• 4,000 firms
  • Independent
  • Trusted
Save up to 70% on staff

Home » Glossary » ISO 27001

ISO 27001

Definition

ISO 27001

ISO 27001 is the international standard for an information security management system (ISMS) — a risk-based framework to spot, treat, and monitor threats to data, apps, and staff. Enterprise buyers use it as a vendor gate before outsourcing sensitive or regulated work.

The International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) first published the standard in 2005. The current edition, ISO/IEC 27001:2022, arrived in October 2022.

The 2022 refresh added controls around cloud services, threat intelligence, physical security monitoring, and secure development practices. Certification runs on a three-year cycle — with annual surveillance audits by an accredited body.

ISO 27001 prescribes outcomes, not specific tools. That flexibility is why it sits atop most vendor-security questionnaires from banks, hospitals, and government tenders, and why buyers treat it as shorthand for a serious data protection program.

Key takeaways

  • ISO 27001 is the global information security certification most enterprise buyers ask for before signing an outsourcing contract.
  • The standard is built around risk assessment, a Statement of Applicability, and 93 Annex A controls (2022 edition).
  • Certification lasts three years, with annual surveillance audits by an accredited body in between.
  • Common adopters: BPO providers, cloud vendors, financial services, healthcare payers, and government contractors.

How it works

ISO 27001 works by making organizations build, document, and continually improve an information security management system. The Plan-Do-Check-Act loop drives risk assessment, control selection, implementation, and monitoring.

The management-system clauses (4-10) tell you WHAT to build; Annex A lists 93 candidate controls you pick from. You keep and justify the ones you need in a Statement of Applicability (SoA), then defend that document to the auditor.

ClauseFocus areaKey output
4-7Context, leadership, planningRisk assessment + ISMS scope
8OperationStatement of Applicability
9Performance evaluationInternal audit + management review
10ImprovementCorrective actions
Annex A93 controls (2022 edition)Selected and justified in the SoA

Certification is a two-stage process. Stage 1 checks documentation and readiness; Stage 2 samples live evidence across the ISMS. Pass both, and the certificate lasts three years with annual surveillance audits and a full recertification in year four.

Certification bodies like BSI, DNV, and TÜV must themselves be accredited by a national body — the United Kingdom Accreditation Service (UKAS), or the ANSI National Accreditation Board (ANAB).

That accreditation chain is what makes the certificate credible in a client risk management file, and it explains why frameworks like NIST’s Cybersecurity Framework and ENISA’s EU risk management guidance map cleanly onto Annex A.

Examples

ISO 27001 shows up wherever a client wants proof, not promises, that a partner can hold data safely. Below are named-vendor and named-market examples where the certificate is routine in business process outsourcing (BPO) buying conversations.

Amazon Web Services (AWS) has held ISO 27001 certification since 2010 and lists it as a baseline compliance artifact enterprise buyers can reference when picking cloud regions.

Manila-based BPO Sutherland Global holds ISO 27001 across its Philippine delivery centers, using the certificate to unlock financial-services and healthcare accounts that would otherwise reject an offshore vendor.

Microsoft Azure carries ISO 27001 alongside ISO 27017 (cloud services) and ISO 27018 (personal data in the cloud), reissuing the audit reports each year so procurement teams can attach them to their vendor files with zero friction.

Global consulting firm Accenture publishes its ISO 27001 certificate scope publicly and requires ISO 27001 or an equivalent standard from subcontractors handling regulated-industry work.

Buyers themselves increasingly require ISO 27001 in the request for proposal (RFP) itself. In 2024, procurement teams at UK banks and US healthcare payers routinely listed the current certificate as a pass/fail item before scoring price or capability.

Related terms

  • Information security: the parent field ISO 27001 formalizes into a certifiable management system.
  • Data security: protecting data itself, a subset of what ISO 27001 controls address.
  • Risk management: the assessment engine at the core of every ISO 27001 audit cycle.
  • GDPR: the EU data-protection law whose control requirements overlap with ISO 27001.
  • SOC 2: the US audit report on service-organization controls, often paired with ISO 27001.
  • Compliance: the broader discipline of proving adherence to standards like ISO 27001.

FAQ

How much does ISO 27001 certification cost?

Certification fees depend on scope, employee count, and the certification body. A mid-sized BPO with 500 staff typically pays $15,000-$40,000 for the two-stage audit, plus internal preparation time worth 3-6 months of a security lead’s calendar.

How long does ISO 27001 take to implement?

Timelines run from four months for a small Software-as-a-Service (SaaS) team with strong controls, to 12-18 months for a large BPO consolidating multiple sites. Most first-time programs land between eight and 12 months.

What’s the difference between ISO 27001 and SOC 2?

ISO 27001 is a certifiable international standard for a full management system; SOC 2 is a US audit report against service-organization criteria. Global buyers tend to prefer ISO 27001, and US enterprise buyers tend to prefer SOC 2 — many providers hold both.

Do I need ISO 27001 to outsource?

Not legally, but for regulated data most enterprise buyers will not sign without it.

Find ISO 27001-certified partners in the Outsource Accelerator directory, where certification status sits alongside pricing and capability for every listed BPO.

Companies you might be interested in

Get Inside Outsourcing

An insider's view on why remote and offshore staffing is radically changing the future of work.

Order now

Start your
journey today

  • Independent
  • Secure
  • Transparent

About OA

Outsource Accelerator is the trusted source of independent information, advisory and expert implementation of Business Process Outsourcing (BPO).

The #1 outsourcing authority

Outsource Accelerator offers the world’s leading aggregator marketplace for outsourcing. It specifically provides the conduit between world-leading outsourcing suppliers and the businesses – clients – across the globe.

The Outsource Accelerator website has over 5,000 articles, 450+ podcast episodes, and a comprehensive directory with 4,700+ BPO companies… all designed to make it easier for clients to learn about – and engage with – outsourcing.

About Derek Gallimore

Derek Gallimore has been in business for 20 years, outsourcing for over eight years, and has been living in Manila (the heart of global outsourcing) since 2014. Derek is the founder and CEO of Outsource Accelerator, and is regarded as a leading expert on all things outsourcing.

“Excellent service for outsourcing advice and expertise for my business.”

Learn more
Banner Image
Get 3 Free Quotes Verified Outsourcing Suppliers
4,000 firms.Just 2 minutes to complete.
SAVE UP TO
70% ON STAFF COSTS
Learn more

Connect with over 4,000 outsourcing services providers.

Banner Image

Transform your business with skilled offshore talent.

  • 4,000 firms
  • Simple
  • Transparent
Banner Image