What is ISO 27001?
ISO 27001 is the international standard for information security management systems, published jointly by the International Organization for Standardization and the International Electrotechnical Commission. It specifies how an organization identifies information risk, selects controls to treat that risk, and proves to an external auditor that the resulting system actually operates.
The current edition is ISO/IEC 27001:2022, which added eleven controls covering threat intelligence, cloud services, secure coding, and where customer data physically lives. It replaced the 2013 edition, and certified organizations were given a three-year transition window. Around 70,000 organizations worldwide hold a certificate.
How ISO 27001 works
An information security management system (ISMS) is a documented loop, and the standard defines four stages of it: plan, do, check, act. Planning starts with scope, which names the entities, locations, systems, and services the ISMS covers. Everything downstream inherits that boundary, which is why the scope statement is the first thing a serious buyer reads.
The risk assessment comes next. Teams inventory information assets, rate threats and vulnerabilities against confidentiality, integrity, and availability, then decide which risks to treat, transfer, or accept. The same register catalogues obligations the business already carries, which for a support operation can include HIPAA compliance for health data or DORA compliance for financial services. Each accepted risk maps to one or more Annex A controls, and every inclusion and exclusion is recorded in the Statement of Applicability.
Then the system has to run. Internal audits test whether controls operate, management review examines the evidence, and corrective actions close nonconformities. That clause structure repeats across other management-system standards, including ISO 42001, so an organization that has built one ISMS can extend the machinery to a second scope.
What ISO 27001 requires
Five artifacts carry most of the weight in an audit.
A defined scope: A written statement naming which legal entities, products, integrations, and physical sites the ISMS covers, with any exclusion justified.
A risk assessment and treatment plan: A repeatable method for identifying information risks and a documented decision on how each one is handled.
A Statement of Applicability: The record mapping accepted risks to selected controls, listing every Annex A control and why it is in or out.
Annex A controls: The 2022 revision contains 93 controls grouped into four themes: organizational, people, physical, and technological.
Evidence that the system operates: Internal audit reports, management review minutes, corrective action records, and logs showing controls ran on real days.
ISO 27001 vs SOC 2 Type II vs ISO 42001
Security questionnaires ask for all three, and the labels blur in procurement threads. ISO 27001 certifies a management system for information security against an international standard, audited by an accredited certification body. SOC 2 Type II reports on whether a service organization's controls operated effectively across a defined observation window. ISO 42001 certifies a management system for artificial intelligence, covering governance and lifecycle controls. ISO 27001 is the broadest of these three: it governs how information is protected everywhere inside the declared scope, while the other two answer narrower questions about evidence and about AI.
Who it binds | What it requires | How it is evidenced | |
|---|---|---|---|
ISO 27001 | Any organization certifying an ISMS, inside its declared scope | A risk-driven ISMS with documented Annex A control decisions | An accredited certificate plus ongoing surveillance audits |
SOC 2 Type II | Service organizations, largely at customer insistence | Security controls operating effectively over a 6 to 12 month period | An AICPA audit report, usually shared under NDA |
ISO 42001 | Organizations developing or deploying AI systems | An AI management system covering governance, risk, and lifecycle controls | An accredited certificate against the AI management standard |
If enterprise procurement is blocking deals, ISO 27001 opens the most doors internationally. If your buyers are US-based and want control-by-control evidence they can read, SOC 2 Type II answers faster. If you ship AI features, ISO 42001 stacks on top.
Why ISO 27001 matters for customer experience
A certificate never improves the answer a customer receives. Its effect sits upstream, deciding whether a support platform is deployed at all. Procurement teams in regulated industries filter vendors by certification status before any product evaluation begins, so an uncertified tool loses on a form rather than on merit.
Absence has an operational cost too. Without an ISMS, every security review is negotiated from scratch, access to production customer data is governed by memory, exceptions are approved verbally, and incident response gets invented during the incident. The tradeoff is real: building and running the system consumes engineering hours that would otherwise ship features, and a badly run ISMS produces a shelf of documents nobody consults between audits.
How is ISO 27001 measured?
Certification produces a binary outcome on top and graded findings underneath. The certificate says yes or no; the audit report says how close the system came, counting major nonconformities, minor nonconformities, and observations, and naming the clause each one sits under. A second measure is scope breadth, since two certificates with identical logos can cover wildly different amounts of a business.
Some of the numbers an ISMS is measured against come from outside the standard entirely. A support operation running outbound automation, for example, is tested against the delivery restrictions codified at 47 CFR 64.1200, which hold automated calls to a local-time window of 8 a.m. to 9 p.m. Thresholds like that become auditable control objectives, because an auditor can sample call logs and see whether the boundary held.
How AI agents change ISO 27001
AI support agents move customer data through more hands. A single reply may pull a ticket, retrieve knowledge base passages, embed them, send them to a model provider, and write an update back into a CRM. Each hop adds an asset to the inventory and a subprocessor to the register, and the model provider becomes a third-party risk the ISMS has to treat.
The controls then map to concrete engineering work: encryption of prompts and retrieved records, adversarial testing of model behavior, tamper-evident logging, and documented incident response for a bad autonomous action. Teams building ISO 27001 audit trails in ServiceNow usually discover that logging what the agent did is easier than logging why it did it. Runtime constraints matter here as evidence, which is why guardrails in support automation and the wider AI guardrails discipline now appear in security reviews.
Implementing ISO 27001 and reading a certificate
Implementation runs in sequence: define scope, run the risk assessment, select controls and write the Statement of Applicability, operate the system long enough to generate evidence, then pass a two-stage external audit. Stage 1 reviews documentation, scope, and ISMS design. Stage 2 verifies that the controls actually operate.
Reading someone else's certificate is a different skill. Check that the certification body is accredited, check the validity dates and surveillance history, and read the scope statement against the deployment you plan. A chatbot wired into a CRM needs each integration inside that scope. Regulated buyers commonly ask whether ISO 42001 sits alongside for AI systems and how HIPAA obligations are handled contractually. The constraint teams underestimate is scope drift: new integrations ship between surveillance audits, and the certificate does not follow automatically.
ISO 27001 and AI compliance
ISO 27001 governs information; a broader AI compliance program governs behavior, covering how a model is trained, what it may decide autonomously, and how those decisions are explained. Certification gives that program its evidence layer: access control, logging, change management, and supplier review already exist and can be pointed at the AI stack.
Standards written specifically for autonomous agents, such as AIUC-1, assume that kind of underlying security posture. Building on a running ISMS is faster than assembling one for each new certification request.
What does ISO 27001 mean in plain terms?
Think of ISO 27001 as a food safety inspection for information. Nobody checks every meal; an inspector checks that the kitchen has rules, follows them, keeps records, and fixes problems it finds. The letters stand for the standards bodies behind it: ISO is the International Organization for Standardization, IEC is the International Electrotechnical Commission, and 27001 is the number of this particular document in the 27000 family.
Without it, security is whatever the current engineering team happens to believe on a given quarter, and that belief leaves when they do. With it, decisions are written down, reviewed on a schedule, and checked by someone with no stake in the answer.
The tradeoff is bureaucracy. Every exception needs a record, every change needs an approver, and small teams feel that drag daily.
Common ISO 27001 mistakes
Scoping to the smallest survivable footprint is the most common error. A certificate covering a head office and a corporate wiki reads identically to one covering the production platform, and buyers who skip the scope statement discover the gap during an incident.
Treating certification as an event is second. The audit is a sample of a system that is supposed to run continuously, so teams that generate evidence in the six weeks before Stage 2 are testing their sprint capacity.
Writing the Statement of Applicability to avoid work is third. Excluding a control because implementing it is inconvenient creates a documented, auditable record of that decision, which is the opposite of what the exclusion was meant to achieve.
The fourth is the claim itself. Self-declared alignment with the standard and an audited certificate from an accredited body are different assertions, and questionnaires increasingly ask for the certificate number.
What is an ISO 27001 certified company?
An ISO 27001 certified company has had its information security management system audited by an accredited certification body across two stages and holds a valid certificate naming the scope of that system. The scope matters as much as the certificate, because it defines which entities, products, and integrations were actually examined.
What is the difference between ISO 27001 certification and compliance?
ISO 27001 compliance describes alignment with the standard as claimed by the organization itself. Certification is the audited outcome: an accredited body reviewed the documentation, tested whether controls operate, issued a certificate, and returns for surveillance audits. Procurement teams treat these as different assertions, and questionnaires increasingly ask for a certificate number.
ISO 27001 vs SOC 2 Type II: which do enterprise buyers ask for?
ISO 27001 travels better internationally and certifies a whole management system, while SOC 2 Type II is requested more often by US buyers who want control-by-control evidence across an observation window. Many vendors carry both because the underlying work overlaps heavily once risk assessment, access control, and logging are already documented.
How many controls are in Annex A of ISO 27001?
Annex A of the 2022 revision lists 93 controls, grouped into four themes: organizational, people, physical, and technological. The 2013 edition organized a longer list differently, and the 2022 update introduced eleven new controls covering areas such as threat intelligence, cloud services, secure coding, and data location.
How long does ISO 27001 certification take?
ISO 27001 certification timelines depend on scope size, how much documentation already exists, and how long the system must run before it produces auditable evidence. The two-stage audit itself is brief compared with preparation. Organizations with mature access control and change management move faster, since much of the evidence is already being generated.
Does ISO 27001 cover AI chatbots and CRM integrations?
ISO 27001 covers whatever the scope statement names. An AI chatbot writing into a CRM involves additional assets and subprocessors, including model providers, so each integration has to appear inside the certified scope. Buyers should read the scope against the specific deployment they plan, since core products are often covered while integrations are not.

