Short answer. Crowd platforms control the account; controlled delivery centres control the room. That difference sounds cosmetic until you look at what goes wrong — 53% of insider incidents come from negligent employees rather than malicious ones, and negligence is largely a function of environment. A phone on the desk, a screenshot for a colleague, a shared login at home: none of these are attacks, and all of them are breaches. You cannot write a policy that removes a camera from someone's pocket. You can only remove the pocket from the room.
Key takeaways
- Insider risk now costs an average of $19.5 million per organisation annually, up from $17.4 million and roughly 123% above the 2018 figure of $8.76 million.
- 53% of insider incidents come from negligent employees, 27% from malicious insiders and 20% from credential theft — the majority are environmental, not criminal.
- Average containment takes 67 days and only 13% of incidents close within 30 days, and slow containment costs organisations far more than fast containment.
- ISO 27001 requires zoned facilities with logged entry points, no photography, no unauthorised personal devices, escorted visitors and enforced clean desk practice.
- SOC 2 is an attestation, so buyers should ask for the report; ISO 27001 is a certification, so buyers should ask for the certificate and Statement of Applicability.
What risk are we actually controlling for?
Not the hacker at the perimeter, but the person already inside, usually doing something careless rather than criminal.
The insider numbers have got hard to ignore. Insider risk is the exposure an organisation carries from people who already have legitimate access to its data, whether they misuse it deliberately or expose it by accident. The Ponemon Institute and DTEX put the average annual cost of insider risk at $19.5 million per organisation in the 2026 edition of their Cost of Insider Risks Global Report, up from $17.4 million previously and roughly 123% higher than the $8.76 million recorded in 2018. Organisations logged an average of 25 insider-related incidents in 2025, up from 23 the year before. Verizon's DBIR attributes 30% of confirmed breaches to insiders, and IBM's 2025 breach report named malicious insiders the single most expensive attack vector at $4.92 million per incident.
But the composition of those incidents is the part that should shape how a facility is designed. Two more findings sharpen the picture for anyone weighing distributed against on-site delivery: remote workers are reported to be three times more likely to expose data, and 78% of insider incidents involve cloud or SaaS platforms — which is to say, the surfaces distributed work depends on. Third-party involvement in breaches doubled year over year to 30% in Verizon's 2025 report, a direct comment on the vendor layer that annotation sits in. Anyone weighing this trade-off alongside broader questions of data sovereignty and where training data actually lives is really asking the same question from two directions: who can reach the data, and from where.
And detection speed decides the bill. The average containment window is 67 days, and only 13% of insider incidents are closed within 30. That gap is the strongest financial argument for on-site supervision that most security posts never make: a floor supervisor who notices something on Tuesday is not a soft control. They are the difference between a contained incident and a six-figure one.
What does a controlled delivery centre involve?
Zoning, device exclusion, non-persistent access and supervision — four things that only work together, not four options to pick from.
The architecture follows the standard rather than the marketing. A clean-room model is a facility design that removes the physical means of exfiltration — cameras, personal storage, unsupervised exits — rather than relying on staff to follow a policy voluntarily. ISO 27001's approach to securing offices, rooms and facilities is built on a zoning strategy: divide the premises into security zones based on the sensitivity of what is inside, with access becoming progressively more restrictive as you move from public zones toward sensitive ones, and all entry and exit points to restricted areas controlled via badge readers, keypads or biometrics and logged for audit. A useful detail in the guidance tells you whether a facility was designed by someone who has done this before: the walls, floors and ceilings of secure areas must extend to the structural boundary, not stop at drop-ceiling tiles that anyone in the next room can lift.
Device exclusion is the part clients picture when they hear "clean room," and the standards do back it. In practice, ISO 27001 physical controls mean no photography, no personal devices unless specifically authorised, no unescorted visitors, clean desk enforcement before leaving, and clear supervision of contractors and maintenance workers. Visitors are logged at reception, badged visibly and escorted at all times.
The technical half is non-persistent access. Secure delivery facilities with clean-room policies are typically paired with VDI or on-premise access so that data never leaves the client's environment, alongside role-based access, signed NDAs for every annotator and full audit logging. Nothing is stored locally, because there is no local to store it in — the same principle that underpins layered quality control before data is delivered, where evidence of who touched what, and when, matters as much as the label itself.
Running these rooms across multiple countries is a large part of what Lifewood does, and the honest lesson from operating them is that cameras and badge readers are the easy part. The hard part is daily discipline: the locker routine at shift start, the supervisor who actually walks the floor, the QA lead sitting in the same room as the work rather than reviewing it from another time zone three days later. Facilities do not make data secure. Habits enforced inside facilities do.
| Control | Crowd platform | Controlled delivery centre |
|---|---|---|
| Who is working | Account identity; verification varies by platform | Employed, badged, background-checked, physically present |
| Device capture | Unenforceable — a second phone is invisible | Removed at entry; no photography; clean desk on exit |
| Working environment | Unknown; shared homes, cafes, shared screens | Zoned facility with logged entry and exit |
| Data residence | Data reaches an endpoint the client does not control | VDI or on-prem; nothing stored locally |
| Supervision | Asynchronous; anomalies found in logs, later | On-site QA and floor supervision in real time |
| Audit evidence | Platform-level logs; limited facility evidence | Access logs, training records, walkthroughs, spot checks |
| Best suited to | Public or synthetic data; broad demographic reach; volume | PII, PHI, financial records, unreleased IP, regulated data |
This is a fit question, not a quality one. Crowd platforms reach a diversity of contributors no single facility can match, which matters enormously for some datasets and not at all for others — a distinction worth applying before comparing how human-in-the-loop annotation actually routes work between the two models.
What do the standards actually require?
Evidence that controls operate, not documents that describe them — and there is a vocabulary trap worth knowing.
The enforcement gap is where most organisations stumble. Having a clean desk policy in an employee handbook is insufficient evidence for ISO 27001 certification; auditors look for training records, supervisor enforcement procedures, and documented evidence of compliance checks, and certification audits assess actual control effectiveness rather than policy documentation. Some assessors go further with physical penetration testing — attempting entry through social engineering, tailgating or stolen credentials — which surfaces weaknesses that paper reviews miss.
The vocabulary trap: SOC 2 is an attestation, not a certification, produced under the AICPA's attestation standards by a licensed CPA firm examining controls against the Trust Services Criteria; it results in a report and an opinion, and there is no certificate and no accredited "SOC 2 body." ISO 27001 is a certification, issued by an accredited body against a defined scope with a Statement of Applicability. So the correct ask differs: for SOC 2, request the report; for ISO 27001, request the certificate and the Statement of Applicability. And a corporate ISO 27001 certificate is not the same as a certificate covering the specific facility the data will sit in — the second certifies a building.
For the specific controls: SOC 2's CC6.4 covers logical and physical access and explicitly addresses clear desk and clear screen, with examiners reviewing evidence that the policy exists, training was delivered, and periodic spot checks occur. HIPAA's Physical Safeguards require facility access controls, workstation security and device and media controls. PCI DSS Requirement 9 governs physical access to cardholder data environments, including visitor management and media protection. Buyers assembling an RFP around these obligations often find it faster to work from criteria built for choosing an annotation vendor than to derive a checklist from the standards themselves.
When is crowd work the right answer?
More often than facility vendors like to admit, and the honest version of this argument says so.
| Controlled facility earns its cost | Crowd is the better fit |
|---|---|
| Identifiable patient, financial or customer records | Public, synthetic or already-published data |
| Unreleased product, model or IP material | Work needing broad demographic or geographic diversity |
| Data with residency or sovereignty constraints | Short bursts and spiky volume |
| Regulated workloads needing facility-level audit evidence | Perception studies where varied backgrounds are the point |
| Content requiring on-site wellbeing support | Anything where facility overhead buys nothing |
| Long-running programmes where a stable trained team compounds | — |
For the left column, the client is buying evidence as much as security: access logs, training records, walkthroughs. Paying for a clean room to label public images is a governance decision nobody will thank you for.
Most serious programmes end up hybrid, and the sensible split is by data class rather than by task type: sensitive work behind the badge readers, everything else wherever it is cheapest and most diverse, which is also where a mature gold-set and audit-sampling QA process earns its keep regardless of delivery model. What matters is that the classification decision is made deliberately at the start, written into the statement of work, and enforced technically, not left to whichever team has capacity that week.
One last point that gets lost in security conversations. The clean-room model is often framed purely as a control, but it also carries a duty of care. When people are reviewing distressing material, having them in a supervised facility with colleagues, an on-site lead and access to support is not just better for the data — it is better for them. That is a large part of why Lifewood runs facilities staffed and trained through a structured annotator certification path rather than an anonymous pool, alongside the compliance case. It also connects to the broader question of what enterprise-grade data validation actually requires once the data has left the room.
Classify the data before choosing the delivery model — the question is not "how secure is your vendor" but "what class of data is this, and what does that class require." Ask for the report and the certificate, precisely: SOC 2 report; ISO 27001 certificate plus Statement of Applicability, and check the scope covers the delivery site rather than just head office. Ask what evidence exists, not what policy exists: training records, access logs, spot-check documentation. Insist on non-persistent access, so data never lands on a local machine. Put on-site QA in the same room as the work, since real-time supervision is a financial control, not a nicety. Design for negligence, not just malice, since just over half of incidents are mistakes. Walk the floor before signing, and check the walls reach the structural boundary. Write the split into the statement of work: which data classes go where, enforced technically, agreed before volume arrives. Vendors who can speak to this in specifics rather than slogans are usually the ones worth shortlisting through Lifewood's wider annotation and AI data services.