Appearance
ISO/IEC 27701 — PIMS foundations
ISO 27701 is a management-system standard. Audits test whether the PIMS works in practice — privacy governance, risk management, control execution, continual improvement. This page covers the foundations: the Clause 4.3 scope statement, the controller / processor / joint-controller role distinction that drives which Annex A control table applies, and the Stage 1 / Stage 2 / surveillance / recertification cycle.
Quick decision
- You need to write the PIMS scope statement → Clause 4.3. Cover processing activities, categories of PII, PII principals, organization's role per activity (controller / processor / both).
- You determine purposes and means of processing → you are a PII controller for that activity. Apply Annex A Table A.1 controls (plus Table A.3, which applies to both roles).
- You process PII on behalf of another organization → you are a PII processor for that activity. Apply Annex A Table A.2 controls (plus Table A.3).
- You operate ISO 27001 already → the 2019 PIMS edition required ISMS-first; the 2025 edition makes the PIMS standalone. Either way, the Annex SL clauses are shared.
TL;DR
- PIMS scope (Clause 4.3) is mandatory documented information naming processing activities, PII categories, principals and organization's role.
- Controller / processor / joint-controller distinction drives which Annex A control table applies. Table A.1 = controller controls; Table A.2 = processor controls; Table A.3 = controls for both roles. Many organizations operate as more than one.
- Stage 1 = documentation review. Stage 2 = operational audit. Same three-year cycle as ISO 27001 / 42001.
- Edition status: ISO/IEC 27701:2025 is the current published edition; ISO/IEC 27701:2019 is the withdrawn prior edition. The Modulos OFF-12 / MFF-13 templates label the standard ISO/IEC 27701:2025 directly.
- Auditors sample operational reality — control execution records, PII principals' rights handling, supplier evidence, breach-notification process.
Primary source
ISO/IEC 27701:2025 — Privacy information management — Requirements and guidance, Clauses 4.1, 4.2, 4.3, 5.3, 6.1.2, 6.1.3, 9.2, 9.3. Withdrawn prior edition: ISO/IEC 27701:2019. Available via the ISO Online Browsing Platform. © ISO.
PIMS scope you can defend (Clause 4.3)
A defensible PIMS scope statement is:
- Specific — names processing activities (e.g., "HR processing of employee data", "customer-data processing for SaaS service X").
- PII-aware — names which categories of PII are inside the scope (employee data, customer data, special-category data).
- Role-aware — specifies the organization's role (controller / processor / both) per processing activity.
- Principal-aware — names the PII principals affected (employees, customers, end-users, prospects).
- Reviewable — describes how scope changes are approved and recorded.
For AI systems, the PIMS scope often extends to the data pipeline (training data, inference data) and to downstream consequences of automated decision-making.
Controller vs processor
The controller / processor distinction is the most consequential decision in any PIMS:
| PII controller | PII processor | |
|---|---|---|
| Determines | Purposes and means of processing | Acts on documented instructions from a controller |
| GDPR equivalent | Article 4(7) (Article 26 where jointly determined) | Article 4(8) |
| PIMS control table | Annex A Table A.1 | Annex A Table A.2 |
| Typical examples | Organization processing its own employee or customer data; B2C SaaS controller of end-user accounts | B2B SaaS processing customer data on behalf of customer organizations; AI inference services |
Role is not an exhaustive binary. Where two or more organizations jointly determine the purposes and means of processing, each is a joint controller (GDPR Article 26) and records that arrangement in the role determination. And a third control table — Annex A Table A.3 — applies to both controllers and processors: it adapts information-security controls to the protection of PII and is selected regardless of role. A single organization is typically a controller for some activities (HR data, marketing leads) and a processor for others (customer data in a B2B SaaS context); the PIMS applies the relevant tables per processing activity, not per organization.
For AI systems, the role determination often depends on whether the AI provider sets the purposes (e.g., a general-purpose chatbot) or whether the customer sets the purposes (e.g., a customer-built AI on a SaaS inference platform).
The certification audit cycle
Governance loop
Four stations, one operating model.
PIMS audit loop
Audit readiness is a cadence, not a sprint.
Plan
Define PIMS scope, privacy policy and risk method
Operate
Execute Annex A controls (Tables A.1–A.3) and collect evidence
Assure
Internal audits and management review
Improve
Corrective actions and updates
The dashed arc marks restart — every cycle re-enters Plan with what changed since the last pass.
| Stage | Timing | Auditor focus |
|---|---|---|
| Stage 1 | Initial certification | Scope, privacy policy, role determination, risk + treatment, internal audit, management review |
| Stage 2 | Initial certification | Operational evidence — control execution, PII principals' rights handling, supplier governance, breach process |
| Year 1 surveillance | ~12 months | Sample of clauses + always: nonconformities, audit, review, changes |
| Year 2 surveillance | ~24 months | Same depth as year 1 |
| Recertification | ~36 months | Full audit at Stage 2 depth; new three-year certificate |
Audit pack
How three export surfaces collapse into one shippable bundle.
Inputs
Project PDF export
Evidence files (per-file download)
Asset files (Download File)
Audit pack
Single shippable bundle
All three inputs, versioned together, ready for the auditor.
Snapshot Exports are snapshots. Keep scope stable before exporting — the bundle freezes whatever was in place at export time.
What auditors typically test
- PIMS scope and PII categories are current and the PIMS operates within them.
- The Clause 4.1 context determination records whether climate change is a relevant issue for the PIMS — a determination added by the 2024 climate-action amendment to the harmonized management-system structure, which the 2025 edition already reflects.
- Controller / processor / joint-controller role determination is documented per processing activity.
- Privacy risk assessment (Clause 6.1.2) is reproducible and drives Annex A control-table selection.
- Annex A controls (Tables A.1 / A.2 / A.3) are executed with evidence.
- PII principals' rights (access, rectification, erasure, portability) are handled within statutory deadlines.
- Supplier / sub-processor governance is operating.
- Cross-border transfer arrangements (where applicable) are documented and current.
- Breach notification works to required deadlines (typically 72 hours under GDPR Article 33).
- Internal audit findings feed corrective actions; management review takes decisions.
How to operationalize PIMS foundations in Modulos
Modulos models the PIMS scope + role determination against the OFF-12 framework template:
| OFF-12 requirement | Description | ISO 27701 clause |
|---|---|---|
ORF-256 | Understanding the organization and its context | 4.1 |
ORF-257 | Understanding the needs and expectations of interested parties | 4.2 |
ORF-258 | Determining the scope of the PIMS | 4.3 |
ORF-259 | Privacy information management system | 4.4 |
ORF-261 | Privacy policy | 5.2 |
ORF-262 | Roles, responsibilities and authorities | 5.3 |
ORF-264 | Privacy risk assessment | 6.1.2 |
ORF-265 | Privacy risk treatment + control selection | 6.1.3 |
ORF-277 / ORF-278 | Internal audit + audit program | 9.2.1 / 9.2.2 |
ORF-279 / ORF-280 / ORF-281 | Management review (process, inputs, outputs) | 9.3.1 / 9.3.2 / 9.3.3 |
The PIMS scope statement is owner-authored documentation stored as control-level evidence on ORF-258 (Clause 4.3); the controller / processor role determination is recorded on the dedicated PII role-determination control under ORF-256 (Clause 4.1). The Annex A control-table selection (Tables A.1 / A.2 / A.3) is captured on ORF-265 (Clause 6.1.3 risk treatment).
Clause 6.1.3 also carries an obligation unique to ISO 27701: the organization must identify and document the information-security program it operates to protect the PII it processes. This is a 27701-only control on ORF-265 — ISO 27001 and ISO 42001 do not impose it, so it appears only on the PIMS checklist.
Cross-framework mapping (preview)
| ISO 27701 element | Adjacent provision |
|---|---|
| Clause 4.3 PIMS scope | ISO 27001 Clause 4.3 ISMS scope; ISO 42001 Clause 4.3 AIMS scope |
| Controller / processor distinction | GDPR Article 4(7) controller / 4(8) processor |
| Clause 6.1.2 privacy risk assessment | GDPR Article 35 DPIA; ISO 27001 Clause 6.1.2 |
| Stage 1 / Stage 2 cycle | Identical across ISO 27001, 42001, 9001 |
| Internal audit (Clause 9.2) | ISO 27001 / 42001 / 9001 Clause 9.2 |
| Breach notification | GDPR Article 33; ISO 27001 Annex A.5.24–A.5.28 |
Related pages
ISO 27701 overview
Hub: PIMS structure, controller / processor distinction, GDPR alignment
Clauses 4–10 (implementation guide)
Annex SL backbone — Context, Leadership, Planning, Support, Operation, Performance evaluation, Improvement
Annexes (controls reference)
Annex A Tables A.1–A.3 (controllers / processors / both) + Annex D GDPR mapping
Operationalizing in Modulos
OFF-12 + MFF-13 rollout, PIMS evidence patterns
Source attribution
ISO/IEC 27701:2025 — Privacy information management — Requirements and guidance, Clauses 4.1, 4.2, 4.3, 4.4, 5.2, 5.3, 6.1.2, 6.1.3, 9.2, 9.3 + Annex A Tables A.1 (PII controllers), A.2 (PII processors) and A.3 (both roles). © ISO/IEC. Available via the ISO Online Browsing Platform.
Disclaimer
This page is for general informational purposes and does not constitute legal or certification advice.