Eric Appiah · 24 June 2026 · 7 min read
More Ghanaian organisations are being asked for ISO 27001 — by international clients, by partners running third-party risk assessments, and increasingly by regulators who want evidence rather than assurances. The question I am usually asked is how quickly it can be obtained. That framing is where most failed attempts begin.
It is a management system, not a certificate
ISO 27001 specifies an Information Security Management System: a set of processes for identifying risks to your information, deciding what to do about them, implementing controls, and reviewing whether any of it is working. The certificate attests that this system exists and operates. It does not attest that you are secure.
This matters practically. An auditor is not primarily checking whether you have a firewall. They are checking whether you decided you needed one through a documented risk assessment, whether someone owns it, and whether you have evidence it has been reviewed since. Organisations with genuinely good security frequently fail their first audit because none of that reasoning was written down.
What preparation actually involves
- Defining scope: which parts of the business, which systems, which locations. Scope that is too broad is the most common reason a first attempt collapses under its own weight.
- An asset and risk register: what information you hold, what could go wrong, how likely and how damaging, and what you have decided to do about each item.
- A Statement of Applicability: for every control in Annex A, whether it applies to you, and if not, why not. This document is where auditors spend their time.
- Policies people follow: an access control policy that describes what actually happens when someone joins or leaves is worth more than a thirty-page document nobody has read.
- Evidence of operation: access reviews conducted, incidents logged, training delivered, backups tested. Auditors ask for records, not intentions.
The local realities that catch organisations out
Two patterns show up repeatedly in Ghanaian organisations. The first is shared credentials — a single administrator login used by several people because it was convenient when the team was four people and never revisited. This fails on accountability grounds, and remediating it late is disruptive.
The second is supplier management. Most organisations depend on hosting providers, software vendors, and contractors who touch sensitive data, and almost none have documented what those parties are permitted to do or what happens if they suffer a breach. Annex A is explicit about supplier relationships, and it is a frequent source of findings.
An honest note on timelines and consultants
For an organisation starting from a standing start, six to twelve months to audit readiness is realistic, depending on scope and how much you already do informally. Anyone offering certification in weeks is selling documentation, not a management system, and the gap becomes visible at surveillance audit.
One structural point worth knowing: no consultant can both prepare you and certify you. Certification is issued by an accredited certification body, and that separation exists for good reason. If a firm offers to do both, that alone tells you something about the certificate you would receive.
