SCRM Supplier Compliance & Risk Management

Home

ISO/IEC 27701 · extension to ISO/IEC 27001

Who processes on whose instruction – and who sits behind them?

ISO/IEC 27701 turns an information security management system into a privacy management system. Clarifying roles along the chain is the most demanding part.

The standard extends ISO/IEC 27001 and 27002 with requirements and guidance on protecting personal data. It distinguishes consistently between the controller role and the processor role and requires distinct measures for each.

For the supply chain that is the decisive point. A provider is rarely only one of the two: they process on instruction, engage their own subcontractors and answer for choosing them. Without mapping that chain, neither the GDPR nor the Swiss FADP can be served cleanly.

Who this concerns

  • Providers processing personal data on instruction who must evidence it.
  • Companies holding ISO 27001 who want to cover privacy without building a second system.
  • Vendors whose customers ask for privacy evidence during procurement.
  • Groups with intra-group processing across borders.

What counts for the chain

Role clarity
Establish for each processing activity who is controller and who is processor.
Sub-processing
Govern, approve and document the use of further processors.
Instructions
Process only on documented instruction, with a traceable trail.
Data subject rights
Procedures that work when data sits with sub-processors.
Transfers
Document cross-border processing and its legal basis.

How SCRM covers it

Role per provider

Controller or processor as a field, not a matter of interpretation.

Sub-processors

Approved sub-processing visible, and so are changes.

Contracts with expiry

Processing agreements with validity and recall dates.

Processing locations

Site and jurisdiction as checked data.

Frequently asked

Does 27701 replace a GDPR assessment?

No. The standard structures the management system; legal assessment remains separate. It does make the evidence considerably easier.

Do we need ISO 27001 first?

Yes, 27701 presumes an existing ISMS and extends it.

What does it give Swiss companies?

The revised FADP requires you to satisfy yourself about a processor’s data security. A provider certificate is a strong, checkable argument for that.

Contact

Request a consultation

A few details is all we need. We reply within one working day with an honest read on whether SCRM fits your situation.

  • A free seven-day demo account on request
  • Reply within one working day
  • No newsletter, no sharing with third parties
  • An honest read, including when we are not the fit
What drives your supply chain monitoring? *

Select all that apply

How can we reach you? *

Either one of the two is enough.

No leading zero, e.g. 79 123 45 67

* Required