Security and quality · Assurance
How ISO certification supports security and quality
Understand what Data-Driven's ISO 27001 and ISO 9001 certifications cover, how external audits work, and what clients should verify.
In January 2025, Data-Driven announced certification to ISO/IEC 27001:2022 and ISO 9001:2015. The two standards cover different management systems.
Certification provides evidence for supplier assurance. It does not make every project secure, compliant, or high quality by itself.
What ISO/IEC 27001 covers
ISO/IEC 27001 defines requirements for an information-security management system. The system gives an organisation a structured way to identify, treat, monitor, and improve information-security risks.
ISO’s official ISO/IEC 27001 introduction describes the standard and its current edition.
A client review should still map the certified scope to the people, systems, data, and delivery activities involved in the engagement.
What ISO 9001 covers
ISO 9001 defines requirements for a quality-management system. It focuses on controlled processes, customer requirements, review, and continual improvement.
The ISO 9000 family overview explains the role of ISO 9001 within quality management.
A quality-management certificate does not prove that a particular deliverable meets its acceptance criteria. The project still needs agreed requirements, review, testing, and change control.
What an external audit establishes
A certification body audits the management system against the stated standard and scope. The certificate should identify the legal entity, standard and edition, certification body, validity dates, and certified activities or locations.
For assurance, request:
- the current certificate and scope statement
- the certification body’s accreditation details
- any relevant exclusions or locations
- the most recent surveillance or recertification status
- the controls and responsibilities that apply to your project
These checks matter because certificates expire, scopes change, and a company-level system may not cover every service.
What clients should expect at project level
Connect the management systems to the proposed work. Define data classification, identity, access, environment ownership, logging, incident handling, backup, change control, acceptance, and evidence retention.
Also record which responsibilities belong to Data-Driven, the client, Microsoft, and any other provider.
That project boundary is where certification becomes useful assurance rather than a logo.
Read the current assurance record
The Data-Driven certification page explains the evidence to request during review.
For a formal decision, use the current certificates and scope supplied for due diligence. Do not rely on this announcement alone.
Need certification evidence for assurance?
Tell us what your procurement, security, or risk team needs to assess.