HomeFrameworksTrade, Ethics & FranchiseISO 27701

Framework  Trade, Ethics & Franchise

ISO 27701

ISO/IEC 27701 is the international standard for a privacy information management system (PIMS). The first edition (2019) was written as an extension to ISO/IEC 27001 and 27002, so an organization could only certify to it alongside an ISO 27001 certificate.

The second edition, published October 14, 2025, rewrites it as a standalone management system standard under the title "Information security, cybersecurity and privacy protection: Privacy information management systems: Requirements and guidance".

Organizations can now certify a PIMS on its own, though most still pair it with ISO 27001 because the security controls overlap heavily.

The standard covers both PII controllers and PII processors, with separate annexes of controls for each role, and maps to GDPR-style obligations such as lawful basis, purpose limitation, data subject rights, processor contracts, and transfer records.

In writing, a PIMS needs a scope statement that identifies the organization's role (controller, processor, or both), a privacy policy, a privacy risk assessment method and results, a record of processing activities, a statement of applicability covering the privacy controls, procedures for consent, notices, data subject requests, retention and deletion, breach notification, and processor and subprocessor management, plus the usual management system records: objectives, competence, internal audit, management review, and corrective action.

AI-compiled
Share
Sponsored
Policy  Acknowledgment  Proof
AcknowledgedPIMS policy v2by name, on record
Clause 7.5 Handledwith AllyMatter
Privacy, the Modern WayEvery PIMS policy, acknowledged by the people who process
01
Approve it, lock the version
Non-author approval, obsolete copies blocked
02
Every processor on record
Who read which version, and when
03
Hand the registrar the trail
From $29/mo, 20 editors, unlimited staff (published)

Who has to comply

Voluntary. Any organization that processes personal data. The commercial trigger is usually a customer, regulator, or tender asking for evidence of a privacy program; processors and SaaS providers serving EU or UK customers are the most common certificants.

What the assessor asks to see

PIMS scope and role identification; privacy policy; legal and regulatory register; record of processing activities; privacy risk assessment and treatment plan; statement of applicability for the controller or processor annex; consent and notice records; data subject request logs; retention schedule and deletion evidence; processor and subprocessor contracts and oversight; cross-border transfer records; breach handling procedure and incident log; training records; internal audit reports; management review minutes; corrective actions.

Where the requirement sits: ISO 27701 clauses 5-8 extending 27001/27002

2025 edition transition

ISO/IEC 27701:2025 replaced the 2019 edition on publication in October 2025 and can be certified without ISO/IEC 27001. Certification bodies are extending accreditation scopes during 2026; organizations certified to the 2019 edition should agree a transition audit plan with their body before the IAF deadline.

What AllyMatter does here

Policy layer of the PIMS.

AllyMatter publishes this site.

Assessors

Who assesses ISO 27701

Accredited certification bodies operating under ISO/IEC 17021-1 with the sector-specific requirements of ISO/IEC 27006-2 (PIMS audits). Accredited by National accreditation bodies that are signatories to the IAF (now Global ACI) multilateral arrangement, for example ANAB, UKAS, DAkkS, JAS-ANZ.

Not every accreditation body has yet extended scopes to the 2025 edition; check the certificate's accreditation mark.

Public register of assessors: https://www.iafcertsearch.org/

No firm has claimed a ISO 27701 assessor listing yet. Claim yours →

Consultants

Who helps with ISO 27701

The ISO 27001 consultant ecosystem covers ISO 27701 as an add-on and is now retooling for the standalone edition. Typical engagements run a gap analysis against the controller and processor control sets, build the record of processing and privacy risk assessment, draft the privacy procedures, and run an internal audit before the certification body arrives.

Three to nine months is typical when starting from an existing ISMS.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

ArchlightMinneapolis, MN, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Archlight is a vCISO / ISO 27001 consultancy based in Minneapolis, MN, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
BEMOUSANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
BEMO is a vCISO / ISO 27001 consultancy based in USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
Control and FunctionDenver, CO, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Control and Function is a vCISO / ISO 27001 consultancy based in Denver, CO, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
Coral EsecureNew Jersey, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Coral Esecure is a vCISO / ISO 27001 consultancy based in New Jersey, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
CycoreMiami, FL, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Cycore is a vCISO / ISO 27001 consultancy based in Miami, FL, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
Genius GRCWoodstock, GA, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Genius GRC is a vCISO / ISO 27001 consultancy based in Woodstock, GA, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
IllumenPacific Northwest, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Illumen is a vCISO / ISO 27001 consultancy based in Pacific Northwest, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
Neutral PartnersMiami, FL, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Neutral Partners is a vCISO / ISO 27001 consultancy based in Miami, FL, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
Securis360Pittsburgh, PA, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Securis360 is a vCISO / ISO 27001 consultancy based in Pittsburgh, PA, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
Soter AdvisoryUSANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Soter Advisory is a vCISO / ISO 27001 consultancy based in USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
TestprosReston, VA, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Testpros is a vCISO / ISO 27001 consultancy based in Reston, VA, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
TrustedCISORemote, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
TrustedCISO is a vCISO / ISO 27001 consultancy based in Remote, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published

Related reading

  1. ISO/IEC 27701:2025 explained: your questions answeredCovers the change that matters most: the 2025 edition turns a bolt-on to ISO 27001 into a standard you can certify alone.Northwave Cyber Security
  2. ISO/IEC 27701 compliance: frequently asked questionsClarifies how the controller and processor control sets divide up, and what a customer can rely on from a certified provider.Amazon Web Services

Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.

Need a hand implementing it?

Find a Consultant for ISO 27701

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

From the publisher

Run the Policy Side of ISO 27701 in AllyMatter

Approve the policies ISO 27701 asks for, keep every version, and record a named acknowledgment from each person who has to read them.

See how AllyMatter works From $29/mo, 20 editors, unlimited staff

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

corrections@policyandcompliance.com
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

ads@policyandcompliance.com
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.