03

Technology and Data

On the software and data side, what decides is not the sector but which data you process, whether you provide a defined service to customers, and your role in the AI chain. For most technology companies several standards become candidates at once.

The questions we ask before producing a result

  1. Do you process customer data or personal data?
  2. Do you provide a cloud service, or only develop software?
  3. Do you carry SLA or service desk obligations?
  4. Do you develop, provide or use AI in high-impact contexts?
  5. How critical is a service interruption for your customer?

Candidate ISO standards 11

Most commonly confused in this field

ISO/IEC 27017 and 27018 are not standalone certificates

They are cloud security and personal data controls, not standalone Type A management system standards, although they are frequently marketed as separate certificates.

ISO 27001 does not mean data protection compliance

An information security management system does not substitute for KVKK or GDPR compliance or legal advice. ISO/IEC 27701 strengthens this side but is still not a legal compliance certificate.

Using AI is not a trigger on its own

A team using a chat tool does not create ISO/IEC 42001 candidacy. The developer, provider or high-impact user role is questioned.

Non-ISO programmes common in this field

These are not ISO standards; each has its own scheme owner, issuing body and rules. Whether they are candidates is decided by activity and buyer requirement.

  • Cloud and data centre customer audit programmes
  • Sector cyber security frameworks

Last verified:

This page is for information only; it is not legal advice. A record appearing here does not mean it is required for your business. This library does not issue certificates.

All industry guides