ISO 27001 Documentation Requirements: Essential Documents for Certification
Updated: Sep 6
ISO 27001 certification is not awarded for having a large folder of documents. It is awarded when an organization can show that its Information Security Management System, or ISMS, is planned, operated, checked, and improved in a controlled way.
Documentation is how that control becomes visible.
For ISO/IEC 27001:2022, the standard uses the term documented information. That includes documents you maintain, such as policies and procedures, and records you retain, such as audit results, risk assessment outputs, and evidence of corrective action.
Good ISO 27001 documentation helps answer three basic audit questions:
What did the organization decide to do?
How does it carry out those decisions?
What evidence proves it happened?
When those answers are clear, the certification process becomes far easier to manage.

ISO 27001 Documentation Requirements starts with the ISMS foundation
The first group of documents defines the scope, direction, and governance of the ISMS. These are not just formal statements. They set the boundaries for everything that follows.
ISMS scope
The ISMS scope explains what parts of the organization the ISMS covers. It may include specific locations, departments, systems, services, products, or business processes.
Its purpose is to make certification boundaries clear. For example, a software company may include product development, cloud hosting, customer support, and related corporate systems. Another organization may limit the initial scope to one business unit.
A strong scope statement should include:
The business activities covered
Relevant locations or remote work arrangements
Key systems, applications, and services
Important internal and external dependencies
Interfaces with suppliers, customers, or other departments
Auditors will check whether the scope is reasonable and whether controls match the risks inside that scope.
Information security policy
The information security policy is a required document under ISO 27001. It states the organization’s commitment to protecting information and supporting the ISMS.
At a minimum, it should align with business objectives, commit to meeting applicable requirements, and support continual improvement. It should also be communicated to relevant staff and interested parties where appropriate.
This policy does not need to be long. A clear one-page policy, approved by leadership and understood by staff, is far more useful than a ten-page document no one reads.
Information security objectives
ISO 27001 requires documented information about information security objectives. These objectives turn broad intent into measurable direction.
Examples may include:
Complete risk treatment actions within approved target dates
Review privileged access at defined intervals
Reduce repeat security incidents through improved root cause analysis
Complete security awareness training for relevant personnel
Each objective should include what will be done, who owns it, how progress will be evaluated, and when it will be reviewed.
Roles, responsibilities, and authorities
The standard expects leadership to assign and communicate ISMS responsibilities. While ISO 27001 does not require a single document with a specific title, most organizations keep a responsibility matrix, job descriptions, or an ISMS roles document.
This helps avoid confusion during implementation and audit. For example, it should be clear who owns risk assessments, who approves risk treatment, who manages incidents, and who reports ISMS performance to leadership.
Risk and control documents form the core of certification evidence
Risk management is at the center of ISO 27001. The ISMS exists to manage information security risks in a structured and repeatable way.
This is where many certification projects succeed or struggle.
Risk assessment methodology
ISO 27001 requires organizations to define and apply an information security risk assessment process. The documented method should explain how risks are identified, analyzed, evaluated, and accepted.
A practical methodology will define:
Risk criteria
Impact and likelihood scales
How risk levels are calculated
What makes a risk acceptable or unacceptable
How often risk assessments are reviewed
Who approves results
The goal is consistency. Two different teams should be able to apply the method and reach comparable results.
Risk assessment results
The results of risk assessments must be retained as documented information. These records show which risks were identified and how the organization evaluated them.
Typical risk assessment records include:
Assets, processes, or scenarios assessed
Threats and vulnerabilities considered
Potential business impact
Existing controls
Risk rating before treatment
Risk owner
Decision on whether treatment is needed
These records demonstrate that the organization understands its risk environment and makes informed decisions.
Risk treatment plan
The risk treatment plan explains what the organization will do about unacceptable risks. It connects risk assessment results to planned actions.
The plan should show:
Selected treatment option
Control or action to be implemented
Responsible owner
Target completion date
Current status
Residual risk after treatment
Approval of residual risk where needed
Common treatment options include reducing the risk with controls, accepting the risk, avoiding the activity, or sharing the risk through contracts or insurance. Any acceptance decision should be documented and approved at the right level.
Statement of Applicability
The Statement of Applicability, often called the SoA, is one of the most important ISO 27001 documents.
It lists the Annex A controls and explains whether each control applies to the organization. For each applicable control, it should identify implementation status and reference related policies, procedures, or evidence. For controls that do not apply, it should give a clear justification.
The SoA matters because it connects risk treatment decisions to the control set in Annex A. It also gives auditors a practical map for testing the ISMS.
The Statement of Applicability should not be treated as a checkbox list. It should explain why controls were selected and how they support risk treatment.

Policies and procedures explain how the ISMS operates
Policies set expectations. Procedures explain how work is done. Together, they make the ISMS repeatable.
The exact set of policies and procedures depends on the organization’s scope, risks, legal requirements, and selected Annex A controls. ISO 27001 does not require every organization to use identical document titles.
Still, most certification-ready ISMS documentation includes the following.
Document | Purpose | How it supports the ISMS |
Access control policy | Defines rules for user access, privileged access, and access reviews | Reduces unauthorized access risk |
Asset management procedure | Identifies and manages information assets | Helps protect systems, data, and services based on value and risk |
Acceptable use policy | Sets rules for use of company systems, devices, and information | Guides staff behavior and reduces misuse |
Incident management procedure | Explains how incidents are reported, assessed, handled, and learned from | Supports fast response and evidence of control |
Supplier security procedure | Defines security checks and ongoing oversight for suppliers | Manages third-party risk |
Change management procedure | Controls changes to systems, applications, and infrastructure | Reduces disruption and security gaps |
Backup and recovery procedure | Sets backup frequency, responsibilities, and recovery checks | Supports availability and recovery planning |
Business continuity or ICT readiness procedure | Defines response and recovery arrangements for disruption | Helps maintain critical operations |
Document control procedure | Manages creation, approval, review, version control, and retention | Keeps ISMS documents accurate and current |
Internal audit procedure | Explains how audits are planned, performed, reported, and followed up | Supports independent checking of the ISMS |
Corrective action procedure | Defines how nonconformities are investigated and resolved | Drives improvement and prevents repeat issues |
For ISO 27001 certification, ISO 27001 MANUALS are optional. Some organizations still create an ISMS manual because it gives a simple overview of scope, processes, documents, and responsibilities. If used, keep it short and useful. Do not turn it into a duplicate of every policy and procedure.
Annex A control documents
ISO/IEC 27001:2022 Annex A contains controls across organizational, people, physical, and technological themes. The SoA determines which controls apply.
Many Annex A controls can be supported by existing documents. For example:
Screening and confidentiality agreements may sit with HR records
Physical security rules may sit with facilities procedures
Logging and monitoring may sit with IT operations procedures
Secure development rules may sit with engineering standards
Data retention may sit with privacy or records management procedures
This is acceptable as long as the documents are controlled, current, and available to the people who need them.
Records prove that the ISMS is working
A policy says what should happen. A record proves what did happen.
During a certification audit, auditors will sample records to confirm that the ISMS operates in practice. Weak records are one of the most common reasons organizations receive findings.
Core ISO 27001 records usually include:
Risk assessment results
Risk treatment results
Evidence of competence, training, and awareness
Monitoring and measurement results
Internal audit program and audit results
Management review results
Nonconformities and corrective actions
Evidence of control operation, such as access reviews, incident logs, backup test results, supplier reviews, and change approvals
Training and awareness records
Training records show that people performing ISMS-related work are competent and aware of their responsibilities.
Records may include attendance logs, learning platform reports, role-based training evidence, phishing simulation results, or signed acknowledgments of key policies.
The focus should be practical. A system administrator needs different training from a sales employee handling customer information.
Monitoring and performance records
ISO 27001 requires organizations to evaluate ISMS performance. Records may include metrics, dashboards, reports, or meeting notes.
Useful measures may include:
Status of risk treatment actions
Number and type of security incidents
Timeliness of access reviews
Backup success and recovery test results
Internal audit findings
Corrective action status
Supplier review results
Choose measures that support decisions. Avoid collecting data only because it looks impressive.
Internal audit and management review records
Internal audits check whether the ISMS conforms to ISO 27001, the organization’s own requirements, and planned arrangements. Audit records should include the audit program, scope, criteria, findings, evidence reviewed, and follow-up actions.
Management review records show that leadership evaluates ISMS performance and makes decisions. They should capture inputs such as audit results, risk status, incidents, objectives, changes affecting the ISMS, and opportunities for improvement.
These records are important because they show top management involvement, not just technical activity.

How to create and maintain ISO 27001 documents effectively
The best documentation is clear, controlled, and used. It does not need to be complicated.
Start with the standard and the risk assessment
Build documents around actual requirements and real risks. Avoid downloading a large template library and filling in company names without understanding the content.
A good sequence is:
Define the ISMS scope
Approve the information security policy
Define the risk assessment and treatment process
Complete the risk assessment
Build the Statement of Applicability
Create needed policies and procedures based on selected controls
Generate records by operating the ISMS
Audit, review, and improve the system
This sequence keeps the documentation connected to the ISMS rather than separate from it.
Use simple document control
Every controlled document should have a clear owner, version, approval date, and review cycle. Staff should know where to find the current version.
At minimum, document control should cover:
Creation and approval
Version history
Access and distribution
Periodic review
Change approval
Obsolete document handling
Record retention
This prevents an auditor from finding three different versions of the same access control policy in use.
Write for the people who will use the document
A policy should be short enough for staff to understand. A procedure should be specific enough for someone to follow.
Use plain language. Define terms only where needed. Replace vague instructions such as “review access regularly” with clear expectations such as “system owners review privileged access every quarter.”
Also avoid over-documenting. If a team cannot realistically follow a procedure, either improve the process or simplify the document.
Keep records as work happens
Do not wait until the certification audit to gather evidence. Build records into normal work.
For example:
Save access review approvals when the review is completed
Record incident decisions during the incident process
Update the risk treatment plan when actions change status
Keep management review minutes at the time of the review
Store audit evidence with the audit report
This approach reduces audit stress and improves trust in the ISMS.
Review documents after meaningful change
Annual review is common, but it should not be the only trigger. Update documents when there are major changes to systems, services, laws, suppliers, risks, or organizational structure.
A practical ISMS document review should ask:
Is the document still accurate?
Does it match how the process works today?
Are responsibilities still correct?
Do records show the process is being followed?
Did incidents, audits, or corrective actions reveal gaps?
ISO 27001 DOCUMENTATION should support decision-making and control. If a document does not help someone operate, verify, or improve the ISMS, revise it or consider whether it is needed.

Frequently asked questions
Does ISO 27001 require a formal ISMS manual?
No. ISO/IEC 27001:2022 does not require a document titled “ISMS manual.” Some organizations create one as a helpful summary, but certification depends on meeting the standard’s documented information requirements and proving the ISMS works.
What is the most important ISO 27001 document?
The Statement of Applicability is often the most important because it links Annex A controls to risk treatment decisions. The risk assessment, risk treatment plan, scope, and information security policy are also central.
Can small businesses have simple ISO 27001 documents?
Yes. Documentation should match the size, complexity, and risk profile of the organization. A small business can use concise documents if they clearly define requirements and produce reliable records.
How often should ISO 27001 documents be reviewed?
Many organizations review key ISMS documents at least once a year. They should also be reviewed after major changes, incidents, audit findings, new legal requirements, or significant changes in risk.
Are templates enough for certification?
Templates can help, but they are not enough by themselves. Documents must reflect the organization’s real scope, risks, controls, responsibilities, and evidence. Auditors will test whether the documents match actual practice.
The practical path to certification-ready documentation
ISO 27001 documentation is not paperwork for its own sake. It is the structure that shows how the ISMS is planned, operated, monitored, and improved.
Start with the required foundation documents. Build risk and control documents from real assessments. Create procedures that people can follow. Keep records as evidence of daily operation. Review and improve documents as the business changes.
For a clear walkthrough of the certification process, watch this guide on ISO 27001 Certification Explained - Complete Process from Documentation to Certification
A well-documented ISMS gives leadership, employees, customers, and auditors confidence that information security is managed with discipline, not guesswork.



Comments