Standards / Information security, privacy and AI
ISO/IEC 27701 Privacy information management
Extends an ISMS to manage personal data as a controller or processor.
Core documents AMS builds
- Privacy policy
- Records of processing
- Data subject request procedure
- Privacy impact assessments
Drafted from your actual processes and systems, then kept under version control with review dates.
The path to ISO/IEC 27701
Six steps from first conversation to ISO/IEC 27701. AMS and our consultants handle each one with you.
- 1Scope
Define which sites, teams, processes and systems ISO/IEC 27701 will cover.
- 2Gap assessment
Compare what you do today with every ISO/IEC 27701 requirement and list what is missing.
- 3Documents
Write the policies, procedures and records ISO/IEC 27701 expects, starting with the privacy policy.
- 4Implement and collect evidence
Put the processes into daily work and capture proof that they run, on a schedule.
- 5Internal review
Check readiness with an internal audit or self-assessment, and close the findings.
- 6Certification audit
An accredited certification body runs a stage 1 document review and a stage 2 audit, then issues the certificate. Surveillance audits follow every year.
ISO/IEC 27701 questions
Planning ISO/IEC 27701? Talk to our team
How long does ISO/IEC 27701 implementation take?
Most organizations need about 8–14 weeks, depending on size, number of sites and how much is already in place. A gap assessment gives a firm estimate.
What documents does ISO/IEC 27701 require?
Core documents usually include: privacy policy, records of processing, data subject request procedure, privacy impact assessments. AMS drafts them from your actual processes and keeps them under version control.
Can ISO/IEC 27701 be combined with other standards?
Yes. ISO/IEC 27701 is often run together with ISO/IEC 20000-1, ISO/IEC 27001, ISO/IEC 42001. AMS maps shared requirements, so one record can count toward several standards.
How does AMS help with ISO/IEC 27701?
AMS runs the full ISO/IEC 27701 program: scoping, gap assessment, documents, evidence capture, internal audits, corrective actions and the audit pack for your certification body.