30 Days Gen AI Risk Trial -Start Now
Skip to main content

Compliance decisions

Does an AI vendor’s ISO 27001 scope cover you?

Check the certificate’s legal entity, scope and validity against the exact AI service you plan to use. Verify the issuing body and relevant accreditation independently. A genuine certificate can still cover a different service or exclude the feature you need; it is not a blanket guarantee about every AI interaction.

For Security assurance, procurement and ISMS teams

Aona field notesC23
The scope is the evidence
Which entity, which service?

The specimen’s excluded desktop client changes the buyer’s conclusion.

Every certificate field, entity, issuer and date is fictional. No certification, accreditation, signature or authoritative lookup result exists for this specimen.

01

Match the certificate to the legal supplier

Start with the organisation named on the certificate and the entity in your proposed agreement. A parent company, trading name or reseller may not be the same certified legal entity. Record the certificate number and any attached scope schedule before interpreting the supplier’s assurance claim.

The specimen below is wholly fictional. It names Example Text Services Ltd and a hosted business workspace, while excluding a consumer app and standalone desktop client. It is designed to teach scope reading, not to resemble a valid certificate issued to a real company.

Source context: UKAS: Validating management-system certificates

02

Read the scope and exclusions as carefully as the title

An information-security management-system certificate must be evaluated within its stated scope. Identify the activities, locations and service boundaries described, then compare them with the feature, account and delivery model you will use. A certificate attached to a sales email may not cover that exact arrangement.

In the example, a buyer considering the excluded desktop client cannot use the hosted-workspace scope as evidence that the client is covered. That does not establish that the client is insecure; it establishes that this particular specimen does not support the proposed coverage claim.

Source context: UKAS: Validating management-system certificates

03

Verify the issuer and relevant accreditation

UKAS guidance describes checking the certification body, the accreditation body and the applicable accreditation scope. A certification body can hold accreditation that does not include the management system relevant to the certificate. A logo alone is not sufficient evidence.

Use the actual accreditation body’s directory and the issuing certification body’s verification process. UKAS CertCheck is a public route for claims of UKAS-accredited management-system certification. It is not a universal registry of every certificate under every accreditation system.

Source context: UKAS: Validating management-system certificates · UKAS CertCheck

04

Check status as well as printed dates

Compare the issue and expiry dates, scope schedule and current status in the appropriate verification source. Record what was checked and when. An apparently in-date PDF does not by itself establish that a certificate has not been suspended, withdrawn or superseded.

If the certificate cannot be found, resolve that through the relevant issuer or accreditation route rather than assuming a single directory is globally complete. For the fictional specimen, no lookup success is claimed and no real certification body or accreditation mark is used.

Source context: UKAS: Validating management-system certificates · UKAS CertCheck

05

Turn the result into a scoped procurement finding

Record a conclusion such as “the supplied certificate does not establish coverage of the desktop service in this proposal” and the evidence needed to resolve it. Keep authenticity, service fit and your own implementation responsibilities separate.

This page does not reproduce a licensed ISO control standard or assign a certification outcome. The certificate review is one input to supplier assurance. Data flow, contract, customer configuration and the actual employee input path still require their own assessment.

Source context: UKAS: Validating management-system certificates

Put it into practice

Annotated fictional certificate

Read the full specimen before completing the scope worksheet. The teaching case deliberately excludes the buyer’s proposed desktop service.

Every certificate field, entity, issuer and date is fictional. No certification, accreditation, signature or authoritative lookup result exists for this specimen.

Fictional certificate scope
01

TRAINING ONLY

Example Text Services Ltd

No actual certificate or issuer.

02

Included

Hosted Business Workspace

03

Excluded

Standalone Desktop Client

This is the buyer’s intended service.

04

Verification

Issuer, accreditation and current status

No lookup result is invented.

Annotated fictional certificate
Specimen fieldFictional valueAnnotation
Named entityExample Text Services LtdMatch the legal supplier, not only its brand.
Certificate referenceTRAINING-ONLY-27001-23Use the real issuer’s authoritative verification route in a real review.
ScopeHosted Example Business WorkspaceThe certificate scope must match the service actually purchased.
ExclusionsConsumer App and standalone Desktop ClientThe proposed desktop use is not established as covered.
Validity1 March 2026 to 28 February 2029, inventedPrinted dates are not proof of current status.
Issuer/accreditationInvented issuer; no accreditation claimDo not infer trust from a logo or a fictional registry lookup.

Work through your review

Use the checks to organise the evidence you need. Your selections stay in this tab.

0 of 3 reviewed

Example files for this task

Keep the source material and the instructions together. You can also download the complete worksheet or matrix as CSV.

fictional-iso27001-certificate.mdInspect
# FICTIONAL CERTIFICATE SPECIMEN: NOT VALID

No certificate has been issued. Every organisation, reference and date below is invented for this exercise. No signature, accreditation logo or official mark is represented.

## Specimen face

- Claimed standard: ISO/IEC 27001:2022, shown only as a fictional certificate field.
- Certificate reference: TRAINING-ONLY-27001-23.
- Named organisation: Example Text Services Ltd (fictional).
- Management-system scope: operation and support of the Example Business Workspace hosted text service.
- Named site: Example Operations Centre, fictional location.
- Scope exclusions: Example Consumer App and the standalone Example Desktop Client are not included.
- Illustrative issue date: 1 March 2026.
- Illustrative expiry date: 28 February 2029.
- Issuing body: Example Certification Body, invented for this exercise.
- Accreditation claim: none. No accreditation body has assessed this fictional issuer.

## Buyer’s proposed use

The fictional buyer intends to deploy Example Desktop Client. The supplied specimen therefore does not establish that the intended service is within the stated scope. This is a reading conclusion about the exercise, not a finding about a real supplier.

## Annotation key

1. Match the named entity to the contract. A group brand is not enough.
2. Read the service and location scope, including attached schedules.
3. Compare the proposed feature with the explicit exclusions.
4. Verify issuer accreditation for the relevant scheme using an authoritative directory.
5. Verify the actual certificate and current status through the relevant issuer or registry.
6. Keep the lookup record and date; do not invent a successful lookup for this specimen.

## Source and scope

Guide: https://aona.ai/resources/guides/ai-vendor-iso27001-certificate-scope/

Source check: 21 September 2026. General information, not professional approval or a completed control test.

- UKAS: Validating management-system certificates: https://www.ukas.com/accreditation/about/validating-ms-certificates/
- UKAS CertCheck: https://www.ukas.com/certcheck/
Download fictional-iso27001-certificate.md
iso27001-certificate-scope-exercise.mdInspect
# Annotated fictional certificate

Every certificate field, entity, issuer and date is fictional. No certification, accreditation, signature or authoritative lookup result exists for this specimen.

Read the full specimen before completing the scope worksheet. The teaching case deliberately excludes the buyer’s proposed desktop service.

| Specimen field | Fictional value | Annotation |
| --- | --- | --- |
| Named entity | Example Text Services Ltd | Match the legal supplier, not only its brand. |
| Certificate reference | TRAINING-ONLY-27001-23 | Use the real issuer’s authoritative verification route in a real review. |
| Scope | Hosted Example Business Workspace | The certificate scope must match the service actually purchased. |
| Exclusions | Consumer App and standalone Desktop Client | The proposed desktop use is not established as covered. |
| Validity | 1 March 2026 to 28 February 2029, invented | Printed dates are not proof of current status. |
| Issuer/accreditation | Invented issuer; no accreditation claim | Do not infer trust from a logo or a fictional registry lookup. |

## Review steps

- Compare proposed use with scope: Identify the entity, feature, delivery model and exclusions before relying on the certificate.
- Verify issuer and accreditation: Use the relevant accreditation body and certification body, checking the applicable scheme scope.
- Record a real verification result: Retain the checked source, date and actual status; do not describe a missing lookup as automatically invalid.

# FICTIONAL CERTIFICATE SPECIMEN: NOT VALID

No certificate has been issued. Every organisation, reference and date below is invented for this exercise. No signature, accreditation logo or official mark is represented.

## Specimen face

- Claimed standard: ISO/IEC 27001:2022, shown only as a fictional certificate field.
- Certificate reference: TRAINING-ONLY-27001-23.
- Named organisation: Example Text Services Ltd (fictional).
- Management-system scope: operation and support of the Example Business Workspace hosted text service.
- Named site: Example Operations Centre, fictional location.
- Scope exclusions: Example Consumer App and the standalone Example Desktop Client are not included.
- Illustrative issue date: 1 March 2026.
- Illustrative expiry date: 28 February 2029.
- Issuing body: Example Certification Body, invented for this exercise.
- Accreditation claim: none. No accreditation body has assessed this fictional issuer.

## Buyer’s proposed use

The fictional buyer intends to deploy Example Desktop Client. The supplied specimen therefore does not establish that the intended service is within the stated scope. This is a reading conclusion about the exercise, not a finding about a real supplier.

## Annotation key

1. Match the named entity to the contract. A group brand is not enough.
2. Read the service and location scope, including attached schedules.
3. Compare the proposed feature with the explicit exclusions.
4. Verify issuer accreditation for the relevant scheme using an authoritative directory.
5. Verify the actual certificate and current status through the relevant issuer or registry.
6. Keep the lookup record and date; do not invent a successful lookup for this specimen.


## Source and scope

Guide: https://aona.ai/resources/guides/ai-vendor-iso27001-certificate-scope/

Source check: 21 September 2026. General information, not professional approval or a completed control test.

- UKAS: Validating management-system certificates: https://www.ukas.com/accreditation/about/validating-ms-certificates/
- UKAS CertCheck: https://www.ukas.com/certcheck/
Download iso27001-certificate-scope-exercise.md
iso27001-certificate-scope-exercise.csvInspect
Specimen field,Fictional value,Annotation
Named entity,Example Text Services Ltd,"Match the legal supplier, not only its brand."
Certificate reference,TRAINING-ONLY-27001-23,Use the real issuer’s authoritative verification route in a real review.
Scope,Hosted Example Business Workspace,The certificate scope must match the service actually purchased.
Exclusions,Consumer App and standalone Desktop Client,The proposed desktop use is not established as covered.
Validity,"1 March 2026 to 28 February 2029, invented",Printed dates are not proof of current status.
Issuer/accreditation,Invented issuer; no accreditation claim,Do not infer trust from a logo or a fictional registry lookup.
Download iso27001-certificate-scope-exercise.csv

Before you proceed

Keep these distinctions clear

Authentic can still be out of scope
A genuine document may not establish coverage for the service you need.
A badge is not a verification record
Check the actual issuer, accreditation scope and certificate status.

Apply it to employee AI use

Bring your actual data path.

Aona can provide scoped product and handling information for a supplier review and a supported-path security evaluation.

Aona does not validate another vendor’s ISO certificate or certify the customer’s ISMS.

Keep the certificate finding alongside a separate review of the intended employee AI input path and controls.

Review your use case

FAQ

Questions for this decision

Does a certificate cover every product sold by the company?
Not automatically. Read the named entity, activities, sites and scope schedule, then compare the actual service and exclusions.
Is the specimen a real vendor certificate?
No. Its entity, issuer, reference and dates are invented. It contains no real accreditation mark, signature or claim of a successful verification.
Does no result in one registry prove a certificate is false?
Not necessarily. Use the appropriate registry and issuer verification route for the claimed accreditation. Do not assume one directory covers every scheme worldwide.
Does a valid certificate guarantee that no AI data can leak?
No. Certificate scope and management-system assurance do not guarantee every configured application, feature or employee input. Assess the actual use and controls separately.

Evidence behind the guide

Sources and scope

Prepared by Aona. Sources checked 2026-09-21. The cited material supports the specific points below; it does not certify a product or your use case.

  1. UKAS: Validating management-system certificates

    Independent checks of certificate authenticity, certification-body accreditation and the relevant verification route.

    standard · checked 2026-09-21
  2. UKAS CertCheck

    Public verification of claims of UKAS-accredited management-system certification; its scope is UKAS-accredited certificates.

    standard · checked 2026-09-21
Does an AI vendor’s ISO 27001 scope cover you? | Aona