Most providers say they take security seriously. Certification is the part you can check. Here is what ISO 27001:2022 covers, what it does not, and how to verify any provider's claim in five minutes.

By Sahil Chand, Chief Operating Officer at Proficient Customer Solutions (PCS)
ISO/IEC 27001 is the international standard for an Information Security Management System. It certifies that an organisation runs a documented, audited system for managing information risk, rather than a collection of good intentions. The current version is ISO/IEC 27001:2022, and it is the version a certificate should name.
The distinction that matters to a buyer is this: ISO 27001 does not certify that a company is secure. It certifies that the company has a system for staying secure, and that an accredited third party has tested that system and will keep testing it every year.
The 2022 revision sets out 93 controls across four themes. A certified organisation does not implement all 93 blindly. It assesses which apply, documents the reasoning in a Statement of Applicability, and is audited against that.
| Theme | Controls | What it covers in practice |
|---|---|---|
| Organisational | 37 | Policies, supplier relationships, incident management, continuity, and how information risk is owned and governed. |
| People | 8 | Screening before hire, terms of employment, confidentiality agreements, training, and what happens when someone leaves. |
| Physical | 14 | Secure areas, entry control, equipment siting, clear desk and clear screen, and secure disposal. |
| Technological | 34 | Access control, encryption, logging and monitoring, secure configuration, and data leakage prevention. |
For an outsourcing engagement the People and Physical themes are the ones most buyers underrate. They are the difference between a team in a controlled centre and a team working from home on personal laptops.
Any provider can write "ISO 27001 certified" on a website. Very few buyers check. The check takes five minutes and it is the single most useful thing you can do in a procurement process.
If a provider hesitates at any of those five, you have learned something more useful than the certificate would have told you.
PCS is certified to ISO/IEC 27001:2022. We publish the detail so it can be checked rather than taken on trust.
The certification was covered by The Fiji Times and fijivillage in August 2025.
According to Josefa Wivou, Executive Director of Outsource Fiji, speaking to The Fiji Times in August 2025: “Fiji is proving itself to be a safe, secure and ethical outsourcing destination.”
Our founder and director Yogesh Chand put the internal view more plainly: “We didn’t just implement controls; we changed the way we think and work. Security is now part of our DNA.”
Certification is not a substitute for your own legal obligations. It is evidence you can point to when discharging them.
Information Privacy Principle 12 governs disclosing personal information overseas. You may do so where the receiving agency is subject to comparable safeguards. A certified information security management system, combined with contractual data-handling terms, is the practical way most New Zealand businesses evidence that.
APP 8 covers cross-border disclosure, and the disclosing entity generally remains accountable for how the overseas recipient handles the data. It must take reasonable steps to ensure compliance. Certified controls plus contractual provisions are how that responsibility is discharged in practice.
In both cases the obligation stays with you. What certification does is make the reasonable-steps argument short and documented instead of long and subjective. For the full detail, see data security and compliance.
Those three questions, asked alongside a verified certificate, will tell you more about an offshore provider than any capability deck.
ISO 27001:2022 certification means an accredited third party has audited a provider's information security management system and will re-audit it annually. It is checkable, it is specific, and it is the one security claim in outsourcing that does not rest on trust. Ask for the certificate, read the scope, check the dates, and confirm the accreditation. Five minutes.
No. ISO 27001 certifies an information security management system. Privacy law compliance is a separate legal obligation that stays with you as the disclosing party. Certification is strong evidence of the reasonable steps those laws require, not a substitute for them.
The 2022 revision restructured the control set from 114 controls in 14 groups to 93 controls in four themes, and added controls covering threat intelligence, cloud services, data leakage prevention and secure coding. A certificate should name the 2022 version.
Three years, with annual surveillance audits in between and a full recertification audit at the end of the cycle. A certificate within its date range can still be suspended if a surveillance audit is missed, so check the surveillance cycle as well as the expiry date.
Generally yes. APP 8 permits cross-border disclosure where you take reasonable steps to ensure the overseas recipient handles the information consistently with the Australian Privacy Principles. Certified security controls and contractual data-handling provisions are how that is normally evidenced.
Ask for the certificate of registration, check the legal entity matches your contracting party, read the scope statement, confirm the certification body is accredited by an International Accreditation Forum member, and check the issue, expiry and surveillance dates.
See what it's like to have your offshore team working the same hours as you.
Get in Touch → Book a Call