bcom ICT holds no organisational ISO certification. bcom ICT operates practices aligned to ISO/IEC 27001:2022, ISO/IEC 20000-1:2018 and ISO 22301, and delivers AI work under an ISO/IEC 42001-aligned framework. Ollie holds ISO/IEC 42001:2023 Lead Implementer certification issued by BSI — an individual credential, not an organisational one.
Aligned is not certified
An organisation is certified to an ISO standard when an accredited certification body has audited it and issued a certificate. In Australia those bodies are accredited by JAS-ANZ. Everything short of that is alignment: operating and documenting the practices a standard describes, without an independent auditor verifying them.
The distinction matters for two reasons. Practically, if your procurement process requires certified suppliers, alignment won't satisfy it — better you know that now than at the end of a tender. Legally, implying a certification you don't hold is misleading conduct under Australian Consumer Law.
So bcom ICT does not describe itself as ISO certified, ISO accredited or ISO compliant, and if you ever see those words used about us, they're wrong and we'd like to know where you saw them.
What we work to, and our status against each
| Standard | How we use it | Status |
|---|---|---|
| ISO/IEC 27001:2022 Information security management | The one clients and tenders name. bcom ICT operates an information security management system built around it — asset inventory, access control, supplier management, incident handling and documented review. | Aligned. Not certified. |
| ISO/IEC 20000-1:2018 IT service management | The ISO standard ITIL practices map into. For a managed service provider this describes how we deliver better than 27001 does: service catalogue, service levels, incident and problem management, change control. | Aligned. Not certified. |
| ISO/IEC 42001:2023 AI management systems | Governance for AI systems — policy, risk assessment, acceptable use, human oversight and audit evidence. This is the one where we have a formally certified individual rather than just familiarity. | Aligned. Ollie holds Lead Implementer certification, issued by BSI. |
| ISO 22301 Business continuity | Underpins how we design backup, disaster recovery and incident response — recovery objectives agreed in advance, restores tested rather than assumed, and a documented plan rather than an intention. | Aligned. Not certified. |
| ISO/IEC 27017 & 27018 Cloud security and cloud privacy | Referenced when we design Microsoft 365 and Azure environments, particularly around tenant configuration, data residency and handling personal information in cloud services. | Referenced. Not a programme we run. |
What ISO 27001 alignment actually involves here
"Aligned" can mean anything from a genuine management system to a downloaded policy nobody reads. Ours means the following are in place, documented and reviewed:
- An asset inventory covering the systems and tooling we use to reach client environments
- Named individual access with multi-factor authentication enforced — no shared logins
- Access reviewed on staff change and revoked the day someone leaves
- Client credentials held in a dedicated password management platform
- A documented incident response process, including our obligations to notify affected clients
- Supplier and subcontractor management, covering the cabling contractors and vendor platforms we engage
- Backup and recovery for our own systems, with restores tested rather than assumed
- Periodic internal review, with findings recorded and actioned
Policies are available on request, under NDA where the content is sensitive. Procurement teams usually ask for the information security, access control and incident response ones.
Where the Essential Eight fits
For most Australian small and medium businesses, the ASD Essential Eight is more useful than anything ISO-related. It's the baseline Australian auditors, insurers and boards actually reference, it costs nothing to work against, and progress is measurable in maturity levels rather than a pass/fail audit.
We operate client environments against it and can assess where you currently sit — see Essential Eight assessment and uplift. If you're weighing up where to spend a limited security budget, that's almost always the better first question.
AI work is delivered under an ISO/IEC 42001-aligned governance framework — policy, risk assessment, acceptable-use controls, human oversight and audit evidence. See ISO/IEC 42001 AI governance.
Questions Gold Coast businesses ask us
Is bcom ICT certified to ISO 27001?
No. bcom ICT operates an information security management system aligned to ISO/IEC 27001:2022, but has not been audited or certified by an accredited certification body. In Australia those bodies are accredited by JAS-ANZ. Alignment means the controls are operated and documented; certification means an independent auditor has verified them. bcom ICT will not describe itself as ISO certified, ISO accredited or ISO compliant.
What's the practical difference between aligned and certified?
Alignment is our word for it. Certification is somebody else's. If your procurement process requires evidence from an accredited auditor, alignment won't satisfy it and we'll tell you that at the first conversation. If what you need is a provider that actually operates the controls and can show you the documentation, alignment is the substance and certification is the receipt.
Why aren't you certified?
Certification is a significant ongoing cost for a business our size, and for most of our clients it wouldn't change the service they receive. We've chosen to spend that money on the controls rather than the audit. If enough client demand makes certification worthwhile we'll pursue it, and we'd say so here before claiming it.
Ollie is ISO 42001 certified — doesn't that make the company certified?
No, and conflating those is the most common way IT providers overstate their position. Ollie holds a personal Lead Implementer certification issued by BSI, which means Ollie has been assessed as competent to implement an AI management system. It says nothing about whether bcom ICT as an organisation has been audited. We keep those claims separate everywhere on this site and in our schema markup.
Can we see your policies?
Yes, on request and under NDA where the content is sensitive. Information security policy, access control, incident response and supplier management are the ones usually asked for during a procurement process.
Which framework matters most for an Australian business?
The ASD Essential Eight, generally. It's the baseline Australian auditors, insurers and boards actually reference, it's free to work against, and it's far more achievable for a small business than ISO certification. Most of our clients get more value from moving up an Essential Eight maturity level than from anything ISO-related.
Need our policies for a procurement process?
Tell us which ones and we'll send them, under NDA where the content is sensitive.