Glossary
ISO 27001
An international certification that an organisation runs a recognised information security management system, checked by an outside body and confirmable with the issuer.
In plain terms
A certificate saying an organisation runs its security according to an international standard, checked by an outside body. What it certifies is the way the organisation manages security, rather than any particular product being secure. That distinction sounds academic and is the whole of what a buyer needs to understand about it.
Why it matters
Because it is frequently offered as an answer to a question it does not address. A vendor holding it has demonstrated that it identifies risks, decides what to do about them and reviews that regularly. It has not thereby demonstrated anything about the specific handling of the material you are about to send, and a buyer who reads the certificate as covering the second has stopped asking one question early.
How it works
It certifies a management system rather than a product. The standard is about having a process for identifying risks, deciding on controls, and reviewing both. An organisation running that process well can still make a decision you would disagree with, because the standard governs how decisions are reached rather than what they conclude.
The certificate names a scope and the scope is the part to read. It may cover an organisation, a division or particular services, and it may cover the platform without covering everything built on it. A certificate is a short document and finding out what it applies to takes about a minute, which is a minute more than most buyers spend.
There is a document behind it that says considerably more, and it can be asked for. The statement recording which controls the organisation applies, and which it decided against and why, is where the substance is, and vendors will frequently share it. That document answers questions the certificate itself cannot.
It is verifiable in a way an audit report is not, which is the practical advantage. Certificates are issued by named bodies and can be checked with the issuer, so the artefact is confirmable rather than taken on trust. That is the reason it is often accepted where sharing a full report would be awkward.
It runs on a cycle with periodic checks between renewals, so it describes a live arrangement rather than a closed window. That is a genuine difference from an audit report and it is not the same as continuous assurance, since the checks are periodic and sampled like any other.
What each artefact can answer
Seen in the wild
Accepting a certificate from an assistant's vendor where a full audit report is not available for sharing.
ChatGPTChecking whether a search vendor's scope statement covers the connectors as well as the core platform.
GleanAsking an automation vendor for the document listing applied controls, rather than only the certificate.
Make
Common misconceptions
People assume
It certifies that the product is secure.
In fact
It certifies that the organisation runs a recognised process for managing security. That is worth something real and it is a statement about method rather than about any particular product, so it does not answer questions about how your specific material will be handled.
People assume
It is interchangeable with a SOC 2 report.
In fact
They answer different questions. One confirms a status that can be verified with the issuer; the other is a document you read for scope, findings and exceptions. Buyers commonly accept either, and the two are complementary rather than equivalent, which is worth knowing when only one is offered.
Telling them apart
ISO 27001 vs SOC 2
ISO 27001
A verifiable status: this organisation runs a recognised management system.
A readable document: this was examined, and here is what was found.
You can check one with the issuer and cannot read it. You can read the other and cannot look it up.
Questions
- What does it actually tell us?
- That the organisation identifies security risks, decides what to do about them and reviews that on a cycle, checked by an outside body. It is a statement about how decisions are made rather than about what any particular decision concluded, which is the boundary worth holding in mind.
- What should we ask for beyond the certificate?
- The scope statement and the document recording which controls are applied and which were decided against. The certificate is short and confirms a status; that second document is where the substance sits, and vendors will frequently share it when asked.
- Is it enough on its own?
- It answers a question about process and leaves questions about your specific material unanswered: what is retained, where it is processed, what it may be used for. Those live in the contract and the vendor's commitments rather than in any certification, and they are the ones an AI buyer usually cares about most.
Key takeaways
- It certifies a management system, not a product.
- The scope statement is short and decides what the certificate applies to.
- The document listing applied controls carries the substance; ask for it.
- It is verifiable with the issuer, which an audit report is not.
Last checked July 2026