ISO 27701 certification

Preparation for ISO/IEC 27701:2025 Certification

What does preparation for certification involve?

Preparation for ISO/IEC 27701:2025 certification is the process through which an organisation ensures that its Privacy Information Management System (PIMS):

  • • has been fully implemented
  • • operates effectively
  • • conforms to all requirements of the standard

The objective is to ensure that the organisation is fully prepared for the external Stage 1 and Stage 2 audits and to minimise the risk of nonconformities.

Certification is conducted by an accredited body using a two-stage model. The system should have been operating in practice for at least three months and should have undergone an internal audit and management review.

What does the preparation include?

Our certification preparation service covers the elements needed to complete the audit successfully:

  • • review of the PIMS scope
  • • validation of documentation, including policies, procedures and registers
  • • review of the risk assessment and risk treatment measures
  • • analysis of conformity with ISO/IEC 27701:2025
  • • preparation of audit evidence

The focus is on ensuring that the system is implemented in practice and can be demonstrated through objective evidence.

Readiness assessment

We conduct a detailed assessment of the organisation's readiness, including whether:

  • • all requirements of the standard have been addressed
  • • the processes are being performed in practice
  • • sufficient records and other evidence are available
  • • employees understand their responsibilities

This simulates a Stage 1 audit, including the documentation review.

Operational validation

We assess how the system operates in practice, including:

  • • application of controls for protecting personal data
  • • incident and breach management
  • • third-party management
  • • traceability and logging
  • • staff awareness

This reflects the purpose of a Stage 2 audit: verification of practical implementation.

Internal audit

We conduct a full internal audit that includes:

  • • an audit of processes and controls
  • • interviews with employees
  • • verification of evidence
  • • identification of nonconformities and weaknesses

An internal audit is a mandatory requirement before certification.

Management review

We support the management review process through:

  • • evaluation of system effectiveness
  • • risk analysis
  • • decisions on improvements
  • • preparation of evidence for management review

This is an important element that auditors always examine.

Correcting nonconformities

Following our assessments, we:

  • • identify all nonconformities
  • • define corrective actions
  • • support their implementation
  • • validate readiness for the audit

Preparation for the certification audit

We prepare the organisation for the actual audit through:

  • • preparation for Stage 1 and Stage 2
  • • simulated audit interviews
  • • structured organisation of evidence
  • • support in communications with the certification body

Following a successful audit, a certificate is issued for three years and maintained through annual surveillance audits.

Our approach

We ensure that:

  • • the system is operational, not merely documented
  • • all requirements have been addressed effectively
  • • the organisation is prepared for an actual audit, not only on paper
  • • the process is structured and predictable

The result

After completing the certification preparation process, your organisation:

  • • is fully prepared for the external audit
  • • minimises the risk of nonconformities
  • • demonstrates maturity and control over personal data
  • • improves the likelihood of obtaining certification at the first attempt

How can we help?

We provide:

  • • readiness assessments
  • • internal audits
  • • preparation for certification
  • • corrective action support
  • • training on managing an ISO/IEC 27701:2025 Privacy Information Management System (PIMS)
  • • audit support