Regulation & Assurance

ISO 27001 vs a Vendor Security Questionnaire

Compare ISO 27001 certification with vendor questionnaires, check scope and accreditation, and decide which additional evidence your engagement needs.

A scoped ISMS model connects to a vendor questionnaire through supporting evidence.
In this article 7 sections
ShareLinkedInWhatsAppEmail

Two documents that look similar and answer different questions

A completed vendor security questionnaire and an ISO/IEC 27001 certificate can sit in the same procurement folder and look like they answer the same question. They do not. ISO: ISO/IEC 27001

What a questionnaire can establish

A questionnaire collects the vendor’s answers to your questions. Those answers may be self-reported or corroborated by documents, demonstrations and independent reports. Its assurance value depends on the evidence requested and evaluated, not on the questionnaire format alone.

What ISO 27001 certification actually verifies

ISO/IEC 27001 is an information security management system standard. Certification against it means an external certification body has assessed the vendor’s security management system — not just whether individual controls exist, but whether the organisation has an ongoing process for identifying risk, treating it, and reviewing that treatment over time. Certified organisations are also subject to periodic surveillance audits to maintain certification, not a one-time assessment. Check the certification body’s accreditation separately; accreditation is not automatic for every certificate.

Compare what each document actually supports: a scoped management-system certification and evidence about specific controls or contractual requirements. A corroborated questionnaire can answer questions that the certificate does not cover.

Why both still have a place

Use the certificate to understand the assessed management-system scope, then investigate the controls relevant to your engagement. Certification is not a guarantee that every configuration is correct or that an incident cannot occur.

What to ask before accepting either on its own

Ask for the certificate itself, and check its scope statement — certification can be scoped narrowly to certain business units, locations or services, and a vendor can be legitimately certified while the part of their business relevant to you sits outside that scope.

Ask when the certificate was last audited, not just when it was first issued, since surveillance audits are what keep a certification meaningful between full recertification cycles.

Ask your own questionnaire questions anyway, specific to your engagement, rather than treating certification as a reason to skip due diligence on the details that matter to your particular requirement.

Use both in a single buying decision

For an illustrative hosted HR service, the buyer needs to understand both the provider’s management system and how its own employee data will be handled. The following checks connect those questions without requiring unnecessary disclosure.

  • Match the legal entity, locations and services on the certificate to the contracting entity and proposed delivery. If a group company holds the certificate, ask how the supplying entity falls within scope. Keep the answer with the procurement record.
  • Confirm the certificate’s current status with its issuer or appropriate verification directory. Check the certification body’s accreditation separately. ISO develops standards but does not itself certify organisations; a logo is not sufficient verification.
  • Ask engagement-specific questions about administrator access, deletion, backups, subprocessors and incident contact. For each material answer, agree a proportionate evidence item, such as a redacted procedure, demonstration or relevant report section.
  • Record contradictions instead of averaging them away. If a questionnaire promises deletion in a period that backups cannot support, ask for the real retention behaviour and whether the contract and privacy representation need correction.
  • Close with a decision register: evidence accepted, conditions before onboarding, residual risk owner and next review trigger. A service change or a new processing location may warrant reassessment before the scheduled annual review.

Do not collect raw customer records, production credentials or an entire restricted audit file simply to make the folder look complete. Ask for evidence that answers the specific control question, with suitable confidentiality arrangements. Where an important gap cannot be verified, describe it as unresolved rather than inferring assurance from an unrelated certificate.

Sources and further guidance

Regulatory applicability depends on the organisation and the provisions in force. Check the linked primary sources before acting.

Related reading and capabilities

Frequently asked questions

Does ISO issue the certificate?

No. External certification bodies perform certification. Accreditation of the certification body is a separate consideration and should be verified rather than assumed.

Can a questionnaire provide independent evidence?

Its answers can be supported by independent reports or verified demonstrations. Evaluate that evidence and its scope; do not automatically treat every questionnaire as either proven or worthless.

Does certification remove the need for a contract review?

No. The agreement still needs to address your service, responsibilities, access, incident cooperation and exit arrangements. A management-system certificate does not negotiate those terms for you.