← All insights

ISO 27001 · ISO 27701

ISO 27001 + 27701: the privacy extension, done once.

How to scope a combined ISMS and PIMS programme so you build the privacy work into the security work — instead of paying for it twice.

Why 27701 is now the default follow-on

Enterprise procurement has quietly converged. A 27001 certificate alone used to clear most security questionnaires; in 2026 it increasingly arrives at the desk with a follow-up: does it include the 27701 extension? Buyers regulated under UK GDPR, EU GDPR or comparable regimes want a single, audited answer to both their security and privacy diligence — and 27701 is the standard that gives it to them.

That shift makes the sequencing question concrete. If 27701 is coming within twelve months anyway, doing it in the same programme as 27001 is materially cheaper, faster, and produces a tidier management system. Doing them sequentially almost always costs more for less.

What 27701 actually adds

  1. Component 01

    A Privacy Information Management System

    27701 sits on top of your ISMS and adds the governance specifically required to manage personal data — roles, records of processing, data-subject rights handling, and privacy-by-design embedded in change control.

  2. Component 02

    Split obligations for controllers and processors

    Annex A covers PII controller controls; Annex B covers processor controls. Most organisations are both, for different processing activities, and need to declare and operate against the relevant set for each.

  3. Component 03

    Records of processing and transfer mechanisms

    27701 requires you to maintain processing records aligned to GDPR Article 30, document lawful bases, and operate concrete safeguards for international transfers — the evidence regulators ask for first.

  4. Component 04

    Data-subject rights operationalised

    Access, rectification, erasure, portability and objection requests get response timelines, owners, and audit trails. The PIMS is what turns a privacy notice from a document into a working process.

  5. Component 05

    Sub-processor governance

    27701 sharpens 27001's supplier-management controls specifically for processors of personal data: due diligence, contracts, transfer mechanisms, and meaningful oversight that survives an ICO audit.

How to scope the combined programme

The cleanest scope is the one where ISMS and PIMS share boundaries: same business units, same systems, same suppliers. Build one risk assessment with privacy treated as a category of risk alongside security, not a separate register. Use the existing 27001 Annex A controls as the spine and let 27701's Annex A and B controls hang off it.

Most policies — access control, supplier management, incident response, change management — extend rather than duplicate. The new artefacts you will actually write from scratch are the records of processing, the privacy notice inventory, the data-subject rights procedure, the transfer-mechanism register, and a privacy impact assessment template that plugs into your change process.

Six scoping mistakes that double the bill

  • Scoping 27701 narrower than 27001 — auditors flag the gap and you end up rescoping mid-programme.
  • Treating 27701 as a documentation exercise rather than an extension of the operating ISMS.
  • Forgetting to declare both controller and processor roles where the organisation acts as both.
  • Building privacy controls outside the ISMS, creating two parallel risk registers no one reconciles.
  • Leaving sub-processor due diligence as a procurement task rather than a PIMS-owned control.
  • Ignoring data residency and transfer mechanisms until the auditor asks for the evidence pack.

Timeline and effort delta

A 27001-only programme for a small-to-mid organisation typically runs three to six months from kick-off to Stage 2. Adding 27701 in the same programme usually adds four to six weeks — concentrated in the records-of-processing build, the controller/processor declaration, and the data-subject-rights workflow.

Done a year later as a separate project, the same scope tends to take three to four months of its own, because the team rebuilds context, the certification body runs a more substantial Stage 1, and policies written without privacy in mind need editing back into shape. The combined path is almost always the right call once 27701 is on the horizon.

Next step

Scope your combined programme

A short scoping call will tell you whether running 27001 and 27701 together makes sense for your organisation, and what the realistic delta looks like in fees and audit days.