Preparation for ISO/IEC 27701:2025 Certification
What does preparation for certification involve?
Preparation for ISO/IEC 27701:2025 certification is the process through which an organisation ensures that its Privacy Information Management System (PIMS):
- • has been fully implemented
- • operates effectively
- • conforms to all requirements of the standard
The objective is to ensure that the organisation is fully prepared for the external Stage 1 and Stage 2 audits and to minimise the risk of nonconformities.
Certification is conducted by an accredited body using a two-stage model. The system should have been operating in practice for at least three months and should have undergone an internal audit and management review.
What does the preparation include?
Our certification preparation service covers the elements needed to complete the audit successfully:
- • review of the PIMS scope
- • validation of documentation, including policies, procedures and registers
- • review of the risk assessment and risk treatment measures
- • analysis of conformity with ISO/IEC 27701:2025
- • preparation of audit evidence
The focus is on ensuring that the system is implemented in practice and can be demonstrated through objective evidence.
Readiness assessment
We conduct a detailed assessment of the organisation's readiness, including whether:
- • all requirements of the standard have been addressed
- • the processes are being performed in practice
- • sufficient records and other evidence are available
- • employees understand their responsibilities
This simulates a Stage 1 audit, including the documentation review.
Operational validation
We assess how the system operates in practice, including:
- • application of controls for protecting personal data
- • incident and breach management
- • third-party management
- • traceability and logging
- • staff awareness
This reflects the purpose of a Stage 2 audit: verification of practical implementation.
Internal audit
We conduct a full internal audit that includes:
- • an audit of processes and controls
- • interviews with employees
- • verification of evidence
- • identification of nonconformities and weaknesses
An internal audit is a mandatory requirement before certification.
Management review
We support the management review process through:
- • evaluation of system effectiveness
- • risk analysis
- • decisions on improvements
- • preparation of evidence for management review
This is an important element that auditors always examine.
Correcting nonconformities
Following our assessments, we:
- • identify all nonconformities
- • define corrective actions
- • support their implementation
- • validate readiness for the audit
Preparation for the certification audit
We prepare the organisation for the actual audit through:
- • preparation for Stage 1 and Stage 2
- • simulated audit interviews
- • structured organisation of evidence
- • support in communications with the certification body
Following a successful audit, a certificate is issued for three years and maintained through annual surveillance audits.
Our approach
We ensure that:
- • the system is operational, not merely documented
- • all requirements have been addressed effectively
- • the organisation is prepared for an actual audit, not only on paper
- • the process is structured and predictable
The result
After completing the certification preparation process, your organisation:
- • is fully prepared for the external audit
- • minimises the risk of nonconformities
- • demonstrates maturity and control over personal data
- • improves the likelihood of obtaining certification at the first attempt
How can we help?
We provide:
- • readiness assessments
- • internal audits
- • preparation for certification
- • corrective action support
- • training on managing an ISO/IEC 27701:2025 Privacy Information Management System (PIMS)
- • audit support
