Governance Excellence Series · Article 100

International Standards: Not Every ISO Standard Requires Costly Certification

ISO's own whistleblowing guidance is weaker than Australian law already requires. Check the two directly

Strategic & External Environment · 27 July 2027

Many boards assume any conversation about adopting an international standard automatically means a costly, months-long certification process. For governance specifically, this is not the case, and understanding which standards require formal certification and which are guidance frameworks an association can adopt freely changes the actual cost-benefit calculation considerably.

The Distinction Most Boards Do Not Know

ISO 37000, the international standard specifically addressing organisational governance, is explicitly not a certifiable standard. It is guidance, and an association can adopt its framework, structure governance documentation around it, and demonstrate conformance through performance reviews and stakeholder feedback, all without paying for or undergoing formal third-party certification. This stands in contrast to standards like ISO 9001, which is certifiable and increasingly required as a prerequisite for tendering on government and larger private sector contracts, with real certification costs in Australia typically running several thousand dollars and a six to twelve month implementation timeline.

The Specific Warning Worth Knowing Precisely

An important, specific caution applies to whistleblowing standards. ISO 37002, the international guidance on whistleblowing management systems, is a useful framework, but its confidentiality requirements are less strict than what Australian law already requires for whistleblower protection. An association assuming that adopting ISO 37002 alone satisfies its actual Australian legal obligations for whistleblower confidentiality, connecting directly to the whistleblower culture discussion earlier in this quarter, would be mistaken. The international guidance is a useful complement to, not a substitute for, the specific and often stricter obligations Australian law already imposes. Adopting an international standard's framework does not automatically mean an association has met its actual Australian legal obligations in the same area. The two need to be checked against each other specifically, not assumed to align.

Why Multiple Standards Fit Together More Easily Than Expected

Modern ISO management system standards, quality, anti-bribery, compliance, information security, increasingly share a common underlying structure, making it easier to integrate several standards together than to implement each one as an entirely separate system. An association considering both a certifiable standard for tendering purposes and a guidance framework for governance improvement should investigate this compatibility directly, since a combined approach can meaningfully reduce the administrative burden compared with treating each standard as an isolated project.

International standards can offer a useful structure for an association looking to formalise its governance, quality, or risk management practices. Understanding which standards require certification, which do not, and where a standard's guidance may fall short of Australia's own specific legal requirements is what separates a useful adoption from an expensive credential that adds less real substance than assumed.

This is one of the practical governance topics built into our Association CEO course — alongside the papers, tools and frameworks that turn the principle into your board's actual practice. Explore the course →

— Annie

← Back to the Governance Excellence Series