The privacy extension to ISO/IEC 27001. We audit your PIMS against ISO/IEC 27701 and, on the evidence, issue certification — independently of the audit team.
ISO/IEC 27701:2019 extends ISO/IEC 27001 into a privacy information management system (PIMS): adding the controls and responsibilities needed to manage personal data as a controller or processor, supporting obligations under privacy law.
As an independent certification body, Skyeblanc Certification audits your privacy information management system against ISO 27701 and, where the evidence supports conformity, issues certification. We do not design, document or improve your system — that separation is a requirement of ISO/IEC 17021-1 and is exactly what gives a ISO 27701 certificate its meaning.
Certification is delivered under ISO/IEC 27006 series, with the certification decision made by an independent decision-maker who did not conduct your audit.
The same defined path for every applicant — the certification decision held independent of the audit team.
A readiness review of your documented PIMS, scope and objectives, and audit planning.
On-site or ICT-assisted assessment of the PIMS in operation against ISO 27701.
An independent decision-maker reviews the evidence and grants — or declines — certification.
Annual surveillance audits, then a full recertification at year three renews the cycle.
Audit duration for ISO 27701 is determined per ISO/IEC 27006 series — never a flat rate. The main factors:
The number of people — including shifts and part-time — is the primary driver of audit duration.
How many sites and where. Multi-site sampling follows IAF MD1.
The range of activities and processes within your certified scope.
Operations across multiple shifts can extend on-site audit time.
Transfers from another accredited body are reviewed under IAF MD2.
On-site or ICT-assisted remote auditing per IAF MD4, matched to risk.
Fees are fixed for the defined audit programme. A fixed fee covers the audit; it never buys an outcome — certification is granted only on the evidence, by an independent decision-maker.
ISO/IEC 27701 suits any organisation that processes personal data and wants to demonstrate privacy governance. We routinely audit across:
Tell us your scope, sites and employee numbers, and we'll return a fixed-fee audit quotation with the programme and timeline.
Prefer pricing first? Request an audit quotation →