ISO Certifications · Privacy Information Management
ISO 27701 certification that proves you handle personal data well.
We extend your existing ISO 27001 system into a privacy management system that maps to your GDPR obligations, then guide you through certification with an accredited body.
ISO/IEC 27701 is a privacy extension to ISO 27001 that builds a Privacy Information Management System, or PIMS, on top of your existing security controls. FinAudit CPA runs the readiness and mapping work, then an accredited certification body issues the certificate. It shows customers and regulators that you manage personal data with the same rigor you apply to security.
Reviewed by Debraj Hazra, CPA (USA), ACA (ICAEW, ICAI)
Last updated July 2026
What is ISO 27701, really?
ISO/IEC 27701 is the international standard for a Privacy Information Management System, usually shortened to PIMS. It was written as an extension to ISO 27001 and ISO 27002, which means it does not stand on its own. You take the security management system you already run under ISO 27001 and add a layer of privacy-specific requirements and controls to it. The result is one integrated system that governs both information security and the handling of personal data.
The reason it works this way is practical. Protecting personal data and protecting information in general share most of the same machinery: access control, risk assessment, supplier management, incident response, and internal audit. Rather than duplicate all of that, ISO 27701 reuses your ISMS and bolts on what privacy specifically demands — a lawful basis for processing, data subject rights, records of processing, privacy by design, and clear accountability for the personal data you hold.
An ISO 27701 certification tells anyone who reads it that an independent, accredited auditor examined how you manage personal data and confirmed it meets a recognized global standard. That is a stronger signal than a policy document or a self-assessment, because someone outside your company put their name to the finding.
ISO 27701 does not replace your security program. It proves that the way you handle personal data is governed with the same discipline, and that an accredited auditor checked the work rather than taking your word for it.
Who needs ISO 27701, and when?
ISO 27701 fits a specific profile: you already hold, or are close to holding, an ISO 27001 certificate, and your business handles personal data that customers or regulators care about. If that is you, a few situations tend to push it up the priority list:
- A large customer wants privacy assurance, not just security. Your ISO 27001 certificate answers the security question, but the procurement team now asks how you govern personal data. A privacy management system answers that in the language they already trust.
- You process personal data on behalf of others. If you are a processor handling customer records, employee data, or health information for your clients, ISO 27701 gives you a clean way to show you meet the obligations they are contractually pushing down to you.
- You operate across borders and face overlapping privacy laws. A single structured system helps you demonstrate accountability under GDPR and other regimes without rebuilding your evidence for each one.
If none of that applies yet, ISO 27701 can wait. It is most valuable once personal data is central to what you do and someone with buying power has started asking how you protect it.
ISO 27701 vs GDPR: how they relate
People often ask whether ISO 27701 makes them GDPR compliant. It does not, and no certificate can. GDPR is a law you obey; ISO 27701 is a management system you certify. But they overlap heavily, and the standard is built to help you demonstrate the accountability GDPR demands.
| ISO 27701 | GDPR | |
|---|---|---|
| What it is | A certifiable international management-system standard | A binding EU law with regulatory penalties |
| How you satisfy it | Build a PIMS and pass an accredited audit | Meet legal obligations and prove accountability on demand |
| Who confirms it | An accredited certification body | Regulators and, ultimately, the courts |
| Roles it recognizes | PII controller and PII processor duties | Data controller and data processor duties |
| What you can show | A certificate a buyer can verify | Records, contracts, and evidence of compliance |
How our ISO 27701 process runs
You always know where you are and what happens next. We prepare you; an accredited certification body runs the certification audit.
-
01
Scoping and roles
We confirm your ISMS status, define the personal data in scope, and establish where you act as a PII controller and where you act as a PII processor. You get a fixed fee before we start.
-
02
Gap assessment
We measure your current program against ISO 27701 and hand you a plain-language list of what to build or fix, mapped to your existing ISO 27001 controls so you reuse what already works.
-
03
PIMS build and mapping
We help you put the privacy-specific pieces in place — records of processing, lawful basis, data subject rights, and privacy by design — and map them to your GDPR obligations.
-
04
Internal audit and review
We test the system the way an external auditor will, run a management review, and close findings before the certification body arrives.
-
05
Certification audit
An accredited certification body conducts the Stage 1 and Stage 2 audits. We prepare your team, sit alongside you, and help you respond to any findings.
-
06
Certification and upkeep
The body issues your certificate, typically valid for 3 years with annual surveillance. We help you keep the system audit-ready between visits.
What you get, and how long it takes
By the end, you hold a Privacy Information Management System that runs as one integrated program with your ISO 27001 ISMS, plus a certificate issued by an accredited certification body. Along the way you get the working parts of a real privacy program: a records-of-processing inventory, defined controller and processor responsibilities, a data subject rights process, supplier terms that push privacy duties down your chain, and a mapping that shows how each piece supports your GDPR obligations.
Timing depends on where you start. If your ISO 27001 system is mature and your privacy practices are already reasonable, readiness can move in a couple of months, followed by the certification body's Stage 1 and Stage 2 audits. If personal data governance is newer to you, the build takes longer because you are standing up processes, not just documenting them. Because ISO 27701 rides on ISO 27001, companies that certify both together usually save time over doing them months apart.
What actually drives the cost
We quote a fixed fee for our readiness work, and the certification body prices its own audit separately. The total depends on real factors, not guesswork:
ISMS maturity
If your ISO 27001 system already runs cleanly, much of the foundation is in place and readiness moves faster. A weak or missing ISMS is where the early effort goes.
Volume and sensitivity of data
More personal data, more processing activities, and more sensitive categories mean more records, more controls, and more to examine.
Controller and processor mix
Acting as both a controller and a processor across different services widens the scope of what the PIMS has to cover.
Certification body fees
The accredited body sets its own audit fee based on your size and scope. We are transparent that this is separate from our readiness fee.
Why run your ISO 27701 with FinAudit CPA
Here is the honest structure of how ISO certification works, because some firms blur it. An accredited certification body — not a consultant, and not us — is the only party that can issue an ISO 27701 certificate. Our role is to get you ready: we assess your gaps, help you build the Privacy Information Management System, map it to your GDPR obligations, run the internal audit, and stand with you through the certification body's audit. That separation is a feature. The party that prepares you should not be the party that certifies you, and we keep those roles clean.
What we add is judgment. As a licensed US CPA firm, we spend our days examining control environments and testing whether they actually work, not just whether a policy exists on paper. That discipline carries directly into a privacy program. We also map your privacy management system to overlap with your ISO 27001 ISMS and your SOC 2 controls, so you build evidence once and reuse it, rather than paying to prove the same thing three times. You get senior attention, fixed scope, and a partner who tells you plainly what an auditor will and will not accept.
Pair your ISO 27701 with
- ISO 27001 certification, the security management system ISO 27701 must extend
- GDPR assessment, to translate the standard into your specific legal obligations
- SOC 2, when US buyers want an attestation report alongside your certificate
- VAPT, to show buyers you actively test the defenses your privacy program relies on
ISO/IEC 27701 (Privacy) · questions buyers ask
Yes. ISO 27701 is an extension of ISO 27001, not a standalone standard. You certify a Privacy Information Management System on top of a working Information Security Management System, and the certification audit assesses both together. In practice you either hold an ISO 27001 certificate already or pursue both at the same time. We often help clients certify the two together to save time and cost.
No single certificate can make you GDPR compliant, because GDPR is a law and compliance depends on your specific processing and legal basis. What ISO 27701 does is give you a structured, auditable system that demonstrates the accountability GDPR expects. Its controller and processor controls map closely to GDPR duties, so certification is strong evidence of a serious privacy program, not a legal guarantee.
A PII controller decides why and how personal data is processed; a PII processor handles that data on the controller's behalf. ISO 27701 defines separate controls for each role, mirroring the controller and processor split in GDPR. Many companies act as both, depending on the service. We help you identify where you sit for each activity so your PIMS covers the right obligations.
An accredited certification body issues the certificate, not a consultant and not FinAudit CPA. Our role is to prepare you: we run the gap assessment, help you build the privacy management system, map it to your GDPR obligations, and guide you through the audit. Keeping preparation and certification separate is deliberate, because the party that readies you should not be the party that certifies you.
It depends on where you start. If your ISO 27001 system is mature and your privacy practices are reasonable, readiness can take a couple of months, followed by the certification body's Stage 1 and Stage 2 audits. If personal data governance is new to you, the build takes longer because you are creating processes rather than documenting existing ones. Certifying alongside ISO 27001 usually saves time.
ISO 27001 governs information security in general; ISO 27701 extends it to the specific handling of personal data. The two share most of their machinery, such as risk assessment, access control, and internal audit. ISO 27701 adds privacy requirements like lawful basis, records of processing, data subject rights, and controller and processor duties. You cannot certify ISO 27701 without an ISO 27001 foundation underneath it.
Yes, and it should. A privacy management system shares many controls with your ISO 27001 ISMS and your SOC 2 program, including access management, supplier oversight, and incident response. We map the overlap so the evidence you build carries across frameworks. You prepare once and reuse the work instead of standing up three separate programs that test nearly the same things.
Examining whether controls actually operate, not just whether a policy exists, is the core of what a licensed CPA firm does every day. That discipline carries directly into readiness for a privacy management system. We assess your program honestly, tell you what an accredited auditor will accept, and map your privacy controls to your existing security work so you get certified efficiently and stay audit-ready afterward.
Pair it with
Audit once, comply many.
GDPR Assessment
A practical GDPR assessment for US companies that handle EU personal data.
ISO/IEC 27001 Certification
The international security certificate your global customers recognize on sight.
SOC 2 Audit
The report SaaS buyers ask for first — done by a licensed CPA firm.