Certification
ISO/IEC 27001:2022 certified
TicketMatch is built and operated by W69 AI Consultancy, which holds an ISO/IEC 27001:2022 certificate issued by an independent, accredited certification body. This page sets out what that covers and how you can verify it yourself.
The certificate
The details exactly as they appear on the certificate.
| Certificate holder | W69 AI Consultancy, Oosterhoutlaan 15, 1181 AL Amstelveen, The Netherlands |
|---|---|
| Relationship to TicketMatch | W69 AI Consultancy builds and operates the TicketMatch platform |
| Standard | ISO/IEC 27001:2022 |
| Scope | Information Security Management System for the provision of Artificial Intelligence (AI) advisory and implementation consultancy services |
| Certificate number | IQ002141S0926WAC |
| Date of issue | 14 September 2026 |
| Valid until | 13 September 2029 |
| Statement of Applicability | version 1.1, dated 1 September 2026 |
| Certification body | Innovative Quality Certifications Pvt. Ltd. (IQCPL) |
| Accreditation | NABCB, signatory to the IAF Multilateral Recognition Arrangement |
| Surveillance | annual surveillance audits in 2027 and 2028, recertification in 2029 |
We do not display the NABCB or IAF marks here. Those marks belong to the accreditation body and carry their own conditions of use. They appear on the certificate itself, which you are welcome to request.
What the management system covers
Of the 93 controls in Annex A, 83 are declared applicable; the exclusions are justified in the Statement of Applicability. These are the main domains.
Policy and risk assessment
A formal information security policy with a risk assessment that is reviewed periodically, and a management review that records decisions.
Classification and use of AI services
Which language models and AI services may be used, per classification level, and whether a data processing agreement is in place.
Access control and authentication
An access register and multi-factor authentication on every account that supports it, with a documented emergency access procedure.
Client engagements and privileged access
Administrator access at client organisations is recorded with date, reason and end date, and reviewed periodically.
Suppliers and processors
A supplier register recording whether a processing agreement exists for each party, plus the GDPR article 30 record of processing activities.
Backup and restore
A backup schedule with a restore test that has actually been performed and documented.
Incidents and notification duties
An incident procedure with notification deadlines and root cause analysis, exercised in practice and evaluated.
Retention and document control
A retention schedule per data type, and version control on every controlled document.
Verify it yourself
A certificate you cannot check is not a certificate. Three steps, all free of charge.
1. The certificate
Request it from us and verify number IQ002141S0926WAC with the certification body at [email protected].
2. The body
Verify that IQCPL is accredited for ISMS in the register of NABCB, the Indian accreditation body.
3. The recognition
Verify that NABCB is a signatory to the IAF Multilateral Recognition Arrangement, which gives the certificate international standing.
Frequently asked questions
Who holds the certificate?
W69 AI Consultancy, the company that builds and operates TicketMatch. The certificate is issued in that name and can be verified under that name with the certification body.
What does the scope cover?
The scope as printed on the certificate is the provision of artificial intelligence advisory and implementation consultancy services. If your procurement process needs the exact wording, it is quoted in full above and we will send you the certificate on request.
Which version of the standard is this?
The 2022 version, ISO/IEC 27001:2022, with 93 controls across four themes. Certificates against the older 2013 version expired in 2025 and are no longer valid.
How do I verify this certificate?
Request the certificate from us and verify the number with the certification body at [email protected]. Then verify that IQCPL is accredited for ISMS in the NABCB register, and that NABCB is a signatory to the IAF Multilateral Recognition Arrangement.
Can I see the underlying documents?
We share the Statement of Applicability and the information security policy on request as part of a supplier assessment. The risk assessment and the registers are internal, because they contain data relating to other clients.
Does your procurement team send a supplier questionnaire?
We will complete it. Get in touch and we will include the certificate and the Statement of Applicability.
Email us