Skip to main content
WIDTH Intelligence›Privacy Management
ISO 27701 certification

Why WIDTH Is Pursuing ISO/IEC 27701 Certification

Learn what ISO/IEC 27701 covers, why WIDTH is pursuing certification and how stronger privacy governance benefits clients and compliance teams.

10-min readPublished 16 September 2026Last reviewed 16 September 2026
PRIVACY INFORMATION MANAGEMENTPIMS
01Privacy governanceAccountability and responsibilitiesDEFINE
02Privacy risksIdentify and assessASSESS
03Lifecycle governanceCollection through deletionCONTROL
04Continual improvementReview and improveIMPROVE
STANDARDISO/IEC 27701FOCUSPrivacy management
Why WIDTH Is Pursuing ISO/IEC 27701 Certification

Trust in a compliance platform depends on more than what the software can do.

Banks, fintechs and other regulated organisations also need confidence in how their technology providers manage personal data. They need to understand who can access it, why it is processed, how long it is retained and what happens when a privacy risk or incident is identified.

That is why WIDTH is pursuing ISO/IEC 27701 certification.

The certification journey strengthens how privacy responsibilities are defined, documented, reviewed and continually improved across our organisation. It also gives clients a clearer and independently assessed basis for evaluating WIDTH during procurement, security review and ongoing vendor oversight.

What is ISO/IEC 27701?

ISO/IEC 27701 is an international standard for establishing, implementing, maintaining and continually improving a Privacy Information Management System, commonly known as a PIMS.

A PIMS provides a structured framework for managing personally identifiable information. It connects privacy policies with practical responsibilities, operating procedures, risk assessments, controls, records and continual improvement.

The standard is designed for organisations acting as personal information controllers, processors or both. Its requirements can apply to areas such as:

  • privacy governance and accountability;
  • identifying and assessing privacy risks;
  • defining purposes and lawful grounds for processing;
  • managing data-subject rights;
  • controlling the collection, use, disclosure and retention of personal information;
  • managing processors, subprocessors and other third parties;
  • privacy incident management;
  • privacy by design;
  • maintaining evidence of privacy-related decisions; and
  • monitoring and improving the privacy management system.

The current edition, ISO/IEC 27701:2025, can operate as an independent management system standard. It also remains aligned with ISO/IEC 27001, allowing privacy and information-security controls to work together as part of an integrated management system. ISO’s overview of ISO/IEC 27701

How is ISO 27701 different from ISO 27001?

ISO/IEC 27001 focuses on information-security management. It helps organisations manage risks affecting the confidentiality, integrity and availability of information.

ISO/IEC 27701 focuses more specifically on privacy information management and the responsible processing of personal information.

The two standards are closely related, but they answer different questions.

ISO/IEC 27001 asks whether an organisation has a structured system for managing information-security risk. ISO/IEC 27701 adds greater depth around personal information, privacy obligations and the responsibilities of controllers and processors.

WIDTH already states that its information-security management system is certified to ISO/IEC 27001:2022. Pursuing ISO/IEC 27701 builds on that foundation by giving personal-data governance a more explicit and independently assessed framework. WIDTH Security Centre

What does ISO 27701 certification mean?

Certification means that an independent certification body evaluates whether an organisation’s privacy information management system conforms to the applicable requirements of the standard.

ISO develops and publishes the standard, but ISO itself does not audit companies or issue certificates. Certification is conducted by an external certification body. ISO guidance on management-system certification

The audit looks beyond whether privacy policies exist.

It examines whether responsibilities are assigned, controls are implemented, records are maintained, risks are reviewed and the management system operates in practice. It also considers how the organisation identifies gaps, responds to findings and improves its controls over time.

Certification therefore provides independent assurance about the management system within the defined certification scope.

It does not guarantee that an organisation will never experience a privacy incident. It also does not automatically prove compliance with every privacy law in every jurisdiction. Privacy obligations still need to be assessed according to the organisation’s role, processing activities and applicable laws.

Why WIDTH is pursuing ISO 27701 certification

Personal information is central to compliance work

Compliance processes frequently involve personal and commercially sensitive information.

KYC and KYB reviews may include identity documents, contact details, ownership records and information about directors or beneficial owners. Screening and investigation workflows can add risk indicators, reviewer comments, supporting evidence and decision records.

For WIDTH, privacy management is therefore not a peripheral administrative concern. It is closely connected to the systems and workflows our clients rely on.

Our privacy controls need to reflect the sensitivity of this information throughout its lifecycle—from collection and use to access, disclosure, retention and deletion.

Privacy needs an operational system

A privacy policy explains an organisation’s commitments. A privacy information management system determines how those commitments are implemented and maintained.

Pursuing certification requires privacy responsibilities to be translated into repeatable operating practices. This includes defining ownership, evaluating risks, maintaining records, reviewing third parties, testing controls and addressing findings.

That discipline helps privacy remain part of day-to-day operations rather than a document reviewed only when a client sends a questionnaire or a regulator requests evidence.

Independent assessment strengthens accountability

Clients should not have to rely solely on a technology provider’s own description of its controls.

An independent certification audit introduces external scrutiny. Auditors assess the management system against defined requirements and examine whether documented controls are operating within the certification scope.

This does not replace a client’s own due diligence. It gives the client an additional, structured source of assurance.

Privacy expectations continue to evolve

WIDTH serves organisations operating across different markets and regulatory environments. Each organisation may have its own privacy obligations, risk appetite and procurement requirements.

A recognised privacy management framework provides a consistent foundation from which WIDTH can evaluate those requirements and improve its practices.

The management-system approach is especially important because privacy risk is not static. Products change, subprocessors change, laws evolve and new uses of data emerge. The system must be capable of responding to those changes.

How ISO 27701 can benefit WIDTH clients

More efficient vendor due diligence

Regulated organisations often conduct extensive security and privacy reviews before appointing a technology provider.

An ISO/IEC 27701 certificate, supported by clearly scoped assurance documentation, can help procurement, privacy, compliance and security teams understand how the provider’s privacy management system has been assessed.

Certification does not eliminate client due diligence, but it can give review teams a more consistent starting point and reduce reliance on unsupported declarations.

Clearer privacy responsibilities

A mature PIMS requires an organisation to define its role in relation to personal information and assign responsibility for relevant controls.

For clients, this can support clearer conversations about:

  • controller and processor responsibilities;
  • approved purposes for processing;
  • access to personal information;
  • subprocessors and third parties;
  • retention and deletion;
  • privacy incidents;
  • cross-border considerations; and
  • evidence required during reviews or audits.

These matters still need to be addressed in contracts, data-processing agreements and solution design. Certification supports the underlying management practices used to meet those commitments.

Stronger lifecycle governance

Privacy protection should not begin only when information is stored, nor end when an onboarding decision is made.

Personal information needs to be managed throughout its lifecycle. This includes how it is collected, used, shared, retained, corrected and eventually deleted.

A structured privacy management system helps WIDTH review these lifecycle controls systematically rather than treating each stage as a separate concern.

Better evidence for client reviews

Regulated clients may need to demonstrate that they have assessed the risks associated with their service providers.

Independent certification can become one part of that evidence. Depending on eligibility, scope and confidentiality requirements, clients may also request relevant security and privacy documentation through WIDTH’s established review process.

The certificate should always be read carefully. Clients should review the certified legal entity, applicable standard, scope, issue date, expiry date and certification body rather than relying only on a logo or general claim.

Continual improvement

Management-system certification is not intended to be a one-time exercise.

The organisation must continue monitoring the system, reviewing risks, correcting issues and improving its controls. Surveillance and renewal activities provide further opportunities for independent review.

For clients, this matters because privacy risks, products and regulatory expectations change. Trust should be supported by an operating system that can adapt rather than by a single historical assessment.

Why ISO 27701 matters to WIDTH

WIDTH helps regulated teams connect customer onboarding, screening, monitoring and investigations through shared workflows and decision records.

These processes can involve sensitive information and complex responsibilities. Privacy governance must therefore develop alongside the WIDTH platform, its integrations and the organisations that use it.

Pursuing ISO/IEC 27701 certification supports WIDTH in four important ways:

  1. It makes privacy accountability more explicit across teams and processes.
  2. It connects privacy risk management with our established information-security framework.
  3. It provides a recognised structure for evaluating and improving privacy controls.
  4. It gives clients additional evidence for their own governance and vendor-review processes.

This is important not simply because certification may appear in a procurement checklist. It is important because disciplined privacy management supports better decisions about how personal information should be handled.

How clients can place greater trust in WIDTH

Trust should be based on evidence, not a badge alone.

ISO/IEC 27701 certification can provide meaningful independent assurance, but clients should also consider the wider control environment. This includes information-security governance, contractual commitments, access controls, incident processes, data-location requirements and the technical design of the relevant deployment.

WIDTH supports this evaluation through its Security Centre, privacy policy and security-review process.

Our objective is to give clients a clear understanding of:

  • how privacy and security responsibilities are governed;
  • which controls apply to the services they use;
  • what evidence is available;
  • how risks and incidents are managed; and
  • how the control environment is reviewed and improved.

ISO/IEC 27701 certification will add another independently assessed layer to that trust framework.

Privacy assurance is an ongoing commitment

Privacy cannot be reduced to a certificate hanging on a wall.

It requires continuous attention to people, processes, technology and the changing ways in which personal information is used. Certification provides a recognised structure and independent assessment, but the underlying work must continue every day.

For WIDTH, pursuing ISO/IEC 27701 certification reflects our commitment to making privacy accountability part of how we design, operate and improve our services.

For clients, it means stronger evidence, clearer governance and greater confidence when entrusting sensitive compliance information to WIDTH.

To learn more about WIDTH’s security and privacy programme, visit the WIDTH Security Centre. To discuss security, privacy or deployment requirements for your organisation, book a demonstration.

Frequently asked questions