Two documents that look similar and answer different questions
A completed vendor security questionnaire and an ISO/IEC 27001 certificate can sit in the same procurement folder and look like they answer the same question. They do not. ISO: ISO/IEC 27001
What a questionnaire can establish
A questionnaire collects the vendor’s answers to your questions. Those answers may be self-reported or corroborated by documents, demonstrations and independent reports. Its assurance value depends on the evidence requested and evaluated, not on the questionnaire format alone.
What ISO 27001 certification actually verifies
ISO/IEC 27001 is an information security management system standard. Certification against it means an external certification body has assessed the vendor’s security management system — not just whether individual controls exist, but whether the organisation has an ongoing process for identifying risk, treating it, and reviewing that treatment over time. Certified organisations are also subject to periodic surveillance audits to maintain certification, not a one-time assessment. Check the certification body’s accreditation separately; accreditation is not automatic for every certificate.
Compare what each document actually supports: a scoped management-system certification and evidence about specific controls or contractual requirements. A corroborated questionnaire can answer questions that the certificate does not cover.
Why both still have a place
Use the certificate to understand the assessed management-system scope, then investigate the controls relevant to your engagement. Certification is not a guarantee that every configuration is correct or that an incident cannot occur.
What to ask before accepting either on its own
Ask for the certificate itself, and check its scope statement — certification can be scoped narrowly to certain business units, locations or services, and a vendor can be legitimately certified while the part of their business relevant to you sits outside that scope.
Ask when the certificate was last audited, not just when it was first issued, since surveillance audits are what keep a certification meaningful between full recertification cycles.
Ask your own questionnaire questions anyway, specific to your engagement, rather than treating certification as a reason to skip due diligence on the details that matter to your particular requirement.
Use both in a single buying decision
For an illustrative hosted HR service, the buyer needs to understand both the provider’s management system and how its own employee data will be handled. The following checks connect those questions without requiring unnecessary disclosure.
- Match the legal entity, locations and services on the certificate to the contracting entity and proposed delivery. If a group company holds the certificate, ask how the supplying entity falls within scope. Keep the answer with the procurement record.
- Confirm the certificate’s current status with its issuer or appropriate verification directory. Check the certification body’s accreditation separately. ISO develops standards but does not itself certify organisations; a logo is not sufficient verification.
- Ask engagement-specific questions about administrator access, deletion, backups, subprocessors and incident contact. For each material answer, agree a proportionate evidence item, such as a redacted procedure, demonstration or relevant report section.
- Record contradictions instead of averaging them away. If a questionnaire promises deletion in a period that backups cannot support, ask for the real retention behaviour and whether the contract and privacy representation need correction.
- Close with a decision register: evidence accepted, conditions before onboarding, residual risk owner and next review trigger. A service change or a new processing location may warrant reassessment before the scheduled annual review.
Do not collect raw customer records, production credentials or an entire restricted audit file simply to make the folder look complete. Ask for evidence that answers the specific control question, with suitable confidentiality arrangements. Where an important gap cannot be verified, describe it as unresolved rather than inferring assurance from an unrelated certificate.

