Read Time
Categories
Share
The four fields on a vendor's ISO 27001 certificate that decide whether it says anything about your bank's digital channel, and how to check each one in minutes.

The words "ISO" and "SNI" appear 0 times in POJK 11/POJK.03/2022, SEOJK 29/SEOJK.03/2022, POJK 4/POJK.05/2021 and PBI 2/2024. That's our count across the official OJK and Bank Indonesia PDFs on 14 September 2026. Of the rules we read, only BSSN Regulation 8/2020 Article 9 makes SNI ISO/IEC 27001 mandatory. So for an Indonesian bank, ISO 27001 certification is a matter for BSSN, the national cyber agency, and for electronic system operators (PSE). It's also an input to vendor due diligence. It isn't an OJK requirement. What a certificate tells you about your digital channel comes down to four fields you can check in minutes: the edition (certificates on the 2013 edition expired or were withdrawn on 31 October 2025), the scope, the Statement of Applicability version, and the certification body's accreditation and recognition.

This piece is for the Head of Digital or CIO who's handed an ISO 27001 certificate for a channel, whether by a vendor, a regional group IT hub in Singapore or Kuala Lumpur, or their own team. It's also for the CISO and the Compliance officer who'll have to defend that certificate in an OJK examination or a vendor due-diligence file.

ISO 27001 in Indonesian financial regulation: the count, instrument by instrument

You can repeat the method. We downloaded each PDF from its issuer's own site and searched for "ISO", "SNI" and "27001" as whole words. The count was re-run on 14 September 2026.

InstrumentSignedISOSNI27001Position on ISO 27001
POJK 11/POJK.03/2022, IT at commercial banks6 July 2022000Not mentioned
SEOJK 29/SEOJK.03/2022, bank cyber security and resilience27 December 2022000Not mentioned
POJK 4/POJK.05/2021, IT risk at non-bank financial institutions9 March 2021000Not mentioned
SEOJK 22/SEOJK.05/2021, its implementing circular24 August 2021000Not mentioned
PBI 2/2024, information system security and cyber resilience18 April 2024000Not mentioned
PADK OJK 1/2026, IT at commercial banks23 January 2026110An example of an external standard, not required
POJK 40/2024, P2P lending24 December 2024100An example, in the Elucidation of Article 162(3)
SEOJK 6/SEOJK.07/2024, registration of financial-sector tech innovators (ITSK)3 June 2024404Optional; a security policy document is accepted instead
BSSN Regulation 8/2020, security of electronic systems16 November 2020555Mandatory by system category (Article 9)

SEOJK 6/2024 is the only OJK text we found that names ISO 27001 at all, and it addresses applicants for ITSK registration, not banks. Chapter II point 3.c.5 accepts a certificate from a body accredited by KAN, Indonesia's National Accreditation Committee, or from another body authorised to issue it, or some other security policy document. So even OJK's most explicit text neither requires a certificate nor insists on KAN.

One Indonesian consultancy page cited by Google's AI Overview for "iso 27001" says that under POJK 11/2022 an ISO 27001-based ISMS is "regarded as" a form of compliance you can prove to the regulator (our translation). It cites no article. The same page says the rule binds insurers and finance companies, when POJK 11/POJK.03/2022 governs commercial banks. No article of that kind exists. What does exist is Article 30(5)(b): the bank assesses its provider's IT controls "as evidenced by the results of an audit and/or assessment carried out by an independent party" (our translation). In our view a certificate that clears the four fields below can be one piece of that evidence. That's our reading, not the wording of the article.

The English query isn't better served. Searched from Indonesia on 14 September 2026, "iso 27001 certification" returned an AI Overview citing seven web pages and two videos. One of the seven is an Indonesian site. None is a regulator.

The binding obligation sits with BSSN. BSSN Regulation 8/2020 was signed on 16 November 2020 and promulgated on 23 November 2020 under Government Regulation (PP) 71/2019, and it covers private-scope operators as well as public ones (Article 4). Its Article 9 requires strategic electronic systems to apply SNI ISO/IEC 27001 plus BSSN's own standards and any sector standard from the relevant ministry or agency. High-category systems must apply SNI ISO/IEC 27001 and/or the BSSN standard. Low-category systems must apply one of the two.

You'll still see the older rule quoted. Permenkominfo 4/2016 on information security management systems (SMPI) was signed on 8 April 2016 and promulgated on 11 April 2016 (BN 2016/551). Its Article 12(2)(c) lists KAN accreditation as one of five requirements for a certification body recognised by the Minister. Articles 2 and 3 confine it to electronic systems used for public services, run by four kinds of operator: state bodies and government agencies, BUMN and BUMD, independent institutions set up by statute, and other legal entities that provide public services as part of a state mission. It's never been expressly revoked, and BPK's legal database still lists it as in force. In practice, though, SMPI now runs under BSSN 8/2020, which gives BSSN rather than the Minister the power to recognise certification bodies (Article 26). Bodies recognised under the Kominfo rules keep that status only where it doesn't conflict with the BSSN regulation (Article 43(4)). Cite BSSN 8/2020 as the operative rule. The regulation itself never names KAN; the KAN requirement comes from BSSN's recognition procedure, covered below.

The four fields to read, and how to check each one

FieldWhat it should sayRed flagHow to check
EditionISO/IEC 27001:2022ISO/IEC 27001:2013, whatever expiry date is printedThe certificate, plus its status in IAF CertSearch
ScopeThe services, processes and locations that run your channel"Head office", development without hosting, a certificate belonging to the cloud providerCompare it with the channel's architecture
SoA versionA reference to the Statement of Applicability versionNo version reference, or an SoA supplied at a different versionAsk for the SoA and match the version
Certification bodyThe body's name and its accreditation bodyAbsent from CertSearch, not KAN-accredited, not on BSSN's whitelist where an SMPI certificate is neededCertSearch, the KAN directory, the BSSN whitelist

Edition: "27001:2013" means the certificate is no longer valid

ISO published ISO/IEC 27001:2022 on 25 October 2022. IAF MD 26:2023 Issue 2 (15 February 2023) set a 36-month transition. From 30 April 2024, initial certification and recertification could only use the 2022 edition, and client transitions had to finish by 31 October 2025. Clause 4.2, item 4 says all certifications based on the 2013 edition "shall expire or be withdrawn at the end of the transition period". A later expiry date printed on the certificate doesn't save it.

The same clause holds a second trap. Where a certificate is reissued only because the client passed its transition audit, the end date of its certification cycle stays where it was. A certificate that reads 2022 and was issued in 2025 can run out well short of three years. Read the expiry date. Don't count forward from the issue date.

IAF ceased operating on 1 January 2026 and was replaced by the Global Accreditation Cooperation Incorporated (Global ACI). Global ACI Resolution 2025-25 keeps the IAF Mandatory Documents in force until replacements are adopted, so MD 26 still applies. As of 14 September 2026, the highest-ranked Indonesian page in Google's organic results for "iso 27001" still calls the 2013 edition the current version, and another page in the Indonesian top ten says organisations are "recommended" to move to 2022. MD 26 offers no such choice.

Scope: a certificate covers only what its scope statement says

IAF MD 28:2023 clause 4.2.1 item vii requires the scope to be recorded per site "without being misleading or ambiguous". Controls outside that sentence weren't audited, even when they sit inside the same company. Patterns worth a written question:

  • A scope that reads "head office", or gives only a building address in South Jakarta, without naming the service that was audited.
  • Software development in scope, but hosting and production operations out of it, when the same vendor will run your channel in production.
  • A certificate that belongs to the cloud or data-centre provider. It covers their controls, not your vendor's application or team.
  • Integrations that carry customer data, into core banking, Dukcapil (the civil registry) or a payment gateway, that sit under no named process or site.

For an SMPI certificate, the report format in the Annex to BSSN Regulation 8/2020 lists "ruang lingkup audit", the audit scope, among the data a certification body reports to BSSN.

Statement of Applicability version: ask for the document, match the number

The Statement of Applicability (SoA) lists which Annex A controls are applied and which are excluded, with reasons. ISO/IEC 27006, the standard for bodies certifying an ISMS, expects certification documents to reference the version of the SoA that was audited. Without that reference there's no way to confirm that the SoA a vendor sends today is the one the auditor examined.

Match the version number against the certificate. Confirm the SoA was written against the 2022 edition: MD 26 §2.2 notes that the SoA clause, 6.1.3 d), was restructured "to remove potential ambiguity", so a 2013-era SoA is a different document. Then check that controls touching your channel, such as secure development and technical vulnerability management, aren't among the exclusions.

Certification body: three registers, three different questions

  1. IAF CertSearch: is this an accredited certification? MD 28 (published 26 October 2023, mandatory from 26 October 2024) requires certification bodies to upload each certificate's number, scope, expiry date, status and accreditation body, refreshed at least monthly. The verification guide uses four statuses: Active, Suspended, Withdrawn and Expired. A public user can verify 3 certificates a day, or 30 free verifications with an account.
  2. KAN: is the body accredited in Indonesia? According to the IAF MLA member list as of 31 December 2025, KAN has held the ISO/IEC 27006 and ISO/IEC 27001 sub-scopes since 21 June 2019. Match the body's legal entity name against KAN's directory of accredited ISMS certification bodies. For a bank this is a procurement test, not an OJK condition.
  3. BSSN's whitelist: may the body issue an SMPI certificate? BSSN Regulation 8/2020 Article 26 states that SMPI certification is carried out by a certification body recognised by BSSN. BSSN's recognition page, citing BSSN Circular 52/2023, requires among other things a current KAN accreditation and at least one auditor who is an Indonesian citizen registered with BSSN.

The three registers answer different questions, and a certificate can pass one while failing another. A certificate from a body accredited by the UK's UKAS or the US's ANAB can show Active in CertSearch and still fail the KAN and BSSN tests, because those two ask about the body's standing in Indonesia rather than the certificate's. Watch for exactly that when a regional hub or an offshore vendor supplies the certificate.

A certificate missing from CertSearch isn't necessarily fake. DAkkS, Germany's accreditation body, stated on 15 November 2024 that it doesn't apply MD 28's requirements in its accreditations, and MD 28 clause 6.2 lets data be marked "confidential" so it doesn't display. Treat absence as grounds for a written explanation, not an automatic rejection.

BSSN's whitelist for the period of 11 September 2026 names 11 certification bodies and 66 SMPI consultancies:

Certification bodyRecognised until
PT BSI Group Indonesia19 April 2027
PT TSI Sertifikasi Internasional24 May 2027
PT Bureau Veritas Indonesia28 August 2027
PT TUV Rheinland Indonesia15 September 2029
PT Intertek Utama Services15 September 2029
PT SGS Indonesia3 October 2029
PT TUV SUD Indonesia18 November 2029
PT Ekualindo Artha Sinergi20 November 2029
PT CBQA Global Indonesia19 December 2029
PT Mutuagung Lestari Tbk29 December 2029
PT TUV Nord Indonesia19 January 2030

Three of those recognitions end in 2027, so check the list on the date you procure. The whitelist names Indonesian legal entities: a global group's name on a certificate doesn't prove its local PT is the entity BSSN recognised. PT Sucofindo, whose service page Google's AI Overview cites for the Indonesian query, doesn't appear for the 11 September 2026 period. As far as we can read, that concerns the SMPI certificate, not its ISO accreditation. An SMPI certificate is valid for at most 3 years (Article 28), needs a surveillance audit at least once a year (Article 33), and can be revoked if a failed audit isn't remedied within 90 calendar days (Article 34). Ask for a surveillance audit report less than 12 months old.

What the certificate does not prove: POJK 11/2022 Article 30(3)

Article 30(3) of POJK 11/POJK.03/2022 requires a bank's agreement with an IT service provider to address at least nine matters. A breach draws a written warning, and under Article 33 further sanctions include a ban on launching new bank products. Here's how far a certificate that clears the four fields above covers each item:

ItemWhat must be addressedISO 27001 certificateRequest separately
aQualifications and competence of the provider's staffPartly: the ISMS has a competence process, which isn't proof of the project team's competenceTeam list, CVs, personnel certifications
bConfidentiality of bank and customer dataHelps, if the scope covers processing of the bank's dataConfidentiality clause; a DPIA and processor obligations under Indonesia's PDP Law
cPeriodic IT audit results from an independent auditorPartly: surveillance audits test the management system, not the IT service delivered to the bankIT audit report, a penetration test report for the channel
dSubcontracting only with the bank's written approvalNot at allContract clause, list of subcontractors
eReporting of critical incidents to the bankPartly: an incident process exists, but not the deadline or the channel to the bankEscalation procedure with incident reporting clocks per regulator
fEarly termination of the agreementNot at allContract clause, including return of data
gCompliance with laws and regulationsPartly: only as far as the scope and SoA name those rulesA compliance statement per rule; an SMPI certificate where it applies
hWillingness to meet the agreement's obligationsNot at allContract clause
iOJK access to examine the providerNot at allAudit-right and examination-access clause

The tally: helps on one item, partly on four, not at all on four. That's our assessment of the article's wording. The Elucidation of Article 30 doesn't expand on paragraph (3).

What to request separately

  1. A DPIA. Law 27/2022 on Personal Data Protection, Article 34(1), requires one where processing carries a potentially high risk. For a channel with e-KYC or Dukcapil data matching, the question is rarely whether.
  2. A penetration test report scoped to the channel. The Elucidation of POJK 11/2022 Article 24(1) names the penetration test as an example of cyber security testing, and under SEOJK 29/2022 Chapter VII point 5 the bank remains responsible for that testing.
  3. A budget for VA, pentest and certification across one three-year cycle. An SMPI certificate also runs three years, so cost it on the same horizon.
  4. An evidence map per security layer. Who owns each document, which rule asks for it, and when it falls due.
  5. Contract clauses for items d, f, h and i. That's work for the bank's legal team. The vendor's ISO auditor never looks at them.

Each of the first four gets its own follow-up article in this security and data protection series.

What this means for the buying committee

Our view: delete the yes/no "Is the vendor ISO 27001 certified?" line from your due-diligence questionnaire. A "yes" tells you nothing about your channel. Put the four fields in its place.

Head of Digital and CIO: make the four fields a document requirement in the RFP. That means a copy of the certificate, a dated CertSearch capture, a version-numbered SoA and the latest surveillance audit report. If the channel is built as a cloud native application, the scope has to name its production environment, not just the development team's office.

CISO: any status other than Active, or a certificate that can't be found, gets a written question before the contract is signed. A certificate supplied by a regional hub or offshore vendor gets the KAN and BSSN checks as well as CertSearch.

Compliance and internal audit (SKAI): don't write that the certificate "satisfies POJK 11/2022". Write that it's one piece of evidence under Article 30(5)(b), and attach separate evidence for Article 30(3). If the system is strategic under BSSN Regulation 8/2020, what you need is an SMPI certificate from a body on BSSN's whitelist.

The regulation count, the BSSN whitelist, the IAF status and the Google results above were checked on 14 September 2026.

Back to List