BAT Software is now ISO 27001 certified
28/09/2026
We are very proud to announce that BAT Software has achieved ISO 27001 certification.
For a platform that handles important business and client information every day, security has always been a fundamental part of how BAT was built. Achieving ISO 27001 certification provides independent recognition of the work, processes and controls we have put in place to manage information securely.
What is ISO 27001?
ISO 27001 is the world's best-known standard for Information Security Management Systems (ISMS). It sets out the requirements organisations must follow to establish, implement, maintain and continually improve the way they manage information security.
Importantly, ISO 27001 is not simply about having antivirus software, strong passwords or secure servers.
It looks at information security across the organisation, including how risks are identified and managed, how access to information is controlled, how incidents are handled, how employees work with sensitive information and how security processes are continually reviewed and improved.
It provides a structured, risk-based approach to protecting information rather than treating cybersecurity as a collection of individual technical measures.
Why is this important for BAT customers?
Financial services businesses deal with significant amounts of sensitive information, so customers need to know that the technology providers they work with take information security seriously.
Our ISO 27001 certification demonstrates that BAT has implemented a formal Information Security Management System and that information security is embedded into the way we operate.
For our customers, this provides additional reassurance around areas such as:
- Protecting sensitive business and client information
- Identifying and managing information security risks
- Maintaining appropriate access controls
- Having defined processes for managing security incidents
- Regularly reviewing our security arrangements
- Continually improving the way information security is managed
ISO 27001 specifically requires organisations to maintain and continually improve their information security, meaning certification is not simply a one-off security exercise.
A major achievement for BAT
Achieving ISO 27001 certification is a significant milestone for BAT.
It requires much more than introducing a handful of new security policies. It involves reviewing how information is handled throughout the business, formally assessing risks, documenting processes, implementing appropriate controls and demonstrating that those processes are being followed.
A huge amount of work has therefore taken place behind the scenes to reach this point.
The project has been led by our Cyber Security Lead, Alvaro Gonzalez, who has worked extensively across the business to develop, review and implement the processes required to achieve certification.
We would like to recognise Alvaro's work and commitment throughout the process. Reaching this standard is a fantastic achievement and represents an important step in the continued development of BAT.
So, what now?
BAT has developed considerably over the last few years, with new features, integrations and AI capabilities becoming an increasingly important part of the platform.
As the platform continues to grow, the way we protect information needs to grow with it.
Achieving ISO 27001 certification gives us a strong framework for doing exactly that, ensuring cyber security continues to be considered across our technology, our processes and the way we operate as a business.
ISO 27001 certification is not the end of that work. It is an important confirmation of the standards we have established and a framework for continuing to improve them in the future.