What ISO 27001 Actually Means When You Offshore Your Data

Most providers say they take security seriously. Certification is the part you can check. Here is what ISO 27001:2022 covers, what it does not, and how to verify any provider's claim in five minutes.

Monitored operations floor at the PCS certified site in Suva, Fiji
The PCS operations floor in Suva. Physical controls sit inside the certified scope alongside the technological ones.

By Sahil Chand, Chief Operating Officer at Proficient Customer Solutions (PCS)

What ISO 27001 is

ISO/IEC 27001 is the international standard for an Information Security Management System. It certifies that an organisation runs a documented, audited system for managing information risk, rather than a collection of good intentions. The current version is ISO/IEC 27001:2022, and it is the version a certificate should name.

The distinction that matters to a buyer is this: ISO 27001 does not certify that a company is secure. It certifies that the company has a system for staying secure, and that an accredited third party has tested that system and will keep testing it every year.

What the certificate actually covers

The 2022 revision sets out 93 controls across four themes. A certified organisation does not implement all 93 blindly. It assesses which apply, documents the reasoning in a Statement of Applicability, and is audited against that.

ThemeControlsWhat it covers in practice
Organisational37Policies, supplier relationships, incident management, continuity, and how information risk is owned and governed.
People8Screening before hire, terms of employment, confidentiality agreements, training, and what happens when someone leaves.
Physical14Secure areas, entry control, equipment siting, clear desk and clear screen, and secure disposal.
Technological34Access control, encryption, logging and monitoring, secure configuration, and data leakage prevention.

For an outsourcing engagement the People and Physical themes are the ones most buyers underrate. They are the difference between a team in a controlled centre and a team working from home on personal laptops.

How to verify a provider's certificate in five minutes

Any provider can write "ISO 27001 certified" on a website. Very few buyers check. The check takes five minutes and it is the single most useful thing you can do in a procurement process.

  1. Ask for the certificate of registration, not a logo. A real certificate names the legal entity, the certificate number, the standard and version, the issue and expiry dates, and the certification body.
  2. Check the legal entity matches who you are contracting with. A group company being certified is not the same as the entity that will hold your data. Look at the name on the certificate against the name on the contract.
  3. Read the scope statement. Scope is where certificates are narrowest and buyers are least attentive. A certificate scoped to one office or one service line does not cover work delivered elsewhere.
  4. Confirm the accreditation, not just the certifier. The certification body should itself be accredited by a member of the International Accreditation Forum. An unaccredited certificate is a document, not an assurance.
  5. Check the dates and the surveillance cycle. Certification runs three years with annual surveillance audits in between. A certificate inside its date range but with a missed surveillance audit can be suspended.

If a provider hesitates at any of those five, you have learned something more useful than the certificate would have told you.

Where PCS sits

PCS is certified to ISO/IEC 27001:2022. We publish the detail so it can be checked rather than taken on trust.

  • Legal entity: Proficient Customer Solutions (Fiji) Pte Ltd
  • Certificate number: 250208056701
  • Certification body: TNV System Certification, accredited by International Accreditation Services (IAS), an IAF MLA signatory
  • Certified site: Unit 18A, Floor 1, Garden City, Raiwai, Suva, Fiji
  • Valid: 8 February 2025 to 7 February 2028, with annual surveillance audits
  • Scope: management of information security for outsourced data management services, including sales and marketing, customer support and journey management, payroll, finances, specialised technical support and back-office processing

The certification was covered by The Fiji Times and fijivillage in August 2025.

According to Josefa Wivou, Executive Director of Outsource Fiji, speaking to The Fiji Times in August 2025: “Fiji is proving itself to be a safe, secure and ethical outsourcing destination.”

Our founder and director Yogesh Chand put the internal view more plainly: “We didn’t just implement controls; we changed the way we think and work. Security is now part of our DNA.”

How it maps to NZ and Australian privacy law

Certification is not a substitute for your own legal obligations. It is evidence you can point to when discharging them.

New Zealand: Privacy Act 2020, IPP 12

Information Privacy Principle 12 governs disclosing personal information overseas. You may do so where the receiving agency is subject to comparable safeguards. A certified information security management system, combined with contractual data-handling terms, is the practical way most New Zealand businesses evidence that.

Australia: Australian Privacy Principles, APP 8

APP 8 covers cross-border disclosure, and the disclosing entity generally remains accountable for how the overseas recipient handles the data. It must take reasonable steps to ensure compliance. Certified controls plus contractual provisions are how that responsibility is discharged in practice.

In both cases the obligation stays with you. What certification does is make the reasonable-steps argument short and documented instead of long and subjective. For the full detail, see data security and compliance.

Three things certification does not tell you

  • It does not tell you where your data physically sits. Ask which systems are used, whether anything is stored locally on devices, and who holds administrative access.
  • It does not tell you who works on your account. Ask whether people are employed by the provider or subcontracted, and whether anyone works from home.
  • It does not tell you what happens when something goes wrong. Ask for the incident response process, the notification timeframe, and who calls you.

Those three questions, asked alongside a verified certificate, will tell you more about an offshore provider than any capability deck.

The short version

ISO 27001:2022 certification means an accredited third party has audited a provider's information security management system and will re-audit it annually. It is checkable, it is specific, and it is the one security claim in outsourcing that does not rest on trust. Ask for the certificate, read the scope, check the dates, and confirm the accreditation. Five minutes.

Frequently asked questions

Is ISO 27001 the same as being GDPR or Privacy Act compliant?

No. ISO 27001 certifies an information security management system. Privacy law compliance is a separate legal obligation that stays with you as the disclosing party. Certification is strong evidence of the reasonable steps those laws require, not a substitute for them.

What is the difference between ISO 27001:2013 and ISO 27001:2022?

The 2022 revision restructured the control set from 114 controls in 14 groups to 93 controls in four themes, and added controls covering threat intelligence, cloud services, data leakage prevention and secure coding. A certificate should name the 2022 version.

How long does an ISO 27001 certificate last?

Three years, with annual surveillance audits in between and a full recertification audit at the end of the cycle. A certificate within its date range can still be suspended if a surveillance audit is missed, so check the surveillance cycle as well as the expiry date.

Can I outsource to Fiji and stay compliant with Australian privacy law?

Generally yes. APP 8 permits cross-border disclosure where you take reasonable steps to ensure the overseas recipient handles the information consistently with the Australian Privacy Principles. Certified security controls and contractual data-handling provisions are how that is normally evidenced.

How do I verify a provider's ISO 27001 certificate?

Ask for the certificate of registration, check the legal entity matches your contracting party, read the scope statement, confirm the certification body is accredited by an International Accreditation Forum member, and check the issue, expiry and surveillance dates.

Send Us Your Security Questionnaire

See what it's like to have your offshore team working the same hours as you.

Get in Touch → Book a Call
Book a Call