Compliance decisions
Does an AI vendor’s ISO 27001 scope cover you?
Check the certificate’s legal entity, scope and validity against the exact AI service you plan to use. Verify the issuing body and relevant accreditation independently. A genuine certificate can still cover a different service or exclude the feature you need; it is not a blanket guarantee about every AI interaction.
For Security assurance, procurement and ISMS teams
The specimen’s excluded desktop client changes the buyer’s conclusion.
Every certificate field, entity, issuer and date is fictional. No certification, accreditation, signature or authoritative lookup result exists for this specimen.01
Match the certificate to the legal supplier
Start with the organisation named on the certificate and the entity in your proposed agreement. A parent company, trading name or reseller may not be the same certified legal entity. Record the certificate number and any attached scope schedule before interpreting the supplier’s assurance claim.
The specimen below is wholly fictional. It names Example Text Services Ltd and a hosted business workspace, while excluding a consumer app and standalone desktop client. It is designed to teach scope reading, not to resemble a valid certificate issued to a real company.
Source context: UKAS: Validating management-system certificates
02
Read the scope and exclusions as carefully as the title
An information-security management-system certificate must be evaluated within its stated scope. Identify the activities, locations and service boundaries described, then compare them with the feature, account and delivery model you will use. A certificate attached to a sales email may not cover that exact arrangement.
In the example, a buyer considering the excluded desktop client cannot use the hosted-workspace scope as evidence that the client is covered. That does not establish that the client is insecure; it establishes that this particular specimen does not support the proposed coverage claim.
Source context: UKAS: Validating management-system certificates
03
Verify the issuer and relevant accreditation
UKAS guidance describes checking the certification body, the accreditation body and the applicable accreditation scope. A certification body can hold accreditation that does not include the management system relevant to the certificate. A logo alone is not sufficient evidence.
Use the actual accreditation body’s directory and the issuing certification body’s verification process. UKAS CertCheck is a public route for claims of UKAS-accredited management-system certification. It is not a universal registry of every certificate under every accreditation system.
Source context: UKAS: Validating management-system certificates · UKAS CertCheck
04
Check status as well as printed dates
Compare the issue and expiry dates, scope schedule and current status in the appropriate verification source. Record what was checked and when. An apparently in-date PDF does not by itself establish that a certificate has not been suspended, withdrawn or superseded.
If the certificate cannot be found, resolve that through the relevant issuer or accreditation route rather than assuming a single directory is globally complete. For the fictional specimen, no lookup success is claimed and no real certification body or accreditation mark is used.
Source context: UKAS: Validating management-system certificates · UKAS CertCheck
05
Turn the result into a scoped procurement finding
Record a conclusion such as “the supplied certificate does not establish coverage of the desktop service in this proposal” and the evidence needed to resolve it. Keep authenticity, service fit and your own implementation responsibilities separate.
This page does not reproduce a licensed ISO control standard or assign a certification outcome. The certificate review is one input to supplier assurance. Data flow, contract, customer configuration and the actual employee input path still require their own assessment.
Source context: UKAS: Validating management-system certificates
Put it into practice
Annotated fictional certificate
Read the full specimen before completing the scope worksheet. The teaching case deliberately excludes the buyer’s proposed desktop service.
Every certificate field, entity, issuer and date is fictional. No certification, accreditation, signature or authoritative lookup result exists for this specimen.
TRAINING ONLY
Example Text Services Ltd
No actual certificate or issuer.
Included
Hosted Business Workspace
Excluded
Standalone Desktop Client
This is the buyer’s intended service.
Verification
Issuer, accreditation and current status
No lookup result is invented.
| Specimen field | Fictional value | Annotation |
|---|---|---|
| Named entity | Example Text Services Ltd | Match the legal supplier, not only its brand. |
| Certificate reference | TRAINING-ONLY-27001-23 | Use the real issuer’s authoritative verification route in a real review. |
| Scope | Hosted Example Business Workspace | The certificate scope must match the service actually purchased. |
| Exclusions | Consumer App and standalone Desktop Client | The proposed desktop use is not established as covered. |
| Validity | 1 March 2026 to 28 February 2029, invented | Printed dates are not proof of current status. |
| Issuer/accreditation | Invented issuer; no accreditation claim | Do not infer trust from a logo or a fictional registry lookup. |
Work through your review
Use the checks to organise the evidence you need. Your selections stay in this tab.
0 of 3 reviewed
Example files for this task
Keep the source material and the instructions together. You can also download the complete worksheet or matrix as CSV.
fictional-iso27001-certificate.mdInspect
# FICTIONAL CERTIFICATE SPECIMEN: NOT VALID
No certificate has been issued. Every organisation, reference and date below is invented for this exercise. No signature, accreditation logo or official mark is represented.
## Specimen face
- Claimed standard: ISO/IEC 27001:2022, shown only as a fictional certificate field.
- Certificate reference: TRAINING-ONLY-27001-23.
- Named organisation: Example Text Services Ltd (fictional).
- Management-system scope: operation and support of the Example Business Workspace hosted text service.
- Named site: Example Operations Centre, fictional location.
- Scope exclusions: Example Consumer App and the standalone Example Desktop Client are not included.
- Illustrative issue date: 1 March 2026.
- Illustrative expiry date: 28 February 2029.
- Issuing body: Example Certification Body, invented for this exercise.
- Accreditation claim: none. No accreditation body has assessed this fictional issuer.
## Buyer’s proposed use
The fictional buyer intends to deploy Example Desktop Client. The supplied specimen therefore does not establish that the intended service is within the stated scope. This is a reading conclusion about the exercise, not a finding about a real supplier.
## Annotation key
1. Match the named entity to the contract. A group brand is not enough.
2. Read the service and location scope, including attached schedules.
3. Compare the proposed feature with the explicit exclusions.
4. Verify issuer accreditation for the relevant scheme using an authoritative directory.
5. Verify the actual certificate and current status through the relevant issuer or registry.
6. Keep the lookup record and date; do not invent a successful lookup for this specimen.
## Source and scope
Guide: https://aona.ai/resources/guides/ai-vendor-iso27001-certificate-scope/
Source check: 21 September 2026. General information, not professional approval or a completed control test.
- UKAS: Validating management-system certificates: https://www.ukas.com/accreditation/about/validating-ms-certificates/
- UKAS CertCheck: https://www.ukas.com/certcheck/
Download fictional-iso27001-certificate.mdiso27001-certificate-scope-exercise.mdInspect
# Annotated fictional certificate
Every certificate field, entity, issuer and date is fictional. No certification, accreditation, signature or authoritative lookup result exists for this specimen.
Read the full specimen before completing the scope worksheet. The teaching case deliberately excludes the buyer’s proposed desktop service.
| Specimen field | Fictional value | Annotation |
| --- | --- | --- |
| Named entity | Example Text Services Ltd | Match the legal supplier, not only its brand. |
| Certificate reference | TRAINING-ONLY-27001-23 | Use the real issuer’s authoritative verification route in a real review. |
| Scope | Hosted Example Business Workspace | The certificate scope must match the service actually purchased. |
| Exclusions | Consumer App and standalone Desktop Client | The proposed desktop use is not established as covered. |
| Validity | 1 March 2026 to 28 February 2029, invented | Printed dates are not proof of current status. |
| Issuer/accreditation | Invented issuer; no accreditation claim | Do not infer trust from a logo or a fictional registry lookup. |
## Review steps
- Compare proposed use with scope: Identify the entity, feature, delivery model and exclusions before relying on the certificate.
- Verify issuer and accreditation: Use the relevant accreditation body and certification body, checking the applicable scheme scope.
- Record a real verification result: Retain the checked source, date and actual status; do not describe a missing lookup as automatically invalid.
# FICTIONAL CERTIFICATE SPECIMEN: NOT VALID
No certificate has been issued. Every organisation, reference and date below is invented for this exercise. No signature, accreditation logo or official mark is represented.
## Specimen face
- Claimed standard: ISO/IEC 27001:2022, shown only as a fictional certificate field.
- Certificate reference: TRAINING-ONLY-27001-23.
- Named organisation: Example Text Services Ltd (fictional).
- Management-system scope: operation and support of the Example Business Workspace hosted text service.
- Named site: Example Operations Centre, fictional location.
- Scope exclusions: Example Consumer App and the standalone Example Desktop Client are not included.
- Illustrative issue date: 1 March 2026.
- Illustrative expiry date: 28 February 2029.
- Issuing body: Example Certification Body, invented for this exercise.
- Accreditation claim: none. No accreditation body has assessed this fictional issuer.
## Buyer’s proposed use
The fictional buyer intends to deploy Example Desktop Client. The supplied specimen therefore does not establish that the intended service is within the stated scope. This is a reading conclusion about the exercise, not a finding about a real supplier.
## Annotation key
1. Match the named entity to the contract. A group brand is not enough.
2. Read the service and location scope, including attached schedules.
3. Compare the proposed feature with the explicit exclusions.
4. Verify issuer accreditation for the relevant scheme using an authoritative directory.
5. Verify the actual certificate and current status through the relevant issuer or registry.
6. Keep the lookup record and date; do not invent a successful lookup for this specimen.
## Source and scope
Guide: https://aona.ai/resources/guides/ai-vendor-iso27001-certificate-scope/
Source check: 21 September 2026. General information, not professional approval or a completed control test.
- UKAS: Validating management-system certificates: https://www.ukas.com/accreditation/about/validating-ms-certificates/
- UKAS CertCheck: https://www.ukas.com/certcheck/
Download iso27001-certificate-scope-exercise.mdiso27001-certificate-scope-exercise.csvInspect
Specimen field,Fictional value,Annotation
Named entity,Example Text Services Ltd,"Match the legal supplier, not only its brand."
Certificate reference,TRAINING-ONLY-27001-23,Use the real issuer’s authoritative verification route in a real review.
Scope,Hosted Example Business Workspace,The certificate scope must match the service actually purchased.
Exclusions,Consumer App and standalone Desktop Client,The proposed desktop use is not established as covered.
Validity,"1 March 2026 to 28 February 2029, invented",Printed dates are not proof of current status.
Issuer/accreditation,Invented issuer; no accreditation claim,Do not infer trust from a logo or a fictional registry lookup.
Download iso27001-certificate-scope-exercise.csvBefore you proceed
Keep these distinctions clear
- Authentic can still be out of scope
- A genuine document may not establish coverage for the service you need.
- A badge is not a verification record
- Check the actual issuer, accreditation scope and certificate status.
Apply it to employee AI use
Bring your actual data path.
Aona can provide scoped product and handling information for a supplier review and a supported-path security evaluation.
Aona does not validate another vendor’s ISO certificate or certify the customer’s ISMS.
Keep the certificate finding alongside a separate review of the intended employee AI input path and controls.
Review your use caseFAQ
Questions for this decision
Does a certificate cover every product sold by the company?
Is the specimen a real vendor certificate?
Does no result in one registry prove a certificate is false?
Does a valid certificate guarantee that no AI data can leak?
Evidence behind the guide
Sources and scope
Prepared by Aona. Sources checked 2026-09-21. The cited material supports the specific points below; it does not certify a product or your use case.
- UKAS: Validating management-system certificates
Independent checks of certificate authenticity, certification-body accreditation and the relevant verification route.
standard · checked 2026-09-21 - UKAS CertCheck
Public verification of claims of UKAS-accredited management-system certification; its scope is UKAS-accredited certificates.
standard · checked 2026-09-21