Appearance
Operationalizing ISO/IEC 27701 in Modulos
ISO 27701 becomes manageable when the PIMS is treated as an operating model — scope, role determination, privacy risk, control execution, evidence, continual improvement, repeated. This page is the implementation playbook for running the PIMS on Modulos using the OFF-12 + MFF-13 framework templates.
Quick decision
- You are starting a fresh PIMS rollout → one organization project with OFF-12, plus AI-system projects with MFF-13.
- You already run ISO 27001 (ISMS) → add OFF-12 to the existing organization project; reuse the shared Annex SL processes (document control, internal audit, management review, corrective action); only stand up privacy-specific work.
- You need to determine controller / processor / joint-controller role → document per processing activity on the PII role-determination control under
ORF-256(Clause 4.1). Table A.1 applies to controller activities, Table A.2 to processor activities, Table A.3 to both. - You need to scope MFF-13 work → MFF-13 covers the per-AI-system privacy overlap — privacy risk assessment + treatment (
MRF-243/MRF-244) and the applicable Annex A control tables (MRF-394/MRF-395/MRF-396). One MFF-13 project per AI system that processes PII.
TL;DR
- Two framework templates map ISO 27701 evidence:
OFF-12(org, 28 ORF requirements) +MFF-13(app, 5 MRF requirements). - Two project layers: organization project for the PIMS spine; AI-system projects for per-system privacy overlap.
- PIMS spine on the org project: scope, privacy policy, role determination, risk method, Annex A control-table selection (A.1 / A.2 / A.3), internal audit, management review, corrective action.
- Per-AI-system overlap on the app project: privacy risk assessment + treatment for each AI deployment that processes PII, plus the three Annex A control tables as first-class per-table requirements (
MRF-394/MRF-395/MRF-396). - Controller / processor / joint-controller role determination is recorded on the PII role-determination control under
ORF-256(Clause 4.1). Role drives which Annex A table (A.1 / A.2 / A.3) applies. - IMS integration with ISO 27001 / 42001: the Clauses 4–10 controls are one shared set; keep standard-specific risk and control work explicit.
- Edition status: the platform labels OFF-12 / MFF-13 as ISO/IEC 27701:2025 directly. ISO/IEC 27701:2019 is the withdrawn prior edition.
Primary source
ISO/IEC 27701:2025 — Privacy information management — Requirements and guidance. Withdrawn prior edition: ISO/IEC 27701:2019. Modulos framework templates: OFF-12 and MFF-13, labeled ISO/IEC 27701:2025 in modulos_platform/content/templates/frameworks/. Available via the ISO Online Browsing Platform. © ISO.
Recommended project structure
| Project | Template | When to use |
|---|---|---|
| One organization project | OFF-12 (add to existing org project if you already run ISO 27001 / 42001) | Scope statement, role determination, privacy policy, Annex SL processes, privacy risk method, Annex A control-table selection (A.1 / A.2 / A.3), internal audit, management review |
| AI-system projects | MFF-13 | Per-AI-system privacy risk assessment + treatment; the Annex A control tables (A.1 / A.2 / A.3) as first-class requirements |
The split mirrors the standard's logic: organization-wide PIMS spine on one side; per-system operational work on the other.
Set up: a sequence that works
1
Add OFF-12 to your org project
Apply the PIMS template alongside any existing ISO 27001 / 42001 templates.
2
Define the PIMS scope
Clause 4.3 scope statement: processing activities, PII categories, principals.
3
Determine controller / processor / joint-controller role
Per processing activity. Role drives which Annex A table applies.
4
Run privacy risk + treatment
Clause 6.1.2 / 6.1.3 — select applicable Annex A controls from Tables A.1 / A.2 / A.3.
5
Add MFF-13 per AI system
Per-system privacy risk + treatment and the applicable Annex A control tables (A.1 / A.2 / A.3).
6
Operate, audit, review, improve
Control execution, rights handling, internal audit, management review, corrective action.
How to operationalize ISO 27701 in Modulos
OFF-12 (org-level) mapping:
| PIMS element | OFF-12 requirement | Clause |
|---|---|---|
| Organizational context | ORF-256 | 4.1 |
| Interested parties | ORF-257 | 4.2 |
| PIMS scope + controller / processor role determination | ORF-258 | 4.3 |
| PIMS itself | ORF-259 | 4.4 |
| Leadership commitment | ORF-260 | 5.1 |
| Privacy policy | ORF-261 | 5.2 |
| Roles and responsibilities | ORF-262 | 5.3 |
| Risk and opportunities — general | ORF-263 | 6.1.1 |
| Privacy risk assessment | ORF-264 | 6.1.2 |
| Privacy risk treatment + Annex A control-table selection | ORF-265 | 6.1.3 |
| Privacy objectives | ORF-266 | 6.2 |
| Planning of changes | ORF-267 | 6.3 |
| Resources / competence / awareness / communication | ORF-268–ORF-271 | 7.1–7.4 |
| Documented information | ORF-272 / ORF-273 / ORF-274 | 7.5.1–7.5.3 |
| Operational planning and control | ORF-275 | 8.1 |
| Monitoring + measurement | ORF-276 | 9.1 |
| Internal audit + audit program | ORF-277 / ORF-278 | 9.2.1 / 9.2.2 |
| Management review (process / inputs / outputs) | ORF-279 / ORF-280 / ORF-281 | 9.3.1 / 9.3.2 / 9.3.3 |
| Continual improvement | ORF-282 | 10.1 |
| Nonconformity and corrective action | ORF-283 | 10.2 |
MFF-13 (app-level) mapping:
| Requirement | Clause / Annex | Topic |
|---|---|---|
MRF-243 | 8.2 | Privacy risk assessment (per AI system) |
MRF-244 | 8.3 | Privacy risk treatment (per AI system) |
MRF-394 | Annex A, Table A.1 | Controls for PII controllers (31) |
MRF-395 | Annex A, Table A.2 | Controls for PII processors (18) |
MRF-396 | Annex A, Table A.3 | Controls for both roles (29) |
Operating rules:
- Scope, role determination, privacy policy, risk method, internal audit, management review live on OFF-12. One organization project per organization.
- Per-AI-system privacy risk + treatment live on MFF-13. One MFF-13 project per AI system that processes PII.
- The three Annex A control tables are first-class per-table requirements on MFF-13 —
MRF-394(Table A.1, controllers),MRF-395(Table A.2, processors) andMRF-396(Table A.3, both roles) — so each AI-system project tracks control readiness table by table, selected by that system's role. At the organization level, the OFF-12 evidence pattern complements this: the Statement of Applicability and control-selection decisions are captured onORF-265(Clause 6.1.3 risk treatment).
What is first-class UI vs evidence-attached
- First-class — Modulos exposes the OFF-12 / MFF-13 framework template on the project (Settings → Frameworks) and the requirement readiness signal on each ORF / MRF requirement — including the three Annex A control tables, which are first-class MFF-13 requirements (
MRF-394/MRF-395/MRF-396). - Evidence-attached (no dedicated UI) — PIMS scope and role-determination document, privacy risk-assessment method, privacy risk register, DPIA records, RoPA entries, control execution records, PII principals' rights tickets, supplier / sub-processor assessments, cross-border transfer impact assessments, breach-notification records, internal-audit program + reports, management-review minutes. Each is owner-authored documentation stored as control-level evidence on the relevant requirement.
ISO 27701 doesn't prescribe the form of these artifacts — only that they exist, are current and are reviewable.
Controller, processor, joint controller — selecting the Annex A tables
Role is not an exhaustive binary — most organizations operate as more than one, and a third table applies regardless of role:
| Role | Annex A table | MFF-13 requirement | Typical Modulos use |
|---|---|---|---|
| PII controller | Table A.1 | MRF-394 (31) | HR data, marketing leads, B2C product user accounts — your organization determines purposes and means |
| PII processor | Table A.2 | MRF-395 (18) | B2B SaaS customer data, AI inference on customer prompts — your organization processes on documented instructions |
| Joint controller | Table A.1 | MRF-394 (31) | Processing whose purposes and means you jointly determine with another organization (GDPR Article 26) |
| Both roles | Table A.3 | MRF-396 (29) | Information-security controls adapted for PII protection — selected whatever the role |
Mechanics:
- Document the role per processing activity on
ORF-258— controller, processor, or joint controller. - The privacy risk treatment on
ORF-265selects the applicable Annex A controls table by table, recorded in the Statement of Applicability. - On each AI-system project, the three Annex A tables surface as first-class requirements (
MRF-394/MRF-395/MRF-396); per-control execution evidence is linked to the Modulos controls under them.
Cross-framework mapping (preview)
| ISO 27701 element | Adjacent provision |
|---|---|
| Clause 4.3 PIMS scope | ISO 27001 Clause 4.3 ISMS scope; ISO 42001 Clause 4.3 AIMS scope |
| Controller / processor / joint-controller role determination | GDPR Articles 4(7) / 4(8) / 26 |
| Clause 6.1.2 privacy risk assessment | GDPR Article 35 DPIA (triggered); ISO 27001 Clause 6.1.2 |
| Table A.1 (controllers) | GDPR Articles 24, 30 |
| Table A.2 (processors) | GDPR Article 28 |
| Table A.3 (both roles) | GDPR Article 32 security of processing |
| Breach process | GDPR Articles 33–34; ISO 27001 Annex A.5.24–A.5.28 |
| Cross-border transfers | GDPR Articles 44–49 |
| Annex SL Clauses 4–10 | ISO 27001 / 42001 same clauses — implement once, share evidence |
IMS integration — ISO 27001 + 42001 + 27701
The PIMS Clauses 4–10 share the Annex SL backbone with ISO 27001 (ISMS) and ISO 42001 (AIMS). In Modulos, the org-level Clauses 4–10 controls are one shared set across ISO 27001, 27701 and 42001 (and reused by NIS2 and DORA), written to read correctly under whichever management system applies. Where one standard imposes work the others do not, that obligation is its own control mapped only to that standard, so it never appears in another framework's checklist:
- Shared — a single "Communication methods" control completes Clause 7.4 for all three; document control (7.5), internal audit (9.2), management review (9.3) and corrective action (10.2) operate once.
- ISO 27701-only — the Clause 6.1.3 information-security-program documentation.
- ISO 27001 + 27701 — risk-owner identification under Clause 6.1.2.
- ISO 27001-only — determining who is assigned monitoring and measurement under Clause 9.1.
- ISO 42001-only — AI-policy alignment and AIMS documentation.
Each requirement's detail panel makes this explicit — it shows the exact Standard reference (clause / Annex) and a plain-language summary of what the clause requires; the shared Clauses 4–10 requirements also carry Harmonized with links to the sibling ISO standards' matching requirements and Related to links where relevant. What stays standard-specific:
- ISO 27701: privacy risk + treatment; controller / processor / joint-controller distinction; the Annex A privacy control tables (A.1 controllers, A.2 processors, A.3 both); PII principals' rights; cross-border transfers.
- ISO 27001: information-security risk + treatment; Annex A (normative) information-security controls.
- ISO 42001: AI policy, AI risk + impact, AI management-system controls.
Practical pattern in Modulos: add the relevant OFF templates (OFF-9 ISMS, OFF-10 AIMS, OFF-12 PIMS) to the same organization project; the shared Annex SL controls are satisfied once, and the standard-specific risk and control work stays explicit.
Related: Integration with GDPR · ISO 42001 ↔ ISO 27001 comparison.
Common pitfalls
- Treating role determination as a one-off. Controller / processor status changes when processing activities change (new product, new B2B contract, new AI feature). The role record needs to live with the PIMS.
- Conflating DPIA and privacy risk assessment. Clause 6.1.2 privacy risk assessment is the PIMS-wide risk method; the GDPR Article 35 DPIA is triggered for high-risk processing. The DPIA outputs feed Clause 6.1.2 / 6.1.3 but don't replace them.
- Skipping Table A.2. Organizations that are mostly controllers often forget the processor side of the business. If you process PII on behalf of customers, Table A.2 (
MRF-395) applies to those activities. - Reproducing the Annex A control text. © ISO. Reference controls by reference number; describe implementation in your own words.
- Stale supplier register. Sub-processor inventories drift fast. Make the supplier-assessment cadence a planned obligation on
ORF-275.
Related pages
ISO 27701 overview
Hub: PIMS structure, controller / processor distinction, GDPR alignment
PIMS foundations (scope + roles + certification)
Scope statement, role determination, Stage 1 / Stage 2 / surveillance / recertification
Clauses 4–10 (implementation guide)
Annex SL backbone with PIMS-specific additions
Annexes (controls reference)
Annex A Tables A.1–A.3 (controllers / processors / both) + Annex D GDPR mapping
Integration with GDPR
How the PIMS operationalizes GDPR obligations
Source attribution
ISO/IEC 27701:2025 — Privacy information management — Requirements and guidance, Clauses 4–10 + Annex A (normative) — Table A.1 (PII controllers), Table A.2 (PII processors), Table A.3 (both roles) + Annex B (implementation guidance, informative) + Annex D (informative GDPR mapping). © ISO/IEC. Available via the ISO Online Browsing Platform. Modulos framework templates OFF-12 and MFF-13 (labeled ISO/IEC 27701:2025) in modulos_platform/content/templates/frameworks/.
Disclaimer
This page is for general informational purposes and does not constitute legal or certification advice.