ISO/IEC 27001:2022 certified
W69 AI Consultancy, the company behind W69 AI Growth, is ISO/IEC 27001:2022 certified. An independent, accredited auditor has verified that our information security management system conforms to ISO/IEC 27001:2022. This page sets out exactly what that covers and how you can verify it yourself.
The certificate
The details exactly as they appear on the certificate.
| Certificate holder | W69 AI Consultancy, Oosterhoutlaan 15, 1181 AL Amstelveen, The Netherlands |
|---|---|
| Standard | ISO/IEC 27001:2022 |
| Scope | Information Security Management System for the provision of Artificial Intelligence (AI) advisory and implementation consultancy services |
| Date of issue | 14 September 2026 |
| Valid until | 13 September 2029 |
| Statement of Applicability | version 1.1, dated 24 August 2026 |
| Certification body | Innovative Quality Certifications Pvt. Ltd. (IQCPL) |
| Accreditation | NABCB, signatory to the IAF Multilateral Recognition Arrangement |
| Surveillance | annual surveillance audits in 2027 and 2028, recertification in 2029 |
We do not display the NABCB or IAF marks on this site. Those marks belong to the accreditation body and carry their own conditions of use. They do appear on the certificate itself, which you are welcome to request.
What the certification covers
The scope is stated on the certificate and reads:
Information Security Management System for the provision of Artificial Intelligence (AI) advisory and implementation consultancy services
The certification applies to the company as a whole, not to a department or a single project.
What the management system covers
An ISO/IEC 27001 certificate is not a security checkbox on the IT department. It is an audited management system that touches the entire advisory practice. Of the 93 controls in Annex A, 83 are declared applicable; the ten exclusions are justified in the Statement of Applicability. These are the twelve domains the manual covers.
Policy and risk assessment
A formal information security policy with a risk assessment that is reviewed periodically, and a management review that records decisions.
Classification and use of AI services
Which language models and AI services may be used, per classification level, and whether a data processing agreement is in place. Most management systems have no such chapter.
Access control and authentication
An access register, multi-factor authentication on every account that supports it, and an emergency access procedure.
Client engagements and privileged access
Administrator access at client organisations is recorded with date, reason and end date, and reviewed periodically.
Suppliers and processors
A supplier register recording whether a processing agreement exists for each party, plus the GDPR article 30 record of processing activities.
Backup and restore
A backup schedule with a restore test that has actually been performed and documented, not merely promised on paper.
Devices, remote working and premises
Asset inventory, encryption, and rules for working outside the office.
Continuity and key-person absence
What happens if the key person becomes unavailable, including a trusted contact for emergency access.
Incidents and notification duties
An incident procedure with notification deadlines, root cause analysis and contact with authorities. Exercised in practice and evaluated.
Retention periods
A retention schedule stating for each data type how long it is kept and when it is destroyed.
Document control
Version control and approval of all controlled documents, so it is demonstrable which version applied when.
Operating rhythm
A monthly control round with fixed checkpoints, plus an annual internal audit by an independent auditor.
What this means for you
Four things that are concretely different when you work with us.
Your data is classified
Everything you share with us falls under a documented classification scheme. Each level defines where it may be stored, who can access it and how long it is retained.
AI services are explicitly assessed
The language models and AI services we use are listed in the risk assessment, including whether a data processing agreement is in place. Client-confidential material only goes to services where that is arranged.
Access is logged and limited
Administrator access at client organisations is recorded in an access register with date, reason and end date. Multi-factor authentication is mandatory on every account that supports it.
Incidents follow a procedure
There is an incident procedure with notification deadlines and root cause analysis. It is not theoretical: it has been exercised in practice and evaluated.
Verify it yourself
A certificate you cannot check is not a certificate. Three steps, all free of charge.
1. The certificate
Request it from us and verify the number with the certification body at validity@iqcpl.com or on iqcpl.com.
2. The body
Verify that IQCPL is accredited for ISMS in the register of NABCB, the Indian accreditation body.
3. The recognition
Verify that NABCB is a signatory to the IAF Multilateral Recognition Arrangement. That is what gives the certificate international standing.
Frequently asked questions
What does ISO 27001 actually mean?
ISO/IEC 27001 is the international standard for an information security management system. The certificate does not claim that nothing will ever go wrong. It states that there is a system which identifies risks, selects controls, demonstrably applies those controls and periodically audits itself, and that an independent auditor has verified this.
Which version of the standard is this?
The 2022 version, ISO/IEC 27001:2022. This is the current version, with 93 controls across four themes. Certificates against the older 2013 version expired in 2025 and are no longer valid.
Is my project within the scope?
The scope is the provision of artificial intelligence advisory and implementation consultancy services. An advisory engagement, an AI implementation or an architecture assignment falls within it. The software products W69 also operates are not covered by this certificate; they have their own security regime.
How do I verify this certificate?
In three ways. Ask us for the certificate and verify the number with the certification body at validity@iqcpl.com. Verify IQCPL's accreditation in the NABCB register. And verify that NABCB is a signatory to the IAF Multilateral Recognition Arrangement, which is what gives the certificate international recognition.
Can I see the underlying documents?
We share the Statement of Applicability and the information security policy on request in the context of a concrete engagement or supplier assessment. The risk assessment and the registers are internal, because they contain data relating to other clients.
Does your procurement team send a supplier questionnaire?
We will complete it. Get in touch and we will include the certificate and the Statement of Applicability.
Get in touch