Short answer. Crowd platforms control the account. Controlled delivery centres control the room. That difference sounds cosmetic until you look at what actually goes wrong — 53% of insider incidents come from negligent employees rather than malicious ones, and negligence is largely a function of environment. A phone on the desk, a screenshot for a colleague, a shared login at home: none of these are attacks, and all of them are breaches. The cleanroom model exists because you cannot write a policy that removes a camera from someone's pocket. You can only remove the pocket from the room.
What risk are we actually controlling for?
Not the hacker at the perimeter. The person already inside, usually doing something careless rather than criminal.
The insider numbers have got hard to ignore. The Ponemon Institute and DTEX put the average annual cost of insider risk at $19.5 million per organisation in the 2026 edition of their Cost of Insider Risks Global Report, up from $17.4 million previously and roughly 123% higher than the $8.76 million recorded in 2018. Organisations logged an average of 25 insider-related incidents in 2025, up from 23 the year before. Verizon's DBIR attributes 30% of confirmed breaches to insiders, and IBM's 2025 breach report named malicious insiders the single most expensive attack vector at $4.92 million per incident.
But the composition of those incidents is the part that should shape how you design a facility.
Two more findings sharpen the picture for anyone weighing distributed against on-site delivery. Remote workers are reported to be three times more likely to expose data, and 78% of insider incidents involve cloud or SaaS platforms — which is to say, the surfaces distributed work depends on. Third-party involvement in breaches doubled year over year to 30% in Verizon's 2025 report, which is a direct comment on the vendor layer that annotation sits in.
And detection speed decides the bill.
The average containment window is 67 days, and only 13% of insider incidents are closed within 30. That gap is the strongest financial argument for on-site supervision that most security posts never make: a floor supervisor who notices something on Tuesday is not a soft control. They are the difference between the two bars in that chart.
What does a controlled delivery centre involve?
Zoning, device exclusion, non-persistent access and supervision — four things that only work together.
The architecture follows the standard rather than the marketing. ISO 27001's approach to securing offices, rooms and facilities is built on a zoning strategy: divide the premises into security zones based on the sensitivity of what is inside, with access becoming progressively more restrictive as you move from public zones toward sensitive ones, and all entry and exit points to restricted areas controlled via badge readers, keypads or biometrics and logged for audit. There is a nice detail in the guidance that tells you whether a facility was designed by someone who has done this before: the walls, floors and ceilings of secure areas must extend to the structural boundary, not stop at drop-ceiling tiles that anyone in the next room can lift.
Device exclusion is the part clients picture when they hear "clean room", and the standards do back it. In practice, ISO 27001 physical controls mean no photography, no personal devices unless specifically authorised, no unescorted visitors, clean desk enforcement before leaving, and clear supervision of contractors and maintenance workers. Visitors are logged at reception, badged visibly and escorted at all times.
The technical half is non-persistent access. Secure delivery facilities with clean-room policies are typically paired with VDI or on-premise access so that data never leaves the client's environment, alongside role-based access, signed NDAs for every annotator and full audit logging. Nothing is stored locally, because there is no local to store it in.
Running these rooms across multiple countries is a large part of what Lifewood does, and the honest lesson from operating them is that the cameras and badge readers are the easy part. The hard part is the daily discipline: the locker routine at shift start, the supervisor who actually walks the floor, the QA lead sitting in the same room as the work rather than reviewing it from another timezone three days later. Facilities do not make data secure. Habits enforced inside facilities do.
Crowd platform vs controlled delivery centre: what each model can actually guarantee CONTROL CROWD PLATFORM CONTROLLED DELIVERY CENTRE WHO IS WORKING Account identity; verification varies by platform Employed, badged, background-checked, physically present DEVICE CAPTURE Unenforceable — a second phone is invisible Removed at entry; no photography; clean desk on exit WORKING ENVIRONMENT Unknown; shared homes, cafes, shared screens Zoned facility with logged entry and exit DATA RESIDENCE Data reaches an endpoint you do not control VDI or on-prem; nothing stored locally SUPERVISION Asynchronous; anomalies found in logs, later On-site QA and floor supervision in real time AUDIT EVIDENCE Platform-level logs; limited facility evidence Access logs, training records, walkthroughs, spot checks BEST SUITED TO Public or synthetic data; broad demographic reach; volume PII, PHI, financial records, unreleased IP, regulated data This is a fit question, not a quality one. Crowd platforms reach a diversity of contributors no single facility can match — which matters enormously for some datasets and not at all for others.
What do the standards actually require?
Evidence that controls operate, not documents that describe them — and there is a vocabulary trap worth knowing.
The enforcement gap is where most organisations stumble. Having a clean desk policy in an employee handbook is insufficient evidence for ISO 27001 certification; auditors look for training records, supervisor enforcement procedures, and documented evidence of compliance checks, and certification audits assess actual control effectiveness rather than policy documentation.
Some assessors go further with physical penetration testing — attempting entry through social engineering, tailgating or stolen credentials — which surfaces weaknesses that paper reviews miss.
The vocabulary trap: SOC 2 is an attestation, not a certification. It is produced under the AICPA's attestation standards by a licensed CPA firm examining controls against the Trust Services Criteria, and it results in a report and an opinion — there is no certificate and no accredited "SOC 2 body". ISO 27001 is a certification, issued by an accredited body against a defined scope with a Statement of Applicability. So the correct ask differs: for SOC 2 you request the report; for ISO 27001 you request the certificate and the SoA. And a corporate ISO 27001 certificate is not the same as a certificate covering the specific facility your data will sit in — the second certifies a building.
For the specific controls: SOC 2's CC6.4 covers logical and physical access and explicitly addresses clear desk and clear screen, with examiners reviewing evidence that the policy exists, training was delivered, and periodic spot checks occur. HIPAA's Physical Safeguards require facility access controls, workstation security and device and media controls. PCI DSS Requirement 9 governs physical access to cardholder data environments, including visitor management and media protection.
When is crowd work the right answer?
More often than facility vendors like to admit — and the honest version of this argument says so.
CONTROLLED FACILITY EARNS ITS COST CROWD IS THE BETTER FIT
Identifiable patient, financial or customer records
Public, synthetic or already-published data
Unreleased product, model or IP material
Work needing broad demographic or geographic diversity
Data with residency or sovereignty constraints
Regulated workloads needing facility-level audit evidence
Content requiring on-site wellbeing support
Long-running programmes where a stable trained team compounds You are buying evidence as much as security — access logs, training records, walkthroughs.
Short bursts and spiky volume
Perception studies where varied backgrounds are the point
Anything where facility overhead buys you nothing Paying for a clean room to label public images is a governance decision nobody will thank you for.
Most serious programmes end up hybrid, and the sensible split is by data class rather than by task type: sensitive work behind the badge readers, everything else wherever it is cheapest and most diverse. What matters is that the classification decision is made deliberately at the start, written into the statement of work, and enforced technically — not left to whichever team has capacity that week.
One last point that gets lost in security conversations. The clean-room model is often framed purely as a control, but it also carries a duty of care. When people are reviewing distressing material, having them in a supervised facility with colleagues, an on-site lead and access to support is not just better for the data — it is better for them. That is a large part of why we run the model we do at Lifewood, alongside the compliance case.
Classify the data before choosing the delivery model. The question is not "how secure is your vendor" but "what class of data is this, and what does that class require".
Ask for the report and the certificate, precisely. SOC 2 report; ISO 27001 certificate plus Statement of Applicability — and check the scope covers the delivery site, not just head office.
Ask what evidence exists, not what policy exists. Training records, access logs, spot-check documentation. A handbook is not evidence.
Insist on non-persistent access. VDI or on-prem so data never lands on a local machine; role-based access and full audit logging as standard.
Put on-site QA in the same room as the work. With average containment at 67 days, real-time supervision is a financial control, not a nicety.
Design for negligence, not just malice. Just over half of incidents are mistakes; lockers, zoning and clean desk address that majority directly.
Walk the floor before signing. Check the walls reach the structural boundary and watch a shift change. Both tell you more than a certificate.
Write the split into the SOW. Which data classes go where, enforced technically, agreed before volume arrives.
Key takeaways
- Insider risk now costs an average of $19.5 million per organisation annually, up from $17.4 million and roughly 123% above the 2018 figure of $8.76 million.
- 53% of insider incidents come from negligent employees, 27% from malicious insiders and 20% from credential theft — the majority are environmental, not criminal.
- Remote workers are reported to be 3× more likely to expose data, and 78% of insider incidents involve cloud or SaaS platforms.
- Average containment takes 67 days and only 13% of incidents close within 30; under-30-day containment costs $14.2M a year versus $21.9M past 90 days.
- ISO 27001 requires zoned facilities with logged entry points, no photography, no unauthorised personal devices, escorted visitors and enforced clean desk.
- Secure facilities are typically paired with VDI or on-prem access so data never leaves the client environment, plus role-based access and full audit logging.
- SOC 2 is an attestation (ask for the report); ISO 27001 is a certification (ask for the certificate and Statement of Applicability) — and check the scope covers the actual site.
- Auditors want evidence controls operate: training records, enforcement procedures, spot checks, sometimes physical penetration testing.
Sources and further reading
- Ponemon Institute / DTEX, 2026 Cost of Insider Risks Global Report — $19.5M average annual insider-risk cost (up from $17.4M), 67-day average containment, and programme ROI findings
- Swif, "Insider Threat Statistics for 2026" — root-cause split of 53% negligent employees, 27% malicious insiders and 20% credential theft; Verizon DBIR 2025 on third-party involvement doubling to 30%; IBM 2025 on malicious insiders at $4.92M per breach
- StationX, "Insider Threat Statistics [2026]" — the 123% cost rise from $8.76M in 2018, 67-day containment down from 86 days in 2023, remote workers 3× more likely to expose data, and 78% of insider incidents involving cloud or SaaS platforms
- Stingr AI, "Insider Threat Statistics 2026 (Verified Data)" — containment cost gap of $14.2M under 30 days versus $21.9M beyond 90 days (Kiteworks summary of DTEX), and Verizon DBIR breach attribution across 12,195 confirmed breaches
- Syteca, "Insider Threat Statistics for 2026" — 25 insider-related incidents per organisation in 2025 (up from 23), only 13% of incidents contained within 30 days, and ~135% total cost increase 2018–2025. syteca.com/en/blog/insider-threat-statistics-facts-and-figures High Table, "ISO 27001 Securing Offices, Rooms and Facilities (Annex A 7.3)" — the zoning strategy, controlled and logged access points, and environmental protection requirements. hightable.io/iso-27001-7-3-securing-offices-rooms-and-facilities GAICC, "ISO 27001 Physical Controls for Facilities, Equipment and Secure Areas" — no photography, no unauthorised personal devices, no unescorted visitors, clean desk enforcement, the handbook-is-not-evidence enforcement gap, SOC 2 CC6.4 on clear desk and screen, physical penetration testing, and the structural-boundary requirement for secure-area walls and ceilings
- WatchDog Security, "ISO 27001 A.7.3: Securing Offices, Rooms & Facilities (2022)" — on audit evidence expectations (approved policy, documented risk assessment, access logs, physical walkthrough) and visitor logging, badging and escorting. watchdogsecurity.io/iso-27001/securing-offices-rooms-and-facilities Peony, "SOC 2 and ISO 27001 Compliant Data Rooms: Who Actually Holds What (2026)" — on SOC 2 being an AICPA attestation rather than a certification, ISO 27001 being a certification with a Statement of Applicability, and the gap between a corporate certificate and a facility certificate. peony.ink/blog/soc-2-iso-27001-compliant-data-rooms Drone Strategic Partners, "Data Center Physical Security: SOC 2, ISO 27001 & Technology Architecture" — on concentric zone access control, insider threat as the dominant risk category, and HIPAA Physical Safeguards and PCI DSS Requirement 9 obligations. dronestrategicpartners.com/post/data-center-physical-security-compliance-requirements-and-technology-architecture Corpshore AI, "Data Annotation & Labeling Services" — illustrative of the current market model: secure delivery facilities with clean-room policies, VDI or on-prem access so data never leaves the client environment, role-based access, per-annotator NDAs, full audit logging, and security scope agreed per project in the SOW
- Lifewood, AI data, annotation and secure delivery services
- Charts in Figures 1 and 2 were produced by Lifewood from the figures reported in the sources cited beneath each chart.