Why ISO 27001 Matters When Choosing an AI Provider

If you entrust an AI provider with customer conversations, appointments and contact details, you need to know how carefully it handles information security. ISO 27001 is an important pointer when choosing an AI provider, but not a free pass. This article explains what is behind the standard, what a certificate does and doesn't tell you, and which questions you should ask a provider.
What ISO 27001 is
ISO/IEC 27001 is an international standard for information security management systems, or ISMS for short. It doesn't prescribe which firewall a company must use. Instead, it requires the company to identify, assess and treat its information risks systematically with suitable measures, to define who is responsible for what, and to review and improve the whole system regularly. The current version dates from 2022.
A company can have itself audited by an independent, accredited certification body. In Germany such bodies are accredited by DAkkS, the national accreditation body. After a successful audit a certificate is issued, which is usually valid for three years and must be confirmed every year through surveillance audits.
Why ISO 27001 matters especially for AI providers
AI assistants that deal with customers often process precisely the data that most needs protecting. In a medical practice, a caller may give the reason for wanting an appointment. In a law firm, a prospective client describes their legal problem on the phone. A beauty salon stores phone numbers and treatment histories. On top of that, AI providers often work with other service providers, such as hosting providers or language model providers. Each of these links is a potential weak point.
A working ISMS shows that the provider keeps an eye on this chain: who has access, how access is granted and withdrawn, what happens in a security incident, how sub-processors are selected and monitored. For professionals bound by confidentiality, such as doctors, lawyers and tax advisers, this is not optional. Professional law sets out the conditions under which they may bring in service providers, for lawyers for example § 43e BRAO (German Federal Lawyers' Act), and breaches of confidentiality can have criminal consequences.
What an ISO 27001 certificate does and doesn't tell you
| The certificate tells you | The certificate doesn't tell you |
|---|---|
| There is an audited management system for information security. | That the product you are buying falls within the audited area. Only the scope shows that. |
| Risks are assessed and treated systematically. | That no security incidents can occur. |
| An independent body has audited the system. | That data processing complies with the GDPR. That is a separate check. |
| The system is reviewed regularly. | That AI-specific risks such as incorrect answers are covered. |
The scope is what counts
The most important thing to check on a certificate is its scope. A company can, for example, have only its accounting or one particular data centre certified. Also check who holds the certificate. If a provider advertises that its hosting partner is ISO 27001 certified, that tells you something about the data centre, but nothing about the provider's own processes.
Additional evidence
Depending on the industry, there is other evidence too. For cloud services, the C5 criteria catalogue of the BSI (German Federal Office for Information Security) is widely used in Germany; in the automotive industry it's TISAX. Specifically for AI, ISO/IEC 42001 is a standard for AI management systems. None of these replaces the others; each looks at different aspects.
Checklist: questions for your AI provider
- Do you hold an ISO 27001 certificate, and if not, is one in preparation? If so, when is the audit planned?
- What scope is covered, and is the product we want to use part of it? Can we see the certificate and the statement of applicability?
- Where is our data stored and processed, including processing by the language model?
- Which sub-processors do you use, and how will we be told about changes?
- How long is conversation content stored, and can we set the retention periods ourselves?
- Is our data used to train models?
- How, and how quickly, will you inform us of a security incident?
- Do you provide a data processing agreement under Art. 28 GDPR, and does it take into account the requirements for professionals bound by confidentiality?
You'll find further selection criteria in our checklist for evaluating AI providers. The article on EU and US data hosting explains why the storage location matters so much.
When a provider doesn't have a certificate (yet)
Many smaller and younger providers don't yet have an ISO 27001 certificate. That isn't automatically a reason to rule them out. Certification usually takes a while, and a provider can work carefully without one. What matters then is how openly it deals with your questions. A provider that documents its technical and organisational measures in writing, names the storage location clearly and presents a proper data processing agreement is often more trustworthy than one that just points to a logo.
To be transparent about ourselves: Neurobots processes data in line with the GDPR on servers in Frankfurt am Main. ISO 27001 certification is in preparation and not yet complete. Ask us about the current status, as you would any other provider.
Whether a certificate is essential for you depends on your situation. If your own customers or clients require evidence along the supply chain, you'll hardly get around it. For a small practice or a trades business, a solid contract, EU hosting and good documentation are often enough, as long as no particularly sensitive data is processed. You can read more about protecting customer data in automated systems in the article on AI data security for businesses.
Frequently asked questions
Is an ISO 27001 certificate required by law?
For most AI providers, no. The GDPR requires appropriate technical and organisational measures, but not a particular certificate. Certain industries and critical infrastructure do have their own requirements, however.
Does ISO 27001 replace a GDPR compliance check?
No. ISO 27001 is about information security. The GDPR goes further and governs whether and for what purpose data may be processed at all, what rights data subjects have and how long data is kept.
How do I check whether a certificate is genuine and valid?
Ask to see the certificate and check the issuer, expiry date and scope. Many certification bodies offer a way to verify the certificates they have issued. If in doubt, ask the issuing body directly.
What about the EU AI Act?
The EU AI Act governs AI-specific obligations, such as transparency towards customers who are talking to an AI. It has to be considered separately from ISO 27001. Our article on the EU AI Act for SMEs gives an overview.
Conclusion
ISO 27001 is a good sign that an AI provider takes information security seriously, provided the scope covers the product you use. It replaces neither a data protection check nor a close look at storage location, sub-processors and contract. Law firms in particular, with their duty of confidentiality, should settle these questions before they start. The page Digital receptionist for law firms shows how a digital reception for lawyers can be set up.
Neurobots for your industry
See how AI employees handle inquiries and appointments in your industry.
View all industry solutionsNote: This article is for general information only. It is not legal advice and was not written or reviewed by lawyers. For your specific situation, please consult a lawyer. All information is provided without guarantee.
Related Articles

EU vs US Data Hosting for AI Tools: Why Location Matters
What the difference between EU and US hosting means legally for your AI tools, and how to check providers with a checklist.

The EU AI Act: What SMEs Need to Know About AI Regulation
What obligations the EU AI Act brings for small and medium-sized businesses, how to classify your AI applications and what you should get done now.

AI Data Security for Businesses: Protecting Customer Data
Which customer data AI systems collect, where the typical weak points are, and which measures and provider questions help you protect that data effectively.
AI Automation for Your Business
Let's find out together which of your processes can be automated with AI employees — free and without obligation.
Book a free consultationROI
Calculated before the start, measured continuously
