ISO 27001 Outsourcing
Definition
ISO 27001 Outsourcing
ISO 27001 outsourcing is the practice of relying on a provider’s ISO 27001 security certification when placing work with it. The scope statement decides what the certificate is worth, because a provider certifies a defined boundary, not its whole business.
This is the single most misread document in outsourcing procurement.
A certificate is a one-page artefact naming an organisation, a standard and a scope. Buyers read the first two lines and file it — the third line determines whether it covers the team doing your work.
Scope can be a building, a service line, or a legal entity. It can also be drawn narrowly enough to exclude the delivery floor entirely while remaining entirely truthful.
Key takeaways
- ISO/IEC 27001:2022 is the current edition, and Annex A controls draw on ISO/IEC 27002:2022.
- A certificate covers a declared scope, which may not include your delivery site.
- Organisations cannot certify against ISO/IEC 27002, which is guidance rather than a specification.
- A statement of applicability shows which controls the provider excluded and why.
How it works
ISO 27001 specifies an information security management system. Microsoft’s Azure compliance documentation describes the current edition as ISO/IEC 27001:2022, a formal specification setting requirements for implementing, monitoring and improving that system.
The relationship with ISO/IEC 27002 trips people up. Microsoft puts it plainly: an organisation can’t get certified against ISO/IEC 27002:2022 because it isn’t a management standard, and the audit vehicle is ISO/IEC 27001:2022.
So a provider claiming “ISO 27002 certification” is claiming something that does not exist — and that alone is a useful screening question.
Two documents carry the real information. The certificate names the scope. The statement of applicability lists every Annex A control, notes which were excluded, and records the justification.
Shared responsibility is the other thing buyers assume away. Microsoft describes control responsibility as falling to the customer, the provider, or both — and the split is rarely where a buyer expects.
| Document | What it tells you | Common buyer error |
|---|---|---|
| Certificate | Entity, standard, edition, scope | Reading only the entity name |
| Scope statement | Which sites and services are covered | Assuming it covers everything |
| Statement of applicability | Controls applied and excluded | Never asking for it |
| Audit report | Findings and nonconformities | Accepting the certificate instead |
| Accreditation mark | Whether the certifier is accredited | Treating all certifiers as equal |
One use of the certificate is evidential. European law requires a controller to use only processors offering sufficient guarantees to implement appropriate technical and organisational measures, and a scoped certificate helps demonstrate that judgement.
Ask for the statement of applicability. A provider that will not share it is telling you which controls it excluded.
Examples
Security certification behaves very differently in procurement than it does in operation, and the distance between the two is measured in scope statements. The situations below all produced an argument about who was responsible for what.
A fintech accepts a provider’s certificate and later finds it covers a European development office. The Manila operations floor handling its customer data was never in scope.
An insurer requires certification and gets it, then asks for the statement of applicability and finds supplier-relationship controls excluded. Its provider’s own subcontractors sat outside the system.
A healthcare buyer pairs the certificate with its own assessment, treating certification as a floor rather than an answer. That is standard practice in mature vendor management outsourcing.
A retailer discovers its provider certified against the 2013 edition, whose transition window has closed. The certificate was genuine and no longer current.
Related terms
Security standards, the services built on them and the roles that run them are frequently treated as one thing. Each entry here is bounded deliberately, so no two of them can be substituted.
- ISO 27001: the standard itself, considered apart from any outsourcing arrangement.
- Cybersecurity outsourcing: buying security capability as a service, not certifying your own.
- Information security analyst: the role that operates controls, whether or not the employer is certified.
- ISO certification: the general audit mechanism behind every ISO management standard.
- Compliance outsourcing: delegating regulatory work itself, rather than meeting a security standard.
- Vendor management outsourcing: running supplier assurance, including reading these certificates properly.
- Risk outsourcing: moving exposure to a third party, which certification does not accomplish.
FAQ
Does a provider’s ISO 27001 certificate cover my data?
Only if the site and service handling your data sit inside the declared scope. Read the scope statement before relying on the certificate.
What is a statement of applicability?
A document listing every Annex A control, whether the organisation applied it, and the justification for any exclusion. It is more informative than the certificate.
Can a company be certified to ISO 27002?
No. ISO/IEC 27002 is guidance on implementing controls. Certification is only available against ISO/IEC 27001, which is the management system specification.
Which edition should a current certificate name?
ISO/IEC 27001:2022. Certificates naming the 2013 edition are past their transition window and should prompt a question.
Does certification transfer to subcontractors?
No. Your provider’s certificate says nothing about its own suppliers unless supplier-relationship controls are in scope and applied.
Is ISO 27001 enough on its own?
Rarely. It proves a managed system exists, and regulated data usually needs a sector-specific regime layered on top.
Search verified partners in the Outsource Accelerator directory and read the scope statement before you accept the badge.







Independent




