Security

ISO 27001 and GDPR-proof process modelling for EU consultants

Thom Uffing

If you run an EU consultancy and need client processes documented quickly without drawing them by hand, the short answer is this: record the stakeholder interview, let AI generate a BPMN 2.0 model from it, and validate that model in the same session. The compliance part is not a separate step. It comes down to where the data is processed, whether it is encrypted, and whether it is used to train somebody's model.

Those three questions are the ones your client's security officer will ask. This piece answers them, then gives you a checklist for evaluating any tool against them.

The three questions that actually decide it

Most compliance conversations about software get lost in certificates. For process documentation specifically, only three things matter, because process models contain how a business really works and often who does what by name.

  • Where is it processed and stored? Inside the EU, or transferred out under some mechanism you now have to defend.

  • Is it encrypted, in transit and at rest? And who holds the keys.

  • Is your client's data used to train a model? For most AI tools the honest answer is yes by default.

That third one catches people out. A general purpose AI tool will happily ingest a recorded interview about a claims handling process and use it as training material. That is a very different conversation to have with a client than "the file sits encrypted on a server in Frankfurt".

How ISO 27001 and GDPR fit together

They are not the same thing and one does not give you the other.

GDPR is law. It governs how personal data is collected, stored and processed, with fines up to 20 million euro or 4% of global turnover. It requires you to report a breach within 72 hours, to honour the right to erasure, and to have a lawful basis for processing.

ISO 27001 is a voluntary certification. It requires an Information Security Management System with risk assessments, 93 Annex A controls covering access management, encryption, incident response and auditing, and an external audit to prove it.

Where they help each other: an ISMS built to ISO 27001 already implements most of the technical and organisational measures GDPR demands. So certification is good evidence, but it is not a GDPR compliance certificate, and any vendor who implies otherwise is overselling. ISO 27001 says nothing about consent, about the right to be forgotten, or about breach notification to individuals.

For a consultancy, the practical reading is: ISO 27001 tells you the vendor takes security seriously, GDPR tells you what you are still responsible for.

What to check before you put client data in a tool

Four things, in the order a security officer will ask about them.

Data residency. GDPR does not strictly require EU storage, but it heavily regulates transfers outside the EEA. Choosing a platform that processes and stores only within the EU removes that argument entirely. Ask for the actual server locations, not the company address.

A Data Processing Agreement. Any tool processing personal data on your behalf is a processor. You are obliged to have a DPA covering responsibilities, security measures and breach obligations. Check that it names the subprocessors, states retention periods, and says where data lives.

Encryption and access control. In transit and at rest, plus role-based access control so only the right people see a given client's processes. Audit trails matter too: for a compliance audit you need to show who changed what and when.

The training question, in writing. Not a marketing line, a contractual commitment that your input is not used to train models.

How ModelMatic answers those questions

ModelMatic turns a recorded interview, a transcript or an existing document into a validated BPMN 2.0 model in about two minutes, so the manual drawing disappears from your delivery. On the compliance side:

  • EU only. All data is processed and stored inside the EU.

  • Encrypted in transit and at rest, using Fernet and AWS KMS.

  • ISO 27001 certified, with the controls, penetration testing and incident response that comes with it.

  • No training on your data. Customer input, transcripts and generated models are never used to train models, ours or anyone else's. That is in the terms, not just the website.

The full detail, including subprocessors and current certification status, is in the Trust Center.

Because output is standard BPMN 2.0, models import straight into Bizzdesign, Blue Dolphin or SAP Signavio, so your client's process library stays inside their own governed toolchain rather than scattered across whatever each consultant happened to use.

Staying compliant after you have chosen the tool

Picking the right platform is the first step. The rest is your own process.

  1. Run a gap analysis. Compare how you document processes today against ISO 27001 and GDPR requirements. Interview recordings sitting in a personal Drive folder are usually the first thing you find.

  2. Map your data flows. From recording to archive. This is what GDPR Article 30 asks for and it makes a DPIA straightforward when you need one.

  3. Sign DPAs with every processor. Not just the modelling tool. Cloud storage, transcription services, everything in the chain.

  4. Set retention rules and enforce them. Decide how long interview recordings live, and delete them on schedule.

  5. Train the consultants. Most breaches in this space are someone emailing a process model to the wrong address, not an attacker.

Why this is becoming a selling point

Clients increasingly ask about data handling before they ask about price, particularly in finance, healthcare and government. A consultancy that can answer the three questions at the top of this article without checking with anyone wins work from one that cannot.

If you want to see how fast process discovery gets when the drawing disappears, read our playbook on accelerating process discovery, or start with what BPMN is if your team needs a shared baseline. Ready to test it on a real client process? Book a demo and bring one recorded interview.

Frequently Asked Questions

Find answers to the most important questions about ModelMatic.

What exactly is ModelMatic?

ModelMatic is an AI-driven platform that directly converts spoken language and documentation into professional BPMN 2.0 process models. We automate the manual drawing work, allowing business consultants and process analysts to focus on the content instead of the form.

How much time does ModelMatic really save me?

Is my data safe with ModelMatic?

What kind of sources can I convert into a process model?

Does ModelMatic work with my current systems?

What if the AI makes a mistake in the model?

What does ModelMatic cost?

Where can I go with further questions?

Frequently Asked Questions

Find answers to the most important questions about ModelMatic.

What exactly is ModelMatic?

ModelMatic is an AI-driven platform that directly converts spoken language and documentation into professional BPMN 2.0 process models. We automate the manual drawing work, allowing business consultants and process analysts to focus on the content instead of the form.

How much time does ModelMatic really save me?

Is my data safe with ModelMatic?

What kind of sources can I convert into a process model?

Does ModelMatic work with my current systems?

What if the AI makes a mistake in the model?

What does ModelMatic cost?

Where can I go with further questions?

Frequently Asked Questions

Find answers to the most important questions about ModelMatic.

What exactly is ModelMatic?

ModelMatic is an AI-driven platform that directly converts spoken language and documentation into professional BPMN 2.0 process models. We automate the manual drawing work, allowing business consultants and process analysts to focus on the content instead of the form.

How much time does ModelMatic really save me?

Is my data safe with ModelMatic?

What kind of sources can I convert into a process model?

Does ModelMatic work with my current systems?

What if the AI makes a mistake in the model?

What does ModelMatic cost?

Where can I go with further questions?

Purple Gradient Background

The future of process modelling starts now

See how quickly a conversation or a document turns into a model your team can work with.

Purple Gradient Background

The future of process modelling starts now

See how quickly a conversation or a document turns into a model your team can work with.

Purple Gradient Background

The future of process modelling starts now

See how quickly a conversation or a document turns into a model your team can work with.