An independent, third-party certification body · operating to ISO/IEC 17021-1:2015
Verify a Certificate ↗·Global · Remote & on-site·EN
Certification

What ISO/IEC 27701 actually asks of you

The request usually comes from a customer rather than a regulator. A security questionnaire with a privacy section. A data processing agreement returned with tracked changes. Somewhere in it, a question that is harder to answer than it looks: how do we know you handle our people’s data the way you say you do?

Assurances are cheap at that point, and everyone gives the same ones.

ISO/IEC 27701 is the standard that turns the answer into something a customer can examine. As of the 2025 edition, it is also a standard an organisation can hold on its own.

What changed in 2025

The 2019 edition was an extension. It could only be certified alongside ISO/IEC 27001, so any organisation wanting to demonstrate privacy management first had to build and certify an information security management system. For many, that was the reason it never happened: the privacy case was clear, and the security project standing in front of it was not.

The 2025 edition carries its own management system requirements in clauses 4 to 10. A privacy information management system can now be certified in its own right.

If you already hold a certificate to the 2019 edition, there is a date to work back from: certificates transition to the 2025 edition by October 2028. That is further away than it sounds, because a transition means a real audit against a revised standard rather than a reprint of the certificate you have.

The idea underneath it

Privacy law says what you must achieve. It says very little about how, which is why two organisations can both be acting lawfully and look nothing alike internally.

The standard asks a narrower question: can you say what personal data you hold, why you hold it, who you share it with, and can you show that what you say is what actually happens?

It starts with a piece of vocabulary worth getting right, because the duties follow from it. POPIA speaks of a responsible party and an operator. GDPR speaks of a controller and a processor. The standard speaks of a PII controller and a PII processor. They are the same distinction: whoever decides why personal data is processed, and whoever processes it on someone else’s instructions. Most organisations are both, in different parts of the business, and the first thing the standard asks is that you know which you are, activity by activity.

What the standard requires

In outline, ISO/IEC 27701 asks you to:

  • Decide your role for each processing activity, controller or processor, and record it
  • Know what personal data you hold, where it came from, why you have it, and how long you intend to keep it
  • Record the purpose and the basis for each use, and stop the uses that have neither
  • Answer the people whose data it is when they ask, within the time the law allows, and keep evidence that you did
  • Bind the processors you rely on, and know what they do with what you send them
  • Design privacy into new services rather than retrofitting it after launch
  • Detect, investigate and report breaches, and deal with what caused them
  • Train the people who handle the data, and review the whole system at management level

Most organisations already do parts of this. What certification adds is that it is written down, applied when the person who set it up is on leave, and examined by someone who does not work for you.

A healthcare administrator recording patient information at a desk
Personal data is rarely exotic. It is a desk, a system, and someone deciding what to keep and for how long.

What changes in practice

Customer questionnaires. The same questions arrive from every enterprise buyer, and answering them from scratch each time is how contradictions get into writing. A certified system answers them from one set of facts.

Contracts. A data processing agreement is full of warranties about what you will and will not do with personal data. Certification is evidence that those warranties rest on something operational rather than on the drafting.

Several regimes at once. POPIA, GDPR and CCPA ask different questions of the same underlying facts. Building one system that holds those facts is less work than maintaining three answers, and it is far easier to keep current.

Incidents. The difference between a bad week and a bad year is usually whether the route for recording, investigating and reporting a breach existed before the breach did. Under POPIA, notification obligations run to the Information Regulator and, in most cases, to the people affected.

What it does not do

An honest account has to include this, because this standard is oversold more than most.

Certification demonstrates that a privacy information management system exists and is being used. It is not a finding of legal compliance with POPIA, GDPR or any other statute. No certification body can make that finding. Under POPIA that authority sits with the Information Regulator, not with us.

It is also not a GDPR Article 42 certification, which is a separate mechanism requiring approval by a supervisory authority. The two get conflated in sales conversations, and they are not interchangeable.

Nor does it certify your software, your infrastructure or your security controls. Information security is ISO/IEC 27001’s subject. The two interlock, and they are commonly audited in one programme, but a privacy certificate says nothing about how well your systems are defended.

Where it starts

It starts with scope: which processing activities, in which roles, in which parts of the organisation. The scope statement is what appears on the certificate, and it is the first thing a careful customer reads. A narrow scope that is honestly stated is worth more than a broad one that does not survive reading.

If you hold a 2019 certificate, October 2028 is the date to plan back from. If you do not, the question this standard was written to answer is the one your customers will put to you next year, in a questionnaire, with a deadline.

What ISO/IEC 42001 actually asks of you

The question arrives in a procurement form. Describe your AI governance framework. Sometimes it is one line in a security questionnaire that has run to nine pages. Sometimes a customer’s legal team has sent it directly.

Either way the organisation receiving it is usually in the same position: several AI features already in production, no single person accountable for them, and three weeks to produce an answer that sounds deliberate.

ISO/IEC 42001 is what that question is reaching for.

The idea underneath it

ISO/IEC 42001:2023 is an AI management system standard. It follows the same structure as ISO 9001 and ISO/IEC 27001, built on the shared clauses 4 to 10 that every modern management system standard uses, with a set of AI-specific reference controls attached.

What it asks is narrower than people expect, and more useful:

Do you know which AI systems you are running, what they are for, who is accountable for each one, and what you would do if one behaved badly?

That is the whole idea. Not a philosophy of machine ethics. An inventory, an owner, a risk assessment, and a route for something to be escalated, stopped or rolled back by someone with the authority to do it.

Most organisations discover, working through it, that the hard part is not the controls. It is the inventory. Very few can produce a complete list of the AI systems and third-party models in use across their own product.

What the standard requires

In outline, ISO/IEC 42001 asks you to:

  • Identify the AI systems you develop, provide or use, and what each is for
  • Decide which roles your organisation occupies, whether developer, provider or deployer, because the obligations differ
  • Assess the risks each system creates, including risks to people affected by it rather than only risks to you
  • Apply controls proportionate to those risks, and record why the ones you excluded were excluded
  • Keep human oversight meaningful, with a named accountable owner rather than a committee
  • Handle incidents, monitor systems in operation, and improve on what you find
A team leader looking over the shoulder of a developer at a workstation
Governance is not a document. It is a named person who has to answer for a decision.

The phrase to hold onto is impact on people. A quality management system asks whether the output was correct. An AI management system also asks who was affected by it, and whether they had any route to contest it.

The thing it is assumed to prove, and does not

This is the most important paragraph in this article, and it is the one most often left out.

ISO/IEC 42001 certification does not make an AI system compliant with the EU AI Act.

The mechanism people have in mind is Article 40. Under it, applying a harmonised standard, meaning one published in the Official Journal of the European Union for that purpose, earns a presumption of conformity. The burden shifts, and a provider is taken to have met the relevant requirement unless shown otherwise.

ISO/IEC 42001 is not cited as a harmonised standard under the AI Act. It therefore confers no presumption of conformity. A separate European standard, prEN 18286, is being developed for that role.

The practical difference matters. A provider of a high-risk system still has to evidence the quality management system obligations the Act sets out in Article 17, element by element. Holding a 42001 certificate is a strong organisational signal and a genuine head start on that work. It is not the legal shield it is often sold as.

Two colleagues reviewing output on a monitor together
The standard asks what you did when the model was wrong, not whether it ever was.

What else it does not do

An honest account has to include the rest.

It does not certify your models. ISO/IEC 42001 certifies the management system around them. A certified organisation can still ship a model that is biased, wrong, or unsafe. What the standard asks is that the organisation notices, records it, finds the cause, and changes something. That is the same logic ISO 9001 applies to a defective unit.

It does not certify your training data. Data governance sits inside the system’s scope, but no auditor certifies a dataset as fair.

It does not make you better than an uncertified competitor. It demonstrates that you have a system and that an independent party has examined it.

How to check a 42001 certificate

If you are the buyer rather than the seller, this part is worth knowing, because 42001 is new enough that the market has not settled.

Accredited certification against ISO/IEC 42001 runs under ISO/IEC 17021-1 together with ISO/IEC 42006:2025, published on 7 July 2025, which sets what a certification body must demonstrate before an accreditation body will put AI management systems into its scope.

Accreditation is granted per standard, not in general. A certification body accredited for ISO 9001 or ISO/IEC 27001 does not thereby hold ISO/IEC 42001. So the question to ask about any 42001 certificate is not are they accredited. It is is 42001 inside the scope they are accredited for, and that is checkable on the accreditation body’s own schedule.

The same applies to the certificate in front of you: read its scope statement. It names which systems and which activities were assessed. A narrow scope, honestly stated, is worth more than a broad one that will not survive reading.

Where it starts

It starts, as every management system does, with scope: deciding which AI systems and which parts of the business are being certified. That scope is what appears on the certificate, and it is what your customer reads when they check it.

Get the scope wrong and the certificate says something you did not intend.

If a customer has already sent you that question about your AI governance framework, you know what it costs not to have an answer. The question is whether the next one finds you ready.

What ISO 9001 actually asks of you

Most organisations meet ISO 9001 for the first time in a tender document. A buyer asks for it, the deadline is three weeks away, and someone is sent to find out what it involves.

By that point the answer is usually the wrong one: certification takes months, not weeks, and it cannot be produced retrospectively. The organisations that win those tenders started eighteen months earlier, often for reasons that had nothing to do with tendering.

This is what the standard actually asks for.

The idea underneath it

ISO 9001 is a quality management standard, which is an unhelpful phrase because most people hear quality and think inspection. It is not about checking work at the end.

The standard asks a narrower and more useful question: can your organisation produce the same result every time, and can you show how?

That is the whole idea. Not paperwork for its own sake. A documented way of working that means the job you did well last year is the job you will do well next year, whoever happens to be on site, and whether or not the person who originally set it up still works for you.

The certificate is not the point. The certificate is evidence that the system exists and is being used.

What the standard requires

In outline, ISO 9001 asks you to:

  • Understand what your organisation does and who depends on it
  • Identify the risks that would stop you delivering, and decide what to do about them
  • Define how work is actually carried out, in enough detail that it can be repeated
  • Keep records that show it was carried out that way
  • Check the system yourself, at intervals, and act on what you find
  • Have leadership accountable for it, not delegated to a filing cabinet

Almost every organisation already does most of this. What certification adds is that it is written down, applied consistently, and verified by someone who does not work for you.

An inspector recording measurements on a clipboard in a workshop
Records are the difference between doing the work and being able to show it.

What changes in practice

Tenders. Many buyers will not accept a bid from an uncertified supplier. Government procurement, mining, and anyone trading internationally increasingly treat it as a threshold requirement rather than a differentiator. No certificate, no seat at the table.

Rework. Most quality failures are process failures rather than people failures. When the same mistake happens three times with three different people, the process is the cause. A documented system makes that visible, and work done twice is money already spent.

Two workers examining a manufactured component together
When the same fault appears three times with three different people, the process is the cause.

Continuity. Organisations that depend on a handful of experienced people carry a risk they rarely price. When one of them leaves, the knowledge leaves too. A management system is, among other things, an insurance policy against that.

Confidence. Your customer cannot audit you themselves. An accredited certificate is how they know without having to check.

It is a cycle, not an event

This is the part most often misunderstood, and it matters for budgeting.

Certification runs on a three-year cycle. An initial assessment in two stages, then a surveillance audit each year to confirm the system is still operating, then a full reassessment before the cycle renews.

When each audit falls across the three-year cycle
Stage 1 — documentation review 1 month in
Stage 2 — on-site assessment 3 months in
First surveillance audit 12 months in
Second surveillance audit 24 months in
Recertification 36 months in

Source: ISO/IEC 17021-1:2015 — the three-year certification cycle

The audits are not a formality. A certificate can be suspended or withdrawn if the system has stopped being used, and a certification body that never withdrew one would not be worth much. Certification is a state you maintain, not a document you own.

What it does not do

An honest account has to include this.

ISO 9001 does not certify your product. It certifies the management system around it. A certified organisation can still ship a defective unit; what the standard asks is that the organisation notices, records it, finds the cause, and changes something.

It also does not make you better than an uncertified competitor. It demonstrates that you have a system and that an independent party has examined it. Whether you use that system well is up to you.

Anyone who tells you otherwise is selling something.

Where it starts

It starts with scope. Before an audit, before documentation, before anything else, you decide what is being certified: which activities, which sites, which parts of the business. That scope is what appears on the certificate, and it is what a customer reads when they check it.

Get the scope wrong and the certificate says something you did not intend.

If a tender has ever asked you for ISO 9001, you already know what it costs not to have it. The question is whether the next one finds you ready.