The words "ISO" and "SNI" appear 0 times in POJK 11/POJK.03/2022, SEOJK 29/SEOJK.03/2022, POJK 4/POJK.05/2021 and PBI 2/2024. That's our count across the official OJK and Bank Indonesia PDFs on 14 September 2026. Of the rules we read, only BSSN Regulation 8/2020 Article 9 makes SNI ISO/IEC 27001 mandatory. So for an Indonesian bank, ISO 27001 certification is a matter for BSSN, the national cyber agency, and for electronic system operators (PSE). It's also an input to vendor due diligence. It isn't an OJK requirement. What a certificate tells you about your digital channel comes down to four fields you can check in minutes: the edition (certificates on the 2013 edition expired or were withdrawn on 31 October 2025), the scope, the Statement of Applicability version, and the certification body's accreditation and recognition.
This piece is for the Head of Digital or CIO who's handed an ISO 27001 certificate for a channel, whether by a vendor, a regional group IT hub in Singapore or Kuala Lumpur, or their own team. It's also for the CISO and the Compliance officer who'll have to defend that certificate in an OJK examination or a vendor due-diligence file.
You can repeat the method. We downloaded each PDF from its issuer's own site and searched for "ISO", "SNI" and "27001" as whole words. The count was re-run on 14 September 2026.
| Instrument | Signed | ISO | SNI | 27001 | Position on ISO 27001 |
|---|---|---|---|---|---|
| POJK 11/POJK.03/2022, IT at commercial banks | 6 July 2022 | 0 | 0 | 0 | Not mentioned |
| SEOJK 29/SEOJK.03/2022, bank cyber security and resilience | 27 December 2022 | 0 | 0 | 0 | Not mentioned |
| POJK 4/POJK.05/2021, IT risk at non-bank financial institutions | 9 March 2021 | 0 | 0 | 0 | Not mentioned |
| SEOJK 22/SEOJK.05/2021, its implementing circular | 24 August 2021 | 0 | 0 | 0 | Not mentioned |
| PBI 2/2024, information system security and cyber resilience | 18 April 2024 | 0 | 0 | 0 | Not mentioned |
| PADK OJK 1/2026, IT at commercial banks | 23 January 2026 | 1 | 1 | 0 | An example of an external standard, not required |
| POJK 40/2024, P2P lending | 24 December 2024 | 1 | 0 | 0 | An example, in the Elucidation of Article 162(3) |
| SEOJK 6/SEOJK.07/2024, registration of financial-sector tech innovators (ITSK) | 3 June 2024 | 4 | 0 | 4 | Optional; a security policy document is accepted instead |
| BSSN Regulation 8/2020, security of electronic systems | 16 November 2020 | 5 | 5 | 5 | Mandatory by system category (Article 9) |
SEOJK 6/2024 is the only OJK text we found that names ISO 27001 at all, and it addresses applicants for ITSK registration, not banks. Chapter II point 3.c.5 accepts a certificate from a body accredited by KAN, Indonesia's National Accreditation Committee, or from another body authorised to issue it, or some other security policy document. So even OJK's most explicit text neither requires a certificate nor insists on KAN.
One Indonesian consultancy page cited by Google's AI Overview for "iso 27001" says that under POJK 11/2022 an ISO 27001-based ISMS is "regarded as" a form of compliance you can prove to the regulator (our translation). It cites no article. The same page says the rule binds insurers and finance companies, when POJK 11/POJK.03/2022 governs commercial banks. No article of that kind exists. What does exist is Article 30(5)(b): the bank assesses its provider's IT controls "as evidenced by the results of an audit and/or assessment carried out by an independent party" (our translation). In our view a certificate that clears the four fields below can be one piece of that evidence. That's our reading, not the wording of the article.
The English query isn't better served. Searched from Indonesia on 14 September 2026, "iso 27001 certification" returned an AI Overview citing seven web pages and two videos. One of the seven is an Indonesian site. None is a regulator.
The binding obligation sits with BSSN. BSSN Regulation 8/2020 was signed on 16 November 2020 and promulgated on 23 November 2020 under Government Regulation (PP) 71/2019, and it covers private-scope operators as well as public ones (Article 4). Its Article 9 requires strategic electronic systems to apply SNI ISO/IEC 27001 plus BSSN's own standards and any sector standard from the relevant ministry or agency. High-category systems must apply SNI ISO/IEC 27001 and/or the BSSN standard. Low-category systems must apply one of the two.
You'll still see the older rule quoted. Permenkominfo 4/2016 on information security management systems (SMPI) was signed on 8 April 2016 and promulgated on 11 April 2016 (BN 2016/551). Its Article 12(2)(c) lists KAN accreditation as one of five requirements for a certification body recognised by the Minister. Articles 2 and 3 confine it to electronic systems used for public services, run by four kinds of operator: state bodies and government agencies, BUMN and BUMD, independent institutions set up by statute, and other legal entities that provide public services as part of a state mission. It's never been expressly revoked, and BPK's legal database still lists it as in force. In practice, though, SMPI now runs under BSSN 8/2020, which gives BSSN rather than the Minister the power to recognise certification bodies (Article 26). Bodies recognised under the Kominfo rules keep that status only where it doesn't conflict with the BSSN regulation (Article 43(4)). Cite BSSN 8/2020 as the operative rule. The regulation itself never names KAN; the KAN requirement comes from BSSN's recognition procedure, covered below.
| Field | What it should say | Red flag | How to check |
|---|---|---|---|
| Edition | ISO/IEC 27001:2022 | ISO/IEC 27001:2013, whatever expiry date is printed | The certificate, plus its status in IAF CertSearch |
| Scope | The services, processes and locations that run your channel | "Head office", development without hosting, a certificate belonging to the cloud provider | Compare it with the channel's architecture |
| SoA version | A reference to the Statement of Applicability version | No version reference, or an SoA supplied at a different version | Ask for the SoA and match the version |
| Certification body | The body's name and its accreditation body | Absent from CertSearch, not KAN-accredited, not on BSSN's whitelist where an SMPI certificate is needed | CertSearch, the KAN directory, the BSSN whitelist |
ISO published ISO/IEC 27001:2022 on 25 October 2022. IAF MD 26:2023 Issue 2 (15 February 2023) set a 36-month transition. From 30 April 2024, initial certification and recertification could only use the 2022 edition, and client transitions had to finish by 31 October 2025. Clause 4.2, item 4 says all certifications based on the 2013 edition "shall expire or be withdrawn at the end of the transition period". A later expiry date printed on the certificate doesn't save it.
The same clause holds a second trap. Where a certificate is reissued only because the client passed its transition audit, the end date of its certification cycle stays where it was. A certificate that reads 2022 and was issued in 2025 can run out well short of three years. Read the expiry date. Don't count forward from the issue date.
IAF ceased operating on 1 January 2026 and was replaced by the Global Accreditation Cooperation Incorporated (Global ACI). Global ACI Resolution 2025-25 keeps the IAF Mandatory Documents in force until replacements are adopted, so MD 26 still applies. As of 14 September 2026, the highest-ranked Indonesian page in Google's organic results for "iso 27001" still calls the 2013 edition the current version, and another page in the Indonesian top ten says organisations are "recommended" to move to 2022. MD 26 offers no such choice.
IAF MD 28:2023 clause 4.2.1 item vii requires the scope to be recorded per site "without being misleading or ambiguous". Controls outside that sentence weren't audited, even when they sit inside the same company. Patterns worth a written question:
For an SMPI certificate, the report format in the Annex to BSSN Regulation 8/2020 lists "ruang lingkup audit", the audit scope, among the data a certification body reports to BSSN.
The Statement of Applicability (SoA) lists which Annex A controls are applied and which are excluded, with reasons. ISO/IEC 27006, the standard for bodies certifying an ISMS, expects certification documents to reference the version of the SoA that was audited. Without that reference there's no way to confirm that the SoA a vendor sends today is the one the auditor examined.
Match the version number against the certificate. Confirm the SoA was written against the 2022 edition: MD 26 §2.2 notes that the SoA clause, 6.1.3 d), was restructured "to remove potential ambiguity", so a 2013-era SoA is a different document. Then check that controls touching your channel, such as secure development and technical vulnerability management, aren't among the exclusions.
The three registers answer different questions, and a certificate can pass one while failing another. A certificate from a body accredited by the UK's UKAS or the US's ANAB can show Active in CertSearch and still fail the KAN and BSSN tests, because those two ask about the body's standing in Indonesia rather than the certificate's. Watch for exactly that when a regional hub or an offshore vendor supplies the certificate.
A certificate missing from CertSearch isn't necessarily fake. DAkkS, Germany's accreditation body, stated on 15 November 2024 that it doesn't apply MD 28's requirements in its accreditations, and MD 28 clause 6.2 lets data be marked "confidential" so it doesn't display. Treat absence as grounds for a written explanation, not an automatic rejection.
BSSN's whitelist for the period of 11 September 2026 names 11 certification bodies and 66 SMPI consultancies:
| Certification body | Recognised until |
|---|---|
| PT BSI Group Indonesia | 19 April 2027 |
| PT TSI Sertifikasi Internasional | 24 May 2027 |
| PT Bureau Veritas Indonesia | 28 August 2027 |
| PT TUV Rheinland Indonesia | 15 September 2029 |
| PT Intertek Utama Services | 15 September 2029 |
| PT SGS Indonesia | 3 October 2029 |
| PT TUV SUD Indonesia | 18 November 2029 |
| PT Ekualindo Artha Sinergi | 20 November 2029 |
| PT CBQA Global Indonesia | 19 December 2029 |
| PT Mutuagung Lestari Tbk | 29 December 2029 |
| PT TUV Nord Indonesia | 19 January 2030 |
Three of those recognitions end in 2027, so check the list on the date you procure. The whitelist names Indonesian legal entities: a global group's name on a certificate doesn't prove its local PT is the entity BSSN recognised. PT Sucofindo, whose service page Google's AI Overview cites for the Indonesian query, doesn't appear for the 11 September 2026 period. As far as we can read, that concerns the SMPI certificate, not its ISO accreditation. An SMPI certificate is valid for at most 3 years (Article 28), needs a surveillance audit at least once a year (Article 33), and can be revoked if a failed audit isn't remedied within 90 calendar days (Article 34). Ask for a surveillance audit report less than 12 months old.
Article 30(3) of POJK 11/POJK.03/2022 requires a bank's agreement with an IT service provider to address at least nine matters. A breach draws a written warning, and under Article 33 further sanctions include a ban on launching new bank products. Here's how far a certificate that clears the four fields above covers each item:
| Item | What must be addressed | ISO 27001 certificate | Request separately |
|---|---|---|---|
| a | Qualifications and competence of the provider's staff | Partly: the ISMS has a competence process, which isn't proof of the project team's competence | Team list, CVs, personnel certifications |
| b | Confidentiality of bank and customer data | Helps, if the scope covers processing of the bank's data | Confidentiality clause; a DPIA and processor obligations under Indonesia's PDP Law |
| c | Periodic IT audit results from an independent auditor | Partly: surveillance audits test the management system, not the IT service delivered to the bank | IT audit report, a penetration test report for the channel |
| d | Subcontracting only with the bank's written approval | Not at all | Contract clause, list of subcontractors |
| e | Reporting of critical incidents to the bank | Partly: an incident process exists, but not the deadline or the channel to the bank | Escalation procedure with incident reporting clocks per regulator |
| f | Early termination of the agreement | Not at all | Contract clause, including return of data |
| g | Compliance with laws and regulations | Partly: only as far as the scope and SoA name those rules | A compliance statement per rule; an SMPI certificate where it applies |
| h | Willingness to meet the agreement's obligations | Not at all | Contract clause |
| i | OJK access to examine the provider | Not at all | Audit-right and examination-access clause |
The tally: helps on one item, partly on four, not at all on four. That's our assessment of the article's wording. The Elucidation of Article 30 doesn't expand on paragraph (3).
Each of the first four gets its own follow-up article in this security and data protection series.
Our view: delete the yes/no "Is the vendor ISO 27001 certified?" line from your due-diligence questionnaire. A "yes" tells you nothing about your channel. Put the four fields in its place.
Head of Digital and CIO: make the four fields a document requirement in the RFP. That means a copy of the certificate, a dated CertSearch capture, a version-numbered SoA and the latest surveillance audit report. If the channel is built as a cloud native application, the scope has to name its production environment, not just the development team's office.
CISO: any status other than Active, or a certificate that can't be found, gets a written question before the contract is signed. A certificate supplied by a regional hub or offshore vendor gets the KAN and BSSN checks as well as CertSearch.
Compliance and internal audit (SKAI): don't write that the certificate "satisfies POJK 11/2022". Write that it's one piece of evidence under Article 30(5)(b), and attach separate evidence for Article 30(3). If the system is strategic under BSSN Regulation 8/2020, what you need is an SMPI certificate from a body on BSSN's whitelist.
The regulation count, the BSSN whitelist, the IAF status and the Google results above were checked on 14 September 2026.