Skip to content

Operationalizing ISO/IEC 27701 in Modulos

ISO 27701 becomes manageable when the PIMS is treated as an operating model — scope, role determination, privacy risk, control execution, evidence, continual improvement, repeated. This page is the implementation playbook for running the PIMS on Modulos using the OFF-12 + MFF-13 framework templates.

Quick decision

  • You are starting a fresh PIMS rollout → one organization project with OFF-12, plus AI-system projects with MFF-13.
  • You already run ISO 27001 (ISMS) → add OFF-12 to the existing organization project; reuse the shared Annex SL processes (document control, internal audit, management review, corrective action); only stand up privacy-specific work.
  • You need to determine controller / processor / joint-controller role → document per processing activity on the PII role-determination control under ORF-256 (Clause 4.1). Table A.1 applies to controller activities, Table A.2 to processor activities, Table A.3 to both.
  • You need to scope MFF-13 work → MFF-13 covers the per-AI-system privacy overlap — privacy risk assessment + treatment (MRF-243 / MRF-244) and the applicable Annex A control tables (MRF-394 / MRF-395 / MRF-396). One MFF-13 project per AI system that processes PII.

TL;DR

  • Two framework templates map ISO 27701 evidence: OFF-12 (org, 28 ORF requirements) + MFF-13 (app, 5 MRF requirements).
  • Two project layers: organization project for the PIMS spine; AI-system projects for per-system privacy overlap.
  • PIMS spine on the org project: scope, privacy policy, role determination, risk method, Annex A control-table selection (A.1 / A.2 / A.3), internal audit, management review, corrective action.
  • Per-AI-system overlap on the app project: privacy risk assessment + treatment for each AI deployment that processes PII, plus the three Annex A control tables as first-class per-table requirements (MRF-394 / MRF-395 / MRF-396).
  • Controller / processor / joint-controller role determination is recorded on the PII role-determination control under ORF-256 (Clause 4.1). Role drives which Annex A table (A.1 / A.2 / A.3) applies.
  • IMS integration with ISO 27001 / 42001: the Clauses 4–10 controls are one shared set; keep standard-specific risk and control work explicit.
  • Edition status: the platform labels OFF-12 / MFF-13 as ISO/IEC 27701:2025 directly. ISO/IEC 27701:2019 is the withdrawn prior edition.

Primary source

ISO/IEC 27701:2025Privacy information management — Requirements and guidance. Withdrawn prior edition: ISO/IEC 27701:2019. Modulos framework templates: OFF-12 and MFF-13, labeled ISO/IEC 27701:2025 in modulos_platform/content/templates/frameworks/. Available via the ISO Online Browsing Platform. © ISO.

ProjectTemplateWhen to use
One organization projectOFF-12 (add to existing org project if you already run ISO 27001 / 42001)Scope statement, role determination, privacy policy, Annex SL processes, privacy risk method, Annex A control-table selection (A.1 / A.2 / A.3), internal audit, management review
AI-system projectsMFF-13Per-AI-system privacy risk assessment + treatment; the Annex A control tables (A.1 / A.2 / A.3) as first-class requirements

The split mirrors the standard's logic: organization-wide PIMS spine on one side; per-system operational work on the other.

Set up: a sequence that works

How to operationalize ISO 27701 in Modulos

OFF-12 (org-level) mapping:

PIMS elementOFF-12 requirementClause
Organizational contextORF-2564.1
Interested partiesORF-2574.2
PIMS scope + controller / processor role determinationORF-2584.3
PIMS itselfORF-2594.4
Leadership commitmentORF-2605.1
Privacy policyORF-2615.2
Roles and responsibilitiesORF-2625.3
Risk and opportunities — generalORF-2636.1.1
Privacy risk assessmentORF-2646.1.2
Privacy risk treatment + Annex A control-table selectionORF-2656.1.3
Privacy objectivesORF-2666.2
Planning of changesORF-2676.3
Resources / competence / awareness / communicationORF-268ORF-2717.1–7.4
Documented informationORF-272 / ORF-273 / ORF-2747.5.1–7.5.3
Operational planning and controlORF-2758.1
Monitoring + measurementORF-2769.1
Internal audit + audit programORF-277 / ORF-2789.2.1 / 9.2.2
Management review (process / inputs / outputs)ORF-279 / ORF-280 / ORF-2819.3.1 / 9.3.2 / 9.3.3
Continual improvementORF-28210.1
Nonconformity and corrective actionORF-28310.2

MFF-13 (app-level) mapping:

RequirementClause / AnnexTopic
MRF-2438.2Privacy risk assessment (per AI system)
MRF-2448.3Privacy risk treatment (per AI system)
MRF-394Annex A, Table A.1Controls for PII controllers (31)
MRF-395Annex A, Table A.2Controls for PII processors (18)
MRF-396Annex A, Table A.3Controls for both roles (29)

Operating rules:

  • Scope, role determination, privacy policy, risk method, internal audit, management review live on OFF-12. One organization project per organization.
  • Per-AI-system privacy risk + treatment live on MFF-13. One MFF-13 project per AI system that processes PII.
  • The three Annex A control tables are first-class per-table requirements on MFF-13 — MRF-394 (Table A.1, controllers), MRF-395 (Table A.2, processors) and MRF-396 (Table A.3, both roles) — so each AI-system project tracks control readiness table by table, selected by that system's role. At the organization level, the OFF-12 evidence pattern complements this: the Statement of Applicability and control-selection decisions are captured on ORF-265 (Clause 6.1.3 risk treatment).

What is first-class UI vs evidence-attached

  • First-class — Modulos exposes the OFF-12 / MFF-13 framework template on the project (Settings → Frameworks) and the requirement readiness signal on each ORF / MRF requirement — including the three Annex A control tables, which are first-class MFF-13 requirements (MRF-394 / MRF-395 / MRF-396).
  • Evidence-attached (no dedicated UI) — PIMS scope and role-determination document, privacy risk-assessment method, privacy risk register, DPIA records, RoPA entries, control execution records, PII principals' rights tickets, supplier / sub-processor assessments, cross-border transfer impact assessments, breach-notification records, internal-audit program + reports, management-review minutes. Each is owner-authored documentation stored as control-level evidence on the relevant requirement.

ISO 27701 doesn't prescribe the form of these artifacts — only that they exist, are current and are reviewable.

Controller, processor, joint controller — selecting the Annex A tables

Role is not an exhaustive binary — most organizations operate as more than one, and a third table applies regardless of role:

RoleAnnex A tableMFF-13 requirementTypical Modulos use
PII controllerTable A.1MRF-394 (31)HR data, marketing leads, B2C product user accounts — your organization determines purposes and means
PII processorTable A.2MRF-395 (18)B2B SaaS customer data, AI inference on customer prompts — your organization processes on documented instructions
Joint controllerTable A.1MRF-394 (31)Processing whose purposes and means you jointly determine with another organization (GDPR Article 26)
Both rolesTable A.3MRF-396 (29)Information-security controls adapted for PII protection — selected whatever the role

Mechanics:

  • Document the role per processing activity on ORF-258 — controller, processor, or joint controller.
  • The privacy risk treatment on ORF-265 selects the applicable Annex A controls table by table, recorded in the Statement of Applicability.
  • On each AI-system project, the three Annex A tables surface as first-class requirements (MRF-394 / MRF-395 / MRF-396); per-control execution evidence is linked to the Modulos controls under them.

Cross-framework mapping (preview)

ISO 27701 elementAdjacent provision
Clause 4.3 PIMS scopeISO 27001 Clause 4.3 ISMS scope; ISO 42001 Clause 4.3 AIMS scope
Controller / processor / joint-controller role determinationGDPR Articles 4(7) / 4(8) / 26
Clause 6.1.2 privacy risk assessmentGDPR Article 35 DPIA (triggered); ISO 27001 Clause 6.1.2
Table A.1 (controllers)GDPR Articles 24, 30
Table A.2 (processors)GDPR Article 28
Table A.3 (both roles)GDPR Article 32 security of processing
Breach processGDPR Articles 33–34; ISO 27001 Annex A.5.24–A.5.28
Cross-border transfersGDPR Articles 44–49
Annex SL Clauses 4–10ISO 27001 / 42001 same clauses — implement once, share evidence

IMS integration — ISO 27001 + 42001 + 27701

The PIMS Clauses 4–10 share the Annex SL backbone with ISO 27001 (ISMS) and ISO 42001 (AIMS). In Modulos, the org-level Clauses 4–10 controls are one shared set across ISO 27001, 27701 and 42001 (and reused by NIS2 and DORA), written to read correctly under whichever management system applies. Where one standard imposes work the others do not, that obligation is its own control mapped only to that standard, so it never appears in another framework's checklist:

  • Shared — a single "Communication methods" control completes Clause 7.4 for all three; document control (7.5), internal audit (9.2), management review (9.3) and corrective action (10.2) operate once.
  • ISO 27701-only — the Clause 6.1.3 information-security-program documentation.
  • ISO 27001 + 27701 — risk-owner identification under Clause 6.1.2.
  • ISO 27001-only — determining who is assigned monitoring and measurement under Clause 9.1.
  • ISO 42001-only — AI-policy alignment and AIMS documentation.

Each requirement's detail panel makes this explicit — it shows the exact Standard reference (clause / Annex) and a plain-language summary of what the clause requires; the shared Clauses 4–10 requirements also carry Harmonized with links to the sibling ISO standards' matching requirements and Related to links where relevant. What stays standard-specific:

  • ISO 27701: privacy risk + treatment; controller / processor / joint-controller distinction; the Annex A privacy control tables (A.1 controllers, A.2 processors, A.3 both); PII principals' rights; cross-border transfers.
  • ISO 27001: information-security risk + treatment; Annex A (normative) information-security controls.
  • ISO 42001: AI policy, AI risk + impact, AI management-system controls.

Practical pattern in Modulos: add the relevant OFF templates (OFF-9 ISMS, OFF-10 AIMS, OFF-12 PIMS) to the same organization project; the shared Annex SL controls are satisfied once, and the standard-specific risk and control work stays explicit.

Related: Integration with GDPR · ISO 42001 ↔ ISO 27001 comparison.

Common pitfalls

  • Treating role determination as a one-off. Controller / processor status changes when processing activities change (new product, new B2B contract, new AI feature). The role record needs to live with the PIMS.
  • Conflating DPIA and privacy risk assessment. Clause 6.1.2 privacy risk assessment is the PIMS-wide risk method; the GDPR Article 35 DPIA is triggered for high-risk processing. The DPIA outputs feed Clause 6.1.2 / 6.1.3 but don't replace them.
  • Skipping Table A.2. Organizations that are mostly controllers often forget the processor side of the business. If you process PII on behalf of customers, Table A.2 (MRF-395) applies to those activities.
  • Reproducing the Annex A control text. © ISO. Reference controls by reference number; describe implementation in your own words.
  • Stale supplier register. Sub-processor inventories drift fast. Make the supplier-assessment cadence a planned obligation on ORF-275.

Source attribution

ISO/IEC 27701:2025Privacy information management — Requirements and guidance, Clauses 4–10 + Annex A (normative) — Table A.1 (PII controllers), Table A.2 (PII processors), Table A.3 (both roles) + Annex B (implementation guidance, informative) + Annex D (informative GDPR mapping). © ISO/IEC. Available via the ISO Online Browsing Platform. Modulos framework templates OFF-12 and MFF-13 (labeled ISO/IEC 27701:2025) in modulos_platform/content/templates/frameworks/.

Disclaimer

This page is for general informational purposes and does not constitute legal or certification advice.