ISO Aligned vs ISO 27001 Certified: Why the Difference Matters
Monday, 20 July 2026, 5:09 pm

Security has become one of the biggest considerations when organisations choose an online voting provider.
Boards, strata managers, unions, member-based organisations and listed companies all handle sensitive information during elections and ballots. It’s only natural that decision-makers want reassurance that their provider takes information security seriously.
That’s where ISO/IEC 27001 often enters the conversation.
You’ll commonly see businesses describe themselves as “ISO aligned”, “built around ISO 27001”, or “following ISO best practice.” While these statements may be genuine, they are not the same as being ISO/IEC 27001 certified.
Understanding the distinction can help you make more informed procurement decisions and avoid being misled by marketing language.
What is ISO/IEC 27001?
ISO/IEC 27001 is the internationally recognised standard for establishing, implementing, maintaining and continually improving an Information Security Management System (ISMS).
Rather than prescribing a single set of security controls, the standard provides a structured framework for managing information security risks across an organisation.
It covers areas such as:
The current edition is ISO/IEC 27001:2022.
What does “ISO aligned” actually mean?
Being ISO aligned generally means an organisation has chosen to implement some or many of the practices described in ISO/IEC 27001.
For example, they may have:
These are all positive steps.
However, there is no formal definition or independent verification of the phrase “ISO aligned”.
An organisation determines for itself how closely it aligns with the standard.
That means two companies making the same claim could have very different levels of maturity.
One may have implemented nearly every requirement.
Another may simply have adopted a handful of recommended practices.
Without independent assessment, customers have no objective way of knowing.
What does ISO/IEC 27001 certified mean?
Certification is very different.
An organisation that is ISO/IEC 27001 certified has undergone an independent audit conducted by an accredited certification body.
Certification involves much more than implementing technical controls.
Auditors assess whether the organisation has established an effective Information Security Management System that satisfies the requirements of ISO/IEC 27001.
The certification process typically includes:
Stage 1 audit
Auditors review documented policies, procedures and readiness.
Stage 2 audit
Auditors examine whether the Information Security Management System operates effectively in practice. This includes reviewing evidence, interviewing personnel and testing processes.
Ongoing surveillance audits
Certification isn’t permanent. Certified organisations undergo regular surveillance audits and periodic recertification to demonstrate continued compliance and continual improvement.
Why independent certification matters
Independent certification provides confidence that security claims have been tested by an external party rather than assessed internally.
For organisations responsible for confidential member information or commercially sensitive voting data, this independent verification can significantly reduce procurement risk.
It demonstrates that security practices have been examined against an internationally recognised standard using a structured audit process.
That doesn’t mean certification guarantees perfect security—no certification can do that.
But it does provide a much higher level of assurance than unverified marketing claims.
Common misconceptions
“ISO aligned means the same thing.”
It doesn’t. Alignment describes an internal position. Certification confirms successful independent assessment.
“We follow ISO principles.”
Many organisations do. Following good practices is valuable, but unless an accredited certification body has certified the Information Security Management System, the organisation should not represent itself as ISO/IEC 27001 certified.
“Certification is just paperwork.”
Not at all. ISO/IEC 27001 requires organisations to demonstrate that security processes operate effectively and continue to improve over time. The focus extends well beyond documentation.
Questions to ask any online voting provider
When evaluating suppliers, don’t stop at broad security statements.
Instead, ask questions such as:
These questions provide a much clearer picture than simply asking whether a provider is “ISO aligned.”
Why this matters for online voting
Online voting platforms process information that often includes:
Organisations understandably expect these systems to operate securely.
While certification alone shouldn’t be the only selection criterion, it provides valuable independent assurance that recognised information security management practices are in place.
This is particularly important where elections involve directors, shareholders, enterprise agreements, unions, professional associations or strata communities.
How Vero Voting approaches information security
Security underpins every election.
Vero Voting recognises that organisations entrust voting providers with highly sensitive governance information and expects that responsibility to be treated seriously.
As part of that commitment, Vero Voting has invested in recognised information security practices and independent assurance appropriate to its services. When evaluating any voting provider, organisations should look beyond broad claims such as “ISO aligned” and instead seek clear evidence of independently verified security controls, governance processes and ongoing compliance.
Making informed decisions helps reduce organisational risk and strengthens confidence in every election.
Key takeaways
The distinction is straightforward.
ISO aligned means an organisation believes its practices reflect the principles of ISO/IEC 27001.
ISO/IEC 27001 certified means an independent accredited certification body has verified that the organisation’s Information Security Management System meets the requirements of the international standard.
For organisations selecting an online voting provider, that distinction matters.
Independent certification provides greater transparency, stronger assurance and increased confidence that information security claims have been independently assessed rather than simply self-declared.
Need help delivering secure online voting?
If your organisation is planning an AGM, election, ballot or member vote and you’d like to learn more about secure online voting, contact Vero Voting to discuss your requirements or request a demonstration. Our team can explain the security measures, governance processes and voting controls that support reliable, transparent elections.
ISO Aligned vs ISO 27001 Certified
ISO Aligned vs ISO 27001 Certified
FAQ
Is ISO aligned the same as ISO 27001 certified?
No. “ISO aligned” generally means an organisation has implemented some or all of the practices described in ISO/IEC 27001. ISO/IEC 27001 certification means an accredited certification body has independently audited and certified the organisation’s Information Security Management System.
Can a company say it follows ISO 27001 without being certified?
Yes. An organisation may adopt ISO/IEC 27001 principles without seeking certification. However, it should not describe itself as ISO/IEC 27001 certified unless it has successfully completed independent certification.
How can I verify whether a company is ISO 27001 certified?
Ask to see the current certificate, confirm the certification body, review the certification scope and ensure the certificate is still valid.
Why is ISO 27001 certification important for online voting?
Online voting systems handle confidential information and sensitive election data. Independent ISO/IEC 27001 certification provides additional assurance that information security management has been assessed against an internationally recognised standard.
Sources
Frequently Asked Questions
Is ISO aligned the same as ISO 27001 certified?
No. “ISO aligned” generally means an organisation has implemented some or all of the practices described in ISO/IEC 27001. ISO/IEC 27001 certification means an accredited certification body has independently audited and certified the organisation’s Information Security Management System.
Can a company say it follows ISO 27001 without being certified?
Yes. An organisation may adopt ISO/IEC 27001 principles without seeking certification. However, it should not describe itself as ISO/IEC 27001 certified unless it has successfully completed independent certification.
How can I verify whether a company is ISO 27001 certified?
Ask to see the current certificate, confirm the certification body, review the certification scope and ensure the certificate is still valid.
Why is ISO 27001 certification important for online voting?
Online voting systems handle confidential information and sensitive election data. Independent ISO/IEC 27001 certification provides additional assurance that information security management has been assessed against an internationally recognised standard.


