Skip to main content
Create Free Account

Company News

ISO 27001 Certification: What It Proves, and What to Ask a Vendor

ISO/IEC 27001 is the international standard for information security management systems. Certification means an independent certification body assessed a management system against the standard, inside a scope the business itself defined. It does not prove that any single control protects the product you are buying, which is why the scope statement is the first thing to read. ComplyFlow announced its certification in November 2020 and holds it today.

  • Published
  • Updated
  • 5 min read
A social graphic over a photograph of a concrete-frame construction site with a tower crane, three workers in hard hats and high-visibility vests conferring beside stacked timber, and a circular ISO 27001 Information Security Management certification badge beside the words We are now certified
The announcement graphic is the easy part. The scope statement behind the certificate is the part a security reviewer should ask for.

Most people who reach this page are part-way through a vendor security review, with a line in the questionnaire that reads ‘ISO 27001 certified: yes or no’. For ComplyFlow the answer is yes. The useful half of this page is what that answer is worth.

What We Announced in November 2020.

On 17 November 2020 we announced that ComplyFlow had achieved ISO 27001 certification, having refreshed our Information Security Management System as the business grew. Our Help Centre article on platform architecture and hosting still lists ISO 27001 certification among the platform’s credentials, alongside Australian data hosting and an ISO 27001 Statement of Applicability held as technical documentation.1

We do not print a certificate number or a scope statement on a marketing page; those are the details that get copied into a contract schedule and turn out to be a version behind. Ask us and we will send the current certificate, with its scope, in writing.

What ISO 27001 Actually Is.

ISO/IEC 27001 is a management system standard. It does not test a product. It sets out how a business runs information security as a managed discipline: establishing an Information Security Management System, operating it, measuring whether it works, and improving it.2

Two features of it matter to a buyer. The first is that the business sets its own scope, deciding which parts of itself the management system covers.2 Scope is a choice, not a given.

The second is that the controls are selectable. Annex A of the 2022 edition sets out 93 controls, and the business records in a Statement of Applicability which ones it included, which ones it excluded, and the reasoning either way.2 That document, not the certificate, is where the detail lives.

What a Certificate Proves, and What It Does Not.

It proves that an independent certification body assessed the business against the standard, through a two-stage assessment of the system and its documents, and found a management system operating inside the stated scope.2

That finding is only as good as the body that made it. Accreditation is the independent assessment of the organisations that certify, inspect, test, and verify, confirming their competence, impartiality, and capability. JASANZ, the joint accreditation body for Australia and New Zealand, states the consequence plainly: a certificate, test report, or inspection finding is only as credible as the organisation behind it.4 One wrinkle is worth knowing. The International Accreditation Forum, whose members recognised each other’s certificates across borders, ceased operations on 1 January 2026 and now directs readers to the Global Accreditation Cooperation,5 so an older certificate may carry a mark whose body no longer operates.

What a certificate does not prove is that any particular control protects the product in front of you. Amazon Web Services makes the same point about its own certification, which covers a security management process over a specified scope of services and facilities, and says a business is not certified by association with a certified supplier.3 A vendor running on certified infrastructure has not thereby been certified, and neither has the feature you are about to buy.

What to Ask a Vendor Who Says They Are Certified.

Six questions, in writing, sort a shortlist faster than a feature comparison does.

  1. Can we see the certificate. Not a logo on a web page. The document.
  2. What does the scope cover. Read the scope statement before anything else, and check that the product you are buying, and the team who support it, are inside it.
  3. Who is the certification body, and who accredited them. Both names. A vendor with a real certificate gives you both without a delay.
  4. When was it issued, and when does it expire. A certificate has a life, and an expired one is a finding.
  5. When was the last surveillance audit, and was anything raised. The audit between certifications is where a management system either holds or slips.
  6. Can we see the Statement of Applicability. Which Annex A controls are in, which are out, and the reason given for each exclusion.

None of the six is answered by a hosting provider’s certificate. If you hold the pen on this in procurement or compliance and legal, put them to every vendor on your list, including us. What we publish about how the platform is built sits on our security page, and our post on what running on AWS means for your data covers the hosting half of the same review.

The Other Three Standards Worth Knowing.

ISO 27001 is the one that comes up in a software review. Three others turn up in the same procurement pack.

ISO 45001 is the occupational health and safety management system standard, aimed at safe and healthy workplaces through reducing work-related injury and continually improving health and safety performance.6 The Australian detail: AS/NZS 4801 was the previous Australian and New Zealand standard for this, it was superseded by ISO 45001:2018, and JASANZ-accredited certification to AS/NZS 4801 ended after 13 July 2023.6 If a contractor hands you an AS/NZS 4801 certificate, that is the context.

ISO 31000 is the international standard for risk management, and ISO/IEC 27001 points at it as guidance for handling information security risk.2 It is guidance you apply, not a box a supplier ticks.

ISO/IEC 42001 sets requirements for establishing, running, maintaining, and improving an artificial intelligence management system, for businesses that provide or use AI-based products and services.7 Expect it in security questionnaires as AI features spread through compliance software.

Take the Questionnaire to the Vendor, Not the Badge.

A certificate is the start of a conversation, not the end of one. The vendors worth shortlisting answer the six questions without a fortnight’s delay, and can tell you what the scope leaves out.

If you are running that review on us, book a demo and bring the questionnaire. We would rather answer it live than have you infer the answers from a badge.

Sources

  1. Platform Architecture and Hosting ComplyFlow Help Centre, 29 August 2025
  2. ISO/IEC 27001:2022 Information Security: Your implementation guide BSI Group, ISO/IEC 27001:2022 edition, read 12 September 2026
  3. ISO/IEC 27001:2022 Compliance FAQs Amazon Web Services, Read 12 September 2026
  4. What is accreditation JASANZ, the Joint Accreditation System of Australia and New Zealand, Read 12 September 2026
  5. What is accreditation International Accreditation Forum, 20 April 2021, site archived from 1 January 2026
  6. ISO 45001 Occupational Health and Safety BSI Group Australia, Read 12 September 2026
  7. ISO/IEC 42001:2023 Artificial Intelligence Management System FAQs Amazon Web Services, Read 12 September 2026
Rory McNeil

Written by

Rory McNeilHead of Marketing, ComplyFlow

Rory leads marketing at ComplyFlow. He writes about how safety and compliance teams find, judge, and buy software, and about the evidence behind the claims vendors make.

Writes about: Buying compliance software, Evidence and claims, ComplyFlow news

Questions

Questions People Ask About This.

Is ComplyFlow ISO 27001 certified?

Yes. We announced ISO 27001 certification on 17 November 2020, and our Help Centre lists it among the platform's credentials today. We do not publish the certificate number, the certification body, or the scope statement on the website. If your security review needs them, ask us and we will send the current certificate with its scope in writing.

What does ISO 27001 certification actually prove?

That an independent certification body assessed a business against the standard and found an information security management system operating inside a defined scope. It is a finding about how a business manages information security risk, not a test of any one product feature. It does not promise that nothing will ever go wrong.

Why does the scope of an ISO 27001 certificate matter so much?

Because the business being certified defines its own scope, and a certificate can cover part of a business rather than all of it. Amazon Web Services describes its own certification as covering a security management process over a specified set of services and facilities. Read the scope statement first and check that the product you are buying, and the team who support it, sit inside it.

Does running on certified cloud infrastructure make a software vendor certified?

No. Amazon Web Services says on its ISO/IEC 27001 page that a business is not automatically certified by association. The hosting provider's certificate covers the hosting provider. The certificate relevant to the software you are buying is the software vendor's own.

What is the difference between accreditation and certification?

Certification is the assessment of a business, product or system against a standard. Accreditation is the independent assessment of the bodies that do the certifying, confirming their competence, impartiality, and capability. In Australia and New Zealand that is JASANZ. Asking who accredited the certification body is a fair question, and a vendor with a real certificate can answer it.

See it against your own contractors, sites, and rules.

Book a 30-minute demo. We will show ComplyFlow working with your kind of sites, your kind of contractors, and your requirements. No slides, no hard sell.

  • ISO 27001
  • Hosted on AWS
  • Microsoft & Okta SSO
  • API & MCP
  • Data in Australia

Compliance you can prove, instantly.