Skip to main content

WIDTH achieves ISO/IEC 27001:2022 certification

Certified by TÜV SÜD PSB, covering the development, implementation and maintenance of WIDTH's secure e-KYC, AML and CTF technology.

WIDTH ISO/IEC 27001:2022 information security certification
3-min readPublished 6 August 2026

WIDTH is pleased to announce that its Information Security Management System (ISMS) has been certified to ISO/IEC 27001:2022 by TÜV SÜD PSB Pte Ltd, an accredited certification body operating under the Singapore Accreditation Council.

The certification (registration no. IS27-2026-0368) is valid from 24 June 2026 to 23 June 2029. Its scope covers the development, implementation and maintenance of secure regulatory technology solutions, including e-Know Your Customer (e-KYC), Anti-Money Laundering (AML) and Counter-Terrorism Financing (CTF) solutions.

What ISO/IEC 27001 certification means

ISO/IEC 27001 is the international standard for information security management. It is not a checklist exercise or a point-in-time scan. Certification requires an organisation to define its risk appetite, apply documented controls across people, processes and technology, and demonstrate to an independent auditor that the system works as described.

Ongoing surveillance audits across the three-year cycle help confirm that those controls remain effective.

That distinction matters in compliance technology. WIDTH's customers entrust the platform with sensitive information, including identity documents, beneficial ownership structures, transaction histories, sanctions and adverse media findings, and the case records supporting risk decisions. Protecting that information is fundamental to operating a credible compliance platform.

Independent assurance for regulated institutions

For the institutions WIDTH serves, this certification provides practical value. Vendor due diligence and outsourcing reviews are becoming more rigorous. Regulators across Singapore, Hong Kong and the wider region expect financial institutions to evidence how third-party technology providers manage information security risk, rather than simply accept self-declared assurances.

An accredited ISO/IEC 27001:2022 certificate gives compliance, risk and procurement teams independent evidence when assessing WIDTH's security controls.

Why it matters to WIDTH. Certification gives customers independent, accredited assurance that the controls protecting their data are defined, tested and audited. It also supports more efficient vendor due diligence.
Compliance takeaway. As third-party risk expectations tighten across APAC, regulated institutions increasingly need evidence of their technology providers' security posture. Accredited certification offers a clear and recognised form of assurance.

Security and explainability as one operating discipline

The certification also reflects how WIDTH approaches AI-native compliance infrastructure. Automation only earns a place in regulated decision-making when the surrounding system is disciplined. Access must be controlled, changes governed, decisions logged and actions traceable to a person or policy.

The principles that make an AI-assisted review defensible are also central to a certified ISMS. At WIDTH, security and explainability form part of the same operating discipline.

Our thanks go to the WIDTH team whose work made this possible, and to TÜV SÜD PSB for a rigorous audit process. The three-year certification cycle means the work continues — which is exactly the point.

The certificate can be verified through TÜV SÜD's Directory of Management System Certified Companies. For a copy of the certificate or further details about our security programme, contact marketing@width.com or visit our Security page.

About WIDTH

WIDTH is a compliance technology company formed following Vernal Capital's acquisition of Cynopsis. Built on Cynopsis's team, customer relationships and operating foundation, WIDTH provides software for managing regulatory workflows across onboarding, risk, transaction monitoring and ongoing compliance in a more efficient, auditable and scalable way.

See how WIDTH keeps compliance data secure and auditable

Book a 30-minute walkthrough to see how WIDTH connects KYC, KYB, KYT and AML within one controlled compliance platform.