How to check a consultant can turn findings into action
Verify a risk consultant can implement findings, not just identify problems. Check references, implementation history, credentials, and whether they adapt.
You've got a risk assessment report sitting on your desk. It identifies real vulnerabilities in your business—maybe around physical security, supply chain exposure, or data handling. The question now isn't whether the consultant found the problems. It's whether they can actually help you fix them. Some consultants are excellent at diagnosis but poor at implementation. Others hand over a document and vanish. You need someone who can bridge the gap between "here's what's wrong" and "here's how we make it work given what you can do."
Before you sign a contract or pay for implementation support, you can verify whether a consultant has a track record of turning findings into real change.
Proof they've done it before
Ask directly: "Show me a case where your findings led to implemented changes." A genuine consultant will have at least one story they can walk you through—not confidential details, but the shape of it. They should describe what the client's constraints were, how the plan evolved to fit them, and what actually got done. If they hedge or say all their work is under NDA, ask for a reference client who can speak to their implementation approach (see below).
Proof also means looking at their structure. Do they employ implementation specialists, or do they only hand off to other firms? Do they stay involved during execution, or is implementation someone else's problem? A consultant skilled at turning findings into action will have processes and sometimes staff dedicated to the "during" and "after," not just the diagnosis.
Check whether they've worked in your sector or a close one. Risk is context-dependent. A consultant who's implemented controls in financial services may struggle with manufacturing or retail. Ask what proportion of their recent work mirrors your own environment.
What to ask references
When you call a reference—and you should always call, not just email—focus on implementation, not the quality of the assessment itself. Ask these specific things:
- Did the consultant adapt their findings when you explained your budget or operational constraints? Or did they insist you follow the report exactly?
- Were they available during the rollout to answer questions or adjust the plan when something didn't work in practice?
- Did they help you prioritise what to tackle first, or did you have to figure that out alone?
- Looking back, did the changes they recommended actually stick, or did things drift back to how they were?
- Would you hire them again for a follow-up review?
If a reference says the consultant was brilliant but disappeared after handover, that's a yellow flag. If they say the plan was solid but had to be heavily rewritten to fit reality, ask why—the consultant should have anticipated that.
Also ask the reference whether the consultant explained their recommendations clearly. A plan that's technically sound but written in jargon that your team can't understand won't get implemented. Good consultants translate risk language into operational language.
Registration and credentials
Check the consultant is registered with a relevant professional body. In South Africa, look for membership with bodies like the South African Council for Security and Crime Prevention (SASCP) or equivalent certifications in their specialty—cyber, physical security, fraud, supply chain, or whatever your risk sits in. Ask for their registration number and verify it.
Credentials alone don't mean they can implement, but they do signal they've met peer standards. Gaps in registration are a warning sign.
Red flags during the conversation
If a consultant says "I'll tell you what to fix; your team will figure out how," move on. If they're vague about how implementation typically unfolds or won't name examples of changes they've actually seen through, they may be long on analysis and short on delivery. If they seem impatient with your questions about constraints or feasibility, they're not thinking like someone who'll shepherd the work to completion.
A consultant who asks you detailed questions about your team's capacity, your budget flexibility, and how decisions actually get made in your organisation is thinking about implementation. One who asks only about the risks is probably not.
When you're ready to test your shortlist, request a brief call or a proposal that includes their implementation approach and how they stay involved. On Strove, you can check verified consultants' profiles for client reviews that often mention follow-through and real-world impact. That's the fastest filter before you invest time in detailed conversations.
Common questions
- What should I ask a reference about a consultant's implementation skills?
- Ask whether the consultant adapted findings to your constraints, stayed available during rollout, helped prioritise work, and whether changes actually stuck. Also ask if they'd hire them again. References are most valuable when they speak to the gap between a good plan and one that actually gets executed.
- Can a consultant with impressive credentials still be poor at implementation?
- Yes. Credentials show they meet peer standards but don't guarantee they can guide your organisation through change. Always ask for implementation examples and references, and notice during conversations whether they seem focused on diagnosis or on how your team will actually make changes happen.
- What's a red flag that a consultant won't follow through?
- Avoid anyone who won't explain their implementation approach, disappears after handover, seems impatient with your constraints, or can't name examples of changes they've seen through. Good consultants anticipate obstacles and ask detailed questions about your team and budget before recommending fixes.
- Should I check professional registration for risk consultants?
- Yes. Ask for their registration number with a relevant body in their specialty and verify it yourself. Registration doesn't guarantee they'll implement well, but it signals peer vetting and is a baseline check that's quick to run.
Find a verified provider on Strove
Compare vetted risk mitigation planning providers, check their credentials, and book or request a quote — all in one place.
Find a Business