← Back to Case Studies

Health SaaS — ISO 27701 in 10 Weeks

Extended an ISO 27001 ISMS to a PIMS, stood up ROPAs/DPIAs, and automated privacy evidence to achieve ISO 27701 in 10 weeks.

Sector: Health Tech (SaaS) Services: ISO 27701, Privacy Governance, ROPA & DPIA, M365 Evidence Automation Tags: ISO 27701, Privacy, Health
Certification achieved in 10 weeks
50+ processing activities catalogued
DPIA trigger coverage > 95%
Evidence prep time reduced by 60%

At a glance

Problem

Demand from hospitals and payers required robust privacy assurance beyond ISO 27001. The team had fragments of ROPA and DPIA material, but no consistent PIMS or repeatable evidence.

Approach

  1. Privacy governance
    • Established roles (DPO/PO), cadences, and policy set (notices, consent, SRR, retention).
  2. Records & risk
    • Completed ROPA and PII flows; created DPIA triggers and templates; aligned to processing purposes and lawful bases.
  3. Controls & proof
    • Mapped privacy controls (minimisation, access restriction, retention) and automated evidence from M365 (SharePoint/Purview/Entra/Intune).
  4. Readiness & audit support
    • Ran internal privacy audit; closed findings; prepared auditors’ sample set and walkthroughs.

Outcome

Key Results

What we delivered

Need a similar outcome?

We help government, health, and technology organisations achieve certification faster with automated evidence and expert delivery.

Book a call