Choosing among ISO 27701 certification bodies in 2026 comes down to one question: which UKAS-accredited body understands privacy information management well enough to audit it properly, not just tick the ISO 27001 box next to it.
Why this matters
ISO 27701:2019 is the privacy extension to ISO 27001 -- it turns your information security management system into a Privacy Information Management System (PIMS) covering PII controllers and processors. Most UK buyers ask for it now alongside GDPR assurance, especially in SaaS, healthcare, and financial services.
The certification body you pick decides how the audit actually feels. Some bodies run a tight two-stage process and treat the privacy extension as a genuine add-on; others bolt it onto an ISO 27001 audit with an auditor who has never scoped a PIMS before.
OneClickComply automates the evidence collection that any accredited body will ask for at Stage 1 -- policies, records of processing, data mapping, and control evidence tied to Annex A and the PIMS-specific controls. That does not replace the certification body. It just means your audit day is spent answering questions, not hunting for documents.
How we ranked
This list is built on public accreditation scope, sector specialization, and how each body positions itself for combined ISO 27001 and ISO 27701 audits in 2026. It is not a paid placement list and none of these bodies pay OneClickComply for inclusion.
The criteria that matter for ISO 27701 specifically:
- UKAS accreditation for the ISO 27701 extension, not just ISO 27001 -- confirm this before you sign, since not every accredited ISO 27001 body has extended scope to the privacy standard.
- Auditor familiarity with PIMS controls -- ask who will conduct the audit and whether they have privacy-specific experience, not just information security.
- Combined audit capability -- if you do not already hold ISO 27001, look for a body that runs both audits together to cut cost and audit-day count.
- Sector reach -- some bodies are stronger in public sector and enterprise procurement; others are built for lean SME timelines.
The ranked list
BSI -- the enterprise default
BSI is the British Standards Institution and one of the longest-established certification bodies for ISO management systems globally. It is a frequent requirement on public sector and enterprise procurement panels where auditors expect a recognized name.
Expect a formal, structured audit process with well-documented scheme rules. Verdict: Buy if you sell into public sector or enterprise accounts that specifically ask for BSI on the certificate.
DNV -- the multi-sector specialist
DNV originated in maritime and energy assurance and has built out a broad ISO management systems practice, including information security and privacy extensions. It suits organizations already working with DNV on other certifications who want one relationship across schemes.
Verdict: Consider if you already hold another DNV certification and want a single point of contact across your compliance stack.
LRQA -- the engineering heritage pick
LRQA (formerly Lloyd's Register Quality Assurance) carries decades of engineering and industrial audit experience into its ISO management systems arm. It is a solid fit for manufacturing and engineering firms adding ISO 27701 alongside existing quality certifications.
Verdict: Consider for firms with an existing LRQA relationship on ISO 9001 or similar standards.
NQA -- the SME combo pick
NQA is a UK-based certification body with a reputation for running combined ISO 27001 and ISO 27701 audits efficiently for smaller organizations. If you are starting from zero and want both certifications in one process, this is the pragmatic route.
Verdict: Buy for SMEs that want a single audit cycle covering security and privacy management together.
Bureau Veritas -- the global reach pick
Bureau Veritas is a French-founded multinational testing and certification group with a wide international footprint. It fits multi-entity organizations certifying subsidiaries in different countries under one scheme.
Verdict: Consider if you need certificate recognition across multiple jurisdictions rather than UK-only scope.
SGS -- the scale player
SGS is a Swiss-headquartered inspection and certification group operating at large scale across industries. It suits organizations that already use SGS for other testing or certification work and want to consolidate vendors.
Verdict: Consider if consolidating certification bodies across your group is the priority, not audit speed.
Amtivo -- the UK SME scheme specialist
Amtivo focuses heavily on UK SME certification schemes, including Cyber Essentials alongside ISO management systems. It is a reasonable fit for smaller UK businesses that want a body familiar with lighter-touch schemes as well as full ISO audits.
Verdict: Consider for UK-only SMEs already using Amtivo for Cyber Essentials work.
Comparison table
| Body | Best for | Combined ISO 27001 + 27701 audit | Verdict |
|---|---|---|---|
| BSI | Enterprise, public sector | Yes | Buy |
| DNV | Multi-scheme relationships | Yes | Consider |
| LRQA | Engineering, manufacturing | Yes | Consider |
| NQA | SMEs starting from zero | Yes | Buy |
| Bureau Veritas | Multi-country entities | Yes | Consider |
| SGS | Vendor consolidation | Yes | Consider |
| Amtivo | UK SME, Cyber Essentials overlap | Yes | Consider |
How to choose the right body
Get quotes from at least three UKAS-accredited bodies before you commit -- audit day rates and scheme fees vary enough between them to matter for an SME budget. Confirm each quote covers Stage 1 and Stage 2 audit days plus the first year of surveillance, not just the certificate issue fee.
Run an ISO 27001 gap analysis before you approach any certification body -- walking into Stage 1 with known gaps already flagged shortens the audit and avoids nonconformities that delay certification into 2027.
Ask every shortlisted body one direct question: how many ISO 27701 audits has this specific auditor completed, not the company as a whole. The privacy extension is newer than ISO 27001 and auditor depth varies more than the accreditation paperwork suggests.
Get audit-ready before you book a certification body
Automate the evidence collection your auditor will ask for on day one.
Frequently asked questions
One last thing
The accreditation paperwork looks identical across every certification body on this list -- what actually differs is whether the assigned auditor has run a PIMS audit before. Ask for the auditor's specific ISO 27701 track record before you sign, not just the body's general scheme accreditation.
