ISO 27001
Definition
ISO 27001
ISO 27001 is the international standard for an information security management system (ISMS) — a risk-based framework to spot, treat, and monitor threats to data, apps, and staff. Enterprise buyers use it as a vendor gate before outsourcing sensitive or regulated work.
The International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) first published the standard in 2005. The current edition, ISO/IEC 27001:2022, arrived in October 2022.
The 2022 refresh added controls around cloud services, threat intelligence, physical security monitoring, and secure development practices. Certification runs on a three-year cycle — with annual surveillance audits by an accredited body.
ISO 27001 prescribes outcomes, not specific tools. That flexibility is why it sits atop most vendor-security questionnaires from banks, hospitals, and government tenders, and why buyers treat it as shorthand for a serious data protection program.
Key takeaways
- ISO 27001 is the global information security certification most enterprise buyers ask for before signing an outsourcing contract.
- The standard is built around risk assessment, a Statement of Applicability, and 93 Annex A controls (2022 edition).
- Certification lasts three years, with annual surveillance audits by an accredited body in between.
- Common adopters: BPO providers, cloud vendors, financial services, healthcare payers, and government contractors.
How it works
ISO 27001 works by making organizations build, document, and continually improve an information security management system. The Plan-Do-Check-Act loop drives risk assessment, control selection, implementation, and monitoring.
The management-system clauses (4-10) tell you WHAT to build; Annex A lists 93 candidate controls you pick from. You keep and justify the ones you need in a Statement of Applicability (SoA), then defend that document to the auditor.
| Clause | Focus area | Key output |
|---|---|---|
| 4-7 | Context, leadership, planning | Risk assessment + ISMS scope |
| 8 | Operation | Statement of Applicability |
| 9 | Performance evaluation | Internal audit + management review |
| 10 | Improvement | Corrective actions |
| Annex A | 93 controls (2022 edition) | Selected and justified in the SoA |
Certification is a two-stage process. Stage 1 checks documentation and readiness; Stage 2 samples live evidence across the ISMS. Pass both, and the certificate lasts three years with annual surveillance audits and a full recertification in year four.
Certification bodies like BSI, DNV, and TÜV must themselves be accredited by a national body — the United Kingdom Accreditation Service (UKAS), or the ANSI National Accreditation Board (ANAB).
That accreditation chain is what makes the certificate credible in a client risk management file, and it explains why frameworks like NIST’s Cybersecurity Framework and ENISA’s EU risk management guidance map cleanly onto Annex A.
Examples
ISO 27001 shows up wherever a client wants proof, not promises, that a partner can hold data safely. Below are named-vendor and named-market examples where the certificate is routine in business process outsourcing (BPO) buying conversations.
Amazon Web Services (AWS) has held ISO 27001 certification since 2010 and lists it as a baseline compliance artifact enterprise buyers can reference when picking cloud regions.
Manila-based BPO Sutherland Global holds ISO 27001 across its Philippine delivery centers, using the certificate to unlock financial-services and healthcare accounts that would otherwise reject an offshore vendor.
Microsoft Azure carries ISO 27001 alongside ISO 27017 (cloud services) and ISO 27018 (personal data in the cloud), reissuing the audit reports each year so procurement teams can attach them to their vendor files with zero friction.
Global consulting firm Accenture publishes its ISO 27001 certificate scope publicly and requires ISO 27001 or an equivalent standard from subcontractors handling regulated-industry work.
Buyers themselves increasingly require ISO 27001 in the request for proposal (RFP) itself. In 2024, procurement teams at UK banks and US healthcare payers routinely listed the current certificate as a pass/fail item before scoring price or capability.
Related terms
- Information security: the parent field ISO 27001 formalizes into a certifiable management system.
- Data security: protecting data itself, a subset of what ISO 27001 controls address.
- Risk management: the assessment engine at the core of every ISO 27001 audit cycle.
- GDPR: the EU data-protection law whose control requirements overlap with ISO 27001.
- SOC 2: the US audit report on service-organization controls, often paired with ISO 27001.
- Compliance: the broader discipline of proving adherence to standards like ISO 27001.
FAQ
How much does ISO 27001 certification cost?
Certification fees depend on scope, employee count, and the certification body. A mid-sized BPO with 500 staff typically pays $15,000-$40,000 for the two-stage audit, plus internal preparation time worth 3-6 months of a security lead’s calendar.
How long does ISO 27001 take to implement?
Timelines run from four months for a small Software-as-a-Service (SaaS) team with strong controls, to 12-18 months for a large BPO consolidating multiple sites. Most first-time programs land between eight and 12 months.
What’s the difference between ISO 27001 and SOC 2?
ISO 27001 is a certifiable international standard for a full management system; SOC 2 is a US audit report against service-organization criteria. Global buyers tend to prefer ISO 27001, and US enterprise buyers tend to prefer SOC 2 — many providers hold both.
Do I need ISO 27001 to outsource?
Not legally, but for regulated data most enterprise buyers will not sign without it.
Find ISO 27001-certified partners in the Outsource Accelerator directory, where certification status sits alongside pricing and capability for every listed BPO.







Independent




