ISO/IEC 27701 (PII processor)
Version: 2019 (clause 5 and Annex B)
ISO/IEC 27701 extends an ISO/IEC 27001 information security management system into a privacy information management system (PIMS); this catalog covers the PIMS-specific clause 5 requirements and the Annex B controls for organizations processing PII on behalf of customers. ISO/IEC 27701:2025 restructured the standard as a standalone privacy management system; this catalog tracks the 2019 numbering used by current certificates.
Where we stand
Controls
80%
Evidence
0%
Policies
30%
20 of 42 clauses mapped to adopted controls
As of (just now)
Percentages are over clauses mapped to at least one adopted control. Unmapped clauses are listed below and never count as passing. A known gap is a clause that applies to us and that no control covers yet.
Clause-by-clause readiness
| Clause | Title | Controls | Evidence | Policies | Last tested |
|---|---|---|---|---|---|
| 5.2 Context of the organization | |||||
| 5.2.1 | Understanding the organization and its context | Unmapped | Unmapped | Unmapped | Not yet |
| 5.2.2 | Understanding the needs and expectations of interested parties | Unmapped | Unmapped | Unmapped | Not yet |
| 5.2.3 | Determining the scope of the information security management system | Unmapped | Unmapped | Unmapped | Not yet |
| 5.2.4 | Information security management system Controls: BIZ-14 | Passing | Not current | Not approved | Not yet |
| 5.3 Leadership | |||||
| 5.3.1 | Leadership and commitment Controls: BIZ-12, BIZ-14 | Passing | Not current | Not approved | Not yet |
| 5.3.2 | Policy Controls: BIZ-14, PEOPLE-04 | Passing | Not current | Not approved | (4 mo ago) |
| 5.3.3 | Organizational roles, responsibilities and authorities Controls: BIZ-15, PEOPLE-08 | Not passing | Not current | Not approved | Not yet |
| 5.4.1 Actions to address risks and opportunities | |||||
| 5.4.1.1 | General Controls: BIZ-04, BIZ-05 | Passing | Not current | Not approved | (4 mo ago) |
| 5.4.1.2 | Information security risk assessment Controls: BIZ-04 | Passing | Not current | Not approved | Not yet |
| 5.4.1.3 | Information security risk treatment Controls: BIZ-07 | Passing | Not current | Approved | Not yet |
| 5.4 Planning | |||||
| 5.4.2 | Information security objectives and planning to achieve them | Unmapped | Unmapped | Unmapped | Not yet |
| 5.5 Support | |||||
| 5.5.1 | Resources | Unmapped | Unmapped | Unmapped | Not yet |
| 5.5.2 | Competence | Unmapped | Unmapped | Unmapped | Not yet |
| 5.5.3 | Awareness Controls: PEOPLE-04, PEOPLE-06, PEOPLE-07 | Not passing | Not current | Not approved | (8 h ago) |
| 5.5.4 | Communication | Unmapped | Unmapped | Unmapped | Not yet |
| 5.5.5 | Documented information | Unmapped | Unmapped | Unmapped | Not yet |
| 5.6 Operation | |||||
| 5.6.1 | Operational planning and control Controls: PDP-02, PDP-14, VEND-04 | Not passing | Not current | Not approved | (8 h ago) |
| 5.6.2 | Information security risk assessment Controls: BIZ-04 | Passing | Not current | Not approved | Not yet |
| 5.6.3 | Information security risk treatment Controls: BIZ-05, BIZ-07 | Passing | Not current | Not approved | (4 mo ago) |
| 5.7 Performance evaluation | |||||
| 5.7.1 | Monitoring, measurement, analysis and evaluation Controls: BIZ-08 | Passing | Not current | Approved | Not yet |
| 5.7.2 | Internal audit | Unmapped | Unmapped | Unmapped | Not yet |
| 5.7.3 | Management review | Unmapped | Unmapped | Unmapped | Not yet |
| 5.8 Improvement | |||||
| 5.8.1 | Nonconformity and corrective action Controls: BIZ-09 | Passing | Not current | Approved | Not yet |
| 5.8.2 | Continual improvement Controls: BIZ-09 | Passing | Not current | Approved | Not yet |
| B.8.2 Conditions for collection and processing | |||||
| B.8.2.1 | Customer agreement Controls: CUST-02 | Passing | Not current | Approved | Not yet |
| B.8.2.2 | Organization's purposes | Unmapped | Unmapped | Unmapped | Not yet |
| B.8.2.3 | Marketing and advertising use | Unmapped | Unmapped | Unmapped | Not yet |
| B.8.2.4 | Infringing instruction | Unmapped | Unmapped | Unmapped | Not yet |
| B.8.2.5 | Customer obligations Controls: CUST-03 | Passing | Not current | Approved | Not yet |
| B.8.2.6 | Records related to processing PII | Unmapped | Unmapped | Unmapped | Not yet |
| B.8.3 Obligations to PII principals | |||||
| B.8.3.1 | Obligations to PII principals | Unmapped | Unmapped | Unmapped | Not yet |
| B.8.4 Privacy by design and privacy by default | |||||
| B.8.4.1 | Temporary files Controls: DATA-04, DATA-05 | Passing | Not current | Not approved | Not yet |
| B.8.4.2 | Return, transfer or disposal of PII Controls: CUST-02, DATA-05 | Passing | Not current | Not approved | Not yet |
| B.8.4.3 | PII transmission controls Controls: DATA-03, DATA-06 | Not passing | Not current | Not approved | (8 h ago) |
| B.8.5 PII sharing, transfer, and disclosure | |||||
| B.8.5.1 | Basis for PII transfer between jurisdictions | Unmapped | Unmapped | Unmapped | Not yet |
| B.8.5.2 | Countries and international organizations to which PII can be transferred | Unmapped | Unmapped | Unmapped | Not yet |
| B.8.5.3 | Records of PII disclosure to third parties | Unmapped | Unmapped | Unmapped | Not yet |
| B.8.5.4 | Notification of PII disclosure requests | Unmapped | Unmapped | Unmapped | Not yet |
| B.8.5.5 | Legally binding PII disclosures | Unmapped | Unmapped | Unmapped | Not yet |
| B.8.5.6 | Disclosure of subcontractors used to process PII | Unmapped | Unmapped | Unmapped | Not yet |
| B.8.5.7 | Engagement of a subcontractor to process PII Controls: VEND-03 | Passing | Not current | Not approved | Not yet |
| B.8.5.8 | Change of subcontractor to process PII | Unmapped | Unmapped | Unmapped | Not yet |
