ISO 27701 internal audit service

ISO/IEC 27701:2025 Audit

What is an ISO/IEC 27701:2025 audit?

An ISO/IEC 27701:2025 audit is an independent, systematic assessment of the Privacy Information Management System (PIMS), conducted to determine:

  • conformity with the standard
  • the effectiveness of the implemented measures
  • whether the organisation's processes are applied in practice

The audit is not limited to documentation. It verifies whether the organisation actually manages personal data and the related risks in practice.

Types of audit

Internal audit

Internal audit is a mandatory element of the PIMS and is conducted regularly, preferably once a year, to:

  • assess the current state
  • identify nonconformities and risks
  • prepare for an external certification audit

It includes a review of documentation and evidence, as well as verification that processes are being followed in practice.

External certification audit

This audit is performed by an accredited certification body to confirm that the system conforms to ISO/IEC 27701:2025.

The audit follows a standardised two-stage model used for ISO management systems.

Stages of the certification audit

Stage 1 - Readiness review

At this stage, the auditors assess:

  • the scope of the PIMS
  • policies and procedures
  • the risk assessment methodology
  • internal audits and management review
  • evidence that the system has been implemented and is operating

The purpose is to confirm that the organisation is ready for the main audit.

Stage 2 - Implementation assessment

This is the main audit, during which the auditors verify:

  • the practical application of the controls
  • the effectiveness of the processes
  • risk management
  • staff awareness
  • implementation of the measures for protecting personal data

The auditors collect evidence through interviews, observation and review of records.

What evidence is required?

The audit is entirely evidence-based. The evidence usually includes:

  • Documentation: policies, procedures and risk assessments
  • Records: logs, training records, incidents and audits
  • Practical implementation: interviews and operational processes

The aim is to demonstrate that the system is effective, not merely documented.

Audit cycle

ISO/IEC 27701:2025 follows a three-year certification cycle. It starts with initial certification and continues with annual audits to ensure that the Privacy Information Management System (PIMS) remains effective.

Breakdown of the three-year cycle

The standard process for maintaining certification includes the following recurring activities:

Year 0: Initial certification audit

  • Stage 1 (readiness review): A preliminary review of the documentation to confirm that it meets the requirements of the standard.
  • Stage 2 (certification audit): A detailed on-site or remote assessment to verify that the privacy controls have been implemented and are effective.

Years 1 and 2: Surveillance audits

Annual audits confirm that the system continues to meet the requirements. These audits are shorter and focus on key areas such as internal audits and personal data breach management.

Year 3: Recertification audit

A full reassessment at the end of the three-year period. If successful, a new certificate is issued and the cycle begins again.

Transition to the 2025 edition

If you are already certified to ISO/IEC 27701:2019, you have a three-year transition period ending in October 2028.

  • Audit options: You can combine the transition audit with a scheduled surveillance or recertification audit to optimise costs.
  • Standalone standard: Unlike the 2019 edition, ISO/IEC 27701:2025 is now a standalone standard. This means that you can obtain certification without first holding an ISO/IEC 27001 certificate.

How can IS Consult Service help?

We provide audit, training and consulting services, including ISO/IEC 27701 implementation services. We can integrate ISO/IEC 27701:2025 with ISO/IEC 27001:2022 or implement it independently where no ISO/IEC 27001:2022 certificate is in place.

Drawing on extensive international experience in privacy protection, we can support your route to ISO/IEC 27701:2025 certification. Your audit can include a gap assessment and benchmarking. We will assess your information security maturity and advise you on opportunities for continual improvement.

Are you planning to transition from the 2019 edition, or are you starting a new certification process from the beginning?

Get started today by contacting us through the contact form!