Skip to content

Glossary

ISO 27001

An international certification that an organisation runs a recognised information security management system, checked by an outside body and confirmable with the issuer.

In plain terms

A certificate saying an organisation runs its security according to an international standard, checked by an outside body. What it certifies is the way the organisation manages security, rather than any particular product being secure. That distinction sounds academic and is the whole of what a buyer needs to understand about it.

01

Why it matters

Because it is frequently offered as an answer to a question it does not address. A vendor holding it has demonstrated that it identifies risks, decides what to do about them and reviews that regularly. It has not thereby demonstrated anything about the specific handling of the material you are about to send, and a buyer who reads the certificate as covering the second has stopped asking one question early.

02

How it works

It certifies a management system rather than a product. The standard is about having a process for identifying risks, deciding on controls, and reviewing both. An organisation running that process well can still make a decision you would disagree with, because the standard governs how decisions are reached rather than what they conclude.

The certificate names a scope and the scope is the part to read. It may cover an organisation, a division or particular services, and it may cover the platform without covering everything built on it. A certificate is a short document and finding out what it applies to takes about a minute, which is a minute more than most buyers spend.

There is a document behind it that says considerably more, and it can be asked for. The statement recording which controls the organisation applies, and which it decided against and why, is where the substance is, and vendors will frequently share it. That document answers questions the certificate itself cannot.

It is verifiable in a way an audit report is not, which is the practical advantage. Certificates are issued by named bodies and can be checked with the issuer, so the artefact is confirmable rather than taken on trust. That is the reason it is often accepted where sharing a full report would be awkward.

It runs on a cycle with periodic checks between renewals, so it describes a live arrangement rather than a closed window. That is a genuine difference from an audit report and it is not the same as continuous assurance, since the checks are periodic and sampled like any other.

What each artefact can answer

What each artefact can answerThe reason this separation is worth drawing is that the certificate is frequently offered in response to right-hand questions, and the offer is made in good faith. A vendor asked whether it takes security seriously reaches for the strongest general evidence it has, which is exactly what this is. The buyer then has an artefact that is genuine, verifiable and about something else. What resolves it is asking the right-hand questions directly rather than through a proxy: they are specific, vendors are set up to answer them, and the answers are contractual rather than certified. Holding both in mind also stops the opposite error, which is dismissing the certification because it does not answer those questions. It answers a real one, and an organisation with no process for managing security at all is a materially different proposition from one that has it certified.The certificate answersDo they run a recognisedprocess?Over what scope?Can we confirm itindependently?It does not answerWhat is kept, and for how long?Where is our materialprocessed?May it be used to improve theirmodels?The right-hand column is what anAI buyer usually needs, and noneof it lives in a certification.Those answers are in thecontract and the vendor'swritten commitments, which is adifferent conversation entirely.
The reason this separation is worth drawing is that the certificate is frequently offered in response to right-hand questions, and the offer is made in good faith. A vendor asked whether it takes security seriously reaches for the strongest general evidence it has, which is exactly what this is. The buyer then has an artefact that is genuine, verifiable and about something else. What resolves it is asking the right-hand questions directly rather than through a proxy: they are specific, vendors are set up to answer them, and the answers are contractual rather than certified. Holding both in mind also stops the opposite error, which is dismissing the certification because it does not answer those questions. It answers a real one, and an organisation with no process for managing security at all is a materially different proposition from one that has it certified.
03

Seen in the wild

  • Accepting a certificate from an assistant's vendor where a full audit report is not available for sharing.

    ChatGPT
  • Checking whether a search vendor's scope statement covers the connectors as well as the core platform.

    Glean
  • Asking an automation vendor for the document listing applied controls, rather than only the certificate.

    Make
04

Common misconceptions

People assume

It certifies that the product is secure.

In fact

It certifies that the organisation runs a recognised process for managing security. That is worth something real and it is a statement about method rather than about any particular product, so it does not answer questions about how your specific material will be handled.

People assume

It is interchangeable with a SOC 2 report.

In fact

They answer different questions. One confirms a status that can be verified with the issuer; the other is a document you read for scope, findings and exceptions. Buyers commonly accept either, and the two are complementary rather than equivalent, which is worth knowing when only one is offered.

05

Telling them apart

ISO 27001 vs SOC 2

ISO 27001

A verifiable status: this organisation runs a recognised management system.

SOC 2

A readable document: this was examined, and here is what was found.

You can check one with the issuer and cannot read it. You can read the other and cannot look it up.

06

Questions

What does it actually tell us?
That the organisation identifies security risks, decides what to do about them and reviews that on a cycle, checked by an outside body. It is a statement about how decisions are made rather than about what any particular decision concluded, which is the boundary worth holding in mind.
What should we ask for beyond the certificate?
The scope statement and the document recording which controls are applied and which were decided against. The certificate is short and confirms a status; that second document is where the substance sits, and vendors will frequently share it when asked.
Is it enough on its own?
It answers a question about process and leaves questions about your specific material unanswered: what is retained, where it is processed, what it may be used for. Those live in the contract and the vendor's commitments rather than in any certification, and they are the ones an AI buyer usually cares about most.
07

Key takeaways

  • It certifies a management system, not a product.
  • The scope statement is short and decides what the certificate applies to.
  • The document listing applied controls carries the substance; ask for it.
  • It is verifiable with the issuer, which an audit report is not.
09

Tools that use this

  • ChatGPT

    Accepted where a full audit report is not available for sharing.

  • Glean

    Whether the scope statement covers connectors as well as the platform.

  • Make

    Asking for the applied-controls document rather than only the certificate.

Last checked July 2026

All glossary terms