IndiciumIndicium
Log in
← Back to blog
Background checks for HR, Legal and Compliance

Turn public-source risk signals into audit-ready decisions.

Indicium helps regulated teams screen candidates, counterparties and sensitive hires — with dated sources, human review and reports your Legal team can defend.

The Indicium report documents verification of key personnel from dated public sources with a human final review, producing records an ISO 27001 auditor can sample.

ISO 27001 explained: certification for regulated firms in Germany

What ISO/IEC 27001:2022 is, what certification proves for NIS2, KRITIS and DORA, how Stage 1 and Stage 2 audits run, and where personnel controls fit in.

ISO/IEC 27001:2022 is the internationally recognised, certifiable standard for an information security management system (ISMS); certification is voluntary under German law, but for banks, insurers, KRITIS operators and public-sector suppliers it functions as the de-facto evidence framework for NIS2/BSIG, KRITIS and DORA security obligations. That definition carries the whole article: what the standard requires, what a certificate does and does not prove, how the audit process runs in Germany, and which duties sit closest to people rather than technology.

What ISO 27001 is and what an ISMS actually is

ISO/IEC 27001:2022, the third edition, published on 25 October 2022, specifies requirements for establishing, implementing, maintaining and continually improving an information security management system. It applies to all organizations regardless of type, size or nature. An ISMS is not a product and not a stack of documents; it is the management system through which an organization assesses information security risks, decides on treatment, assigns responsibilities, and demonstrates that those decisions were made and reviewed.

The normative core is clauses 4 to 10 on the harmonized Annex SL backbone: context of the organization, leadership, planning, support, operation, performance evaluation, improvement. Clause 6.1.3 d makes the Statement of Applicability (SoA) mandatory documented information, the record that states which Annex A controls apply, which are excluded, and why. In Germany the standard is available as DIN EN ISO/IEC 27001:2024-01, and Amendment 1:2024 with climate-related changes exists alongside the 2022 edition.

What a certificate proves, and what it does not

An accredited certificate attests that a certification body audited the ISMS on given dates against the standard’s requirements and found them implemented, within the stated scope. It does not prove the absence of security incidents, does not transfer liability, and it is not legal conformity with any German statute. The BSI states this precisely: an ISO 27001 certificate is not NIS2 or BSIG conformity and cannot serve as sole proof in supervisory proceedings under §§ 61 and 62 BSIG.

A certificate is evidence of a working management system, not a verdict of compliance. That distinction matters in two directions. For supervisors and clients it is a reviewable signal that the organization runs a documented, audited ISMS. For the certified firm it is a floor, not a ceiling: the BSI also stresses that BSIG excludes the blanket risk acceptance that the ISO standard permits, so a certificate never replaces the statute-specific duties themselves.

The 2022 structure: clauses 4 to 10 and Annex A with 93 controls

The 2022 edition restructured Annex A from 14 domains and 114 controls into four themes with 93 controls: Organizational (A.5, 37 controls), People (A.6, 8), Physical (A.7, 14) and Technological (A.8, 34). Eleven controls are new in this edition. ISO/IEC 27002:2022 mirrors Annex A one to one, same themes, same numbering, and supplies implementation guidance; it is a guidance document and not itself certifiable.

For a certification project the practical unit is the SoA. Each of the 93 controls is either applicable or excluded with justification, and the auditor will test exactly that record. The deep structure of the themes is covered in our article on ISO 27001 Annex A and personnel security screening; here one observation suffices: the themes follow the assets, information is handled by organizations, by people, in buildings, on systems, and Annex A mirrors that order.

How certification runs in Germany: auditors, Stage 1, Stage 2, cycle

In Germany, recognised certificates come from certification bodies accredited by DAkkS under DIN EN ISO/IEC 17021-1 plus the ISMS-specific ISO/IEC 27006-1:2024; DAkkS publishes a public database of accredited bodies, and that database is the first check before you shortlist a provider. The audit itself is two-staged. Stage 1 reviews management-system documentation and readiness: scope, policy, risk assessment, SoA, internal audit programme, management review. Stage 2 audits implementation and effectiveness on site, with document sampling, staff interviews and observation of practice. Both stages are normally performed on-site by the certification body.

After the certificate: it is valid for three years, with surveillance audits in years 1 and 2 and a full recertification audit before expiry. Certificates are issued only once nonconformities are corrected or accepted; a major nonconformity blocks certification until a follow-up audit. Scope is flexible under clause 4.3, partial certification is possible, but the BSI warns against too-narrow scopes precisely because regulated firms need the certified scope to cover the regulated services.

Is ISO 27001 certification mandatory? The regulatory reality

Legally, no. The BSI states it prescribes no specific norm and certification is not a prerequisite for BSIG obligations. De facto, the certificate has become the standard evidence instrument in four places:

  • NIS2 and BSIG: the certificate is not conformity, but the BSI’s own mapping shows large overlap with the § 30 BSIG duties, so firms use it as a foundation for their NIS2 implementation.
  • KRITIS: under § 8a BSIG, a valid ISO 27001 certificate can be used as part of the proof if the certified scope fully covers the critical service; it typically reduces audit effort but is no full substitute.
  • DORA: since 17 January 2025 banks and insurers apply DORA’s ICT risk-management framework; BaFin does not mandate a specific framework but recognises ISO 27001 and BSI IT-Grundschutz as suitable standards.
  • Procurement and sector schemes: certificates appear as client and public-sector requirements, which is where “voluntary” stops being the lived experience.

Why auditors look at personnel controls first

When the Stage 2 audit samples operational evidence, personnel controls come early, and that is not accidental. People control access to information in every theme of Annex A: a screening record is quick to verify, it dates the file, and it tells the auditor whether the ISMS lives in practice or only in documentation. Control A.6.1 (Screening) requires background verification checks on all candidates to become personnel, employees and contractors alike, before they join and on an ongoing basis, bounded by applicable law and scaled in proportion to business requirements, information classification and perceived risk.

For a regulated firm this duty is not an HR footnote. The proportionality clause pushes banks, insurers and KRITIS operators toward documented verification of key personnel: identity, qualifications, employment history, references, and where lawful and role-justified, criminal-record or sanctions checks, with defined re-screening triggers for privileged roles. The operational rule auditors test: nobody receives access to in-scope systems before the check is completed, and the record joins the ISMS evidence trail. Structured, documented, reviewable verification of key personnel, from dated public sources with a human final review, is precisely the capability class that turns this duty into audit-ready records; Indicium’s report does this without claiming that any tool certifies you.

The full control text, the German legal limits under BDSG § 26 and AGG, and the auditor’s evidence expectations are covered in the personnel security article above, and the opening audit requests in ISO 27001 audit: what auditors ask for first.

Frequently asked questions

Was ist ISO 27001, und was ist ein ISMS?

ISO/IEC 27001:2022 is the certifiable international standard for an information security management system. The ISMS is the management framework, risk assessment, treatment, responsibilities, review, through which the organization runs information security systematically rather than as isolated measures.

Ist ISO 27001 Pflicht für Unternehmen?

Legally no, certification is voluntary under German law. De facto it is increasingly expected: as evidence alongside NIS2/BSIG duties, as part of KRITIS proof under § 8a BSIG, as a recognised standard under DORA, and as a procurement requirement in many tenders.

Wie lange gilt das Zertifikat, und wie oft wird geprüft?

Three years of validity, surveillance audits in years 1 and 2, and a recertification audit before expiry. Surveillance audits are sample-based and can suspend the certificate on major nonconformities.

Welche Zertifizierungsstelle ist für ISO 27001 zugelassen?

In Germany, bodies accredited by DAkkS under DIN EN ISO/IEC 17021-1 and ISO/IEC 27006-1. The DAkkS database lists accredited certification bodies and is the place to verify a provider before signing.

This article explains ISO/IEC 27001:2022 certification for regulated firms in Germany and does not constitute legal advice; scope decisions and supervisory questions should be reviewed with your counsel and, where applicable, your auditor.

Ready to move from reading to doing?

See how a reviewable risk report is built – from name to verdict in minutes, not weeks.

Book a demo See a sample report