Who is ISO/IEC 27701 certification for?
ISO/IEC 27701:2025 suits organisations that process personal information and are being asked to demonstrate how that processing is governed. It is used most often by:
SO/IEC 27701:2025 suits organisations that process personal information and are being asked to demonstrate how that processing is governed. It is used most often by:
- Software and technology businesses whose customers raise privacy assurance during procurement or vendor review.
- Processors and service providers handling personal information on behalf of their clients.
- Organisations that act as controllers of customer, employee or patient information and need a defensible basis for privacy decisions.
- Organisations that already run an information security management system and want to extend it to privacy.
Size is not the qualifier. A small organisation with a clearly drawn scope can hold certification; a large one with an ill-defined scope will struggle. What matters is that the boundary is honest and the arrangements inside it are real.
What does an ISO/IEC 27701 audit assess?
ISO/IEC 27701:2025 suits organisations that process personal information and are being asked to demonstrate how that processing is governed. It is used most often by:
- The boundary of the system, including the personal information processed, your role as controller or processor, and processing performed by others.
- Leadership, roles and responsibilities, and the privacy objectives set for the system.
- The privacy risk assessment and treatment process, and whether treatment decisions trace back to the risks recorded.
- The controls determined to be necessary for your role, those excluded, and the justification recorded for each position.
- Controls as they operate, tested through interviews, observation and records rather than documentation alone.
- Performance evaluation: monitoring, measurement, internal audit and management review.
- Nonconformity handling, corrective action and continual improvement.
Certification confirms that the management system meets the standard within the certified scope. It is not a guarantee that privacy incidents will not occur, it is not a legal compliance opinion, and it is not an assessment of any individual product or service.
How does ISO/IEC 27701 certification work?
Application and review
You describe your organisation, sites, activities, requested scope and use of outsourced processes. We determine the competence required and the audit time applicable under the scheme, and confirm that we can take the work impartially.
Stage 1
We examine readiness for Stage 2: how the scope is drawn, your role as controller or processor, the privacy risk assessment method, the applicable controls, internal audit and management review records, and your understanding of the standard. Areas of concern that would become nonconformities at Stage 2 are reported to you.
Stage 2
We test implementation and effectiveness across the certified scope, gather objective evidence and record findings.
Correction and corrective action
Where nonconformities are raised, you analyse cause and act. We review the response and verify effectiveness as required before a decision can be made.
Independent certification decision
Competent personnel who were not members of the audit team review the audit information and make the certification decision.
Surveillance and recertification
Surveillance audits monitor continuing conformity through the certification cycle. A recertification audit evaluates continued fulfilment of the standard before certification expires.
Each stage is described in full on our certification process page.
What evidence should you prepare for an ISO/IEC 27701 audit?
h for an ISO/IEC 27701 audit?
Bring the records the management system actually produces, rather than documents written for the audit. For ISO/IEC 27701 we normally expect to see:
- A scope statement naming the boundary, the personal information processed, your role as controller or processor, and the interfaces and dependencies with other parties.
- The privacy policy and the objectives set beneath it.
information security policy and the objectives set beneath it. - The privacy risk assessment methodology, the current risk register and the risk treatment plan.
- The record of applicable controls, current and under version control.
- Records showing controls in operation: records of processing, consent and notice handling, data subject request handling, retention and disposal, and supplier and processor agreements.
- Incident and breach records, including how each was classified, handled and closed.
- The internal audit programme, the individual audit reports, and the basis on which the auditors were judged competent.
- Management review inputs and the decisions recorded as outputs.
- Arrangements for personal information transfers and disclosures to third parties, together with evidence that they are followed.
What are the most common ISO/IEC 27701 readiness gaps?
These are the issues that most often delay a Stage 2 audit or generate findings.
- Scope drawn for convenience. A scope that excludes the systems customers actually rely on will not survive scrutiny, and the resulting certificate is difficult to use commercially.
- A Statement of Applicability without reasoning. Marking controls as applicable is not sufficient. The justification for inclusion or exclusion must be recorded and must agree with the risk treatment plan.
- k treatment disconnected from risk.
Personal information not mk treatment disconnected from risk. Risks recorded in one document and controls selected in another, with no visible line between the two. - Internal audit as a formality. A single short audit across the whole system, performed by the person who built it, rarely produces useful evidence and raises questions about independence.
- Management review as a calendar entry. Minutes that record attendance but no decisions, with no evidence that the required inputs were considered.
- Supplier arrangements assumed rather than assessed. Cloud platforms and outsourced functions sit inside the dependency chain of the scope and need documented assessment.
- Documentation describing an intended system. Where the written process and daily practice differ, the audit follows practice.
ISO/IEC 27701 enquiries
Tell us what you need certified.
Send us your proposed scope, your locations and an approximate headcount. We will explain what an ISO/IEC 27701 engagement would involve, what evidence to prepare, and where we think your readiness sits.
Start an enquiryRelated information
- What we certify — our full certification scope.
- Certification process — every stage from application to recertification.
- ISO/IEC 42001 certification — artificial intelligence management systems.
- How ISO/IEC 42001 differs from ISO/IEC 27001 — how the two management systems differ and can work together.
- Impartiality statement — how independence is protected.
- Complaints and appeals — how to raise a concern or challenge a decision.
- Contact — the scoping enquiry form.
General enquiries: info@acscert.com.au. Complaints and appeals: complaints@acscert.com.au.
