for Practitioners

Corporate Compliance Seminars emphasizes training taught by practitioners rather than salespeople, with content designed around real audit, risk and compliance problems. CCS is a NASBA-registered CPE sponsor and offers both live webinars and in-person training.


The ISO Compliance category is intended for professionals responsible for areas such as:

  • Quality management

  • Information security

  • Internal Audit

  • Compliance

  • Risk management

  • Operations

  • Cybersecurity

  • Governance


The objective is not merely to introduce ISO terminology.


It is to help attendees understand how management systems are designed, implemented, operated, measured and audited.


Why Learn ISO from David S. Marshall?

David brings a combination of experience that is difficult to replicate in a traditional standards-only course:

  • More than 25 years of professional experience.

  • Hundreds of audits, security assessments and fraud investigations.

  • Big Four auditing and consulting experience.

  • Leadership of an internal audit, IT and compliance practice within a global aerospace and defense company.

  • Extensive SOX and COSO implementation experience.

  • Cybersecurity, ISO and NIST audit experience.

  • CISA, CFE and CFS professional credentials.

  • Experience training thousands of professionals.

  • Global experience across numerous industries.


Most importantly, he approaches ISO from the perspective of someone who has had to determine whether controls work in real organizations.


That matters.

The Bottom Line: ISO Should Make the Organization Better

The value of ISO is not the certificate hanging in the lobby.


The value is what happens inside the organization.

  • Does management understand its objectives?

  • Are important risks identified?

  • Are processes clearly defined?

  • Are responsibilities assigned?

  • Are controls appropriately designed?

  • Do employees perform them?

  • Is performance measured?

  • Are failures identified?

  • Are root causes corrected?

  • Does the organization continually improve?

If the answer to those questions is yes, the organization has something much more valuable than a compliance program.


It has a management system.


Corporate Compliance Seminars’ ISO Compliance training is designed to help professionals reach that level of understanding, and David S. Marshall brings the audit, cybersecurity, risk, compliance and internal-control experience needed to connect ISO requirements with the realities of running and improving an organization.

 
 
 

Recent Posts

See All

Comments


Contact Us

Please white list the email address johnb@cseminars.com to allow for CCS emails to reach you effectively.

Thanks for submitting!

Corporate Compliance Seminars is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.nasbaregistry.org.

In accordance with the standards of the National Registry of CPE Sponsors, CPE credits are granted based on a 50-minute hour.

National Registry of CPE Sponsors ID #108983

Complaints may also be forwarded to the company principals, David S. Marshall (708-205-2366davem@cseminars.com) and/ or John Blackshire (479-200-4373johnb@cseminars.com)

 

bottom of page