What certification does and does not tell you
Certification is one of the strongest signals available in vendor risk assessment— but only if you read it correctly, and this is where a great deal of assurance is lost.
An ISO 27001 certificate is not a blanket guarantee. It confirms that an information security management system has been assessed against the standard within a defined scope, documented in the organisation's Statement of Applicability. That scope may cover a head-office function and exclude the very business line, data centre or product team that serves you. The first question to ask a certified supplier is not "are you certified?" but "what is your certified scope, and does it include the service we are buying?"
Read correctly, though, ISO 27001 is genuinely informative. Its supplier-relationship controls require the certified organisation to manage security in its own supply chain — meaning a properly scoped certificate gives you visibility one layer deeper than a questionnaire ever will. It also evidences something a point-in-time assessment cannot: an operating management system, subject to surveillance audits, with defined ownership and continual improvement.
Where personal data is central to the relationship, ISO 27701 extends the management system into privacy information management, addressing exactly the controller–processor accountability that the PDPO and GDPR both impose.
For automotive supply chains, TISAX® solves a different and very practical problem. Its value is mutual recognition: an assessment result can be shared with multiple participating partners, replacing repeated bilateral audits of the same supplier. For suppliers, that means one rigorous assessment rather than a dozen inconsistent ones. For manufacturers, it means comparable, standardised assurance across a fragmented supplier base.
And where the third party supplies AI capability — an increasingly common and poorly governed category — ISO/IEC 42001 provides management-system requirements specific to AI, covering the governance questions that information security standards alone were never designed to answer.