News

Mongolia's banks are being judged on privacy now, not just security

Khan Bank has entered a new certification cycle for ISO 27001 and ISO 27701, and remains the only bank in Mongolia certified to the privacy standard. What that says about where the sector is heading.

MSCi · ١٢ أغسطس ٢٠٢٦

Khan Bank has entered a new certification cycle for both ISO/IEC 27001 and ISO/IEC 27701, holding accredited certification for its information security management system and for its privacy information management system. It remains the only bank in Mongolia certified to ISO/IEC 27701.

That second point is the interesting one. ISO 27001 is now familiar in Mongolian banking. Boards understand it, procurement teams ask for it, and most of the sector either holds it or is working towards it. ISO 27701 is a different question, and the gap between the two says something about where the pressure is moving.

The difference between securing data and being accountable for it

ISO 27001 asks whether you have control of your information: who can reach it, what happens when something goes wrong, how you know your controls still work. It is a security standard, and it is answered largely in the language of risk.

ISO 27701 extends that system to personal data specifically, and asks a harder set of questions. On what lawful basis are you holding this? What did you tell the customer you would do with it? Can you show, on demand, every place a person's data has travelled inside your organisation and every third party that touched it? Can you act on a request to correct or delete it, within the time the law allows, without a project?

A bank can pass the first and struggle with the second. Data that is well protected can still be data you were never entitled to hold, or held for longer than you said, or shared with a processor nobody documented.

Why this is becoming a Mongolian question

Mongolia's legal position changed in December 2021, when Parliament adopted the Law on Cyber Security and the Law on Personal Data Protection on the same day. The data protection law took effect on 1 May 2022. Taken together they moved two things from good practice to legal obligation: protecting information, and being answerable for personal information.

The cyber security law defines critical information infrastructure to include the payment sector, energy, health, database operators and border ports. Banks sit squarely inside that definition. Operators of critical information infrastructure carry duties that are operational rather than declarative: regular security audits, continuous monitoring, vulnerability management, penetration testing, incident reporting, and business continuity planning. The National Cyber Security Centre coordinates threat intelligence, monitoring and national incident response.

The personal data protection law adds a separate set: a lawful basis for every processing activity, appropriate security controls, confidentiality and integrity of personal data, collection limited to a legitimate purpose, and records of processing activities.

That last one is where a great many organisations discover a problem. A record of processing activities is not a policy. It is an inventory, and building one honestly tends to surface data nobody remembered collecting.

The threats have not changed much, but the consequences have

The threat picture facing Mongolian organisations is the familiar one: ransomware, phishing, financial fraud, insider misuse, supply chain compromise and attacks on critical infrastructure. None of that is unique to Mongolia.

What has changed is what follows an incident. A breach used to be an IT problem with a reputational tail. Under the current framework it is a reportable event with a regulator on the other end, and the questions afterwards are not only about how the attacker got in. They are about what personal data was reachable, why it was there, who else had it and whether anyone had written that down before the incident.

An organisation that can answer those questions in an afternoon is in a very different position from one that starts finding out during an investigation.

What certification is actually worth here

It is worth being blunt: a certificate on a wall prevents nothing. What has value is the system it certifies, and the fact that an independent auditor tested it against a published standard rather than against the organisation's own opinion of itself.

For a bank, three things tend to come out of doing this properly. The first is an honest data inventory, which is usually the first time anyone has seen the full picture. The second is a set of procedures that survive the person who wrote them leaving. The third is evidence, generated as a by product of working normally rather than assembled in a panic when someone asks.

Entering a new certification cycle matters more than a first certificate, because recertification is where systems that were built for the audit tend to come apart. A management system that is still working three years later is one that was built into how the bank runs rather than alongside it.

Where the rest of the sector stands

ISO 27001 has become close to an expectation in Mongolian banking. ISO 27701 has not, yet, and the reason is usually not reluctance. It is that privacy management is genuinely harder to retrofit. It requires the business to say what it does with personal data, not just the security team to say how it is protected, and those conversations reach into product, marketing, collections and procurement.

Our view is that this gap closes rather than widens. Regulators across the region are converging on the same expectations, correspondent banks are asking sharper questions in due diligence, and customers are becoming less tolerant of vague answers about their own data.

If you are considering it

Start with the inventory, not the standard. Before deciding whether to certify, find out what personal data your organisation holds, where it is, who can reach it and what you have already told customers about it. That exercise usually determines both how much work certification will be and whether you have a problem that needs fixing regardless.

We advise organisations in Mongolia on both standards, from gap analysis through implementation and training to audit readiness. We consult and prepare; certification is issued by an independent accredited body, and that separation is what makes the preparation worth paying for.

If a customer, a regulator or a correspondent bank has put one of these standards in front of you, tell us who is asking and what they asked for. That determines the scope, the timeline and the cost, and we will tell you all three in writing before you commit to anything.

See how this looks as a working system

Reading about a requirement and seeing the documentation that satisfies it are different things. In a short demo we open the actual manual, procedures and records set for ISO/IEC 27001, show you how each clause is answered and where your existing way of working already fits. You will know what implementation involves before you commit to it.

Ask us about this

Tell us what is being asked of you and by whom.

What are you looking for?

We reply within one working day. Your details stay with our consultants.

More reading

All articles