ISO 27001: what the certificate proves (and does not prove) about an AI vendor
What ISO/IEC 27001 certification proves about an AI vendor, what it leaves out, how to verify a certificate, and the questions to ask.

What ISO/IEC 27001 actually is
ISO/IEC 27001 is an international standard published jointly by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC). It certifies neither a product, nor a piece of software, nor a data centre. It certifies an information security management system (ISMS): the whole set of policies, roles, risk analyses and controls an organization puts in place to protect information, and then to improve year over year.
The current version, ISO/IEC 27001:2022, offers in its Annex A a reference set of 93 controls grouped into four themes: organizational, people, physical and technological. An organization does not apply them all blindly. It picks the ones that answer its risks and justifies each inclusion and each exclusion in a document called the statement of applicability. That document is the real map of the territory: two certified companies can have very different security postures.
Certification runs through an external audit by an accredited certification body, in two stages: a documentation review, then an on-site audit. The certificate obtained is valid for a three-year cycle, punctuated by annual surveillance audits and closed by a full recertification. Keeping the certificate therefore means staying current every year: a vendor that lets its ISMS slide loses the certification at the auditor’s next visit.
93
reference controls in Annex A of ISO/IEC 27001:2022, across four themes
3 years
length of the certification cycle, with annual surveillance audits
What the certificate really proves
A valid ISO/IEC 27001 certificate proves specific things. The vendor’s management has formally committed to information security. Risks have been inventoried, assessed and treated using a documented method. Controls have been chosen, justified and implemented. Internal audits and management reviews take place. And above all: an independent, accredited third party has verified all of that, on site, and comes back every year.
It is a maturity signal that filters effectively. Standing up an ISMS takes months of work and a discipline many young AI vendors do not yet have. A vendor that has held its certification through two or three cycles has survived several surveillance audits and at least one full recertification. That is not a marketing promise: it is a verifiable track record.
It is also worth placing ISO 27001 against SOC 2, which people often wrongly treat as an alternative. ISO 27001 certifies a management system and is issued by an accredited body. SOC 2 is an attestation report produced by an accounting firm against the AICPA’s trust services criteria; Type II observes how effectively the controls actually operated over a given period. The two are complementary, and a serious vendor can explain what each one covers in their case. That is a lot. But it is not everything.
The blind spots: what the ISO logo does not say
First blind spot: data residency. The standard imposes no location. An AI vendor certified to ISO 27001 can perfectly well host your data in Virginia or Ireland, in full compliance with its certificate. And even if the servers are in Montreal, an American-owned vendor remains subject to the CLOUD Act: physical location is no protection, what counts is the owner’s jurisdiction.
Second blind spot: model training. Nothing in ISO 27001 stops a vendor from using your data to train or fine-tune its AI models. That is purely a contractual question. Yet under Law 25, reusing personal information to train a model amounts to a new purpose, which needs its own legal basis. The undertaking that “your data is never used to train our models” has to appear in black and white in the contract; no logo replaces it.
Third blind spot: scope. A certificate can cover a group’s head office, a subsidiary or a single data centre, and not the product you are buying. Finally, certification is not Law 25 compliance: the assessment required before any disclosure of personal information outside Quebec (s. 17) and the processor contract (s. 18.3) remain your responsibility as the client. The Commission d’accès à l’information can impose administrative penalties of up to $10M or 2% of worldwide revenue, and your vendor’s ISO logo will not shield you.
$10M
ceiling on CAI administrative penalties (or 2% of worldwide revenue) under Law 25
| What the certificate attests | What it does not attest |
|---|---|
| A security management system audited by an accredited third party | That your data stays in Quebec or in Canada |
| A documented risk analysis, reviewed and maintained | That AI models are not trained on your data |
| Controls chosen and verified within a defined scope | That the product you are buying falls within that scope |
| Continuous improvement checked every year | Your Law 25 compliance (ss. 17 and 18.3) or immunity from the CLOUD Act |
How to verify a certificate in ten minutes
Fake certificates and misleading wording both exist. The good news: verification is quick and calls for no technical expertise. Start by asking for a copy of the certificate itself, not a screenshot of the logo on the website. A genuine certificate carries the name of the certification body, a unique number, the issue and expiry dates, the version of the standard (2022) and, above all, the scope statement.
Next, check that the certification body is itself accredited by a member of the International Accreditation Forum (IAF): in Canada that is the Standards Council of Canada; elsewhere, bodies such as ANAB in the United States or UKAS in the United Kingdom. The public IAF CertSearch directory confirms a great many certificates online. A “certificate” issued by an entity nobody accredits is worth nothing.
Finally, be wary of vague wording. “Aligned with ISO 27001,” “meets ISO 27001 requirements” or “ISO 27001 ready” are not certifications: they are self-declarations no third party has verified. They may be sincere, but they prove nothing. In that case, ask for other evidence: a recent SOC 2 Type II report, penetration test results, the security policies themselves.
- Ask for a copy of the certificate: issuing body, number, dates, 2022 version, scope.
- Confirm the body’s accreditation (Standards Council of Canada, ANAB, UKAS or another IAF member).
- Look the certificate up in the IAF CertSearch directory.
- Read the scope statement: the service you are buying has to appear in it.
- Ask for the statement of applicability, or at minimum the list of exclusions.
Seven questions to ask an AI vendor, beyond the logo
Picture the controller of an SME in Granby evaluating an AI tool to automate accounts payable. The salesperson proudly displays the ISO 27001 logo. Fine: that is a good starting point. But the invoices contain names, contact details, payment terms, sometimes banking information. What matters for Law 25 and for commercial confidentiality is settled in the answers to the following questions, and those answers have to be in writing.
- Where does our data physically reside, and in what jurisdiction are your company and its parent incorporated?
- Is our data used, directly or indirectly, to train or fine-tune your AI models? Can you exclude that in writing in the contract?
- What exactly is the scope of your ISO 27001 certificate, and is the service we are buying part of it?
- Which subcontractors are in the chain (host, model provider, analytics tool), and are they covered by your undertakings?
- In the event of a confidentiality incident, how quickly do you notify us, and in what detail? Law 25 obliges us to act promptly.
- Do you accept the contractual clauses required by section 18.3 of Law 25, and do you provide the information we need for our transfer assessment under section 17?
- What becomes of our data at the end of the contract: deletion timelines, return format, reversibility?
An ISO 27001 logo opens the conversation. Written answers, attached to the contract, are what close it.
ISO/IEC 42001: the management standard specific to AI
ISO 27001 governs information security in general. For the questions specific to artificial intelligence, a sister standard has recently appeared: ISO/IEC 42001:2023, the first certifiable AI management system standard. Its structure resembles that of ISO 27001, but its subject differs: governance of AI systems, impact assessments, model lifecycle management, transparency towards the people concerned and human oversight.
Its requirements overlap a good part of the obligations in the European AI Act, which makes it a useful reference point for companies that export or that deal with European partners. In Quebec it is not mandatory. And since the standard is recent, certified organizations remain rare: marketing claims often run ahead of certificates. The checks in the previous section apply in full.
For transparency: at Cogio we document our deployments in line with ISO/IEC 42001, through a timestamped evidence register, an audit log and compliance files, without claiming a certification we do not hold. The distinction we invite you to demand of your vendors, we apply to ourselves first.
2023
the year ISO/IEC 42001 was published, the first AI management system standard
Assessing your next vendor: the concrete approach
Treat the ISO 27001 certificate as an entry filter, never as a conclusion. The full sequence comes down to four moves: verify the certificate and its scope, ask the seven questions in writing, file the answers and the contract in your processor register, then run the assessment section 17 requires if personal information leaves Quebec. And if the new tool processes personal information, a privacy impact assessment is required before deployment (s. 3.3). Our guide to Law 25 compliance sets out each of those obligations.
That diligence takes a few hours per vendor. It is little compared with the cost of an unassessed disclosure of personal information outside Quebec, or a contract with no no-training clause. If you are currently evaluating an AI tool and want an outside eye on the certificates, the contracts and the proposed architecture, our approach starts with exactly that kind of audit. Tell us about your project. And whether you work with us or not: ask for the certificate, read the scope, get the undertakings in writing.
Frequently asked questions
Is ISO 27001 certification mandatory for Quebec businesses?
No. No Quebec law requires ISO 27001, either of you or of your vendors. Law 25 does require reasonable security measures and contractual governance of processors (s. 18.3). Certification is a recognized way of demonstrating that rigour, not a legal obligation.
What is the difference between ISO 27001 and SOC 2?
ISO 27001 certifies a security management system, issued by an accredited body on a three-year cycle. SOC 2 is an attestation report produced against the AICPA’s trust services criteria; Type II assesses how effectively the controls actually operated over a given period, generally 3 to 12 months. The two complement each other: one attests the management system, the other describes how the controls were observed to work.
Is an ISO 27001 certified vendor automatically Law 25 compliant?
No. The certificate attests neither data residency, nor the contractual clauses required by section 18.3, nor the prior assessment for a disclosure outside Quebec under section 17. Those obligations fall on you as the client business, whatever the vendor’s pedigree.
How do we know an ISO 27001 certificate is genuine?
Ask for a copy of the certificate and check four things: the certification body and its accreditation by an IAF member (in Canada, the Standards Council of Canada), the validity dates, the version of the standard and the scope statement. The public IAF CertSearch directory confirms a great many certificates online.
What is “aligned with ISO 27001” worth without certification?
It is a self-declaration no independent third party has verified. It may reflect real effort, but it proves nothing on its own. Ask instead for other verifiable material: a recent SOC 2 Type II report, penetration test results or the security policies themselves, and treat the claim as an aim rather than evidence.
Should we require ISO/IEC 42001 of our AI vendors?
Not yet as a knock-out criterion: the standard dates from 2023 and certified organizations remain rare. Ask instead for the practices it codifies: documented AI governance, impact assessments, an audit log and written undertakings on the use of your data. A claim of ISO 42001 compliance without a certificate is verified like any other self-declaration.
Sources and references
This article is a plain-language summary, accurate as of the date shown. It is not legal advice: for your own situation, consult a legal adviser or contact the Commission d’accès à l’information.
Read next
Security
SOC 2 Type II: reading a vendor report without being sold a story
Read →
Sovereignty
CLOUD Act: why a server in Montreal is not always sovereign
Read →
Compliance
Law 25: the complete compliance guide for Quebec businesses
Read →
A question about your own compliance?
The discovery call is free and takes half an hour. You leave with an honest read on your situation.
Let’s talk