FintastIQTrust Center
LoginBook a Consultation
Framework

ISO/IEC 27701 (PII processor)

Version: 2019 (clause 5 and Annex B)

ISO/IEC 27701 extends an ISO/IEC 27001 information security management system into a privacy information management system (PIMS); this catalog covers the PIMS-specific clause 5 requirements and the Annex B controls for organizations processing PII on behalf of customers. ISO/IEC 27701:2025 restructured the standard as a standalone privacy management system; this catalog tracks the 2019 numbering used by current certificates.

Official source

Summary

Where we stand

Controls
80%
Evidence
0%
Policies
30%

20 of 42 clauses mapped to adopted controls

As of (just now)

Percentages are over clauses mapped to at least one adopted control. Unmapped clauses are listed below and never count as passing. A known gap is a clause that applies to us and that no control covers yet.

Clauses

Clause-by-clause readiness

ClauseTitleControlsEvidencePoliciesLast tested
5.2 Context of the organization
5.2.1Understanding the organization and its contextUnmappedUnmappedUnmappedNot yet
5.2.2Understanding the needs and expectations of interested partiesUnmappedUnmappedUnmappedNot yet
5.2.3Determining the scope of the information security management systemUnmappedUnmappedUnmappedNot yet
5.2.4Information security management system
Controls: BIZ-14
PassingNot currentNot approvedNot yet
5.3 Leadership
5.3.1Leadership and commitment
Controls: BIZ-12, BIZ-14
PassingNot currentNot approvedNot yet
5.3.2Policy
Controls: BIZ-14, PEOPLE-04
PassingNot currentNot approved(4 mo ago)
5.3.3Organizational roles, responsibilities and authorities
Controls: BIZ-15, PEOPLE-08
Not passingNot currentNot approvedNot yet
5.4.1 Actions to address risks and opportunities
5.4.1.1General
Controls: BIZ-04, BIZ-05
PassingNot currentNot approved(4 mo ago)
5.4.1.2Information security risk assessment
Controls: BIZ-04
PassingNot currentNot approvedNot yet
5.4.1.3Information security risk treatment
Controls: BIZ-07
PassingNot currentApprovedNot yet
5.4 Planning
5.4.2Information security objectives and planning to achieve themUnmappedUnmappedUnmappedNot yet
5.5 Support
5.5.1ResourcesUnmappedUnmappedUnmappedNot yet
5.5.2CompetenceUnmappedUnmappedUnmappedNot yet
5.5.3Awareness
Controls: PEOPLE-04, PEOPLE-06, PEOPLE-07
Not passingNot currentNot approved(8 h ago)
5.5.4CommunicationUnmappedUnmappedUnmappedNot yet
5.5.5Documented informationUnmappedUnmappedUnmappedNot yet
5.6 Operation
5.6.1Operational planning and control
Controls: PDP-02, PDP-14, VEND-04
Not passingNot currentNot approved(8 h ago)
5.6.2Information security risk assessment
Controls: BIZ-04
PassingNot currentNot approvedNot yet
5.6.3Information security risk treatment
Controls: BIZ-05, BIZ-07
PassingNot currentNot approved(4 mo ago)
5.7 Performance evaluation
5.7.1Monitoring, measurement, analysis and evaluation
Controls: BIZ-08
PassingNot currentApprovedNot yet
5.7.2Internal auditUnmappedUnmappedUnmappedNot yet
5.7.3Management reviewUnmappedUnmappedUnmappedNot yet
5.8 Improvement
5.8.1Nonconformity and corrective action
Controls: BIZ-09
PassingNot currentApprovedNot yet
5.8.2Continual improvement
Controls: BIZ-09
PassingNot currentApprovedNot yet
B.8.2 Conditions for collection and processing
B.8.2.1Customer agreement
Controls: CUST-02
PassingNot currentApprovedNot yet
B.8.2.2Organization's purposesUnmappedUnmappedUnmappedNot yet
B.8.2.3Marketing and advertising useUnmappedUnmappedUnmappedNot yet
B.8.2.4Infringing instructionUnmappedUnmappedUnmappedNot yet
B.8.2.5Customer obligations
Controls: CUST-03
PassingNot currentApprovedNot yet
B.8.2.6Records related to processing PIIUnmappedUnmappedUnmappedNot yet
B.8.3 Obligations to PII principals
B.8.3.1Obligations to PII principalsUnmappedUnmappedUnmappedNot yet
B.8.4 Privacy by design and privacy by default
B.8.4.1Temporary files
Controls: DATA-04, DATA-05
PassingNot currentNot approvedNot yet
B.8.4.2Return, transfer or disposal of PII
Controls: CUST-02, DATA-05
PassingNot currentNot approvedNot yet
B.8.4.3PII transmission controls
Controls: DATA-03, DATA-06
Not passingNot currentNot approved(8 h ago)
B.8.5 PII sharing, transfer, and disclosure
B.8.5.1Basis for PII transfer between jurisdictionsUnmappedUnmappedUnmappedNot yet
B.8.5.2Countries and international organizations to which PII can be transferredUnmappedUnmappedUnmappedNot yet
B.8.5.3Records of PII disclosure to third partiesUnmappedUnmappedUnmappedNot yet
B.8.5.4Notification of PII disclosure requestsUnmappedUnmappedUnmappedNot yet
B.8.5.5Legally binding PII disclosuresUnmappedUnmappedUnmappedNot yet
B.8.5.6Disclosure of subcontractors used to process PIIUnmappedUnmappedUnmappedNot yet
B.8.5.7Engagement of a subcontractor to process PII
Controls: VEND-03
PassingNot currentNot approvedNot yet
B.8.5.8Change of subcontractor to process PIIUnmappedUnmappedUnmappedNot yet
ISO/IEC 27701 (PII processor) readiness · FintastIQ Trust Center