Knowledge base

ISO 27001: Required Documented Information – Simple Guide

A guide to the key documents required for ISO 27001 compliance.

Neha Dvivedi · 16 agosto 2026

ISO 27001 requires organisations to maintain certain documents and records to show that their Information Security Management System (ISMS) is properly planned, implemented and maintained.

1. Documents You Must Maintain

Your organisation should have documented information covering:

• ISMS Scope – Defines what parts of the organisation, systems, locations and activities are covered by the ISMS.

• Information Security Policy – Explains the organisation’s overall approach to information security.

• Risk Assessment Process – Describes how information security risks are identified and assessed.

• Risk Treatment Process – Explains how identified risks will be managed or reduced.

• Statement of Applicability (SoA) – Shows which security controls apply to the organisation and why.

• Information Security Objectives – Defines what the organisation wants to achieve in information security.

• Other Necessary ISMS Information – Any additional documented information needed to make the ISMS work effectively.

2. Records You Must Keep

You also need to retain evidence that your ISMS activities are actually being carried out. This includes:

• Records showing that employees are competent and properly trained.

• Results of the information security risk assessment.

• Results of risk treatment activities.

• Evidence of monitoring and measurement.

• The internal audit programme and audit results.

• Management review records and results.

• Records of nonconformities and the actions taken to address them.

• Corrective action records and their results.

• Evidence that operational processes were planned and carried out as intended.

3. Documents Commonly Maintained for ISO 27001 Controls

Some documents are not specifically named as mandatory documents in the standard, but organisations commonly maintain them because they help demonstrate that applicable controls are being implemented.

These may include:

• Asset inventory – A list of hardware, software, information and other important assets.

• Access control policy and access review records – Shows who has access to systems and whether that access is regularly reviewed.

• Supplier register and security requirements – Identifies suppliers and the information security requirements they need to follow.

• Incident register and incident response procedure – Records security incidents and explains how incidents are handled.

• Business continuity and backup arrangements – Includes backup procedures and evidence that data can actually be restored.

• Change management records – Shows how important changes to systems and processes are controlled.

• Acceptable use policy – Explains how employees are expected to use company systems and information.

• Secure development policy – Important for organisations that develop software or applications.

4. Statement of Applicability (SoA)

The Statement of Applicability (SoA) is one of the most important documents in an ISO 27001 implementation.

It lists the Annex A controls and explains:

• Which controls are applicable to the organisation.

• Which controls are not applicable.

• Why each decision has been made.

• How applicable controls are implemented.

• Which policies, procedures or records support those controls.

For controls that are excluded, the organisation should provide a clear and organisation-specific reason.

Simply writing “Not Applicable” is generally not enough. For example, saying “We do not have physical infrastructure because all our systems are cloud-hosted” provides a specific reason for excluding certain physical infrastructure-related controls.

5. Practical Documentation Tips

Keep documents useful

Write policies and procedures in a way that employees can actually understand and follow.

A policy that nobody reads is unlikely to result in a control that anybody follows.

Don't create one document for every control

ISO 27001 has many controls, but you do not need a separate document for each one.

Instead, group related controls into practical policies and procedures. This makes the ISMS easier to manage.

Keep documents updated

Every document should have:

• Date

• Version number

• Approval details

• Review/update information

Auditors look at whether documents are current. Old documents referring to systems or processes that no longer exist can become audit findings.

Keep your risk assessment updated

Risk assessment should not be treated as a one-time activity completed only before certification.

It should be reviewed and updated when there are significant changes, new risks, incidents or other relevant developments.

6. Common Documentation Problems Auditors Find

Some common issues include:

1. Generic Statement of Applicability

The justifications are so general that they could apply to almost any organisation.

2. Outdated policies

Policies were approved several years ago but still refer to systems, technologies or processes that no longer exist.

3. Incomplete access reviews

Records show that an access review was completed, but they don't clearly show what access was reviewed or what changes were made.

4. Backups that have never been tested

The organisation has a backup procedure but cannot provide evidence that data has actually been restored successfully.

5. Suppliers without security requirements

Contracts with suppliers who handle company or customer data do not clearly include information security requirements.

Key Takeaway

ISO 27001 documentation is not about creating more paperwork. It is about having the right information and evidence to show that your information security processes are planned, implemented, monitored and continuously improved.

The goal should be to create documentation that is practical, current, easy to understand and supported by real evidence.

What this covers

See how this looks as a working system

Reading about a requirement and seeing the documentation that satisfies it are different things. In a short demo we open the actual manual, procedures and records set for ISO/IEC 27001, show you how each clause is answered and where your existing way of working already fits. You will know what implementation involves before you commit to it.

Ask us about this

Tell us what is being asked of you and by whom.

What are you looking for?

We reply within one working day. Your details stay with our consultants.

More reading

All articles