ISO Procedure Order: The Proven Way to Prevent Rework

Implementation Sequencing

The ISO procedure order you choose at the start decides how much of the work you will do twice. Most first-time implementations open the standard at Clause 4 and write forward, which feels methodical and produces months of avoidable rework. The standard is printed in reading order. Your organization runs in a different one.

Direct Answer: The correct ISO procedure order is by breadth of impact, not by clause number. Write the procedures that touch every department first — document and records control, nonconformity and corrective action, risk management, internal audit — then leadership, then operations, then workforce, then design. The manual, where one is required at all, is written last. This holds across ISO 9001, ISO 13485, ISO 14001, ISO 45001 and ISO 7101.

This article assumes one thing has already happened: a program management planning session. Scope agreed, sponsor named, resources committed, timeline set against a certification target. If that has not happened, the ISO procedure order below is premature — you would be sequencing work that has no agreed boundary. That planning step is covered in the section that follows, with the relevant program for each standard.

Everything here comes out of building management systems across five standards and attending 200+ certification and surveillance audits. It is a sequencing method, not a reading of any one standard, which is why it transfers. Where you would rather adopt finished documents than write from a blank page, MSI’s ISO procedure templates and guides carry the same architecture across all five.


Before Anything Else

What Has to Happen Before ISO Procedure Order Even Matters?

Scope. Sponsor. Sequence.

Direct Answer: A program management planning session comes before any question of ISO procedure order. Leadership agrees the certification scope, names the sponsor and the implementation lead, commits the resource, and sets the timeline against a target date. Sequencing procedures before those decisions exist means sequencing work with no agreed boundary — and scope changes late in a build invalidate procedures that were already written.

This article takes that session as done. It is worth being explicit about why, because skipping it is common and the consequence is severe. The scope statement determines which sites, products, services and processes fall inside the system. Every procedure written afterward inherits that boundary. If the scope changes in month four — a site added, a product line included, a service excluded — the procedures written in months one through three all need review, and the ISO procedure order that looked correct no longer is.

The session also settles the questions only leadership can settle. Which standard or standards, and whether to build them integrated or sequentially. Who sponsors the work and who leads it day to day — MSI’s analysis of the ISO implementation lead role covers what that person actually needs. What resource is genuinely committed, in hours per week rather than in principle. And what the target date is, because a date without a sequence produces panic and a sequence without a date produces drift.

A management system does not fail at the procedures. It fails at the decisions nobody made before the procedures were written, and the procedures then have to carry the ambiguity.

If leadership is still deciding whether to pursue certification at all, that is an earlier conversation again, and the ISO Executive Decision Briefs are the right place to watch it play out before anyone commits budget.

Do This First

Launch Mastery — the program management planning session for your standard

Each program walks a leadership team through scoping, sponsorship, resourcing, stakeholder mapping and the first management review — the decisions that have to be settled before ISO procedure order becomes a live question. Pick the one that matches your standard:

QMS 9001 Launch Mastery — ISO 9001 quality management
EMS 14001 Kickoff and Strategic Planning — ISO 14001 environmental management
ISO 13485 Medical Device Launch Mastery — medical device quality management
ISO Quality & Medical Device Launch Mastery — ISO 9001 and ISO 13485 together
ISO 7101 HealthCare Quality Launch Mastery — healthcare quality management

Building to ISO 45001, or to a combination not listed? Call 760-434-9141 and MSI will run the planning session against your actual scope.


The Expensive Default

Why Does Clause Order Fail as an ISO Procedure Order?

Read. Build. Different.

Direct Answer: Clause order fails as an ISO procedure order because the standards are organized for comprehension, not construction. Clause numbering places context and planning early and puts document control, corrective action and internal audit late. But document control governs the format of every document you are about to write, corrective action is where every other procedure escalates, and risk assessment is what justifies every operational control. Write them last and you revise everything above them.

Watch how it actually unfolds. A team starts at Clause 4, produces a context analysis, moves to Clause 5 for the policy, then works through Clause 8 and generates a stack of operational procedures. Two months in, they arrive at Clauses 7.5, 9.2 and 10.2 and discover four problems simultaneously.

None of the operational procedures carry a document control header, because no document control procedure existed when they were drafted. Each one ends where something goes wrong and says nothing about what happens next, because the corrective action route had not been defined. The operational controls have no documented risk basis, so nobody can explain to an auditor why those controls rather than others. And the internal audit programme has nothing stable to audit against.

Across 200+ audits attended, the most reliable predictor of a slow first certification is not the size of the organization or the maturity of its processes. It is whether the infrastructure procedures were written first or last. The ISO procedure order is the single cheapest decision in the whole project and the one most often made by default.

The correction is one sentence. Order the work by how many departments each procedure affects, from most to fewest. Procedures that touch every department belong to no department and must exist before the departmental ones are written. Procedures that touch one department can wait, because nothing else depends on them.

There is a second reason this ISO procedure order works, and it is about people rather than documents. The infrastructure procedures are the least contentious. Nobody in operations has a strong opinion about revision numbering. Starting there lets the implementation team build competence and credibility on low-conflict work before it walks into the departments where the real negotiation happens. MSI’s piece on document and records control as the place to start develops the point for that procedure specifically.


The Method

The Five Groups That Set ISO Procedure Order

Infrastructure. Leadership. Operations.

Direct Answer: The ISO procedure order runs in five groups. Group 1 is infrastructure: document and records control, nonconformity and corrective action, risk management, internal audit. Group 2 is leadership. Group 3 is operations. Group 4 is workforce. Group 5 is design. Groups 2 and 4 merge in small organizations because the same people approve both. The manual comes last, and only where something other than the standard requires one.
Group Procedures Departments affected
1 — Infrastructure Document and records control · Nonconformity and corrective action · Risk management · Internal audit All of them, which is why it belongs to none of them
2 — Leadership Scope · Policy · Objectives · Roles and authority · Management review · Change control All, but through one approving body
3 — Operations Operational control · Purchasing and supplier control · Monitoring and measurement · Nonconforming output The largest population and the most records
4 — Workforce Competence · Training · Awareness · Roles and job descriptions All, through one function — merges with Group 2 when small
5 — Design Design and development, where the standard and the scope require it Usually one, and downstream of operations
Last — Manual Only where a standard, regulator or customer requires one Describes a system that has to exist first

Group 1 — Infrastructure: four procedures that govern all the others

Document and records control leads the ISO procedure order for a mechanical reason. It defines the header, the approval route, the revision scheme, the review cycle and the retention rule that every subsequent document carries. Write it first and everything after it is born compliant. Write it eighth and you revise seven documents to match.

Nonconformity and corrective action comes second because it is the destination of every exception path in every other procedure. Each procedure you write later contains some version of “if this cannot be completed as described, raise a nonconformity,” and that sentence needs somewhere to point. MSI’s work on continual improvement and the corrective action loop covers what a procedure has to do to stop findings recurring.

Risk management comes third because operational controls without a documented risk basis cannot be defended. The auditor’s question is never whether you have a control — it is why that one. The answer is a risk assessment, and MSI’s risk management procedure template guidance sets out the eight elements that make one hold.

Internal audit comes fourth. It is written in Group 1 and executed after Groups 2 and 3 exist, because it is the mechanism that tests everything else and certification bodies expect a completed cycle before they arrive. Note that the audit standard itself moved: ISO 19011:2026 cancelled the 2018 edition outright with no transition period, so a procedure written to the old guidance is already dated. MSI’s internal audit planning guidance and the internal audit risk matrix cover how to rank processes defensibly rather than alphabetically.

Start With Group 1

Adopt the infrastructure procedures instead of drafting them

Group 1 is the least sector-specific and most transferable part of any ISO procedure order, which makes it the part worth adopting rather than writing. MSI’s ISO Procedure Templates and Guides library covers ISO 9001, ISO 13485, ISO 14001:2026, ISO 45001 and ISO 7101, every procedure written to the same sixteen-section architecture so the set interlocks the day you download it. Single-standard packages $149, integrated multi-standard $249.

See the full procedure library →

Group 2 — Leadership: scope, policy, objectives, authority and review

Group 2 sets the boundaries and the authority that every operational procedure inherits. It is second in the ISO procedure order rather than first because it needs the document control conventions from Group 1 to be settled, and because a policy written before the risk approach exists tends to commit the organization to things it has not yet thought through.

Management review belongs here, and it is required by ISO 9001, ISO 13485, ISO 14001, ISO 45001 and ISO 7101 alike — it is not an ISO 9001 peculiarity. Change control also belongs in Group 2, and it is the most commonly omitted procedure in the whole set. MSI’s coverage of change management explains why an uncontrolled change is the fastest route to a system that no longer matches its documentation.

Group 3 — Operations: the largest block in any ISO procedure order

Group 3 is the heart of the ISO procedure order and where the organization actually is: operational control, purchasing and supplier control, monitoring and measurement, and the handling of nonconforming output. Budget roughly twice the time you gave Group 2 in the ISO procedure order. This is also where the negotiation happens, because these procedures describe what people already do, and describing it accurately requires them to admit what that is.

Supplier control deserves particular attention because it is where most organizations write an aspiration rather than a process. MSI’s piece on the purchasing and supplier control procedure covers why rating suppliers on spend rather than risk is the common failure. And the general test for whether a Group 3 procedure works is in MSI’s effective ISO procedure analysis: hand it to a competent person who has never done the task and see whether they can complete it without asking a colleague anything.

Group 4 — Workforce: and the merge rule for small organizations

Group 4 of the ISO procedure order covers competence, training, awareness and the job descriptions that carry role definitions. Here is the merge rule. Where the same two or three people approve both governance decisions and workforce decisions — typically under roughly 150 staff, or any single-site operation — write Groups 2 and 4 as one document. Same approvers, same review cycle, same meeting. Splitting them produces two documents that must be kept consistent by hand, and hand-maintained consistency is the most reliable source of findings in small organizations. Above that size, keep them separate, because the approval routes genuinely diverge.

Group 5 — Design, and the manual last

Design sits last in the ISO procedure order because it designs into the delivery process Group 3 defines. Where design is excluded from scope, Group 5 disappears entirely — though note that ISO 13485 permits far less exclusion than ISO 9001 does, and design controls carry regulatory weight there rather than merely contractual weight.

The manual comes after everything else in the ISO procedure order. ISO 9001 has not required a quality manual since 2015, and neither do ISO 14001, ISO 45001 or ISO 7101. ISO 13485:2016 still mandates one at Clause 4.2.2, and a regulator, insurer or major customer can require one regardless of what the standard says. When you write it, keep it thin: scope, the processes, how they interact, and pointers to the procedures. A map drawn before the territory exists is fiction that will need redrawing.

The freedom to shape the set this way is deliberate. ISO 10013:2021 replaced the earlier technical report and dropped the prescribed documentation hierarchy, leaving the structure open to the user. Nobody can tell you your documentation is the wrong shape. What replaces the pyramid is sequence, which is precisely why ISO procedure order now carries the weight the hierarchy used to.


Standard By Standard

How Does ISO Procedure Order Change by Standard?

Same groups. Different weight.

Direct Answer: The groups hold across every standard, but the weight inside them shifts. The ISO procedure order stays the same for ISO 9001, ISO 14001, ISO 45001 and ISO 7101 because they share the harmonized ten-clause structure. ISO 13485 is the exception worth knowing: it predates that structure entirely, so the grouping still works but the clause numbers do not map across.

ISO 9001 — and the 2026 edition arriving

ISO 9001:2015 is the reference implementation of this method — balanced groups, no group dominant. One timing note matters right now. ISO/FDIS 9001 is at Final Draft stage with publication expected in September 2026. If you are starting a build today, write to the current edition and design for the revision rather than waiting for it. The ISO procedure order does not change; some content inside Group 2 will.

Organizations transitioning ISO 9001 and ISO 14001 together should read MSI’s analysis of sequencing both 2026 revisions into one plan before deciding how to phase the work.

ISO 13485 — the exception to the structure, not to the method

ISO 13485 predates the harmonized structure and keeps its own clause architecture. Treat it as a separate mapping exercise rather than an extension of ISO 9001 — the five groups still hold, but do not assume a clause number transfers.

Three things weight the ISO procedure order differently here. The quality manual is mandatory at Clause 4.2.2, so it is still written last but it is not optional. The medical device file is a documentation obligation with no equivalent in the other standards. And design controls carry regulatory rather than contractual consequence, which pulls Group 5 forward in importance even though it stays late in sequence. MSI’s work on medical device cybersecurity as a QMS obligation covers a Group 3 area that has expanded sharply.

ISO 14001:2026 — new edition, renumbered clauses

ISO 14001:2026 published on April 15, 2026, and the 2015 edition is withdrawn, with transition running to April 30, 2029. If you are implementing for the first time, build to the 2026 edition directly and skip the transition question entirely.

One practical warning about ISO procedure order here. Clause 6.1 was renumbered — risks and opportunities moved and planning action moved with them — which breaks cross-references in most documents written against the 2015 edition. Anything you inherit from a prior build needs its references checked before it is folded into the new set. Group 2 also carries more weight in an environmental system than in a quality one, because aspects, impacts and compliance obligations all originate there and feed every operational control downstream.

For ISO 14001 Builds And Transitions

ISO 14001:2026 Procedure Templates and Guides

Built for experienced EHS managers who need to move an existing ISO 14001:2015 system to the 2026 edition inside a week, and equally usable as the Group 1 through Group 5 set for a clean-slate build. Written to the 2026 clause numbering, so the cross-reference problem is already solved rather than inherited.

See the ISO 14001:2026 procedure templates →

ISO 45001 — where Group 4 moves up

ISO 45001 is the one standard where the ISO procedure order shifts materially. Worker consultation and participation is a genuine requirement rather than a courtesy, and it is not something you can document after the fact — the workers have to have been consulted while the procedures were being written. In practice this means Group 4 runs alongside Groups 2 and 3 rather than after them, and the consultation records are generated during the build rather than at the end of it.

Hazard identification also sits differently in the ISO procedure order. In a quality system, risk assessment justifies the controls. In a safety system it also determines which operational procedures need to exist at all, which makes the Group 1 risk procedure load-bearing in a way it is not elsewhere.

ISO 7101 — healthcare, and a larger Group 3

ISO 7101:2023 shares the harmonized structure, so the ISO procedure order transfers directly, but Group 3 is larger than in any other standard in this family and the standard adds obligations the others do not carry — a culture of quality, people-centred care and co-production, equity and dignity, and workforce wellbeing alongside patient safety. MSI’s dedicated pillar on ISO 7101 documentation works the groups through in healthcare terms and maps them against accreditation obligations.

Integrated builds — one set, not two

Building two or three standards together does not change the ISO procedure order. It changes what goes inside each group. One document control procedure, one corrective action procedure, one internal audit programme, one management review — each carrying the requirements of every standard in scope. This is where most of the integration saving lives, and it is only available if the integrated decision is made before Group 1 is written. MSI’s guide to integrated management system implementation covers the full pattern, and the certification audit view explains what the auditor sees when it is done well.


The Most Expensive Mistake

Do Not Implement While the ISO Procedure Order Is Still Running

Draft. Map. Then move.

Direct Answer: Wait. Once a team finishes a procedure the urge to roll it out is almost irresistible, and acting on it is the most expensive mistake in the project. The set interlocks, so working through the ISO procedure order will force changes to procedures already written. Anything trained, issued and generating records has to be retrained, reissued and reconciled. Two activities are safe from day one: standardizing job descriptions and titles, and bringing existing documents under document control.

The pressure runs the other way, which is why this needs saying. Leadership wants visible progress. The team that wrote the first procedure is proud of it. Somebody proposes a pilot in one department. All of it feels like momentum and all of it creates rework.

The mechanism is simple, and it holds at every stage of the ISO procedure order. If a procedure has only been drafted, a downstream change costs an afternoon. If it has been trained, issued and used to generate records, the same change costs a retraining cycle, a document reissue, and a set of records now traceable to a superseded revision. Training records against a withdrawn version are a finding in their own right, not merely untidiness.

A procedure is a component, not a product. Nothing in the set is finished until the set is finished.

Exception one: standardize job descriptions and titles first

Do this before the ISO procedure order even begins, and finish it. Every procedure names roles rather than people. If job titles are inconsistent across the organization, every one of those references is built on sand, and correcting the titles later means revising every procedure that used them.

In MSI’s experience across 200+ audits attended, job descriptions are almost always the messiest documents in the organization: several template formats in circulation, titles that differ between the org chart, the payroll system and the door sign, and required fields missing outright. Fixing this early is genuinely safe, because nothing depends on it — everything depends from it.

Fix the template before applying it. A job description that will support the whole ISO procedure order needs, at minimum: the exact title as it will appear in every procedure, the reporting line, required qualifications and licences, required competence and how it is verified, defined responsibilities, defined authority including what the role may decide alone, named alternates for absence, and the review trigger. Miss a field and you reopen every job description later. Then enforce one title per role everywhere — org chart, payroll, training records, rota, procedure — and record any second name as an alias.

Exception two: bring existing documents under document control

The second safe activity, again independent of where you are in the ISO procedure order, is applying control protocols to what already exists. Work instructions, forms, drawings, specifications, policies — nearly all of it exists somewhere and almost none of it is under one regime. Getting to near-total coverage is pure gain, because control concerns custody rather than content: a header, an owner, an approval date, a revision number, a review date, a retention rule, one authoritative location.

This is safe precisely because it does not depend on procedures you have not written. It also produces the documented information register almost as a by-product, which is the item most implementations discover missing at the worst possible moment. MSI’s broader guidance on building and optimizing QMS documentation covers what to keep and what to retire.

The rule while the ISO procedure order is still running: control everything, implement nothing. Documents can be brought under control at any time without risk. Processes cannot be rolled out without committing the organization to a version.

And do not automate yet

The same caution applies harder to software. Teams reach for a quality platform early because configuring something feels like progress. Configuring a platform around procedures that are still moving means configuring it twice, and platform rework is slower and far more political than document rework. Build the procedural foundation first, then select and configure tooling around a system that has stopped changing. MSI’s analysis of why procedure-first always wins in ISO compliance automation works through that sequence and the cost of inverting it.


Week By Week

What Does the ISO Procedure Order Look Like on a Calendar?

Plan. Build. Run.

Direct Answer: A single-site first-time build runs roughly sixteen to twenty-four weeks of drafting through the ISO procedure order, then three to six months of operation before a certification audit. The operating period cannot be compressed. A certification body cannot assess a system that has never generated evidence, however well the documents are written.
Week 0 — Program management planning session. Scope, sponsor, lead, resource, timeline, standards in scope, integrated or sequential. Nothing below starts until this is signed.
Weeks 1–3 — Job titles and Group 1. Fix the job description template, lock one title per role. Draft or adopt document control, corrective action, risk management, internal audit. Open the documented information register on day one.
Weeks 4–7 — Group 2 leadership. Scope statement, policy, measurable objectives with owners, roles and authority, change control, management review cycle. Draw the process interaction map here, not later.
Weeks 8–15 — Group 3 operations. The largest block: operational control, purchasing and supplier control, monitoring and measurement, nonconforming output. Budget twice the Group 2 time. For ISO 45001, run worker consultation in parallel from week 4.
Weeks 16–20 — Group 4, then Group 5. Competence, training, awareness. Merge with Group 2 if the approvers are the same people. Then design, where scope requires it.
Weeks 21+ — Implement, audit, review. Now roll it out. Train once, against final versions. Let records accumulate. Complete one internal audit cycle, hold one real management review with real data, then approach a certification body accredited by a Global ACI member.

Organizations that adopt finished templates rather than drafting from a blank page typically compress the drafting phase substantially, because the judgment calls inside each procedure are already made and annotated. What cannot be compressed is the operating period, and MSI client experience suggests that the organizations trying to shorten it are the ones that end up scheduling a second visit. For budgeting the whole programme, MSI’s breakdown of what ISO certification costs sets expectations honestly.

Where an organization would rather have the programme designed and run alongside its own team, MSI’s ISO consulting practice does exactly that. To talk through your own ISO procedure order against a real scope and timeline, call 760-434-9141 for a planning session.


Ask. Answer.

ISO Procedure Order: Frequently Asked Questions

Direct. Practical. Short.

Which ISO procedure should be written first?

Document and records control. It defines the header, approval route, revision scheme, review cycle and retention rule that every other document will carry, so writing it first means everything after it is born compliant. Before that, outside the procedure set itself, standardize job descriptions and lock one title per role — every procedure names roles rather than people.

Does the ISO procedure order differ between standards?

The groups hold across ISO 9001, ISO 13485, ISO 14001, ISO 45001 and ISO 7101. The weight inside them shifts. ISO 45001 moves workforce consultation to run in parallel rather than after, because workers must be consulted while the procedures are being written. ISO 13485 keeps a mandatory quality manual and adds the medical device file. ISO 7101 carries a much larger operational group. ISO 13485 is also the one standard that predates the harmonized ten-clause structure, so the grouping transfers but the clause numbers do not.

How many procedures does a management system need?

There is no required number, and the count matters far less than coverage. Most single-standard systems land between eight and fourteen procedures depending on how much is consolidated, and consolidation is usually the better choice. The test is whether every requirement in the standard has a trigger, a named owner and a named record attached to it somewhere in the set.

Can we start implementing procedures as we finish drafting them?

No. Hold implementation until the set is mapped and substantially drafted. Procedures interlock, so a later one will force changes to an earlier one, and anything already trained, issued and generating records must be retrained, reissued and reconciled. Training records against a superseded revision are a finding. Two activities are safe from day one: standardizing job descriptions and titles, and bringing existing documents under document control. Software selection waits until the procedures stop moving.

Do we still need a quality manual?

Only for ISO 13485, which mandates one at Clause 4.2.2, or where a regulator, insurer or major customer requires it. ISO 9001 dropped the requirement in 2015, and ISO 14001, ISO 45001 and ISO 7101 do not require one either. ISO 10013:2021 also dropped the prescribed documentation hierarchy, leaving the structure open. Where you do write a manual, write it last and keep it thin.

Does building two standards together change the sequence?

No. It changes what goes inside each group rather than the order of the groups. One document control procedure, one corrective action procedure, one internal audit programme and one management review, each carrying the requirements of every standard in scope. That is where most of the integration saving comes from, and it is only available if the integrated decision is made before Group 1 is written.

Related Reading

Go Deeper on Each Stage of the ISO Procedure Order

Read. Apply. Advance.

Document and Records Control — the first procedure in the sequence, in full.
Effective ISO Procedure — the seven marks and the substitution test.
Risk Management Procedure Template — the eight elements of a mature risk procedure.
Internal Audit Planning — building the programme that tests the rest.
ISO 19011:2026 Internal Audit Procedure — six edits the new edition requires.
ISO Implementation Lead — who runs the build, and the first 90 days.
Integrated Management System Implementation — two or three standards as one system.
ISO 7101 Documentation — the healthcare instance of this method.
ISO Compliance Automation — when to select a platform, and why not yet.
Quality Improvement Culture — what keeps the system alive after certification.
ISO Standards and Integrity — why the record has to match reality.
Become an ISO Consultant — for practitioners building range across standards.
ISO Procedure Templates and Guides — the full library across five standards.
References and Primary Sources

This article is general guidance and does not replace ISO 9001:2015, ISO 13485:2016, ISO 14001:2026, ISO 45001:2018, ISO 7101:2023, ISO 10013:2021, ISO 19011:2026, any applicable regulation, or the judgment of a competent professional. Standards are revised, amended and withdrawn; confirm the current status of any standard at iso.org before relying on clause references. Sources were verified on August 2, 2026.

About Management Systems International (MSI)

Management Systems International (MSI) is a veteran-owned, female-owned ISO consulting firm founded in 1998. With 28 years of experience including extensive AS9100 work in MSI’s early years, MSI’s track record includes 80+ certifications supported, 200+ audits attended, and 600+ professionals trained across manufacturing, technology, medical device, government, healthcare, and other regulated industries.

Today MSI implements ISO 9001, ISO 13485, ISO 14001, and ISO 45001, with an expanding focus on ISO 7101 healthcare quality.

msi-international.com  ·  760-434-9141

Share this post:
post by:
Picture of Diana Lynn

Diana Lynn

Founder and Principal of Management Systems International (MSI), a veteran-owned, female-owned ISO consulting firm she founded in 1998. Diana implements management systems, conducts audits, and develops MSI's entire training curriculum — 80+ organizations certified, 200+ audits, and 600+ professionals trained across manufacturing, technology, aerospace, medical device, government, healthcare, defense, and other regulated industries.
In This Guide
Stay Informed

Join our early-access list for ISO 14001:2026 briefings.

Trusted by Global Leaders

Don't miss our latest news!

Get on our Email list. MSI emails new offers, training dates, and ISO updates to our list before anyone else.

Twenty-eight years of practice, written down.
New: complete ISO procedure templates and guides. 13 procedure topics, five standards and combos, editable Word — with the judgment calls already made.
See the templates →

Buy any Template Packages and the price is credited 100% to ISO Consulting Projects, SurePath or SureResults Online or Traditional. Terms apply