Why we don't build blackbox automation
Blackbox automation means: no traceability, no escalation model, no documentation. That's not how we work at NordFlux.
ISO 27001 as a selection criterion for automation partners: What the certificate really proves and what SMEs should check instead.

Anyone who commissions an external partner to automate accounts receivable, CRM, or recruitment management inevitably gives them access to sensitive data: customer records, financial figures, sometimes also personnel files. The question "is the provider ISO 27001-certified" increasingly appears in tenders and initial talks. However, many SMEs don't know exactly what the certificate proves and what it doesn't cover. This article clarifies what actually matters when selecting an automation partner.
ISO/IEC 27001:2022 specifies the requirements for an information security management system (ISMS) and is therefore not a seal for a single tool, but evidence of systematic, repeatedly verified processes throughout the enterprise. Annex A of the standard contains 93 controls in four categories: 37 organizational, 8 personnel-related, 14 physical, and 34 technological measures, as the expert analysis from secjur on the current version shows. The predecessor version from 2013 still had 114 controls, the reduction to 93 came with a clearer structure and eleven new measures, such as cloud security and activity monitoring.
There are two paths to certification: natively according to ISO/IEC 27001:2022 with free choice of method, or based on IT-Grundschutz according to the methodology of the Federal Office for Information Security (BSI, Standards 200-1 to 200-4). Both paths lead according to BSI to the internationally recognized ISO 27001 certificate, the IT-Grundschutz path is publicly documented in the BSI certificate schema and the issued certificates are viewable there. For the selection of a partner, this is relevant because both paths are considered equivalent, but are verifiable in different levels of detail.
Total damage from data theft, espionage, and sabotage in the German economy was 289.2 billion euros in 2025, according to Bitkom-Studie Wirtschaftsschutz 2025 202.4 billion euros (70 percent) on cyberattacks. 34 percent of surveyed companies were affected by ransomware, almost three times as many as in 2022. An RPA bot, an n8n workflow, or a Copilot agent needs access credentials and API access to ERP, CRM, or DATEV to be able to automate at all. If the automation partner itself is compromised, that's a direct path into the customer's systems. The information security of the partner is therefore not a formal side matter, but a real extension of one's own attack surface.
A displayed certificate alone says little without checking validity and scope. Four points are worth checking concretely:
Important for expectations: At the end of 2022, only around 1,582 companies in Germany were certified to ISO 27001, according to figures from Statista show, out of around 3.1 million companies in total. A missing certificate is thus not an automatic exclusion criterion for a competent automation partner, but it shifts the burden of proof to other, equally verifiable evidence.
Without ISO 27001 certification, a proper data processing agreement (DPA) under Art. 28 GDPR and documented technical and organizational measures (TOMs) are the minimum that every reputable automation partner must be able to provide. The DPA is mandatory anyway once personal data is processed, regardless of any certification. Additionally, it's worth asking about server location (Germany or EU), access concepts for individual automations, and whether incidents in the past were documented and reported.
NordFlux also does not present itself to customers with its own ISO 27001 certificate, but with a DPA per customer, documented TOMs, and data storage in German and European data centers respectively. This transparency, not just a seal, is the standard we recommend to SMEs for selecting any automation partner. These questions therefore belong in every AI Consulting before the first project, because they ultimately concern exactly the Interface Integration through which sensitive data flows.
By Simon Glowik, published July 9, 2026.
No, for most industries. Only in regulated sectors such as CRITIS operators or parts of the financial sector can certification practically be required. For SMEs, ISO 27001 today is more of an increasingly common customer requirement than a legal obligation.
This is the alternative certification path via BSI methodology instead of free choice of method. An auditor approved by BSI reviews reference documents and conducts an on-site review, and the BSI then decides on issuing the ISO 27001 certificate.
A certification based on IT-Grundschutz is valid for three years, after which recertification is required. Annual surveillance audits take place in between. So it's worth asking about the date of the last audit, not just about the certificate itself.
A mere self-declaration without substance is not sufficient. A sound data processing agreement under Art. 28 GDPR and documented technical and organizational measures are the minimum that every automation partner should be able to provide regardless of ISO certification.
For certificates based on IT-Grundschutz, the issuance can be looked up in the BSI's public certificate list. For native ISO 27001 certificates, checking the accreditation of the issuing certification body, such as the German Accreditation Body (DAkkS), or making a direct inquiry to the body helps.
NordFlux builds digital employees for organisations: automations and AI agents that take over repetitive work. You stay in control.
Blackbox automation means: no traceability, no escalation model, no documentation. That's not how we work at NordFlux.
Seven questions that separate a serious partner from a software vendor, from data sovereignty and tool neutrality to the question of who actually owns the solution in the end.
The legitimate fear of dependency: how an automation is handed over so your team understands it, runs it, and can adjust it themselves if needed.
A certificate alone says little about how an automation partner actually handles your data and access rights. We disclose our security measures openly and show you, in conversation, which forms of evidence demonstrate solid security even without ISO 27001 certification.