ISO 27001 Explained for Thai Companies
ISO 27001 certifies that you run a documented, evidenced information security management system — not that you own any particular technology. Expect nine to fifteen months. It overlaps heavily with PDPA on controls, so run them as one programme, but certification alone does not make you PDPA compliant.
ISO 27001 is the international standard for information security management. For Thai companies serving enterprise or overseas clients, certification has shifted from differentiator to entry requirement — it appears in tender documents, in procurement questionnaires, and increasingly in the security reviews that precede any significant B2B contract.
It is also widely misunderstood as a technology purchase. It is not. Understanding what it actually asks of you is the difference between a twelve-month project and a three-year one.
What is ISO 27001?
ISO 27001 is a certifiable standard for running an Information Security Management System — a documented set of policies, risk assessments, controls and review cycles. It certifies that you manage information security systematically and can evidence it, not that you own any particular technology.
The current version is ISO/IEC 27001:2022, which reorganised the Annex A controls into four themes — organisational, people, physical and technological — reducing them from 114 to 93. Organisations certified against the 2013 version were required to transition, so any guidance you find referring to 114 controls is out of date.
The certificate is issued by an accredited certification body after a two-stage audit, and remains valid for three years with annual surveillance audits in between. It is an ongoing commitment, not a one-time achievement.
What does certification actually involve?
Five phases: define the scope, run a risk assessment, select and implement controls, operate the system long enough to generate evidence, then pass a two-stage external audit. For a mid-sized Thai company starting from a reasonable baseline, expect 9–15 months.
Scope is the decision that most affects cost, and the one most often rushed. You may certify the whole organisation or a defined part of it — a particular service, site or business unit. A narrower scope is faster and cheaper, but if clients expect the certificate to cover the service they buy, a narrow scope that excludes it is worthless. Decide scope by asking what your clients will actually ask for.
The evidence requirement is what catches people out. Auditors do not assess whether you have policies; they assess whether you have been operating them. You cannot compress this — a risk register created the week before the audit demonstrates nothing. Budget for several months of genuinely running the system before Stage 2.
| Phase | What happens | Typical duration |
|---|---|---|
| Scoping and gap analysis | Define boundary, compare current state to the standard | 4–6 weeks |
| Risk assessment | Identify assets, threats, and treatment decisions | 4–8 weeks |
| Control implementation | Close the gaps; write policies people will actually follow | 3–6 months |
| Operate and evidence | Run the ISMS, generate records, internal audit, management review | 3–6 months |
| Stage 1 audit | Auditor reviews documentation and readiness | 1–2 days |
| Stage 2 audit | Auditor tests whether the system operates as documented | 3–5 days |
| Surveillance | Annual audits; recertification every three years | Ongoing |
Why Thai companies pursue it
Three reasons, in order of how often they are the real driver: a client or tender requires it, it shortens enterprise security reviews from months to weeks, and the discipline genuinely reduces incidents. The first reason accounts for most certifications, and that is a legitimate motive.
For Thai companies selling into Japan, Singapore, the EU or to multinational subsidiaries locally, ISO 27001 frequently functions as a procurement filter — not because buyers have audited what it means, but because it is the accepted shorthand for "this vendor has thought about security". Being filtered out before a conversation starts is a hard commercial problem to solve any other way.
The second benefit is underrated. Enterprise clients run vendor security assessments regardless, and a certificate plus a Statement of Applicability answers most of a questionnaire in one document. Companies often find the sales-cycle reduction more valuable than the certificate itself.
How ISO 27001 relates to the PDPA
PDPA is Thai law and is mandatory; ISO 27001 is a voluntary international framework. They overlap heavily — access control, encryption, logging, incident response and supplier management satisfy both — so running them as one programme is substantially cheaper than treating them as two.
The key distinction: ISO 27001 protects information generally, while the PDPA protects personal data specifically and grants rights to the individuals it belongs to. ISO 27001 certification does not make you PDPA compliant, because the PDPA also requires things the standard does not address — lawful basis for processing, consent records, and the ability to honour data-subject requests within 30 days.
The efficient sequence for most Thai companies is PDPA first, since it is legally required, then ISO 27001 on top — by the time you have completed PDPA technical work you will have done the data inventory, access review and incident-response planning that ISO 27001 also demands. Doing it in the other order works but duplicates effort.
| PDPA | ISO 27001 | |
|---|---|---|
| Status | Mandatory Thai law | Voluntary international standard |
| Protects | Personal data specifically | All information assets |
| Enforced by | PDPC, with fines and liability | Certification body, via audit |
| Grants individual rights | Yes — access, erasure, portability | No |
| Requires certification | No | Yes, if you want the certificate |
| Shared ground | Access control, encryption, logging, incident response, supplier management |
What it costs, and the common mistakes
Budget for three separate costs: internal time (the largest and most often ignored), consultancy if you use it, and the certification body's audit fees. The most expensive mistake is treating it as a documentation exercise and discovering at Stage 2 that nothing is actually operating.
The failure mode we see most often is buying a set of template policies, filing them, and assuming the work is done. Auditors test operation, not existence. A policy nobody follows is a finding, and a shelf of them is a failed audit.
The second most common is over-scoping — certifying the entire organisation when clients only ever asked about one service. Scope creep here multiplies every subsequent cost, and it is very difficult to narrow later without re-auditing.
Sources
Need help with this?
Cybersecurity services