Overview
ISO/IEC 27706:2025 defines requirements and guidance for bodies that audit and certify Privacy Information Management Systems (PIMS) in accordance with ISO/IEC 27701. It is intended to be used alongside ISO/IEC 17021-1 (requirements for certification bodies) and demonstrates how a certification body can show competence, impartiality and reliability when issuing PIMS certification. The document also serves as a criteria reference for accreditation, peer assessment or other audit processes.
Key topics and requirements
- Scope & principles – establishes the purpose of PIMS certification and high‑level principles required of certification bodies.
- General and structural requirements – legal, contractual and organizational expectations for impartiality, liability and financing.
- Resource & competence requirements – detailed expectations for personnel competence, auditor selection, use of external experts, and personnel records (Annex C outlines required knowledge and skills).
- Information requirements – public information, certification documentation, use of marks, confidentiality and secure exchange of client records.
- Process requirements – end‑to‑end certification lifecycle: pre‑certification (application and review), audit planning and time determination (Annex A/B provide audit time methods), initial certification audits, audit conduct and reporting, certification decision, surveillance and maintenance activities, appeals and complaints handling.
- Management system options – requirements for the certification body’s own management system (Option A) or alignment with ISO 9001 (Option B).
- Supporting annexes – normative and informative annexes on audit time calculations, methods and required auditor competencies.
Practical applications
- Accreditation bodies can use ISO/IEC 27706 as an assessment criterion for accrediting PIMS certification providers.
- Certification bodies adopt the standard to align processes, demonstrate auditor competence and maintain impartiality when certifying ISO/IEC 27701 implementations.
- Privacy auditors and technical experts use the guidance to structure audit programs, calculate audit time and define competence profiles.
- Organizations seeking PIMS certification benefit indirectly: certification bodies applying ISO/IEC 27706 offer more consistent, reliable audits that support privacy management and regulatory compliance efforts.
- Consultants and trainers reference the standard when preparing auditors or advising clients on readiness for PIMS certification.
Related standards
- ISO/IEC 27701 (Privacy information management)
- ISO/IEC 17021‑1 (Conformity assessment - requirements for certification bodies)
(Using ISO/IEC 27706 together with these standards delivers a harmonized framework for credible, consistent PIMS certification.)
Keywords: ISO/IEC 27706:2025, PIMS certification, privacy information management, certification body requirements, ISO/IEC 27701, ISO/IEC 17021-1, auditor competence, audit time, accreditation.