ISO 27001 certification: what the two audit stages actually look for
Certification is not a document review. Stage 1 checks whether the system exists, stage 2 whether it operates — and the second one samples your evidence.
Most GDPR programmes drown in policy templates. The obligations that regulators check are a much shorter list, and each one produces a record.
GDPR compliance means being able to show that personal data you hold is processed lawfully, for stated purposes, with appropriate security, for no longer than needed, and that people can exercise their rights over it. The regulation is principles-based, which is why two companies of the same size can arrive at very different — and both defensible — programmes.
What is not optional is accountability: you must be able to demonstrate compliance, not merely assert it. In practice that turns a set of principles into a set of records, and the records are what an inquiry starts from.
Over-built: policy libraries. A twelve-document policy set for an eight-person company is a maintenance burden that will be out of date within a year, and no regulator asked for it.
Under-built: the processing record and the supplier chain. Most small companies cannot say quickly which third parties hold their customers’ data, and that is the first question in an incident. The same gap turns into a contractual problem the first time an enterprise customer sends a due diligence questionnaire.
Transfers out of the EEA or UK are the obligation most often missed entirely, because they happen invisibly through ordinary SaaS. If a supplier stores or supports data outside the region, that is a transfer, and it needs a lawful mechanism such as standard contractual clauses plus an assessment of the destination.
Documentation with a review date and an approver is the practical form GDPR accountability takes. Ettex Docs keeps the notice, the assessments and the agreements with their approvals and revision history, so a question about what the policy said in March is answered from the document rather than from memory. Ettex does not make an organisation compliant — the processing decisions are the organisation’s.
Yes, where they offer goods or services to people in the EU or monitor their behaviour. Location of the company does not determine applicability; location of the people whose data is processed largely does.
Only where processing is by a public authority, involves large-scale regular monitoring, or large-scale special category data. Many companies appoint a responsible person instead, without the formal DPO role.
Up to 4% of global annual turnover or 20 million euros, whichever is higher, for the most serious infringements. Most enforcement action, however, is corrective rather than financial.
No, and treating it as the default is a common error. Consent is one of six lawful bases; contract, legal obligation and legitimate interests are often more appropriate and more robust.
Certification is not a document review. Stage 1 checks whether the system exists, stage 2 whether it operates — and the second one samples your evidence.
Incoterms allocate cost, risk and customs duties between buyer and seller. Choosing one by habit is how companies end up insuring cargo they do not own.
A standby letter of credit is drawn only when something has gone wrong. That single difference changes how it is drafted, priced and diarised.