• 4,000 firms
  • Independent
  • Trusted
Save up to 70% on staff

Home » Glossary » ISO 27001 Outsourcing

ISO 27001 Outsourcing

Definition

ISO 27001 Outsourcing

ISO 27001 outsourcing is the practice of relying on a provider’s ISO 27001 security certification when placing work with it. The scope statement decides what the certificate is worth, because a provider certifies a defined boundary, not its whole business.

This is the single most misread document in outsourcing procurement.

A certificate is a one-page artefact naming an organisation, a standard and a scope. Buyers read the first two lines and file it — the third line determines whether it covers the team doing your work.

Scope can be a building, a service line, or a legal entity. It can also be drawn narrowly enough to exclude the delivery floor entirely while remaining entirely truthful.

Key takeaways

  • ISO/IEC 27001:2022 is the current edition, and Annex A controls draw on ISO/IEC 27002:2022.
  • A certificate covers a declared scope, which may not include your delivery site.
  • Organisations cannot certify against ISO/IEC 27002, which is guidance rather than a specification.
  • A statement of applicability shows which controls the provider excluded and why.

How it works

ISO 27001 specifies an information security management system. Microsoft’s Azure compliance documentation describes the current edition as ISO/IEC 27001:2022, a formal specification setting requirements for implementing, monitoring and improving that system.

The relationship with ISO/IEC 27002 trips people up. Microsoft puts it plainly: an organisation can’t get certified against ISO/IEC 27002:2022 because it isn’t a management standard, and the audit vehicle is ISO/IEC 27001:2022.

So a provider claiming “ISO 27002 certification” is claiming something that does not exist — and that alone is a useful screening question.

Two documents carry the real information. The certificate names the scope. The statement of applicability lists every Annex A control, notes which were excluded, and records the justification.

Shared responsibility is the other thing buyers assume away. Microsoft describes control responsibility as falling to the customer, the provider, or both — and the split is rarely where a buyer expects.

DocumentWhat it tells youCommon buyer error
CertificateEntity, standard, edition, scopeReading only the entity name
Scope statementWhich sites and services are coveredAssuming it covers everything
Statement of applicabilityControls applied and excludedNever asking for it
Audit reportFindings and nonconformitiesAccepting the certificate instead
Accreditation markWhether the certifier is accreditedTreating all certifiers as equal

One use of the certificate is evidential. European law requires a controller to use only processors offering sufficient guarantees to implement appropriate technical and organisational measures, and a scoped certificate helps demonstrate that judgement.

Ask for the statement of applicability. A provider that will not share it is telling you which controls it excluded.

Examples

Security certification behaves very differently in procurement than it does in operation, and the distance between the two is measured in scope statements. The situations below all produced an argument about who was responsible for what.

A fintech accepts a provider’s certificate and later finds it covers a European development office. The Manila operations floor handling its customer data was never in scope.

An insurer requires certification and gets it, then asks for the statement of applicability and finds supplier-relationship controls excluded. Its provider’s own subcontractors sat outside the system.

A healthcare buyer pairs the certificate with its own assessment, treating certification as a floor rather than an answer. That is standard practice in mature vendor management outsourcing.

A retailer discovers its provider certified against the 2013 edition, whose transition window has closed. The certificate was genuine and no longer current.

Related terms

Security standards, the services built on them and the roles that run them are frequently treated as one thing. Each entry here is bounded deliberately, so no two of them can be substituted.

FAQ

Does a provider’s ISO 27001 certificate cover my data?

Only if the site and service handling your data sit inside the declared scope. Read the scope statement before relying on the certificate.

What is a statement of applicability?

A document listing every Annex A control, whether the organisation applied it, and the justification for any exclusion. It is more informative than the certificate.

Can a company be certified to ISO 27002?

No. ISO/IEC 27002 is guidance on implementing controls. Certification is only available against ISO/IEC 27001, which is the management system specification.

Which edition should a current certificate name?

ISO/IEC 27001:2022. Certificates naming the 2013 edition are past their transition window and should prompt a question.

Does certification transfer to subcontractors?

No. Your provider’s certificate says nothing about its own suppliers unless supplier-relationship controls are in scope and applied.

Is ISO 27001 enough on its own?

Rarely. It proves a managed system exists, and regulated data usually needs a sector-specific regime layered on top.

Search verified partners in the Outsource Accelerator directory and read the scope statement before you accept the badge.

Companies you might be interested in

Get Inside Outsourcing

An insider's view on why remote and offshore staffing is radically changing the future of work.

Order now

Start your
journey today

  • Independent
  • Secure
  • Transparent

About OA

Outsource Accelerator is the trusted source of independent information, advisory and expert implementation of Business Process Outsourcing (BPO).

The #1 outsourcing authority

Outsource Accelerator offers the world’s leading aggregator marketplace for outsourcing. It specifically provides the conduit between world-leading outsourcing suppliers and the businesses – clients – across the globe.

The Outsource Accelerator website has over 5,000 articles, 450+ podcast episodes, and a comprehensive directory with 4,700+ BPO companies… all designed to make it easier for clients to learn about – and engage with – outsourcing.

About Derek Gallimore

Derek Gallimore has been in business for 20 years, outsourcing for over eight years, and has been living in Manila (the heart of global outsourcing) since 2014. Derek is the founder and CEO of Outsource Accelerator, and is regarded as a leading expert on all things outsourcing.

“Excellent service for outsourcing advice and expertise for my business.”

Learn more
Banner Image
Get 3 Free Quotes Verified Outsourcing Suppliers
4,000 firms.Just 2 minutes to complete.
SAVE UP TO
70% ON STAFF COSTS
Learn more

Connect with over 4,000 outsourcing services providers.

Banner Image

Transform your business with skilled offshore talent.

  • 4,000 firms
  • Simple
  • Transparent
Banner Image