ISO 27701 Assessment — CertPro CPA LLC | Licensed CPA Firm
ISO 27701 Assessment
Licensed CPA Firm

ISO/IEC 27701
Assessment for Privacy
Information Management Systems

CertPro assesses Privacy Information Management Systems against ISO/IEC 27701:2019 requirements, conducted as an extension to ISO 27001. The assessment evaluates documented privacy controls and supporting evidence across PII processing, governance, access control, transparency, incident handling, and third-party obligations. Certification is issued by an independent certification body upon completion of the audit process.

CISA ISO 27701
ISO 27701 Assessment Overview
In Progress
PIMS Scope
PII Controller
PII Processor
Annex A / B
Regulatory Mapping
Assessment Completion0%
Kick-off, PIMS Scope Definition and Assessment Planning
Privacy Control Documentation and Evidence Review
Control Design and Operating Effectiveness Evaluation
Assessment Reporting and Certification Body Handover
Credentialed Audit Team
ISO 19011 Aligned
Compliance Certification
400+
Engagements
100%
Independent Audit Engagements
4-Phase
Audit Process
What is ISO 27701

The International Standard for Privacy Information Management

ISO/IEC 27701:2019 is an internationally recognized privacy extension to ISO/IEC 27001, published by the International Organization for Standardization in August 2019. It specifies requirements for establishing, implementing, maintaining, and continually improving a Privacy Information Management System (PIMS). ISO 27701 certification is independent third-party confirmation that an organization's PIMS meets the requirements of ISO/IEC 27701:2019, assessed through a structured assessment and issued by an independent certification body.

ISO/IEC 27701:2019 extends the ISMS framework of ISO 27001 to address privacy management, covering the processing of personally identifiable information (PII) by both PII controllers and PII processors. It also provides guidance to support organizations in putting these requirements into practice. The standard is designed for personally identifiable information (PII) controllers and processors who hold responsibility and accountability for PII processing.

ISO/IEC 27701 is relevant for organizations that collect, process, store, or control PII and is designed as an extension to ISO/IEC 27001 and operates within the ISMS framework for privacy management.

Clauses 5–6: PIMS Requirements (Controllers & Processors)

Establishes requirements and guidance for a Privacy Information Management System covering accountability, governance, and privacy controls for PII processing.

Clause 7: Controller Privacy Guidance

Provides guidance for privacy controls applicable to PII controllers, including transparency, rights handling, disclosure, and transfer governance.

Clause 8: Processor Privacy Guidance

Provides guidance for organizations acting as PII processors, including processor obligations, third-party management, contractual controls, and processing records.

Privacy Control Framework

Privacy controls are evaluated against the requirements and guidance in the applicable ISO/IEC 27701 assessment scope.

Regulatory Mapping

ISO/IEC 27701 supports evidence-based privacy governance that can be aligned with applicable privacy regulations, including GDPR, where relevant.

Scope Your Engagement

How ISO 27701 Certification Works: Two Paths, One Audit Standard

ISO 27701 certification cannot be obtained as a standalone certificate. It must be pursued either as an extension to an existing ISO 27001 certification or concurrently with ISO 27001 in a combined audit engagement. CertPro assesses PIMS conformity against ISO/IEC 27701 requirements under both paths. The certification decision is made by the independent certification body upon satisfactory completion of the assessment.

Path A

ISO 27701 Extension

Organizations that already hold ISO 27001 certification can extend their existing ISMS scope to include PIMS requirements under ISO/IEC 27701:2019. CertPro conducts an additional engagement covering privacy-specific clauses, Annex A and B controls, and applicable GDPR mappings. The extended ISO 27701 certification is issued by the independent certification body and aligned with the existing ISO 27001 certificate validity period.

Requires existing, valid ISO 27001 certification as a prerequisite
CertPro evaluates PIMS conformity as an extension to the established ISMS scope
Privacy-specific clauses 5, 6, 7, and 8 assessed against ISO/IEC 27701:2019
Annex A and B controls evaluated for PII controller and processor obligations
Certificate validity aligned with existing ISO 27001 certification period
Annual surveillance audits cover both ISMS and PIMS conformity
Path B

ISO 27001 + 27701 Certification

Organizations pursuing ISO/IEC 27001 for the first time can undergo a combined assessment covering both ISMS and PIMS requirements. CertPro conducts an integrated evaluation of documentation, control design, and effective control implementation across both standards. This approach supports organizations building information security and privacy programs in parallel.

ISMS and PIMS assessed within a single integrated engagement
Documentation and control frameworks reviewed across both standards
Controls evaluated for design adequacy and effective implementation across in-scope areas
Nonconformities identified and managed across both ISO/IEC 27001 and 27701
Certification decisions made by an independent certification body
Suitable for organizations establishing security and privacy programs together
Engagement Methodology

Four Phases. Structured Process. ISO 19011-Aligned.

Every CertPro ISO/IEC 27701 assessment engagement follows a structured four-phase process aligned with ISO 19011.

1
Phase 1

Kick-off and Audit Scoping

A 30-minute kick-off call is conducted to discuss the PIMS audit scope, ISMS and PIMS boundaries, applicable ISO/IEC 27701:2019 clauses, and engagement timeline. The organization's role as a PII controller, PII processor, or both is confirmed in writing. A single client-side point of contact is identified to ensure streamlined communication throughout the engagement.

2
Phase 2

Documentation Review and Evidence Collection

The client provides access to the evidence repository, including PIMS documentation, privacy risk assessment records, the Statement of Applicability covering both ISO 27001 and ISO/IEC 27701:2019 controls, and privacy control evidence. CertPro performs a detailed review to identify documentation gaps and control coverage across in-scope areas.

3
Phase 3

Control Evaluation and Validation

A Zoom session reviews identified gaps collaboratively. Additional evidence is submitted or controls are demonstrated live. CertPro evaluates control design and implementation across PIMS domains using audit procedures such as interviews, observation, document and record review. Nonconformities are documented with severity classification and supporting evidence.

4
Issued

Report Issuance and Certification

Assessment findings are compiled into a formal report and undergo internal quality review. The finalized report is shared with the client for factual accuracy confirmation. The certification decision is made by an independent certification body upon closure of applicable nonconformities.

Readiness Assessment

Have you designed the right controls for ISO 27701 Certification?

Gaps in the below areas are commonly identified during ISO/IEC 27701 assessments. Each aligns with PIMS requirements and privacy control evaluation. Documentation and evidence are reviewed as part of the assessment process.

Clauses 5–6

PIMS Scope Definition and PII Processing Inventory

A defined PIMS scope and a complete PII processing inventory are core requirements. The inventory should cover PII categories, purposes, retention periods, and third parties. Incomplete records are commonly identified during documentation review.

Annex A / B

Extended Statement of Applicability

The SoA must include Annex A and B controls under ISO 27701, along with ISO 27001 controls. Applicable controls, exclusions, and implementation status must be documented and traceable to the privacy risk assessment. Incomplete or misaligned SoA entries are commonly observed during assessment.

Clause 6.1

Privacy Risk Assessment Documentation

A documented privacy risk assessment should identify risks across PII processing activities, follow a consistent method, and support risk treatment decisions. Outdated or missing assessments are frequently identified during assessment.

Clauses 7–8

PII Controller and Processor Controls

Controls covering data subject rights, transparency, third parties, and data transfers should be documented and implemented. Assessments evaluate whether these controls are established and applied across operational processes.

Clause 9.2

Internal Audit and Management Review Records

Internal audits and management reviews should include the PIMS. Records should show ongoing monitoring, corrective actions, and leadership accountability for privacy performance.

PIMS Readiness Assessment
0/ 100

Readiness Score

Based on a review across ISO/IEC 27701:2019 clause requirements and Annex A and B control domains. Three areas require remediation prior to the beginning assessment.

Clause 6: PIMS-Specific Requirements (PII Controllers)72%
Clause 7: PII Controller Obligations (ISO 27002 Guidance)78%
Clause 8: PII Processor Obligations (ISO 27002 Guidance)69%
Annex A: Extended Controls for PII Controllers75%
Annex B: Extended Controls for PII Processors71%
Gap Findings3 Open
Extended Statement of ApplicabilityAnnex A and B privacy controls not mapped to risk treatment decisions
Annex A/B
Privacy Risk AssessmentAssessment not completed for all in-scope PII processing activities
Clause 6.1
Internal Audit CoverageInternal audit scope does not cover PIMS requirements
Clause 9.2
400+
Engagements
12+
Years Active
25+
Countries
ISO/IEC 27701:2019 ISO 19011 Evidence-Based
Why CertPro

Independent ISO 27701 Assessment. Rigorous Methodology

Six principles govern how CertPro conducts ISO/IEC 27701 assessments based on defined audit principles from ISO/IEC 27701:2019 and ISO 19011. Each engagement follows a structured approach from scope review through report issuance, with clear separation from certification authority.

Audit Independence and Impartiality

CertPro does not provide PIMS implementation, remediation, or advisory services to audit clients. A pre-engagement impartiality check is documented for every engagement. Conclusions are based solely on objective evidence obtained during the assessment, in accordance with ISO 19011 principles.

Conducted Under Standard Guidelines

Assessments are conducted in line with ISO/IEC 27701:2019 and ISO 19011 guidelines using a structured, evidence-based methodology. Certification decisions are made by an independent certification body upon completion of the process.

Evidence-Based Privacy Control Assessment

All conclusions are supported by objective evidence. Annex A and B controls are tested through interview, observation, document and record review. Auditors verify a risk-based sample using system data, configurations, and documented records.

Credentialed Audit Team

Each engagement is led by a qualified ISO Lead Auditor with expertise in privacy and data protection frameworks. The team includes CISA-certified auditors with domain expertise across multiple industries.

Transparent Communication

Findings are communicated clearly at each stage. Nonconformities include clause reference, severity, evidence, and required action. No findings are deferred to the final report.

Globally Trusted

CertPro's ISO 27701 assessments show credible privacy information management practices. Adherence to established audit standards drives consistent acceptance of our reports by enterprise customers worldwide.

Frequently Asked Questions

ISO 27701 Certification: Questions We Hear Most

ISO/IEC 27701:2019 defines requirements for a Privacy Information Management System, extending ISO 27001. Certification confirms that a PIMS meets these requirements through an independent audit. It is relevant for organizations processing PII, including SaaS providers, financial institutions, healthcare firms, and data processors under GDPR and similar regulations.

ISO 27701 builds on the ISO 27001 ISMS. It cannot exist independently. Therefore, organizations must either extend an existing ISO 27001 certification or complete a combined audit for both standards.

CertPro's ISO/IEC 27701 assessment evaluates conformity across PIMS scope, PII processing inventory, privacy risk assessment, controller and processor obligations, third-party controls, and internal audit records. All conclusions are based on objective evidence.

Key requirements include a defined PIMS scope, a completed privacy risk assessment, documented controller and processor controls, incident management, and audit records. Evidence of corrective actions is also considered during the assessment.

Follow-up requirements, including surveillance and recertification where applicable, are determined by the independent certification body and the certification scheme in scope.

ISO/IEC 27701 supports evidence-based privacy governance and can help organizations demonstrate accountability against privacy obligations, including GDPR-related requirements where applicable. It does not replace legal review or regulatory obligations.

Discuss Your ISO 27701 Audit Engagement

Speak with a credentialed auditor to confirm your PIMS audit scope, applicable clauses, and certification path relevant to your organization.

ISO 19011 Aligned ISO/IEC 27701:2019
Client Feedback

"The team was excellent to work with. They were clear in their communications and made the surveillance audit a smooth journey."

— Maria Robinson, Sr Solutions Engineer, Conscia
Get Started Today

Begin Your Compliance Audit with a
Licensed CPA Firm.

Schedule a 30-minute scoping call with a credentialed auditor. We will identify the right framework, discuss audit scope and outline a clear path based on your current state.

Licensed CPA Firm Peer Review Enrolled
Schedule A Meeting