ISO 27001 for recruitment agencies: do you need it, and what's involved?
Recruitment agencies hold a lot of personal data: CVs, contact details, right-to-work documents, references, salary history and sometimes health or criminal-record information. That's why clients, especially larger firms and the public sector, increasingly ask agencies for Cyber Essentials or ISO 27001 before adding them to a supplier list. Neither is legally required, but both are becoming a condition of winning the work.
Why clients ask
- You're part of their supply chain. If a candidate database leaks, the client's name can end up in the story too.
- Public-sector and framework work often requires Cyber Essentials as a minimum.
- Larger clients' procurement teams send security questionnaires; ISO 27001 answers most of them in one go.
- UK GDPR already expects you to protect personal data with appropriate security. ISO 27001 is a structured way to show you do.
Cyber Essentials or ISO 27001?
If a client or framework asks for Cyber Essentials, start there: it's quick and cheap and covers five technical basics. If a client asks for ISO 27001, or you want one answer to every security questionnaire, you need ISO 27001. Many agencies end up with both. See our comparison.
What an auditor will focus on in an agency
| Area | What it means for a recruitment agency |
|---|---|
| Information assets | Your ATS or CRM, email, file storage, job boards, payroll and timesheet systems |
| Access control | Who can see candidate records; removing access when consultants leave |
| Suppliers | Your ATS provider, job boards, background-check and payroll providers |
| Data handling | Retention of CVs and ID documents; sharing candidate details with clients |
| People | Staff training, confidentiality agreements, clear-desk and remote-working rules |
| Incidents | What happens if a CV is sent to the wrong client or a laptop is lost |
| Continuity | Keeping placements and payroll running if a key system goes down |
Common gaps in agencies
- Old CVs kept forever with no retention rule.
- Shared logins to job boards or the ATS.
- Leavers keeping access to email or the CRM on their phone.
- Candidate details emailed to clients without a consistent, safe method.
- Supplier checks that have never been done on the ATS or background-check provider.
None of these needs a big project to fix. They need decisions, owners and a record that you're doing them.
How long and how much
For a small agency, expect several months from start to certificate, most of it spent running the system so there's evidence for the auditor. The certification audit itself typically costs a few thousand pounds for a small business. See what ISO 27001 costs a small UK business.
How ClearIMS helps
ClearIMS is for businesses that need ISO 27001 but don't want to build a compliance team to get there. Describe your agency in plain English and it drafts your scope, risk register, Statement of Applicability, policies and tasks. A named person in your business approves every record; the AI never approves anything. Then it keeps the system running with owned, dated tasks, so leavers' access, supplier reviews and training don't slip. Cyber Essentials is included.
We make the software. Your certificate is awarded by your certification body, and nobody can guarantee it.
Take the 2-minute readiness check, or book a 20-minute call.