ComplianceISO 27001Governance

ISO 27001 for banks: what certification actually requires

Md. Tawfiqul Bari
6 min read · Last reviewed August 9, 2026

ISO/IEC 27001 is the international standard for an information security management system, or ISMS. For a bank it has moved from a nice-to-have to something regulators, partners, and large customers increasingly expect to see. But there is a persistent misconception about what certification actually means. It is not a product you install or a box you tick. This is what the standard asks for, and what an auditor is really looking for.

It is a management system, not a checklist

The heart of ISO 27001 is not a list of controls; it is a risk-based management system. You define the scope of what you are protecting, assess the risks to it, decide how to treat each risk, and then run the whole thing as a repeating cycle of plan, do, check, and act. The controls come after the risk assessment, chosen because a risk justified them, not because a checklist demanded them. That is why two certified banks can look quite different: each built its ISMS around its own risks.

The Annex A controls, in four themes

The 2022 revision of the standard groups its reference controls into four themes: organizational, people, physical, and technological. Organizational controls cover policies, roles, supplier relationships, and incident management. People controls cover screening, awareness, and responsibilities. Physical controls cover facilities and equipment. Technological controls cover the parts most engineers think of first: access control, cryptography, logging and monitoring, secure development, and data protection. You are not required to implement every control; you are required to justify, in a document called the Statement of Applicability, which ones apply and why.

What the certification process looks like

Certification is performed by an accredited third party, not self-declared. It usually runs in two stages. A stage 1 audit reviews your ISMS documentation and readiness. A stage 2 audit tests whether the system is actually operating as described, with evidence. Once certified you are not finished: surveillance audits recur, typically each year, and the full certificate runs on a three-year cycle before recertification. The point of the surveillance model is that security is continuous, so the evidence has to be too.

Where your databases come in

Several of the technological controls land squarely on the data layer. Access to information has to be restricted and reviewed, with privileged access getting particular attention. Logging has to capture the security-relevant events, and the logs themselves have to be protected against tampering. Cryptography and data classification decide how sensitive data is handled. In practice, the database is where a large share of an auditor’s questions end up, because it is where the regulated data lives.

ISO 27001 is not SOC 2

It is worth clearing up a common confusion. ISO 27001 and SOC 2 are different things: ISO 27001 certifies a management system against an international standard, while a SOC 2 report is an attestation produced under a United States auditing standard. They overlap in spirit but are not interchangeable, and holding one does not grant the other. Vigilus Labs Incorporated holds ISO/IEC 27001:2022 and ISO 9001:2015. We do not hold SOC 2, and we are careful never to imply otherwise.

Building for the ISMS, not around it

We went through the certification process ourselves, which is part of why our products are built to produce the evidence an ISMS needs: access is governed and recorded, audit trails are tamper-evident, and reports map activity to the control families an auditor asks about. If you are building or maintaining an ISMS for a regulated database estate, that is the gap we set out to close. Our current certificates, numbers, and accreditation chain are published on our certifications page.

Written by

Md. Tawfiqul Bari

Md. Tawfiqul Bari

Founder & CEO, Vigilus Labs Incorporated

Md. Tawfiqul Bari is the founder and CEO of Vigilus Labs Incorporated, with a career spanning cybersecurity, cloud infrastructure, and enterprise security.

LinkedIn profile

See it against your own database estate.

Request a demo