Skip to content

ISO/IEC 27701 — PIMS foundations

ISO 27701 is a management-system standard. Audits test whether the PIMS works in practice — privacy governance, risk management, control execution, continual improvement. This page covers the foundations: the Clause 4.3 scope statement, the controller / processor / joint-controller role distinction that drives which Annex A control table applies, and the Stage 1 / Stage 2 / surveillance / recertification cycle.

Quick decision

  • You need to write the PIMS scope statement → Clause 4.3. Cover processing activities, categories of PII, PII principals, organization's role per activity (controller / processor / both).
  • You determine purposes and means of processing → you are a PII controller for that activity. Apply Annex A Table A.1 controls (plus Table A.3, which applies to both roles).
  • You process PII on behalf of another organization → you are a PII processor for that activity. Apply Annex A Table A.2 controls (plus Table A.3).
  • You operate ISO 27001 already → the 2019 PIMS edition required ISMS-first; the 2025 edition makes the PIMS standalone. Either way, the Annex SL clauses are shared.

TL;DR

  • PIMS scope (Clause 4.3) is mandatory documented information naming processing activities, PII categories, principals and organization's role.
  • Controller / processor / joint-controller distinction drives which Annex A control table applies. Table A.1 = controller controls; Table A.2 = processor controls; Table A.3 = controls for both roles. Many organizations operate as more than one.
  • Stage 1 = documentation review. Stage 2 = operational audit. Same three-year cycle as ISO 27001 / 42001.
  • Edition status: ISO/IEC 27701:2025 is the current published edition; ISO/IEC 27701:2019 is the withdrawn prior edition. The Modulos OFF-12 / MFF-13 templates label the standard ISO/IEC 27701:2025 directly.
  • Auditors sample operational reality — control execution records, PII principals' rights handling, supplier evidence, breach-notification process.

Primary source

ISO/IEC 27701:2025Privacy information management — Requirements and guidance, Clauses 4.1, 4.2, 4.3, 5.3, 6.1.2, 6.1.3, 9.2, 9.3. Withdrawn prior edition: ISO/IEC 27701:2019. Available via the ISO Online Browsing Platform. © ISO.

PIMS scope you can defend (Clause 4.3)

A defensible PIMS scope statement is:

  • Specific — names processing activities (e.g., "HR processing of employee data", "customer-data processing for SaaS service X").
  • PII-aware — names which categories of PII are inside the scope (employee data, customer data, special-category data).
  • Role-aware — specifies the organization's role (controller / processor / both) per processing activity.
  • Principal-aware — names the PII principals affected (employees, customers, end-users, prospects).
  • Reviewable — describes how scope changes are approved and recorded.

For AI systems, the PIMS scope often extends to the data pipeline (training data, inference data) and to downstream consequences of automated decision-making.

Controller vs processor

The controller / processor distinction is the most consequential decision in any PIMS:

PII controllerPII processor
DeterminesPurposes and means of processingActs on documented instructions from a controller
GDPR equivalentArticle 4(7) (Article 26 where jointly determined)Article 4(8)
PIMS control tableAnnex A Table A.1Annex A Table A.2
Typical examplesOrganization processing its own employee or customer data; B2C SaaS controller of end-user accountsB2B SaaS processing customer data on behalf of customer organizations; AI inference services

Role is not an exhaustive binary. Where two or more organizations jointly determine the purposes and means of processing, each is a joint controller (GDPR Article 26) and records that arrangement in the role determination. And a third control table — Annex A Table A.3 — applies to both controllers and processors: it adapts information-security controls to the protection of PII and is selected regardless of role. A single organization is typically a controller for some activities (HR data, marketing leads) and a processor for others (customer data in a B2B SaaS context); the PIMS applies the relevant tables per processing activity, not per organization.

For AI systems, the role determination often depends on whether the AI provider sets the purposes (e.g., a general-purpose chatbot) or whether the customer sets the purposes (e.g., a customer-built AI on a SaaS inference platform).

The certification audit cycle

StageTimingAuditor focus
Stage 1Initial certificationScope, privacy policy, role determination, risk + treatment, internal audit, management review
Stage 2Initial certificationOperational evidence — control execution, PII principals' rights handling, supplier governance, breach process
Year 1 surveillance~12 monthsSample of clauses + always: nonconformities, audit, review, changes
Year 2 surveillance~24 monthsSame depth as year 1
Recertification~36 monthsFull audit at Stage 2 depth; new three-year certificate

What auditors typically test

  • PIMS scope and PII categories are current and the PIMS operates within them.
  • The Clause 4.1 context determination records whether climate change is a relevant issue for the PIMS — a determination added by the 2024 climate-action amendment to the harmonized management-system structure, which the 2025 edition already reflects.
  • Controller / processor / joint-controller role determination is documented per processing activity.
  • Privacy risk assessment (Clause 6.1.2) is reproducible and drives Annex A control-table selection.
  • Annex A controls (Tables A.1 / A.2 / A.3) are executed with evidence.
  • PII principals' rights (access, rectification, erasure, portability) are handled within statutory deadlines.
  • Supplier / sub-processor governance is operating.
  • Cross-border transfer arrangements (where applicable) are documented and current.
  • Breach notification works to required deadlines (typically 72 hours under GDPR Article 33).
  • Internal audit findings feed corrective actions; management review takes decisions.

How to operationalize PIMS foundations in Modulos

Modulos models the PIMS scope + role determination against the OFF-12 framework template:

OFF-12 requirementDescriptionISO 27701 clause
ORF-256Understanding the organization and its context4.1
ORF-257Understanding the needs and expectations of interested parties4.2
ORF-258Determining the scope of the PIMS4.3
ORF-259Privacy information management system4.4
ORF-261Privacy policy5.2
ORF-262Roles, responsibilities and authorities5.3
ORF-264Privacy risk assessment6.1.2
ORF-265Privacy risk treatment + control selection6.1.3
ORF-277 / ORF-278Internal audit + audit program9.2.1 / 9.2.2
ORF-279 / ORF-280 / ORF-281Management review (process, inputs, outputs)9.3.1 / 9.3.2 / 9.3.3

The PIMS scope statement is owner-authored documentation stored as control-level evidence on ORF-258 (Clause 4.3); the controller / processor role determination is recorded on the dedicated PII role-determination control under ORF-256 (Clause 4.1). The Annex A control-table selection (Tables A.1 / A.2 / A.3) is captured on ORF-265 (Clause 6.1.3 risk treatment).

Clause 6.1.3 also carries an obligation unique to ISO 27701: the organization must identify and document the information-security program it operates to protect the PII it processes. This is a 27701-only control on ORF-265 — ISO 27001 and ISO 42001 do not impose it, so it appears only on the PIMS checklist.

Cross-framework mapping (preview)

ISO 27701 elementAdjacent provision
Clause 4.3 PIMS scopeISO 27001 Clause 4.3 ISMS scope; ISO 42001 Clause 4.3 AIMS scope
Controller / processor distinctionGDPR Article 4(7) controller / 4(8) processor
Clause 6.1.2 privacy risk assessmentGDPR Article 35 DPIA; ISO 27001 Clause 6.1.2
Stage 1 / Stage 2 cycleIdentical across ISO 27001, 42001, 9001
Internal audit (Clause 9.2)ISO 27001 / 42001 / 9001 Clause 9.2
Breach notificationGDPR Article 33; ISO 27001 Annex A.5.24–A.5.28

Source attribution

ISO/IEC 27701:2025Privacy information management — Requirements and guidance, Clauses 4.1, 4.2, 4.3, 4.4, 5.2, 5.3, 6.1.2, 6.1.3, 9.2, 9.3 + Annex A Tables A.1 (PII controllers), A.2 (PII processors) and A.3 (both roles). © ISO/IEC. Available via the ISO Online Browsing Platform.

Disclaimer

This page is for general informational purposes and does not constitute legal or certification advice.