ISO 27001 vendor assessment
An ISO 27001 certificate is useful evidence — it is not the whole vendor decision. Governli reads the certificate, its scope and the vendor's supporting documentation against your requirements, and turns what is covered, missing or ambiguous into findings a reviewer can act on.
Sample assessment
Example SaaS Ltd · ISO/IEC 27001
- CertificateEvidence found
Valid, issued by an accredited certification body
ISO/IEC 27001:2022, valid for the current three-year cycle.
- ScopePartial evidence
Scope statement names the group, not the service
The certified scope covers information security management for the organisation's operations. The purchased analytics service is not named.
- Statement of Applicability
Annex A control status reviewed
Implemented, partially implemented, planned, not implemented and not applicable are read per control — exclusions matter as much as inclusions.
- Surveillance evidenceEvidence found
Most recent surveillance audit summary provided
- FindingPartial evidence
Certification confirmed; applicability to the service is unresolved
Governli reviews certification evidence supplied by the vendor. Governli does not certify organisations.
Decision implication: Request confirmation that the purchased service is inside the certified scope
What an ISO 27001 vendor assessment should establish
Most vendor questionnaires reduce ISO 27001 to a single yes/no field: are you certified? For low-impact suppliers that may be proportionate. For a supplier that will process personal data, hold confidential material or sit in the critical path of your own service, it answers very little. Certification tells you that an accredited body assessed an information security management system against the standard — it does not tell you which service, which controls, or which of your obligations are covered.
A useful assessment separates the existence of a certificate from its relevance. The questions that actually influence a procurement decision are:
- Whether a valid certificate exists, and who issued it
- What the certification scope actually covers
- Whether that scope includes the service you are buying
- Which Annex A controls are implemented, planned or excluded
- Whether supporting documentation evidences your specific requirements
- Which contractual, privacy and residency terms sit outside the certificate
The last point is the one most often missed. Data processing terms, transfer mechanisms, sub-processor change notification, service levels and exit provisions live in the contract and the DPA, not in the certificate — see GDPR and DPA review.
Evidence Governli can review
Evidence is uploaded against the requirements in your assessment. Which documents are needed depends on the framework you assess against and on the vendor — not every assessment needs every document, and a vendor is not penalised for lacking a document that no requirement asks for.
- ISO 27001 certificate — issuer, standard version, validity dates, scope statement
- Statement of Applicability — implemented, partially implemented, planned, not implemented or not applicable controls
- Internal audit, management review, surveillance and recertification records where shared
- Security policies, standards and procedures
- Architecture and security documentation
- SOC 2 Type I/II reports where the vendor provides them as complementary evidence
- DPA, privacy documentation and sub-processor lists
- Incident-response and business-continuity documentation
- Any other document uploaded against a requirement in the assessment
The certificate is evidence, not the conclusion
ISO 27001 is a demanding standard and a current certificate from a reputable certification body is a genuine signal: the vendor runs a governed, externally audited security programme. The point is not to discount it — it is to read it correctly. Four situations recur often enough to be worth checking every time:
A company-wide certificate can exclude the specific SaaS platform, region or delivery team you are contracting with. Read the scope statement against the service description in the contract.
The Statement of Applicability may mark a control implemented, while your requirement asks something more specific — customer-managed keys, EU-only processing, a defined RTO. Implemented is not the same as sufficient.
Processing purposes, transfer mechanisms, sub-processor notification and liability are contractual matters. No certificate resolves them.
Scope wording is often generic, dates unclear, or the Statement of Applicability is not shared at all. Ambiguity is a finding to resolve, not a failure to assume in either direction.
Requirement → Evidence → Finding → Decision
Governli's methodology is Requirements-to-Evidence Mapping. An assessment starts from a requirement catalogue — the Recommended Enterprise Baseline, an ISO 27001 framework selection, or your own uploaded requirements. Each requirement becomes a reviewable item with its own evidence and its own status.
- 1Requirement
A specific thing you need the vendor to satisfy, owned by your organisation and editable at any point.
- 2Evidence
Documents attached to that requirement — certificate, Statement of Applicability, policy, report — with citations back to the source.
- 3Finding
Where evidence is missing, partial, conflicting or ambiguous, the assessment records it as a finding with a recommended follow-up question to the vendor.
- 4Decision
Findings roll up into the Decision Snapshot and the exported Decision Package, so the recommendation can be traced back to individual evidence.
Analysis is decision support, not an automated compliance verdict. Findings are reviewed by a person before a decision is recorded, and the terminal decision passes through a separate reviewer and approver.
Worked example: a valid certificate with an unclear scope
Illustrative only — not an actual customer case. A SaaS vendor supplies a current ISO 27001 certificate issued by an accredited body. The certificate is valid. The scope statement reads "information security management system supporting the provision of software development and managed services" and does not name the platform being procured.
The service processing our data must be covered by a current ISO/IEC 27001 certification.
ISO 27001:2022 certificate uploaded. Issuer, certificate number and validity dates recorded. Scope statement captured verbatim.
Certificate valid; scope relevance not established. The scope wording does not confirm that the procured platform is inside the certified ISMS. Recommended follow-up: request written confirmation from the vendor, or the Statement of Applicability and scope annex naming the service.
Not a rejection and not a pass. The requirement remains open pending clarification, so the reviewer can see exactly why the decision is not yet ready — rather than the certificate being ticked off as satisfied.
What you get out of it
The output is intended to be usable by whoever has to sign off — not a document that needs re-reading before it can be acted on.
- Requirement-level evidence with source citations
- Evidence strength: Found, Partial, Missing, Manual review
- Findings, gaps and recommended follow-up questions
- Assessment status through the review lifecycle
- Decision Snapshot summarising decision readiness
- Exportable Decision Package for procurement and audit
ISO 27001 alongside other vendor evidence
ISO 27001 and SOC 2 are complementary rather than interchangeable: certification shows that a governed management system exists, while a SOC 2 Type II report shows how named controls performed over a defined period, including exceptions. Data protection obligations are evidenced separately through the DPA and privacy documentation. Where your concern is a specific control area rather than the certification itself, a vendor security assessment narrows the scope, and a full vendor due diligence assessment covers all of it in one requirement catalogue.
Background reading: SOC 2 vs ISO 27001 and what counts as strong supplier evidence. Browse all solutions.
What Governli does not do
- Governli is not a certification body and does not issue ISO 27001 certification.
- Governli does not perform certification, surveillance or recertification audits.
- An assessment does not verify controls beyond the evidence made available to it, and does not guarantee that a vendor is secure or compliant.
- Conclusions depend on the completeness and accuracy of the documentation the vendor provides.
- The procurement, security and risk decision remains yours; Governli structures the evidence behind it.
ISO 27001 vendor assessment FAQ
Is an ISO 27001 certificate enough for vendor due diligence?+
Often not on its own. A certificate confirms that an accredited certification body assessed an information security management system, but it does not by itself answer whether the specific service you are buying is inside the certified scope, whether the controls you depend on are implemented rather than excluded, or whether contractual, privacy and data-residency requirements are met. Those questions are answered by reading the certificate together with the Statement of Applicability, the vendor's security documentation and the contract.
Does Governli perform ISO 27001 certification audits?+
No. Governli is not a certification body and does not issue, renew or withdraw ISO 27001 certification. Governli reviews the evidence a vendor provides — including certificates issued by others — and maps that evidence to your requirements so you can make a documented procurement decision. Certification audits can only be performed by an accredited certification body.
What should I check on a vendor's ISO 27001 certificate?+
Check that the certificate is current and not expired, suspended or withdrawn; who issued it and under which accreditation; which standard version it was issued against; and — most importantly — the scope statement. The scope should describe the service, organisational units and locations relevant to what you are purchasing. Governli records these attributes as structured evidence and raises a finding when scope relevance cannot be established from the document.
What if the vendor is not ISO 27001 certified?+
That is not automatically a rejection. Whether certification is mandatory depends on your own requirements. If your requirement catalogue makes certification mandatory, the absence is recorded as a gap against that requirement. If it does not, the underlying requirements — access control, encryption, logging, incident response, continuity — can still be evidenced through other documentation such as a SOC 2 report, security policies or architecture documentation, and assessed on the strength of that evidence.
Can ISO 27001 evidence be assessed together with SOC 2 or DPA documentation?+
Yes. An assessment is organised around your requirements, not around a single framework. A single requirement can be supported by an ISO 27001 certificate, a SOC 2 report section and a clause in the data processing agreement at the same time, and each supporting item is cited individually so a reviewer can trace the conclusion back to the source.