Ziwo Upgrades to ISO/IEC 27001:2022 with Axipro

Product

SOC 2 Type I & II

Industry

Cloud Communications / Contact Center Software

Company size

51 – 200 employees

Location

Dubai, UAE

Ziwo-ISO-27001-Axipro

Share This Post

Introduction

Compliance is not a checkbox. It is a journey. For Ziwo, that journey meant moving beyond their ISO 27001:2013 certification and preparing for the future. They sought to modernize their security practices, reduce manual work, and align with updated international standards.

With Axipro providing advisory guidance, Drata powering automation, and Insight Assurance serving as the audit partner, Ziwo successfully transitioned its compliance program to meet ISO 27001:2022 requirements.

The outcome was a smooth certification process, completed without non-conformities, and a stronger foundation of trust with customers across the Middle East and beyond.

About Ziwo

Ziwo is a leading cloud-native call center and customer experience (CX) platform. Headquartered in Dubai, with offices in Riyadh, Cairo, and Casablanca, Ziwo supports businesses across the MENA region and beyond.

Their platform helps organizations deliver secure, intuitive, and multilingual customer interactions. Industries served include:

  • BPO and customer support
  • Retail and e-commerce
  • Finance and real estate
  • Travel and hospitality

As a trusted provider, Ziwo already held ISO 27001:2013 certification. As a trusted provider, Ziwo already held ISO 27001:2013 certification. But to keep pace with growth and evolving expectations, they chose to pursue ISO 27001:2022 compliance with advisory support from Axipro, while leveraging Drata for automation and working with Insight Assurance as their audit partner.

Challenge: Scaling & Upgrading Compliance

Ziwo’s leadership recognized that while ISO 27001:2013 kept them secure, it also came with challenges:

  • Manual compliance tracking created inefficiencies.
  • Evidence collection for audits consumed valuable time.
  • Processes were fragmented across teams.
  • New ISO 27001:2022 requirements required updated alignment.

The goal was clear: transition smoothly to ISO 27001:2022, reduce administrative overhead, and empower their internal team to manage compliance more effectively. This meant choosing the right advisory, automation, and audit partners to guide the process.

Solution: Axipro’s Guided Transition

Through this coordinated effort, Ziwo:

  • Successfully upgraded from ISO 27001:2013 to ISO 27001:2022 certification.
  • Completed the certification with zero major or minor non-conformities, as confirmed by Insight Assurance.
  • Integrated Drata for continuous, automated compliance monitoring.
  • Strengthened their internal team’s ability to manage compliance independently going forward.

This achievement highlights Ziwo’s commitment to security and governance while also showcasing the value of advisory, automation, and audit working together.

“Thanks a ton for the smooth audit, team! It was a combined effort and great teamwork. We look forward to continuing this success in upcoming audits and certifications on behalf of Ziwo & management.”Ziwo Management

Results: Smooth Audit, Stronger Governance

The partnership delivered results that mattered. With Axipro’s support and Drata’s automation, Ziwo achieved:

  • ISO 27001:2022 certification with zero major or minor non-conformities.
  • Full Drata integration, giving real-time visibility into compliance status.
  • Audit preparation that shifted from manual to automated, saving weeks of effort.
  • An empowered internal team, now confident in managing and scaling compliance.

This wasn’t just an upgrade, it was a transformation. Ziwo replaced administrative burden with operational efficiency. They gained trust, credibility, and a stronger security posture that customers value.

Thanks a ton for the smooth audit, team! It was a combined effort and great teamwork. We look forward to continuing this success in upcoming audits and certifications on behalf of Ziwo & management. Ziwo Management

Ready to see the same results? Modernize your audits today with ISO 27001:2022 compliance with Axipro.

Why Ziwo Chose Axipro

For Ziwo, selecting Axipro as an advisory partner was driven by the need for clarity and structure during the transition. They valued Axipro’s ability to:

  • Provide guidance on aligning with ISO 27001:2022 requirements.
  • Support the adoption of automation tools like Drata.
  • Collaborate with internal teams rather than replace them.
  • Partner effectively alongside Insight Assurance as the independent auditor.

Axipro’s role was not to certify or audit, but to act as a trusted advisor, helping Ziwo navigate the complexity of compliance and build confidence in their processes.

Conclusion

Compliance is not a one-time milestone. It evolves as standards change and organizations grow. Ziwo’s successful transition from ISO 27001:2013 to ISO 27001:2022 certification demonstrates the value of combining advisory guidance, automation, and independent auditing.

With Axipro as their advisory partner, Drata providing automation, and Insight Assurance serving as the audit partner, Ziwo strengthened its compliance program while ensuring alignment with international best practices. The result was a smooth certification process, completed with zero non-conformities, and an internal team better prepared to manage compliance moving forward.

For organizations looking to upgrade or begin their compliance journey, Axipro provides advisory support to help teams align with updated standards, adopt automation tools, and prepare confidently for audits.

KVKK vs GDPR: Key Compliance Gaps for Turkish Exporters

The EU buys more from Türkiye than anyone else. According to the European Commission’s trade profile for Türkiye, about 41% of Turkish goods exports went to the EU in 2024, and the share keeps climbing. Nearly every company behind those shipments holds some EU personal data: a buyer’s name in the CRM, a webshop account, a logistics contact, a support ticket. That data puts the exporter inside the GDPR, and a KVKK compliance file won’t answer the questions an EU customer’s procurement team is going to ask. KVKK and GDPR look alike, and the 2024 amendments brought them closer. They’re still two laws with two regulators, two sets of paperwork and very different fine ceilings. This article walks through the eight places where a KVKK-compliant Turkish exporter falls short of GDPR, covers both directions of data flow, and ends with a roadmap that reflects how long this stuff actually takes. Why KVKK Compliance Doesn’t Make a Turkish Exporter GDPR-Ready Law No. 6698 was written to line Türkiye up with the EU’s 1995 Data Protection Directive. It came into force in April 2016, a few weeks before the EU adopted the GDPR. That timing explains most of what follows. KVKK inherited the Directive’s structure and then developed on its own track under the Personal Data Protection Board, while the GDPR added accountability tools, extraterritorial reach and turnover-based fines that the Directive never had. So a Turkish company can be fully KVKK compliant, registered in VERBİS, privacy notices in place, and still have no records of processing, no DPIA method, no EU representative, and no answer for an EU customer asking which Article 46 mechanism covers the data they’re about to send to Istanbul. When GDPR Applies to a Turkish Company Article 3(2) of the GDPR catches companies with no EU establishment in two situations: offering goods or services to people in the EU, and monitoring their behavior. The European Data Protection Board’s guidelines on territorial scope treat euro pricing, shipping to EU addresses, EU-language storefronts and EU-targeted marketing as “offering.” Analytics, retargeting pixels and personalization count as “monitoring.” There’s a third route that’s easy to miss. A Turkish software house or contract manufacturer that processes EU personal data for an EU customer is a processor under Article 28. The customer will want a data processing agreement, security commitments and help meeting its own GDPR obligations, even if the Turkish company never markets to the EU at all. Important: Selling only B2B to EU companies doesn’t get you out of this. Business contacts are data subjects. The names, emails and phone numbers of a German buyer’s purchasing staff are personal data under both laws, and the exporter is the controller of them. KVKK vs GDPR at a Glance Obligation KVKK (Law No. 6698, as amended 2024) GDPR (Regulation (EU) 2016/679) Default legal basis Explicit consent, with listed exceptions including legitimate interest Six equal lawful bases; consent is one of them Registry Mandatory VERBİS registration for most controllers No public registry; internal Article 30 records Impact assessment No statutory DPIA Mandatory DPIA for high-risk processing DPO Not required Required in defined cases (Article 37) Representative abroad Foreign controllers appoint a Türkiye representative Non-EU controllers appoint an EU representative (Article 27) Data portability Not granted Granted (Article 20) Breach notice Board within 72 hours Supervisory authority within 72 hours Transfers Adequacy, Turkish standard contracts, BCRs; 5-business-day filing Adequacy, EU SCCs, BCRs; transfer impact assessment Maximum fine ₺17,092,242 in 2026 €20 million or 4% of global turnover Gap 1: Lawful Bases and Consent KVKK’s Article 5 puts explicit consent at the top and lists everything else as an exception. Turkish privacy notices reflect that, and most of them lean on consent for almost everything. The GDPR treats consent as one option among six, and in practice it’s the weakest one for core business processing. Regulators expect contract performance for order fulfillment, legal obligation for tax records, and legitimate interest for fraud prevention and B2B marketing. Consent also has a cost that exporters don’t always price in. Under Article 7 it has to be as easy to withdraw as it was to give, and once it’s withdrawn the processing has to stop. An exporter that collects EU customer data “with consent” and then keeps invoicing records for ten years has written a contradiction into its own notice. Law No. 7499 closed one part of this gap in 2024. Health and sexual-life data lost their special carve-out and the list of grounds for processing sensitive data got longer, so KVKK Article 6 now tracks GDPR Article 9 fairly closely. An exporter’s KVKK approach to sensitive data can be reused for GDPR with light editing. Cookies are another point of convergence. The Board’s cookie guidance already asks for opt-in consent for anything beyond strictly necessary cookies, a reject button as visible as the accept one, and no pre-ticked boxes. A banner built to that standard will pass with most EU supervisory authorities too. Gap 2: Accountability Documentation KVKK asks controllers to register in VERBİS, the public Data Controllers’ Registry, and to keep a processing inventory behind that registration. The GDPR has no registry. What it has instead is Article 30: an internal record of processing activities that a supervisory authority can demand at any time, covering purposes, data categories, recipients, transfers, retention periods, and security measures. The VERBİS inventory gets you roughly 70% of the way to an Article 30 record. What’s usually missing is the lawful basis for each purpose (VERBİS doesn’t push for it at the same level of detail), the transfer mechanism per recipient, and the Article 28 processor list. The bigger gap is the Data Protection Impact Assessment. KVKK has nothing like it. GDPR Article 35 makes a DPIA mandatory before high-risk processing starts, and an EU customer may ask to see one before signing. Building the method takes a few weeks. Retrofitting DPIAs onto processing that’s already live takes longer, and it tends to turn up things nobody wanted to find. Insider

Read More »

The ISO 42001 Gap Analysis Checklist Consultants Actually Use

A consultant-grade ISO 42001 gap analysis checklist has 38 Annex A controls, roughly 80 clause-level “shall” statements, and one question attached to every line: where is the evidence, and would a certification body accept it? That last question is what separates the checklists consultants use from the free self-assessment spreadsheets that rank for the same search. This article lays out the checklist itself: what a consultant checks before the engagement starts, the clause-by-clause and control-by-control checkpoints, how evidence gets sampled, how gaps get scored, what the deliverables look like, and what fails most often. Use it to run your own assessment, or to check whether the consultant you’re about to hire is doing the job properly. What Makes a Consultant-Grade ISO 42001 Gap Analysis Checklist Different​ Depth of Evidence Review vs. Self-Assessment Tools A self-assessment tool asks whether you have an AI policy. A consultant asks to see it, checks the approval date and version, reads clause 5.2 against it, and then asks three people in engineering whether they’ve read it. The checklist item is the same. The evidence standard is not. Consultants score every item on three levels: documented, implemented, and effective. A policy that exists but nobody follows scores as “ad hoc,” not “defined.” A control that runs but produces no record scores as unverifiable, which for audit purposes is the same as absent. Self-assessment tools collapse those three levels into a single yes/no, which is why companies that score 85% on a free tool routinely receive major nonconformities at Stage 2. Alignment with Certification Body Expectations Certification bodies auditing against ISO/IEC 42001:2023 now work under ISO/IEC 42006:2025, which sets competence, audit-time, and impartiality requirements for AIMS auditors and builds on ISO/IEC 17021-1. A consultant-grade checklist is written with 42006 in mind: it organizes findings by clause and control identifier, because that’s how the auditor works, and it records evidence locations, because that’s what the auditor will sample. The practical difference shows up in the report. A gap register that says “AI governance needs improvement” is useless in front of an auditor. One that says “A.5.2 not conformant: no documented impact assessment process; two of four in-scope systems have no assessment on file” maps directly to the audit plan. Risk-Weighted Scoring Methodology Self-assessments count gaps. Consultants weight them. A missing AI policy under clause 5.2 and an incomplete competence matrix under 7.2 are both gaps, but the first will block certification and the second will earn you a minor finding. A consultant-grade checklist carries two scores per line: a maturity rating (how far the control is from working) and a certification criticality (what happens at audit if it stays this way). Effort estimates live in the remediation plan, never in the gap score, because mixing them produces a roadmap that fixes easy things first rather than important ones. Insider Note: The fastest tell that a checklist is consultant-grade rather than a marketing download is whether it has a column for evidence location. Auditors don’t accept “yes” as evidence. If the checklist has nowhere to record where the proof lives, it wasn’t built by someone who has sat through a Stage 2. Pre-Engagement Preparation Consultants Complete Before the Gap Analysis Client AI Inventory and Use Case Cataloging Nothing in the checklist works without a complete AI inventory, and it’s the input clients get wrong most often. The inventory records every AI system in use: purpose, the role you play (developer, provider, deployer, or user), data consumed, outputs produced, whether a human sits between the output and the decision, and which third-party model or API it depends on. Consultants push hard on shadow AI here: SaaS tools that added AI features, agents running under employee credentials, and internal scripts calling model APIs. Every one of those is in scope until you document why it isn’t. Defining AIMS Scope Boundaries Clause 4.3 requires a scope statement naming which AI systems, business units, locations, and lifecycle stages the AIMS covers. Consultants draft this from the inventory, not before it. Scope discipline matters commercially too: certification bodies price audits by audit days, and audit days scale with scope. A narrow, well-justified first scope (the customer-facing AI product, say, rather than every internal tool) is usually the right call for a first certification. Stakeholder Interview Planning The checklist needs answers from people who don’t write policies. A typical interview plan covers the executive sponsor (clause 5), the AI or product lead (clauses 6 and 8), data engineering (A.7), procurement or vendor management (A.10), legal or privacy (A.5, A.8), and at least one front-line user of the AI system (A.9). Consultants interview the doers separately from the document owners, because the distance from what the procedure says to what actually happens is the finding. Document Request List (DRL) Consultants Send Clients The DRL goes out one to two weeks before fieldwork. A standard ISO 42001 DRL asks for the AI inventory; existing AI, security, and data policies; org chart with AI governance roles; any AI risk assessments or impact assessments; model documentation (model cards, system cards, or whatever exists); training-data provenance and data quality records; supplier contracts for third-party models; incident and change logs; training records; any ISO 27001 ISMS documentation; and the last internal audit and management review minutes if they exist. Missing items become findings rather than delays. Pro Tip: Return an Honest DRL Return the DRL with a column that says “does not exist” wherever that’s true. Consultants would rather know on day one than discover it in a workshop. An honest DRL shortens fieldwork by days and makes the maturity scores more accurate, which makes the remediation plan cheaper. Clause-by-Clause Checklist Consultants Use (ISO 42001 Clauses 4 to 10) ISO 42001 follows the Harmonized Structure shared with ISO 27001 and ISO 9001, so clauses 4 to 10 will look familiar to anyone who has run an ISMS. What’s different is the content each clause demands. Clause 4 – Context of the Organization Checkpoints Consultants check for a documented analysis of

Read More »