Compliance

ISO 27001 Explained for Thai Companies

By Kittipong SaengthongTechnical Director, NICH TECCISSP · ISO 27001 Lead Auditor · AWS Solutions Architect – ProfessionalLast updated

ISO 27001 certifies that you run a documented, evidenced information security management system — not that you own any particular technology. Expect nine to fifteen months. It overlaps heavily with PDPA on controls, so run them as one programme, but certification alone does not make you PDPA compliant.

ISO 27001 is the international standard for information security management. For Thai companies serving enterprise or overseas clients, certification has shifted from differentiator to entry requirement — it appears in tender documents, in procurement questionnaires, and increasingly in the security reviews that precede any significant B2B contract.

It is also widely misunderstood as a technology purchase. It is not. Understanding what it actually asks of you is the difference between a twelve-month project and a three-year one.

What is ISO 27001?

ISO 27001 is a certifiable standard for running an Information Security Management System — a documented set of policies, risk assessments, controls and review cycles. It certifies that you manage information security systematically and can evidence it, not that you own any particular technology.

The current version is ISO/IEC 27001:2022, which reorganised the Annex A controls into four themes — organisational, people, physical and technological — reducing them from 114 to 93. Organisations certified against the 2013 version were required to transition, so any guidance you find referring to 114 controls is out of date.

The certificate is issued by an accredited certification body after a two-stage audit, and remains valid for three years with annual surveillance audits in between. It is an ongoing commitment, not a one-time achievement.

What does certification actually involve?

Five phases: define the scope, run a risk assessment, select and implement controls, operate the system long enough to generate evidence, then pass a two-stage external audit. For a mid-sized Thai company starting from a reasonable baseline, expect 9–15 months.

Scope is the decision that most affects cost, and the one most often rushed. You may certify the whole organisation or a defined part of it — a particular service, site or business unit. A narrower scope is faster and cheaper, but if clients expect the certificate to cover the service they buy, a narrow scope that excludes it is worthless. Decide scope by asking what your clients will actually ask for.

The evidence requirement is what catches people out. Auditors do not assess whether you have policies; they assess whether you have been operating them. You cannot compress this — a risk register created the week before the audit demonstrates nothing. Budget for several months of genuinely running the system before Stage 2.

PhaseWhat happensTypical duration
Scoping and gap analysisDefine boundary, compare current state to the standard4–6 weeks
Risk assessmentIdentify assets, threats, and treatment decisions4–8 weeks
Control implementationClose the gaps; write policies people will actually follow3–6 months
Operate and evidenceRun the ISMS, generate records, internal audit, management review3–6 months
Stage 1 auditAuditor reviews documentation and readiness1–2 days
Stage 2 auditAuditor tests whether the system operates as documented3–5 days
SurveillanceAnnual audits; recertification every three yearsOngoing
Typical ISO 27001 certification path for a Thai mid-sized company.

Why Thai companies pursue it

Three reasons, in order of how often they are the real driver: a client or tender requires it, it shortens enterprise security reviews from months to weeks, and the discipline genuinely reduces incidents. The first reason accounts for most certifications, and that is a legitimate motive.

For Thai companies selling into Japan, Singapore, the EU or to multinational subsidiaries locally, ISO 27001 frequently functions as a procurement filter — not because buyers have audited what it means, but because it is the accepted shorthand for "this vendor has thought about security". Being filtered out before a conversation starts is a hard commercial problem to solve any other way.

The second benefit is underrated. Enterprise clients run vendor security assessments regardless, and a certificate plus a Statement of Applicability answers most of a questionnaire in one document. Companies often find the sales-cycle reduction more valuable than the certificate itself.

How ISO 27001 relates to the PDPA

PDPA is Thai law and is mandatory; ISO 27001 is a voluntary international framework. They overlap heavily — access control, encryption, logging, incident response and supplier management satisfy both — so running them as one programme is substantially cheaper than treating them as two.

The key distinction: ISO 27001 protects information generally, while the PDPA protects personal data specifically and grants rights to the individuals it belongs to. ISO 27001 certification does not make you PDPA compliant, because the PDPA also requires things the standard does not address — lawful basis for processing, consent records, and the ability to honour data-subject requests within 30 days.

The efficient sequence for most Thai companies is PDPA first, since it is legally required, then ISO 27001 on top — by the time you have completed PDPA technical work you will have done the data inventory, access review and incident-response planning that ISO 27001 also demands. Doing it in the other order works but duplicates effort.

PDPAISO 27001
StatusMandatory Thai lawVoluntary international standard
ProtectsPersonal data specificallyAll information assets
Enforced byPDPC, with fines and liabilityCertification body, via audit
Grants individual rightsYes — access, erasure, portabilityNo
Requires certificationNoYes, if you want the certificate
Shared groundAccess control, encryption, logging, incident response, supplier management

What it costs, and the common mistakes

Budget for three separate costs: internal time (the largest and most often ignored), consultancy if you use it, and the certification body's audit fees. The most expensive mistake is treating it as a documentation exercise and discovering at Stage 2 that nothing is actually operating.

The failure mode we see most often is buying a set of template policies, filing them, and assuming the work is done. Auditors test operation, not existence. A policy nobody follows is a finding, and a shelf of them is a failed audit.

The second most common is over-scoping — certifying the entire organisation when clients only ever asked about one service. Scope creep here multiplies every subsequent cost, and it is very difficult to narrow later without re-auditing.

Sources

Need help with this?

Cybersecurity services