ISO Aligned vs ISO 27001 Certified: Why the Difference Matters

Monday, 20 July 2026, 5:09 pm

ISO Aligned vs ISO 27001 Certified
BlogVoting

Security has become one of the biggest considerations when organisations choose an online voting provider.

Boards, strata managers, unions, member-based organisations and listed companies all handle sensitive information during elections and ballots. It’s only natural that decision-makers want reassurance that their provider takes information security seriously.

That’s where ISO/IEC 27001 often enters the conversation.

You’ll commonly see businesses describe themselves as “ISO aligned”, “built around ISO 27001”, or “following ISO best practice.” While these statements may be genuine, they are not the same as being ISO/IEC 27001 certified.

Understanding the distinction can help you make more informed procurement decisions and avoid being misled by marketing language.

What is ISO/IEC 27001?

ISO/IEC 27001 is the internationally recognised standard for establishing, implementing, maintaining and continually improving an Information Security Management System (ISMS).

Rather than prescribing a single set of security controls, the standard provides a structured framework for managing information security risks across an organisation.

It covers areas such as:

Risk assessment
Information security policies
Access management
Incident response
Supplier management
Staff awareness and training
Business continuity
Continuous improvement

The current edition is ISO/IEC 27001:2022.

What does “ISO aligned” actually mean?

Being ISO aligned generally means an organisation has chosen to implement some or many of the practices described in ISO/IEC 27001.

For example, they may have:

documented security policies
implemented risk management processes
introduced access controls
adopted internal security procedures

These are all positive steps.

However, there is no formal definition or independent verification of the phrase “ISO aligned”.

An organisation determines for itself how closely it aligns with the standard.

That means two companies making the same claim could have very different levels of maturity.

One may have implemented nearly every requirement.

Another may simply have adopted a handful of recommended practices.

Without independent assessment, customers have no objective way of knowing.

What does ISO/IEC 27001 certified mean?

Certification is very different.

An organisation that is ISO/IEC 27001 certified has undergone an independent audit conducted by an accredited certification body.

Certification involves much more than implementing technical controls.

Auditors assess whether the organisation has established an effective Information Security Management System that satisfies the requirements of ISO/IEC 27001.

The certification process typically includes:

Stage 1 audit
Auditors review documented policies, procedures and readiness.

Stage 2 audit
Auditors examine whether the Information Security Management System operates effectively in practice. This includes reviewing evidence, interviewing personnel and testing processes.

Ongoing surveillance audits
Certification isn’t permanent. Certified organisations undergo regular surveillance audits and periodic recertification to demonstrate continued compliance and continual improvement.

Why independent certification matters

Independent certification provides confidence that security claims have been tested by an external party rather than assessed internally.

For organisations responsible for confidential member information or commercially sensitive voting data, this independent verification can significantly reduce procurement risk.

It demonstrates that security practices have been examined against an internationally recognised standard using a structured audit process.

That doesn’t mean certification guarantees perfect security—no certification can do that.

But it does provide a much higher level of assurance than unverified marketing claims.

Common misconceptions

“ISO aligned means the same thing.”
It doesn’t. Alignment describes an internal position. Certification confirms successful independent assessment.

“We follow ISO principles.”
Many organisations do. Following good practices is valuable, but unless an accredited certification body has certified the Information Security Management System, the organisation should not represent itself as ISO/IEC 27001 certified.

“Certification is just paperwork.”
Not at all. ISO/IEC 27001 requires organisations to demonstrate that security processes operate effectively and continue to improve over time. The focus extends well beyond documentation.

Questions to ask any online voting provider

When evaluating suppliers, don’t stop at broad security statements.

Instead, ask questions such as:

Are you ISO/IEC 27001 certified?
Which certification body issued the certificate?
What is the scope of the certification?
Is the certification current?
Does it cover the systems delivering your online voting services?
How often are surveillance audits conducted?

These questions provide a much clearer picture than simply asking whether a provider is “ISO aligned.”

Why this matters for online voting

Online voting platforms process information that often includes:

member details
voter authentication data
election records
ballot information
governance documents
audit logs

Organisations understandably expect these systems to operate securely.

While certification alone shouldn’t be the only selection criterion, it provides valuable independent assurance that recognised information security management practices are in place.

This is particularly important where elections involve directors, shareholders, enterprise agreements, unions, professional associations or strata communities.

How Vero Voting approaches information security

Security underpins every election.

Vero Voting recognises that organisations entrust voting providers with highly sensitive governance information and expects that responsibility to be treated seriously.

As part of that commitment, Vero Voting has invested in recognised information security practices and independent assurance appropriate to its services. When evaluating any voting provider, organisations should look beyond broad claims such as “ISO aligned” and instead seek clear evidence of independently verified security controls, governance processes and ongoing compliance.

Making informed decisions helps reduce organisational risk and strengthens confidence in every election.

Key takeaways

The distinction is straightforward.

ISO aligned means an organisation believes its practices reflect the principles of ISO/IEC 27001.

ISO/IEC 27001 certified means an independent accredited certification body has verified that the organisation’s Information Security Management System meets the requirements of the international standard.

For organisations selecting an online voting provider, that distinction matters.

Independent certification provides greater transparency, stronger assurance and increased confidence that information security claims have been independently assessed rather than simply self-declared.

Need help delivering secure online voting?

If your organisation is planning an AGM, election, ballot or member vote and you’d like to learn more about secure online voting, contact Vero Voting to discuss your requirements or request a demonstration. Our team can explain the security measures, governance processes and voting controls that support reliable, transparent elections.

Sources

ISO – ISO/IEC 27001 Information security management: https://www.iso.org/isoiec-27001-information-security.html
Standards Australia – Information security standards: https://www.standards.org.au
Joint Accreditation System of Australia and New Zealand (JAS-ANZ): https://www.jas-anz.org
International Accreditation Forum (IAF): https://iaf.nu
Australian Cyber Security Centre (ACSC): https://www.cyber.gov.au

Frequently Asked Questions

Is ISO aligned the same as ISO 27001 certified?

No. “ISO aligned” generally means an organisation has implemented some or all of the practices described in ISO/IEC 27001. ISO/IEC 27001 certification means an accredited certification body has independently audited and certified the organisation’s Information Security Management System.

Can a company say it follows ISO 27001 without being certified?

Yes. An organisation may adopt ISO/IEC 27001 principles without seeking certification. However, it should not describe itself as ISO/IEC 27001 certified unless it has successfully completed independent certification.

How can I verify whether a company is ISO 27001 certified?

Ask to see the current certificate, confirm the certification body, review the certification scope and ensure the certificate is still valid.

Why is ISO 27001 certification important for online voting?

Online voting systems handle confidential information and sensitive election data. Independent ISO/IEC 27001 certification provides additional assurance that information security management has been assessed against an internationally recognised standard.

Need support with your next Voting?

Contact Us

Subscribe to our blog

Stay up to date on the latest topics for voting solutions

[stc-subscribe]



    Subscribe

    If you want to personalise your subscription, click here