GLOSSARY
ISO 27001
By Sygnet Research. Written by Sygnet, sourced, checked before publication.
ISO 27001 is the international standard for information security management systems (ISMS). It sets out the requirements an organization must meet to identify, manage, and reduce risks to the confidentiality, integrity, and availability of its data. A company certified against ISO 27001 has had its security controls, policies, and risk processes audited by an accredited third party, not just self-reported.
How it works
ISO 27001 asks an organization to build a formal ISMS: a structured set of policies, risk assessments, and controls covering everything from access management to incident response. The standard doesn't prescribe one fixed toolset. Instead, it requires the organization to identify its specific risks (to customer documents, source code, employee data) and choose controls from Annex A, a catalog covering areas like cryptography, physical security, supplier relationships, and change management.
Certification is not a one-time event. An accredited auditor performs an initial assessment, then returns for annual surveillance audits and full recertification every three years. This ongoing cycle is what separates ISO 27001 from a security whitepaper or a self-assessed questionnaire: someone independent is checking the paperwork matches the practice.
For a vendor processing documents, this typically means documented rules for who can access production data, how encryption keys are managed, how incidents get logged and escalated, and how subcontractors (cloud providers, model APIs) are vetted. It also means employee training records, access reviews, and change logs actually exist and get sampled during audits, not just described in a slide deck.
Why it matters for document processing
Documents like invoices, contracts, and KYC files often contain personal data, financial terms, or trade secrets. When a vendor runs intelligent document processing through OCR or a vision-language model, that data passes through infrastructure the customer doesn't control directly. ISO 27001 certification gives a concrete, auditable signal that the vendor has controls around that infrastructure: encryption, access restrictions, incident response, vendor management.
For buyers in regulated sectors (insurance, banking, legal), procurement teams often require ISO 27001 as a baseline before a vendor is even considered, regardless of how accurate the extraction model is. It doesn't guarantee zero breaches, but it does mean an external party has verified there's a real security process behind the product, not just a claim on a marketing page.
Related terms
FAQ
Is ISO 27001 the same as SOC 2?
No. Both address information security, but ISO 27001 is an international standard with a certified ISMS and formal audits against Annex A controls, while SOC 2 is a US-originated attestation report describing controls against Trust Services Criteria over a review period. Many vendors hold both, since they serve overlapping but distinct buyer expectations.
Does ISO 27001 certification mean my documents are GDPR compliant?
Not automatically. ISO 27001 covers information security management broadly, while GDPR imposes specific legal obligations around personal data: lawful basis, data subject rights, retention limits. A vendor can be ISO 27001 certified and still need separate GDPR safeguards, such as data residency controls or data processing agreements.
NEXT STEP
See it on your own documents
One email when we publish something worth your time.