OneClickComply
    Back to BlogCompliance

    ISO 27701 Certification: How to Prepare in 2026

    24 August 2026
    How to prepare for ISO 27701 privacy certification

    TL;DR

    • ISO 27701 certification extends an existing ISO 27001 ISMS into a full privacy information management system (PIMS).
    • Map every PII processing activity before the gap analysis — auditors check data flows, not just policies.
    • Assign PII controller and processor roles under ISO 27701 Annex A and B before drafting a single control.
    • OneClickComply automates evidence collection for privacy controls — skip the spreadsheet-based audit trail.
    • Plan for a multi-month rollout on top of ISO 27001, not a bolt-on afternoon project.

    ISO 27701 certification proves your organisation runs a working privacy information management system, not just a folder of GDPR policies. Here's the practical path to get certified in 2026, without duplicating work you've already done for ISO 27001.

    Why this matters

    ISO 27701 isn't a standalone certificate. It's an extension to ISO 27001, published by ISO in 2019 to give organisations a certifiable way to manage personal data alongside information security.

    Certification bodies audit ISO 27701 controls together with your ISO 27001 ISMS — you cannot get ISO 27701 certified in isolation. If your ISO 27001 foundation is shaky, ISO 27701 certification stalls before it starts.

    Clients and regulators increasingly ask for it as proof you handle personal data with the same rigour as security incidents. OneClickComply automates the evidence trail across both standards so you're not maintaining two audit binders in 2026.

    What you'll need

    • An active ISO 27001 certification, or an ISMS far enough along to add privacy controls on top
    • A current inventory of every place personal data enters, moves through, and leaves your business
    • A named privacy lead or DPO who owns the PIMS
    • Data processing agreements with every third-party processor touching personal data
    • A compliance automation platform to track evidence instead of spreadsheets
    • Management sign-off on scope: which entities, systems, and data types are in-scope for 2026 certification

    The steps

    1. Confirm your ISO 27001 foundation is solid

    ISO 27701 controls sit inside your existing ISMS structure — they don't replace it. Check your Statement of Applicability, risk register, and internal audit history are current before adding privacy scope.

    If your last ISO 27001 surveillance audit raised nonconformities, resolve those first. Auditors will not certify ISO 27701 on top of an ISMS with open findings.

    Common mistake: starting ISO 27701 work while ISO 27001 documentation is stale. Fix the base layer first — a gap analysis before certification shows exactly where the ISMS needs work.

    2. Map every PII processing activity

    Build a record of processing activities (RoPA): what personal data you collect, why, where it's stored, who accesses it, and how long you keep it. This becomes the backbone of your PIMS.

    Cover HR data, customer data, marketing lists, and any data processed on behalf of clients. Missing categories here is the single biggest reason ISO 27701 gap analyses run long.

    Expected outcome: a data flow map covering every system that touches personal data, reviewed by both IT and legal.

    3. Classify controller and processor roles

    ISO 27701 splits controls into Annex A (PII controllers) and Annex B (PII processors). Most businesses are both — you control your own employee data and process client data under contract.

    Go through each processing activity from step 2 and tag it controller or processor. This determines which annex controls apply and stops you implementing controls that don't fit your role.

    Common mistake: treating every activity as a controller activity by default. Processor-only relationships need different consent and sub-processor controls — get this wrong and the audit stalls.

    4. Run a gap analysis against ISO 27701 Annex A/B controls

    Compare current practice against every applicable Annex A and Annex B control. Score each as met, partially met, or not met, with a named owner and a target date for each gap.

    This is where most teams find the real gaps: consent tracking, data subject request handling, retention schedules, and cross-border transfer controls are the usual weak points.

    Expected outcome: a prioritised action list, not a vague needs-work note. Every gap gets an owner and a date.

    5. Build or update PIMS documentation

    Write (or extend) your privacy policy, data retention schedule, data subject request procedure, and privacy impact assessment template. These sit alongside your existing ISO 27001 policy set, not in a separate binder.

    Keep version control tight — auditors check document history as much as content in 2026 assessments.

    Common mistake: writing generic policy text copied from a template site. Auditors ask process questions like show me the last data subject access request you handled, and generic policies fall apart under that.

    6. Automate evidence collection for privacy controls

    Manual evidence gathering is the slowest part of any ISO 27701 certification run. Screenshots, email chains, and spreadsheet trackers don't scale once you're managing both ISO 27001 and ISO 27701 evidence in parallel.

    Automated evidence collection for audits pulls proof of consent tracking, access reviews, and retention enforcement straight from your systems, timestamped and ready for the auditor.

    Expected outcome: an evidence library that updates itself instead of a folder you rebuild every quarter.

    Automate your ISO 27701 evidence trail

    OneClickComply handles evidence collection across ISO 27001 and ISO 27701 in one place.

    7. Run an internal audit and management review

    Before the certification body sees anything, run your own internal audit against the full Annex A/B control set. Log findings the same way an external auditor would — no soft-pedalling.

    Hold a management review that covers the internal audit findings, the risk register, and any incidents involving personal data since the last review. Minute it properly; auditors ask to see this record.

    Common mistake: skipping the management review because everyone already knows the status. Certification bodies check for a documented review, not verbal agreement.

    8. Book your certification audit

    Confirm with your certification body that ISO 27701 will be assessed alongside your ISO 27001 audit (initial certification or surveillance cycle, whichever applies). Stage 1 checks documentation; Stage 2 checks operation.

    Give the auditor advance sight of your RoPA, gap analysis results, and evidence library. Auditors move faster — and find fewer surprises — when the paperwork is organised before day one.

    Troubleshooting

    Auditor flags missing data flow diagrams. Rebuild the map at data-category level, not system level — show where each type of personal data moves, not just which servers hold it.

    PII inventory is out of date. Set a quarterly review cycle owned by your privacy lead; an inventory older than a few months is treated as unreliable evidence.

    Confusion between controller and processor duties. Re-run step 3 for every new client contract — role changes if the contract terms change, even if the data itself doesn't.

    Overlapping controls with ISO 27001 create duplicate paperwork. Map ISO 27701 controls against your existing ISO 27001 Annex A controls first; most privacy controls extend an existing security control rather than replacing it.

    Third-party processors lack signed DPAs. Chase these before the audit, not during it — a missing DPA on a live processing relationship is an automatic nonconformity.

    Certification body doesn't offer combined audits. Confirm accreditation for ISO 27701 before booking. Not every ISO 27001 certification body is accredited to certify the extension.

    Tools and resources

    • OneClickComply — automates evidence collection across ISO 27001 and ISO 27701 controls
    • Record of Processing Activities (RoPA) template covering controller and processor activities
    • GDPR compliance software for UK small businesses — for teams handling the privacy side without a full ISMS in place yet
    • Internal audit checklist covering both ISO 27001 and ISO 27701 Annex controls
    • Data subject request log and retention schedule tracker

    What to do next

    If your ISO 27001 documentation isn't current, fix that before you touch ISO 27701. A SOC 2 readiness checklist is useful reading too if you're weighing ISO 27701 against SOC 2 privacy criteria for US-facing clients — the evidence discipline overlaps heavily.

    Frequently asked questions

    One last thing

    ISO 27701 was published in 2019 specifically so certification bodies could audit privacy management without inventing a new standalone scheme — that's why it only exists bolted onto ISO 27001. Businesses that treat the two as one continuous audit cycle, rather than two separate projects, get through certification with far less rework in 2026.