Monk is Now ISO 27001 Certified

Monk is now certified to ISO/IEC 27001:2022. Sensiba, the firm that issued our SOC 2 Type II report, performed the audit. The certification covers the Monk platform and the information security management system behind it.
If you are here because a security questionnaire asked, the answer is yes. The certificate is available on request from your Monk contact, along with our SOC 2 Type II report and our most recent penetration test.
What ISO 27001 certifies
ISO 27001 certifies a management system, not a product. The auditor checks two things: that the company has a documented way to identify security risks and decide how to handle them, and that it actually runs that process.
Four things have to be in place:
- A documented Information Security Management System
- A risk assessment built from the business as it exists
- A set of controls selected from Annex A, which holds 93 controls across organizational, people, physical and technological categories, with a written justification for every control excluded
- A cycle of internal audits and management review that keeps all of it current
If you are reviewing a vendor, check which edition the certificate names. ISO/IEC 27001:2022 replaced the 2013 version and restructured Annex A from 114 controls into 93, adding eleven new ones covering areas including threat intelligence, cloud services and secure coding.
How we got here
We started in June 2026 and ran ISO 27001 alongside our SOC 2 Type II, so the two landed close together.
Cognisys ran the gap assessment, wrote the ISMS policy set with us, and conducted our internal audit over two days in August. Sensiba performed the external audit in two stages, beginning in September. Vanta held the control evidence throughout and mapped it to the 27001:2022 framework.
It took about three months from kickoff to a passed Stage 2 audit. Most of the underlying controls already existed from SOC 2, so what ISO added was the management system around them: the risk methodology, the Statement of Applicability, the governance cadence, and a documented review that happens on a schedule rather than when a customer asks for it.
The rest was evidence collection: pulling twelve months of operational data, closing out documentation tests one at a time, and getting every person and device in scope onto the same posture, which at a company our size means chasing individual laptops.
What is in scope
The certification covers Monk's platform and the information security management system supporting it, across the company.
We run a bring your own device model for laptops. In-scope machines are tracked for required posture: screen lock, malware protection, password manager and agent enrollment. Access runs through SSO with MFA. Mobile devices sit outside the ISO device scope unless they are used for privileged or administrative access.
Our infrastructure runs on AWS, Vercel and Supabase, each holding its own ISO 27001 certification. We review each sub-processor as part of our own risk assessment.
The certificate carries the formal scope wording. Ask your Monk contact for a copy if your security review needs it verbatim.
ISO 27001 and SOC 2 answer different questions
We hold both, which is increasingly what larger buyers ask for.
| SOC 2 Type II | ISO 27001 | |
|---|---|---|
| What it produces | An attestation report from an audit firm | A certificate from a certification body |
| What it examines | Whether stated controls operated effectively over a defined period | Whether a management system for security exists and is being run |
| Where it is expected | Predominantly North America | International, and common in European and enterprise procurement |
| How it renews | A new report each period | Surveillance audits annually, full recertification every three years |
The short version: SOC 2 shows specific controls worked over a period. ISO 27001 shows there is a system keeping those controls current.
Why this matters for receivables data
More than $2B in receivables runs on Monk. The data behind that includes customer lists, payment histories, banking details and the full contents of collections conversations between our customers and their customers.
A finance team handing that over is handing over the record of who owes them money, who pays late, and what was said about it. That is why security review sits where it does in the buying process. More buyers now ask for ISO 27001 by name, and outside North America it is often the default requirement.
What changes for customers
Nothing changes in how Monk works day to day. The controls have been in place, and the certification is independent confirmation that they hold together as a system.
What it does change:
- Security review can be shorter. If your process accepts ISO 27001 in place of a custom questionnaire, you can now use it.
- International procurement gets easier. ISO 27001 is the more common ask outside North America and in regulated sectors.
- It gets checked every year. Surveillance audits run annually, with full recertification every three years. If a surveillance audit is not passed, the certificate lapses.
How to get the documentation
Ask your Monk contact for the certificate, our SOC 2 Type II report or our latest penetration test. We share them under NDA where required. If your security team needs something this post does not cover, we will send it directly.
Frequently asked questions
Is Monk ISO 27001 certified?
Yes. Monk is certified to ISO/IEC 27001:2022. The certificate is available on request, alongside our SOC 2 Type II report.
Who certified Monk?
Sensiba performed the certification audit. ISO does not certify organizations itself. Certification is always carried out by an external certification body, and certificates can be verified through the International Accreditation Forum's IAF CertSearch database.
Does Monk have SOC 2?
Yes. Monk holds a SOC 2 Type II attestation, which we maintain alongside ISO 27001. Most buyers accept either. Enterprise and international buyers often ask for both.
What is the difference between ISO 27001 and SOC 2?
SOC 2 is an attestation report on whether specific controls operated effectively over a defined period. ISO 27001 is a certification that an information security management system exists and is being run. SOC 2 is more common in North America and ISO 27001 internationally.
What is in scope of the certification?
The Monk platform and the information security management system supporting it. The certificate carries the formal scope wording, which we provide on request.
How long is the certification valid?
Three years, with surveillance audits each year. Certification lapses if a surveillance audit is not passed.
How do I get a copy of the certificate?
Ask your Monk contact. We provide the certificate, the SOC 2 Type II report and our latest penetration test under NDA where required.



.avif)