Go back

A security review a video tool cannot pass: what ISO 27001 changes

A vendor security review that clears the SOC 2 question can still stall on a different one: does the vendor hold ISO 27001 certification. For international buyers, and for organizations that build their security programs around ISO-based frameworks generally, this can be just as much of a hard requirement as SOC 2 is elsewhere, and it’s worth understanding what actually distinguishes the two standards before assuming one automatically substitutes for the other.

What ISO 27001 actually is

ISO 27001 is an international standard, published by the International Organization for Standardization, that specifies requirements for establishing, implementing, maintaining, and continually improving an information security management system, commonly abbreviated as an ISMS. Unlike SOC 2, which evaluates specific controls against a defined set of criteria over a period of time, ISO 27001 certification evaluates whether an organization has built a structured, ongoing system for managing information security risk, including regular risk assessments, documented policies, and continual improvement processes.

How this differs meaningfully from SOC 2

The practical difference is one of focus. SOC 2 asks: did this specific set of controls operate effectively during this specific period. ISO 27001 asks: has this organization built a systematic, ongoing process for identifying and managing security risk, one that’s expected to keep functioning and improving over time, not just during an audit window. Both are valuable, and they’re not mutually exclusive, many vendors pursue both certifications because they demonstrate related but distinct things to different audiences.

Why some reviews specifically require ISO 27001

Geography and industry norms play a significant role here. Security reviews in Europe, the UK, and parts of Asia more commonly reference ISO 27001 as a baseline expectation, reflecting broader regional familiarity with ISO-based frameworks generally. Some industries, particularly ones with a strong international regulatory footprint, also default to ISO 27001 as their standard reference point. A vendor selling primarily to US-based customers may reasonably prioritize SOC 2, but that same vendor expanding into international markets will likely find ISO 27001 becomes a much more frequent request.

What the certification process actually verifies

ISO 27001 certification requires an accredited external certification body to audit the organization’s ISMS against the standard’s requirements, covering areas like risk assessment methodology, access control policies, incident management procedures, and business continuity planning. Certification isn’t a one-time event either, it requires periodic surveillance audits, typically annual, and a full recertification audit roughly every three years, which means an active ISO 27001 certificate reflects an ongoing commitment, not a credential earned once and left unmaintained.

What to verify when a vendor claims ISO 27001 compliance

Request the actual certificate, not just a claim. A genuine ISO 27001 certificate names the accredited certification body that issued it and includes a specific scope statement describing what parts of the organization and its systems are actually covered.

Check the certificate’s scope carefully. It’s possible for a certification to cover a narrower part of an organization’s operations than the specific product or service you’re evaluating, so confirm the scope statement actually includes what you need it to.

Confirm the certificate is current. Given the recertification cycle, check the issue and expiration dates rather than assuming a certification mentioned on a website is still active.

Ask who conducts the surveillance audits and how recently one occurred. A certificate that’s technically unexpired but hasn’t had a recent surveillance audit is a weaker signal than one with an active, on-schedule audit history behind it.

Why holding both standards signals something specific

A vendor that maintains both SOC 2 and ISO 27001 is effectively running two parallel, independently verified security programs rather than one, since the two standards evaluate meaningfully different things and require separate audit processes to maintain. This is a more demanding commitment than pursuing either certification alone, and it tends to signal a security program built around genuine, ongoing practice rather than one designed narrowly to satisfy whichever single framework the vendor’s primary market happens to expect. For a buyer comparing vendors, this is worth treating as a meaningfully stronger signal than a single certification, not simply a duplicate of the same underlying assurance.

What happens when a vendor holds neither certification

Not holding either SOC 2 or ISO 27001 doesn’t automatically mean a vendor is insecure, particularly for an early-stage company that hasn’t yet invested in formal certification. But it does mean a buyer has no independently verified basis for assessing the vendor’s security practices, and needs to either accept that gap explicitly, request alternative compensating evidence, or factor the absence of certification into the overall risk assessment for that vendor. This is a reasonable trade-off in some circumstances, particularly for lower-risk use cases, but it should be a deliberate decision rather than an overlooked gap.

Why this matters for AI video specifically

Video platforms that process source material and generate derived content sit within the kind of information-handling scope that ISO 27001’s risk management framework is designed to address. For international buyers evaluating an AI video tool, particularly ones already running ISO-based security programs internally, confirming a vendor’s ISO 27001 status is often one of the first and most concrete ways to assess whether that vendor’s own security practices are likely to meet the buyer’s internal standards.

Velo’s approach

Velo meets ISO 27001 security and compliance requirements alongside SOC 2, with documentation available directly to support a security review. Holding both reflects a security posture built to satisfy both the US-centric SOC 2 expectation and the internationally common ISO 27001 requirement, rather than optimizing for one market’s compliance norms at the expense of the other.

How to factor this into a broader vendor comparison

When ISO 27001 comes up as part of a larger vendor comparison, treat it alongside SOC 2 rather than as a separate, isolated checkbox, since together they give a more complete picture of a vendor’s security maturity than either one alone. A vendor holding both, with current, verifiable certificates and a track record of maintaining them through renewal cycles, has demonstrated a level of sustained investment in security practice that’s genuinely useful signal, independent of anything else in the broader evaluation.

Ask which standard your review actually requires

Before assuming SOC 2 alone will satisfy a given security review, confirm directly which standard, or standards, the reviewing organization actually expects. A vendor holding only one certification isn’t automatically disqualified, but knowing which one is required, and confirming the vendor holds it, avoids a late-stage surprise similar to the one a missing SOC 2 report can cause, and gives your team a clear, specific ask rather than a vague sense that “more compliance is probably better.”

Try Velo for free · See how it works


About the author

Ritu Parakh is Growth Lead at Velo, the AI video messaging platform that turns a screen recording, a deck, or a URL into a polished, narrated video - and an editable written doc. She writes about video for demos, onboarding, training, and enablement. Connect on LinkedIn

Velo meets ISO 27001 security and compliance requirements alongside SOC 2, and can provide relevant documentation directly during a vendor security review.

ISO 27001 is an international standard focused on the design and operation of an ongoing information security management system, while SOC 2 is an American Institute of CPAs auditing standard focused on specific control outcomes over a defined period.

It depends on your organization's own requirements and geography. US-based security reviews more often ask for SOC 2, while ISO 27001 is more commonly requested by international buyers or organizations following ISO-based frameworks generally.

Some organizations, particularly those outside the US or in industries that standardize on ISO frameworks, treat ISO 27001 as their baseline requirement, similar to how SOC 2 functions in many US-based reviews.

Bring the video layer to your product team