1 min read
Choosing the right compliance training platform
A compliance training platform is software that assigns mandatory training to the right people, tracks who has finished it, and keeps time-stamped...
6 min read
Mathan Allington
Updated on September 14, 2026
An ISO 27001 certified HR platform is one whose provider holds a current certificate issued by an accredited certification body, with the HR product itself named inside the certificate's scope. Ask for the certificate, read the scope statement, check the issue and expiry dates, then look at how the product actually handles access, logging and retention of employee records. Certification tells you a management system was audited. It does not, on its own, tell you your data is well handled.
Last reviewed September 2026.
ISO/IEC 27001 is the international standard for an information security management system. A certificate says an accredited auditor examined how an organisation identifies risks to information, decides which controls to apply, documents those decisions, and reviews them over time. The audit is of the management system, not of any single feature.
That distinction matters when you are buying. A vendor can hold a valid certificate covering its corporate IT and still run your HR module on infrastructure sitting outside the certified scope. It can also hold a certificate that covers everything and still give a department head more access to employee records than that person needs, because scope and configuration are different questions. Read the certificate for what is in, then ask product questions separately.
The standard sits alongside privacy law rather than replacing it. Meeting ISO 27001 helps an organisation show it takes security seriously, and it generates much of the evidence that a privacy regulator or a client's risk team will ask for. This article is general information for people buying software. Where legal obligations are in question, take professional advice from someone who knows your jurisdiction and your industry.
Most zero-click frustration with this topic comes from vendors putting a badge on a website and buyers having no way to test it. There are five checks, and none of them take long.
Ask for the certificate itself, not the badge. A real certificate carries a certificate number, the name of the legal entity it was issued to, the issuing certification body, an issue date and an expiry date. If what comes back is a screenshot of a logo, keep asking.
Check the certification body is accredited. Certification bodies are themselves accredited by a national accreditation body, and most publish a searchable register of the certificates they have issued. Look the certificate number up on the issuer's register rather than taking the PDF at face value.
Read the scope statement. This is the sentence on the certificate that says what was audited. You want the product you are buying and the infrastructure it runs on to be inside that sentence. A scope limited to "head office corporate services" covers the vendor's own laptops, not your employee records.
Check the dates and the surveillance cycle. Certificates run on a three-year cycle with annual surveillance audits in between. A certificate that expired last year, or one where the most recent surveillance audit cannot be evidenced, is a flag worth raising.
Ask for the Statement of Applicability. This document lists the controls the organisation applied and, importantly, the ones it excluded and why. Vendors will not always share it in full, and that is reasonable. A vendor that will walk you through the relevant sections under a confidentiality agreement is behaving normally. A vendor that has never heard of it is not certified in any meaningful sense.
The certificate is the same everywhere. What changes by sector is the second layer of questions you should be asking once the certificate checks out, because the consequences of a mishandled record differ.
| Sector | What raises the stakes in the HR data | What to ask beyond the certificate |
|---|---|---|
| Health and aged care | Worker immunisation and health records, police and working-with-vulnerable-people checks, incident records | Whether health and check data is held under tighter access rules than general HR data, and how long it is retained after a worker leaves |
| Financial services | Background and probity checks, conflict declarations, regulated-role registers | Whether the audit log is exportable in a form your own auditors accept, and which staff at the vendor can read a record |
| Government and public sector | Credential and licence registers, clearance status, contractor records at volume | Where data is hosted, which country's laws apply to it, and whether any sub-processor sits offshore |
| Security, utilities and critical infrastructure | Site access rights tied to competency records, contractor induction evidence | How quickly access is revoked when someone leaves, and whether revocation is evidenced rather than assumed |
| Education and training | Student-facing staff checks, qualification evidence, assessment records | How assessment and qualification evidence is versioned, and who can amend a record after it is signed |
None of those questions require a legal team. They require a vendor willing to answer in writing. If you are running a formal selection, the HR tech requirements builder gives you a structure to put security questions next to functional ones so they get weighted rather than waved through at the end.
A polished interface hides a lot. Four things are worth looking at directly in a trial environment rather than reading about in a brochure.
Access control should be granular enough that a line manager can see a performance record without seeing a bank account or a home address. Ask the vendor to show you the permission model and then try to break it with a test account.
Audit logging should record every view, edit, export and deletion, with a user and a timestamp, and the log should be readable by you rather than only by the vendor's support team. Exports matter more than views in practice, because a spreadsheet downloaded to a laptop leaves the system entirely.
Encryption in transit and at rest is close to universal now, so the more useful question is about key management and about backups. Ask how often backups are tested by restoring them, not how often they are taken.
Retention and deletion is where most HR systems are weakest. Employee and candidate records accumulate for years past any purpose. Ask whether retention rules can be set per record type, whether deletion is real deletion, and what happens to your data if you leave the vendor. The same logic applies to the people analytics layer, where aggregated reporting often quietly keeps the underlying rows alive.
For a wider view of how these controls fit together across a people stack, our guide to data security in HR software covers the operational side in more detail.
Send these in writing and keep the replies with your selection file.
Compono is ISO 27001 certified, and the honest position is that you should put every one of those questions to us as readily as to anyone else. Our fit boundary is worth saying plainly: Compono holds hiring, engagement, learning and competency data across the HR software platform. It is not a payroll or finance system, so pay and banking records sit with your payroll vendor and need the same questions asked there. If you are still working out which system holds which record, the difference between an ATS and an HRIS is the place to start, because the split determines who is responsible for the most sensitive fields.
Performance data is one of the few HR record types that is both highly sensitive and widely shared. Reviews get copied into slide decks for calibration meetings, forwarded to new managers during a restructure, and left in shared drives long after anyone needs them.
Working to ISO 27001 changes that in two practical ways. It forces a decision about who is allowed to read a review and for how long, which is a conversation most organisations have never actually had. And it creates a record of who read what, which protects the reviewer as much as the employee when a decision is later challenged. People also write more candidly when they believe the document will not circulate, so tighter access tends to improve the content of reviews rather than restrict it.
The gain is real but modest. Certification will not make a badly designed review process useful. It will stop a useful one from quietly turning into a liability.
Compono is ISO 27001 certified. Bring your security checklist and we will walk through the certificate, the scope and the access model with you.
Talk to usAsk for the certificate rather than the badge, then look the certificate number up on the issuing certification body's public register. Check that the issuer is itself accredited, that the certificate has not expired, and that the scope statement names the product you are buying.
Certified means an accredited external auditor has examined the information security management system and issued a certificate. Compliant is a self-description with no independent audit behind it. Both can be honest, but only one is verifiable.
It means the vendor has an audited system for managing security risk, which is a good sign. It does not guarantee the specific controls you need are switched on in your instance, so still check access permissions, audit logging and retention settings yourself.
They are related but different. ISO 27001 is a framework for how you manage information security. Privacy laws such as GDPR or the Australian Privacy Act set legal obligations about personal data. Working to the standard helps you meet those obligations, and professional advice is the right way to confirm you have.
Whatever your size, you hold sensitive data covered by privacy law. Smaller organisations rarely certify themselves, but buying from a certified vendor is a practical way to inherit a level of assurance you could not build alone.
Indirectly, yes. It forces a decision about who can read review data and for how long, and it logs who actually did. Reviewers tend to write more candidly when they trust the document will not circulate.

Compono Hire helps you predict job-fit and team-fit using behavioural science, so you can shortlist with confidence.
Request a demoBuilt for mid-market hiring teams.

Voice-first coaching that adapts to your personality. Get actionable steps you can take this week.
Start freeBuilt by Compono. Not therapy — practical behaviour change.
1 min read
A compliance training platform is software that assigns mandatory training to the right people, tracks who has finished it, and keeps time-stamped...
1 min read
Compliance training management is how an organisation plans, assigns, delivers and evidences mandatory training so every worker holds the current...
1 min read
WHS software is an umbrella term for two different products that buyers often confuse. A WHS management system records incidents, hazards, risk...