Skip to main content
Create Free Account

ISO 27001 Certification: What It Proves, and What to Ask a Vendor

ISO/IEC 27001 is the international standard for information security management systems. Certification means an independent certification body assessed a management system against the standard, inside a scope the business itself defined. It does not prove that any single control protects the product you are buying, which is why the scope statement is the first thing to read. ComplyFlow announced its certification in November 2020 and holds it today.

enterprisebusiness
A social graphic over a photograph of a concrete-frame construction site with a tower crane, three workers in hard hats and high-visibility vests conferring beside stacked timber, and a circular ISO 27001 Information Security Management certification badge beside the words We are now certified

Read more about our Platform

Hosting & Architecture Information

Most people who reach this page are part-way through a vendor security review, with a line in the questionnaire that reads ‘ISO 27001 certified: yes or no’. For ComplyFlow the answer is yes. The useful half of this page is what that answer is worth.

What We Announced in November 2020.

On 17 November 2020 we announced that ComplyFlow had achieved ISO 27001 certification, having refreshed our Information Security Management System as the business grew. Our Help Centre article on platform architecture and hosting still lists ISO 27001 certification among the platform’s credentials, alongside Australian data hosting and an ISO 27001 Statement of Applicability held as technical documentation.1

We do not print a certificate number or a scope statement on a marketing page; those are the details that get copied into a contract schedule and turn out to be a version behind. Ask us and we will send the current certificate, with its scope, in writing.

What ISO 27001 Actually Is.

ISO/IEC 27001 is a management system standard. It does not test a product. It sets out how a business runs information security as a managed discipline: establishing an Information Security Management System, operating it, measuring whether it works, and improving it.2

Two features of it matter to a buyer. The first is that the business sets its own scope, deciding which parts of itself the management system covers.2 Scope is a choice, not a given.

The second is that the controls are selectable. Annex A of the 2022 edition sets out 93 controls, and the business records in a Statement of Applicability which ones it included, which ones it excluded, and the reasoning either way.2 That document, not the certificate, is where the detail lives.

What a Certificate Proves, and What It Does Not.

It proves that an independent certification body assessed the business against the standard, through a two-stage assessment of the system and its documents, and found a management system operating inside the stated scope.2

That finding is only as good as the body that made it. Accreditation is the independent assessment of the organisations that certify, inspect, test, and verify, confirming their competence, impartiality, and capability. JASANZ, the joint accreditation body for Australia and New Zealand, states the consequence plainly: a certificate, test report, or inspection finding is only as credible as the organisation behind it.4 One wrinkle is worth knowing. The International Accreditation Forum, whose members recognised each other’s certificates across borders, ceased operations on 1 January 2026 and now directs readers to the Global Accreditation Cooperation,5 so an older certificate may carry a mark whose body no longer operates.

What a certificate does not prove is that any particular control protects the product in front of you. Amazon Web Services makes the same point about its own certification, which covers a security management process over a specified scope of services and facilities, and says a business is not certified by association with a certified supplier.3 A vendor running on certified infrastructure has not thereby been certified, and neither has the feature you are about to buy.

What to Ask a Vendor Who Says They Are Certified.

Six questions, in writing, sort a shortlist faster than a feature comparison does.

  1. Can we see the certificate. Not a logo on a web page. The document.
  2. What does the scope cover. Read the scope statement before anything else, and check that the product you are buying, and the team who support it, are inside it.
  3. Who is the certification body, and who accredited them. Both names. A vendor with a real certificate gives you both without a delay.
  4. When was it issued, and when does it expire. A certificate has a life, and an expired one is a finding.
  5. When was the last surveillance audit, and was anything raised. The audit between certifications is where a management system either holds or slips.
  6. Can we see the Statement of Applicability. Which Annex A controls are in, which are out, and the reason given for each exclusion.

None of the six is answered by a hosting provider’s certificate. If you hold the pen on this in procurement or compliance and legal, put them to every vendor on your list, including us. What we publish about how the platform is built sits on our security page, and our post on what running on AWS means for your data covers the hosting half of the same review.

The Other Three Standards Worth Knowing.

ISO 27001 is the one that comes up in a software review. Three others turn up in the same procurement pack.

ISO 45001 is the occupational health and safety management system standard, aimed at safe and healthy workplaces through reducing work-related injury and continually improving health and safety performance.6 The Australian detail: AS/NZS 4801 was the previous Australian and New Zealand standard for this, it was superseded by ISO 45001:2018, and JASANZ-accredited certification to AS/NZS 4801 ended after 13 July 2023.6 If a contractor hands you an AS/NZS 4801 certificate, that is the context.

ISO 31000 is the international standard for risk management, and ISO/IEC 27001 points at it as guidance for handling information security risk.2 It is guidance you apply, not a box a supplier ticks.

ISO/IEC 42001 sets requirements for establishing, running, maintaining, and improving an artificial intelligence management system, for businesses that provide or use AI-based products and services.7 Expect it in security questionnaires as AI features spread through compliance software.

Take the Questionnaire to the Vendor, Not the Badge.

A certificate is the start of a conversation, not the end of one. The vendors worth shortlisting answer the six questions without a fortnight’s delay, and can tell you what the scope leaves out.

If you are running that review on us, book a demo and bring the questionnaire. We would rather answer it live than have you infer the answers from a badge.

Contact our sales team to see how ComplyFlow can simplify compliance and keep your business safe.

Contact SalesCalculate Pricing