Most writing about ISMS assumes an organisation of several hundred people: departments, an IT function, an audit office.
Healthcare startups and small vendors look nothing like that. Twenty people in total, eight engineers, two in back office is a normal shape. Read the standard's requirements at that size and phrases like "segregate duties" and "ensure the independence of the audit" look physically impossible.
The conclusion first: small organisations can and do certify. The standard is size-agnostic. But copying what a large organisation does will jam. This article separates what size helps with from what it hurts, how to document role overlap, and which roles can legitimately go outside. For the overall picture, see What Is an ISMS (ISO/IEC 27001)?.
Disclaimer: This article is general information. The authoritative texts are ISO/IEC 27001 (JIS Q 27001) itself and the publications of the accreditation and certification bodies. Whether a particular overlap of roles is acceptable is ultimately the certification body's judgement.
What Size Helps With
Being small is not only a handicap. The parts that give large organisations the most trouble simply do not exist.
1. Scope is naturally narrow
One site, one business line, and there is nothing to argue about. Large organisations can spend months on "which departments" and "what about the overseas office." See Defining ISMS Scope.
2. Asset inventory is actually achievable
At several hundred people, just establishing who uses which SaaS is a project. At twenty, you can ask everyone. See Building an Information Asset Register.
3. Decisions happen fast
Executives are close by, and policy and objectives get settled in one meeting rather than three weeks of circulation and inter-departmental alignment.
4. Few legacy exceptions
There is less accumulated practice to grandfather in, so rules can be defined cleanly.
Together, these mean effort scales roughly with headcount. Audit fees are priced by auditor-days, so a small organisation's audit is genuinely shorter. See The Full Cost of ISMS Certification.
Two Walls Specific to Small Organisations
Two obstacles decide feasibility in practice.
| Wall | The problem | How large organisations avoid it |
|---|---|---|
| No separation of duties | The same person requests and approves, or writes the code and deploys it | Departmental boundaries separate them naturally |
| No independent internal audit | You would be auditing your own work, which is not an audit | Auditors come from an audit office or another department |
The first shows up as:
- The engineer who wrote the code also runs the production deploy
- The same administrator both requests and approves account creation
- The person taking backups also verifies them
What the standard asks for is not more headcount but that you do not leave a state in which one person's fraud or error would go undetected. Design compensating measures and be able to explain them, and that requirement is satisfied.
The second is stricter. Auditing the system you built and run, and reporting "no findings," is not an audit. This is where small organisations most often stall. See Running Internal Audits.
Documenting Role Overlap Defensibly
Auditors do not ask whether roles overlap. They ask how you recognise the risk it creates and what compensates for it. Explained in writing, overlap itself is not rejected.
Three parts to the explanation:
- State who holds which roles — organisation chart and a table of duties
- Identify the specific risk the overlap creates — recorded in the risk assessment
- Define compensating measures and keep records — procedure plus operating records
Examples of compensating measures:
| Where separation is impossible | Compensating measure |
|---|---|
| Developers deploy to production | Mandatory peer review of pull requests, automatic deploy logging, monthly log review by an executive or third party |
| One administrator requests and approves accounts | Every issue and removal recorded in a register, reconciled quarterly by a different person |
| Same person takes and verifies backups | Scheduled restore tests reported to executives, with date and result recorded |
| The security lead also does the hands-on work | Management review where executives independently evaluate effectiveness, minuted |
The common shape is: keep records, and create an occasion for a second pair of eyes. Where real-time separation is impossible, after-the-fact review prevents a single person's error from sitting undetected.
And without records the explanation collapses. "We do review it in practice" does not pass an audit; the operating record is the evidence. See Running a Risk Assessment, Risk Treatment and Acceptance, and Adapting Procedure Templates. On the technical side, Security by Design for Medical Systems is also relevant.
Which Roles Can Go Outside
The key to certifying at small scale is knowing exactly which roles must stay in-house.
| Role | Responsibility | Outsourceable? |
|---|---|---|
| Top management | Integrating the ISMS, providing resources, owning risk, management review | No — the executive team |
| ISMS manager | Overall construction and operation | No — appointed internally |
| ISMS officers | Supporting operation in each area | No — appointed internally |
| Internal audit manager | Planning and improving audits, documenting results | Yes |
| Internal auditors | Performing audits | Yes |
That internal audit can be outsourced is decisive at this size, because it dissolves the independence wall. What remains internal is the executive team plus the appointment of an ISMS manager and officers.
The other realistic lever is narrowing scope. Confine it to what customers actually require rather than the whole company, and both assets and documents shrink. But the scope is printed on the certificate and read by customers, so confirm it covers their requirement — see When ISMS Becomes a Condition of Trade.
If the prior question — whether to certify at all — is still open, see When Not to Certify. For small organisations, building documentation without certifying yet is sometimes the rational path.
Conclusion
- The standard is size-agnostic. Small organisations can certify — but not by copying large-organisation practice
- Size helps with narrow scope, achievable inventory, fast agreement, few legacy exceptions; effort scales with headcount
- Two handicaps: no separation of duties and no independent internal audit
- Overlap is not rejected. What is asked is the recognised risk, the compensating measure, and the record
- The pattern for compensation is keep records and create a second pair of eyes — substitute after-the-fact review
- Internal audit can be outsourced. Only top management and the ISMS manager and officers must stay internal
Pottech supports ISMS certification with a focus on healthcare. Our first-certification programme assumes an organisation of up to roughly 50 people using our document templates — designed for exactly the scale this article addresses. We can also serve as your internal audit manager and internal auditors, leaving only the executive team and your ISMS manager and officers to appoint internally.
See ISMS Certification Support for scope and pricing, or contact us to discuss your situation.
References and Sources
- Information Management System Accreditation Center (ISMS-AC)
- ISO/IEC 27001 Information security management systems | ISO
- Information Security Guidelines for SMEs | IPA
- Guidelines for the Safe Management of Medical Information Systems | MHLW
Note: interpretation of requirements and controls, and the handling of accreditation and certification, are governed by the standard itself and the publications of the accreditation and certification bodies. Whether a given overlap of roles is acceptable is decided in the individual audit.