iso-27001-documentation-list

By July 25th, 2026ISO Audit And Certificate11 min read

ISO 27001 Documentation List: Mandatory Documents and Records

If you are implementing ISO 27001, knowing exactly which documents and records are mandatory can save you weeks of unnecessary work and thousands of dollars in consulting fees. This complete ISO 27001 documentation list covers every required document, every mandatory record, the Annex A evidence you need for certification, and practical tips for keeping your ISMS documentation lean and effective.

ISO 27001:2022 is the international standard for information security management. It follows the Annex SL framework, which means it shares a common structure with ISO 9001, ISO 14001, and ISO 45001. This common structure makes integrated management system documentation possible, but the specific documentation requirements for information security are unique and must be carefully addressed.

What Documentation Does ISO 27001 Require?

ISO 27001:2022 distinguishes between two types of documented information, just like other ISO management system standards. Understanding this distinction is essential for building a compliant ISMS:

  • Maintained documented information – Documents that must be kept current and reviewed regularly. These include policies, procedures, and plans that define what the organisation commits to do for information security
  • Retained documented information – Records that provide evidence that the ISMS is operating effectively. These prove that activities were carried out as planned and that controls are working

Mandatory Documents for ISO 27001:2022

The standard explicitly requires these documents to be maintained. They form the policy and planning layer of your ISMS. Every organisation seeking ISO 27001 certification must have these documents in place.

ClauseRequired DocumentPurposeKey Content
4.3ISMS ScopeDefines the boundaries and applicability of the ISMSOrganisational context, products/services, locations, assets, technology interfaces, exclusions with justification
5.2Information Security PolicySets top management direction for information securityCommitment to security, policy objectives, applicable frameworks (e.g. NIST, CIS), review frequency, accountability
6.1.2Information Security Risk Assessment ProcessDescribes how risk assessments are performed across the organisationRisk methodology (qualitative or quantitative), risk criteria, risk acceptance criteria, risk scales (likelihood and impact), assessment schedule
6.1.3 dStatement of Applicability (SoA)Documents which Annex A controls are applicable and whyAll 93 controls listed, applicability status (applicable or not applicable), justification for exclusions, control implementation status, references to supporting documents
6.2Information Security ObjectivesDefines measurable security objectives aligned to the information security policyObjectives with KPIs, target values, timeframes, responsible owners, resource requirements, progress tracking
7.5.3 bDocumented Information Control ProcedureControls the creation, approval, distribution, and changes to all ISMS documentsDocument numbering, version control, approval workflows, access permissions, retention periods, disposal procedures

Mandatory Records for ISO 27001:2022

These records must be retained as evidence that the ISMS is operating effectively. External auditors will examine these records carefully during certification and surveillance visits. Missing or incomplete records are one of the most common findings during ISO 27001 audits.

ClauseRequired RecordWhat It Demonstrates
6.1.2Risk assessment resultsRisks are identified, scored, prioritised, and assigned to risk owners
6.1.3Risk treatment plan (RTP)Treatment options selected, deadlines assigned, resources allocated, status tracked
7.2Competence recordsPersonnel have appropriate information security training, qualifications, and experience
7.5.1Documented information evidenceDocuments and records are properly identified, stored, protected, and retrievable
8.1Operational planning and control resultsRisk treatment plans executed and operational controls are effective
8.2Risk assessment results for changesSecurity risks of changes (new systems, processes, technologies) assessed before implementation
9.1ISMS monitoring and measurement resultsSecurity KPIs, metrics, and performance data collected, analysed, and acted upon
9.2Internal audit programme and resultsAudit schedule, completed audit reports, nonconformities, findings, and closure evidence
9.3Management review resultsReview inputs, outputs, top management decisions, action items, and resource commitments
10.1Nonconformity and corrective action recordsNonconformities identified, root cause analysis performed, actions taken, effectiveness verified

Annex A Control Documentation and Evidence

For every applicable control in your Statement of Applicability, you need documented evidence that the control is implemented and effective. This is where most organisations underestimate the documentation effort. Each of the 93 controls may require supporting policies, procedures, configuration records, or monitoring evidence.

Annex A ThemeControl CountTypical Documents NeededTypical Records / Evidence
Organisational (37 controls)37Information security policies, access control policy, incident response plan, business continuity policy, supplier security policy, data classification policyIncident reports, BCP test results, supplier assessment reports, policy acknowledgement forms, classification register
People (8 controls)8Code of conduct, remote working policy, disciplinary procedure, background screening procedureBackground check results, training attendance records, signed confidentiality agreements, performance review records
Physical (14 controls)14Physical security policy, clear desk and clear screen policy, equipment maintenance procedure, secure disposal procedureAccess badge logs, visitor registers, CCTV maintenance records, asset inventory, disposal certificates
Technological (34 controls)34Access control procedure, cryptographic policy, network security policy, malware protection procedure, backup procedure, logging and monitoring procedure, patch management policyUser access reviews, encryption configuration audits, antivirus status reports, backup restore test logs, SIEM alert records, vulnerability scan reports

Document Control Requirements for ISO 27001

Your ISMS documented information control procedure (Clause 7.5) must address the following elements. Document control is particularly important for ISO 27001 because uncontrolled documents can lead to security gaps when outdated policies or procedures are followed.

  • Creation and identification – Each document must have a unique identifier, title, revision number, date, owner, and classification level (e.g. public, internal, confidential, restricted)
  • Review and approval – Documents must be reviewed for adequacy and approved by authorised personnel before issue
  • Distribution and access – Only authorised personnel should access sensitive ISMS documents; relevant documents must be available to those who need them at points of use
  • Change control – Changes must be reviewed and approved; revision history must be maintained with a summary of changes
  • Storage and preservation – Documents must be stored securely, protected from unauthorised access, damage, deterioration, or loss; backups must be maintained
  • Obsolete document management – Obsolete documents must be removed from circulation or clearly identified to prevent unintended use; obsolete copies should be securely destroyed if they contain sensitive information
  • External document management – External documents (laws, regulations, standards, customer requirements) must be identified, controlled, and their distribution managed

Documentation Tips for ISO 27001

Keep your ISMS documentation practical, efficient, and audit-ready with these strategies developed through years of helping organisations across the Middle East achieve ISO 27001 certification:

  • Adopt a tiered structure – Use the standard four-tier pyramid: Tier 1 (Policy) for high-level direction, Tier 2 (Procedures) for who does what, Tier 3 (Work Instructions or Standards) for how to do specific tasks, and Tier 4 (Records) for evidence. This structure aligns with ISO 27001 terminology and makes audits straightforward
  • Integrate with existing documents – Many security documents already exist in your organisation. IT policies, HR policies, physical security procedures, and data protection policies can be reviewed and updated rather than recreated from scratch
  • Use an ISMS software platform – Purpose-built ISMS tools automate document control, versioning, access permissions, audit trails, and retention schedules. They save significant time and reduce the risk of document control nonconformities
  • Write for the reader – Use plain language. Short sentences, bullet points, tables, and flowcharts make documents easier to understand and follow. Avoid legal or technical jargon where possible, or include a glossary
  • Link documents together – Cross-reference your SoA to risk treatment plans, policies to procedures, and procedures to records. A well-linked documentation set creates a coherent system that auditors can easily navigate
  • Schedule annual reviews – Outdated documents are a common finding in ISO 27001 audits. Set a calendar reminder for each document review. Include document review as a standing agenda item in management review meetings
  • Classify documents by sensitivity – Not all ISMS documents should be accessible to all employees. Implement document classification labels (public, internal, confidential, restricted) and control access accordingly

Frequently Asked Questions

How many documents do I need for ISO 27001 certification?

There is no fixed number. Most small to medium organisations maintain 20–40 documents (policies, procedures, plans) plus supporting records. The key is to document what is needed to demonstrate conformance, not to create paperwork for its own sake. Quality matters more than quantity.

Does ISO 27001 require a documented risk assessment methodology?

Yes. Clause 6.1.2 explicitly requires that you maintain documented information about the risk assessment process. This document must describe your risk criteria, scoring methodology, risk acceptance criteria, and how risk assessments are conducted.

What is the Statement of Applicability and why is it so important?

The SoA is the central document linking your risk assessment to Annex A controls. It lists all 93 controls, marks each as applicable or not applicable, justifies every exclusion, and references control implementation. External auditors examine the SoA carefully because it demonstrates that your ISMS is built on a thorough risk assessment.

Can I have one document that covers multiple ISO 27001 controls?

Yes. An Information Security Policy can address multiple organisational controls. An Access Control Policy can cover 5–6 technological controls. Grouping related controls into single documents is efficient, practical, and recommended by certification bodies.

Do I need to translate ISO 27001 documents for multi-language workforces?

Yes, where worker understanding is at stake. Policies and procedures that affect employees (such as the information security policy, acceptable use policy, and remote working policy) must be available in a language they understand. Auditors will verify this by interviewing staff in their local language.

How should I organise my ISMS document structure?

Most organisations use a four-tier pyramid: Policy (level 1), Procedure (level 2), Work Instruction or Technical Standard (level 3), and Record (level 4). This structure aligns with ISO 27001 terminology and makes audits straightforward for both internal and external auditors.

Can I use my existing IT security policies for ISO 27001?

Yes, but they may need to be restructured and enhanced to meet the specific requirements of ISO 27001. Many existing IT policies are technical and operational; they need to be expanded to include governance, accountability, review cycles, and alignment with the ISMS risk assessment.

What is the difference between a policy and a procedure in ISO 27001?

A policy states management’s intent, direction, and expectations for information security (e.g. ‘all data at rest shall be encrypted’). A procedure describes the specific steps to implement the policy (e.g. ‘how to enable BitLocker encryption on company laptops’). Both are typically needed.

Common Documentation Mistakes in ISO 27001

Avoid these common documentation mistakes that lead to nonconformities during certification audits. Being aware of them early saves time and cost:

  • SoA does not match the risk assessment – The Statement of Applicability must directly reference the risk assessment. Every applicable control must be traceable to a risk. If the SoA lists controls that do not map to identified risks, the auditor will flag this as a gap
  • Policies without implementation evidence – Writing a policy is not enough. You must demonstrate that the policy is implemented, communicated, and enforced. An access control policy without user access reviews is a nonconformity waiting to happen
  • Copying templates without customisation – Generic templates from the internet do not reflect your organisation’s specific context, risks, or structure. Certification auditors see this immediately, and it results in findings
  • Excessive documentation volume – More documents do not mean better security. Focus on mandatory documents first, then add optional documentation only where it adds value to your ISMS. Over-documentation creates a maintenance burden that leads to outdated documents
  • No version control or approval records – Uncontrolled documents are one of the most frequent findings in ISO 27001 audits. Every document must have version history and evidence of approval before issue
  • Ignoring retention periods – Records must be retained for defined periods and disposed of when the retention period expires. Without a retention schedule, records accumulate indefinitely, creating information security risks

Get ISO 27001 Documentation Support

Building an ISO 27001 compliant ISMS requires the right documentation structure, content, and evidence. Bitrixme helps organisations across the Middle East develop complete, audit-ready ISMS documentation packages, including policies, procedures, SoA, risk assessment methodology, and risk treatment plans.

Our team of certified information security professionals has extensive experience across banking, fintech, healthcare, government, and technology sectors. We provide documentation gap analysis, template customisation, full documentation development, and ISMS software implementation support.

Contact Bitrixme for ISO 27001 documentation services or send us a message on WhatsApp for a free consultation.