Does ISO/IEC 27001 ISMS certification — increasingly customer-mandated apply to fintech (non-bank) businesses?
A computed answer from the Rules Mate applicability engine, with the exact condition, the outcome for every structure and size, and the primary source.
Short answer: Only if
Only if your customers or tenders require ISO 27001. Being in this industry makes the obligation worth checking (Industry: Fintech (non-bank)), but the trigger is a fact the industry alone does not settle.
The obligation in brief
ISO/IEC 27001 ISMS certification — increasingly customer-mandated. ISO/IEC 27001 sets requirements for an Information Security Management System (ISMS). Certification by accredited certification body (JAS-ANZ).
Trigger: Customer or tender requirement.
Why fintech (non-bank) get a different answer
Rules Mate runs its applicability engine across 9 business structures and 6 size bands for each of the 35 industries it maps. For 33 of those industries the answer for "ISO/IEC 27001 ISMS certification — increasingly customer-mandated" is no. Fintech (non-bank) is one of the 2 where the answer is different: only if.
The deciding fact for fintech (non-bank) businesses: Industry: Fintech (non-bank); applies only if your customers or tenders require ISO 27001.
About the industry: Non-bank financial technology businesses — neobanks, BNPL, payment processors, crypto exchanges.
Compare a professional services (general) business with 6–19 employees structured as a Pty Ltd company: the obligation does not apply (Requires a trigger outside this questionnaire).
Answer by business structure and size
Each cell is the engine's outcome for a business in fintech (non-bank) with that structure and size, assuming it sells to consumers and small businesses and holds customer contact details. "Check" means the obligation turns on a fact the industry does not settle.
| Structure | No employees | 1–5 employees | 6–19 employees | 20–99 employees | 100–499 employees | 500+ employees |
|---|---|---|---|---|---|---|
| Sole trader | Check | Check | Check | Check | Check | Check |
| Partnership | Check | Check | Check | Check | Check | Check |
| Trust | Check | Check | Check | Check | Check | Check |
| Pty Ltd company | Check | Check | Check | Check | Check | Check |
| Public company | Check | Check | Check | Check | Check | Check |
| Not-for-profit (unregistered) | Check | Check | Check | Check | Check | Check |
| Registered charity | Check | Check | Check | Check | Check | Check |
| Super fund | Check | Check | Check | Check | Check | Check |
| Foreign company | Check | Check | Check | Check | Check | Check |
What the obligation requires
- When due
- Continuous; surveillance audits + recertification cycle.
- Evidence to keep
- ISMS documentation; ISO 27001 certificate; audit reports.
- Maximum penalty
- Loss of certification + commercial / tender consequences
- Regulator
- ASD
- Jurisdiction
- Commonwealth (national)
Other obligations where fintech (non-bank) differ from the norm
- Major banks must provide CDR Banking + Action Initiation (2026): Only if
- Comply with CDR Banking (Open Banking) — major + non-major ADIs: Only if
- Comply with Stored Value Facility rules (banking exception): Only if
- Consumer Data Right (CDR) participant accreditation + compliance: Only if
- Payment Service Provider (PSP) licensing reform — implementation pending: Only if
- Register R&D activities for the R&D Tax Incentive: Only if
- All 8 answers for fintech (non-bank)
Other industries with a non-default answer
Questions
- Does ISO/IEC 27001 ISMS certification — increasingly customer-mandated apply to fintech (non-bank) businesses?
- Only if your customers or tenders require ISO 27001. Being in this industry makes the obligation worth checking (Industry: Fintech (non-bank)), but the trigger is a fact the industry alone does not settle.
- Is the answer the same for every industry?
- No. For 33 of the 35 industries Rules Mate maps, the answer is no. Fintech (non-bank) is one of 2 industries with a different answer.
Related
Sources
Computed by the Rules Mate applicability engine from the published obligation corpus; facts last checked 3 October 2026. Rules Mate is not a law firm and this is general information, not legal advice. Confirm your position with the regulator source or a qualified adviser before acting.