In this article

Monk is Now ISO 27001 Certified

September 30, 2026
5
min read
Company-News
Monk is now ISO 27001 certified, with an engraved Information Security Management seal

Monk is now certified to ISO/IEC 27001:2022. Sensiba, the firm that issued our SOC 2 Type II report, performed the audit. The certification covers the Monk platform and the information security management system behind it.

If you are here because a security questionnaire asked, the answer is yes. The certificate is available on request from your Monk contact, along with our SOC 2 Type II report and our most recent penetration test.

What ISO 27001 certifies

ISO 27001 certifies a management system, not a product. The auditor checks two things: that the company has a documented way to identify security risks and decide how to handle them, and that it actually runs that process.

Four things have to be in place:

  • A documented Information Security Management System
  • A risk assessment built from the business as it exists
  • A set of controls selected from Annex A, which holds 93 controls across organizational, people, physical and technological categories, with a written justification for every control excluded
  • A cycle of internal audits and management review that keeps all of it current

If you are reviewing a vendor, check which edition the certificate names. ISO/IEC 27001:2022 replaced the 2013 version and restructured Annex A from 114 controls into 93, adding eleven new ones covering areas including threat intelligence, cloud services and secure coding.

How we got here

We started in June 2026 and ran ISO 27001 alongside our SOC 2 Type II, so the two landed close together.

Cognisys ran the gap assessment, wrote the ISMS policy set with us, and conducted our internal audit over two days in August. Sensiba performed the external audit in two stages, beginning in September. Vanta held the control evidence throughout and mapped it to the 27001:2022 framework.

It took about three months from kickoff to a passed Stage 2 audit. Most of the underlying controls already existed from SOC 2, so what ISO added was the management system around them: the risk methodology, the Statement of Applicability, the governance cadence, and a documented review that happens on a schedule rather than when a customer asks for it.

The rest was evidence collection: pulling twelve months of operational data, closing out documentation tests one at a time, and getting every person and device in scope onto the same posture, which at a company our size means chasing individual laptops.

What is in scope

The certification covers Monk's platform and the information security management system supporting it, across the company.

We run a bring your own device model for laptops. In-scope machines are tracked for required posture: screen lock, malware protection, password manager and agent enrollment. Access runs through SSO with MFA. Mobile devices sit outside the ISO device scope unless they are used for privileged or administrative access.

Our infrastructure runs on AWS, Vercel and Supabase, each holding its own ISO 27001 certification. We review each sub-processor as part of our own risk assessment.

The certificate carries the formal scope wording. Ask your Monk contact for a copy if your security review needs it verbatim.

ISO 27001 and SOC 2 answer different questions

We hold both, which is increasingly what larger buyers ask for.

SOC 2 Type IIISO 27001
What it producesAn attestation report from an audit firmA certificate from a certification body
What it examinesWhether stated controls operated effectively over a defined periodWhether a management system for security exists and is being run
Where it is expectedPredominantly North AmericaInternational, and common in European and enterprise procurement
How it renewsA new report each periodSurveillance audits annually, full recertification every three years

The short version: SOC 2 shows specific controls worked over a period. ISO 27001 shows there is a system keeping those controls current.

Why this matters for receivables data

More than $2B in receivables runs on Monk. The data behind that includes customer lists, payment histories, banking details and the full contents of collections conversations between our customers and their customers.

A finance team handing that over is handing over the record of who owes them money, who pays late, and what was said about it. That is why security review sits where it does in the buying process. More buyers now ask for ISO 27001 by name, and outside North America it is often the default requirement.

What changes for customers

Nothing changes in how Monk works day to day. The controls have been in place, and the certification is independent confirmation that they hold together as a system.

What it does change:

  • Security review can be shorter. If your process accepts ISO 27001 in place of a custom questionnaire, you can now use it.
  • International procurement gets easier. ISO 27001 is the more common ask outside North America and in regulated sectors.
  • It gets checked every year. Surveillance audits run annually, with full recertification every three years. If a surveillance audit is not passed, the certificate lapses.

How to get the documentation

Ask your Monk contact for the certificate, our SOC 2 Type II report or our latest penetration test. We share them under NDA where required. If your security team needs something this post does not cover, we will send it directly.

Frequently asked questions

Is Monk ISO 27001 certified?

Yes. Monk is certified to ISO/IEC 27001:2022. The certificate is available on request, alongside our SOC 2 Type II report.

Who certified Monk?

Sensiba performed the certification audit. ISO does not certify organizations itself. Certification is always carried out by an external certification body, and certificates can be verified through the International Accreditation Forum's IAF CertSearch database.

Does Monk have SOC 2?

Yes. Monk holds a SOC 2 Type II attestation, which we maintain alongside ISO 27001. Most buyers accept either. Enterprise and international buyers often ask for both.

What is the difference between ISO 27001 and SOC 2?

SOC 2 is an attestation report on whether specific controls operated effectively over a defined period. ISO 27001 is a certification that an information security management system exists and is being run. SOC 2 is more common in North America and ISO 27001 internationally.

What is in scope of the certification?

The Monk platform and the information security management system supporting it. The certificate carries the formal scope wording, which we provide on request.

How long is the certification valid?

Three years, with surveillance audits each year. Certification lapses if a surveillance audit is not passed.

How do I get a copy of the certificate?

Ask your Monk contact. We provide the certificate, the SOC 2 Type II report and our latest penetration test under NDA where required.

Automate Accounts Receivable with Monk
Monk brings together collections, cash application, and forecasting. 40% DSO reduction. $2B+ in receivables managed. 26 hours a month back to your team.
Book a demo

Manual AR is death by a thousand cuts

Deploy the Monk platform on your toughest AR problems.