Compliance auditISO/IEC 27701:2025
ISO/IEC 27701:2025 — Privacy information management (PIMS)
Requirements to establish, implement, maintain and improve a privacy information management system (PIMS), for controllers and processors of personally identifiable information.
- control points
- 59
- anchored clauses
- 24
- Clauses covered
- 8
Clauses covered
| Context of the organisation | 4 | 4.1 · 4.2 · 4.3 · 4.4 |
| Leadership | 3 | 5.1 · 5.2 · 5.3 |
| Planning | 4 | 6.1.2 · 6.1.3 · 6.2 · 6.3 |
| Support | 4 | 7.1 · 7.3 · 7.4 · 7.5 |
| Operation | 3 | 8.1 · 8.2 · 8.3 |
| Performance evaluation | 3 | 9.1 · 9.2 · 9.3 |
| Improvement | 2 | 10.1 · 10.2 |
| Privacy controls (PII controller / processor) | 8 | Annexe A |
Scale
CompliantOpportunity for improvementNon-compliantNot applicable
This template is used inside the platform: every finding becomes a corrective action tracked through to its evidence — something a printed grid cannot do.
Use this template14-day trial, no credit card. The template opens in your workspace.
How this grid is built
Every control point is written in our own words, then tied to the standard's clause number. The normative text is never reproduced: the standard itself remains to be purchased from the body that publishes it. Grids are reviewed at every new edition of a standard.
Published by NormePulse — HEMC, management consulting firmUpdated