Certified to ISO/IEC 27001:2022

Information security is governed, not assumed

Procura is certified to ISO/IEC 27001:2022, the internationally recognised standard for information security management systems.

The certification provides independent evidence that information security is managed through a structured, risk-based system of governance, controls, responsibilities and continuous review.

For Procura’s clients and institutional counterparties, this means that the management of information is embedded within a formally assessed operating framework.

Why this matters

Financial-grade infrastructure depends on the integrity of the information supporting decisions, transactions and governance.

ISO/IEC 27001:2022 provides a systematic framework for protecting the confidentiality, integrity and availability of information. It requires information-security risks to be identified, assessed, controlled and reviewed as systems, threats and business requirements evolve.

The certification demonstrates that Procura maintains a defined and independently assessed system for managing information-security risk.

What covers

The certification is formally held by Procura Services Germany GmbH, Procura’s German entity, and applies to the activities included within the certified scope.

These activities include:

  • data analytics;

  • reporting capabilities and transactional reports;

  • administrative support and corporate governance services;

  • operational consulting;

  • compliance advisory;

  • information technology services.

Across this scope, ISO/IEC 27001:2022 provides a structured framework for identifying and assessing information-security risks, implementing appropriate controls and maintaining clearly defined responsibilities.

This supports the consistent management of information and the continuous review and improvement of information-security practices across Procura’s certified activities.

Independent
certification by DEKRA

Procura Services Germany GmbH was certified by DEKRA Certification GmbH following an independent audit against the requirements of ISO/IEC 27001:2022.

DEKRA is an independent certification body providing audits and certifications against recognised national and international standards. Its role is different from that of the International Organization for Standardization and the International Electrotechnical Commission, which jointly publish the standard but do not certify individual organisations.

DEKRA’s independent assessment provides external validation that Procura’s certified information security management system meets the requirements of the standard.

Accredited certification

DEKRA Certification GmbH operates as an independent and accredited certification body.

The certificate carries the mark of DAkkS, the national accreditation body of the Federal Republic of Germany. Operating under a statutory mandate, DAkkS assesses the technical competence, independence and impartiality of certification bodies against internationally applicable requirements.

The certificate also carries the relevant international multilateral recognition mark. DAkkS’s participation in European and international recognition arrangements supports confidence in accredited certifications across global markets.

These accreditation references provide an additional level of assurance regarding the independence, competence and international standing of the certification process. The DAkkS and international accreditation marks are presented only as part of the original certificate and are not used as separate Procura communication assets.

The validity and details of the certification can be independently verified through DEKRA.

Verify the certification with DEKRA

Certificate details

Certified organisation
Procura Services Germany GmbH

Registered address
An der Welle 5
60322 Frankfurt
Germany

Standard
ISO/IEC 27001:2022

Certification body
DEKRA Certification GmbH

Certificate registration number
DS-0926030

Audit report number
A26041005

Statement of applicability
None

Valid from
2 September 2026

Valid until
1 September 2029

A continuing system of control

Certification is not a one-off statement. Maintaining conformity requires ongoing monitoring, risk assessment, internal review, employee awareness and continuous improvement.

For Procura, ISO/IEC 27001:2022 is not simply a credential. It is part of the governance framework supporting how information is managed across the certified activities.