top of page
bg_3.png
bg_3.png

ISO 27001 Documentation Requirements: Essential Documents for Certification

Sep 5
9 min read

Updated: Sep 6

ISO 27001 certification is not awarded for having a large folder of documents. It is awarded when an organization can show that its Information Security Management System, or ISMS, is planned, operated, checked, and improved in a controlled way.



Documentation is how that control becomes visible.


For ISO/IEC 27001:2022, the standard uses the term documented information. That includes documents you maintain, such as policies and procedures, and records you retain, such as audit results, risk assessment outputs, and evidence of corrective action.


Good ISO 27001 documentation helps answer three basic audit questions:


  • What did the organization decide to do?

  • How does it carry out those decisions?

  • What evidence proves it happened?


When those answers are clear, the certification process becomes far easier to manage.


Wide-angle view of labeled compliance binders on a wooden archive shelf
Organized documentation makes the ISMS easier to explain and audit.

ISO 27001 Documentation Requirements starts with the ISMS foundation


The first group of documents defines the scope, direction, and governance of the ISMS. These are not just formal statements. They set the boundaries for everything that follows.


ISMS scope


The ISMS scope explains what parts of the organization the ISMS covers. It may include specific locations, departments, systems, services, products, or business processes.


Its purpose is to make certification boundaries clear. For example, a software company may include product development, cloud hosting, customer support, and related corporate systems. Another organization may limit the initial scope to one business unit.


A strong scope statement should include:


  • The business activities covered

  • Relevant locations or remote work arrangements

  • Key systems, applications, and services

  • Important internal and external dependencies

  • Interfaces with suppliers, customers, or other departments


Auditors will check whether the scope is reasonable and whether controls match the risks inside that scope.


Information security policy


The information security policy is a required document under ISO 27001. It states the organization’s commitment to protecting information and supporting the ISMS.


At a minimum, it should align with business objectives, commit to meeting applicable requirements, and support continual improvement. It should also be communicated to relevant staff and interested parties where appropriate.


This policy does not need to be long. A clear one-page policy, approved by leadership and understood by staff, is far more useful than a ten-page document no one reads.


Information security objectives


ISO 27001 requires documented information about information security objectives. These objectives turn broad intent into measurable direction.


Examples may include:


  • Complete risk treatment actions within approved target dates

  • Review privileged access at defined intervals

  • Reduce repeat security incidents through improved root cause analysis

  • Complete security awareness training for relevant personnel


Each objective should include what will be done, who owns it, how progress will be evaluated, and when it will be reviewed.


Roles, responsibilities, and authorities


The standard expects leadership to assign and communicate ISMS responsibilities. While ISO 27001 does not require a single document with a specific title, most organizations keep a responsibility matrix, job descriptions, or an ISMS roles document.


This helps avoid confusion during implementation and audit. For example, it should be clear who owns risk assessments, who approves risk treatment, who manages incidents, and who reports ISMS performance to leadership.


Risk and control documents form the core of certification evidence


Risk management is at the center of ISO 27001. The ISMS exists to manage information security risks in a structured and repeatable way.


This is where many certification projects succeed or struggle.


Risk assessment methodology


ISO 27001 requires organizations to define and apply an information security risk assessment process. The documented method should explain how risks are identified, analyzed, evaluated, and accepted.


A practical methodology will define:


  • Risk criteria

  • Impact and likelihood scales

  • How risk levels are calculated

  • What makes a risk acceptable or unacceptable

  • How often risk assessments are reviewed

  • Who approves results


The goal is consistency. Two different teams should be able to apply the method and reach comparable results.


Risk assessment results


The results of risk assessments must be retained as documented information. These records show which risks were identified and how the organization evaluated them.


Typical risk assessment records include:


  • Assets, processes, or scenarios assessed

  • Threats and vulnerabilities considered

  • Potential business impact

  • Existing controls

  • Risk rating before treatment

  • Risk owner

  • Decision on whether treatment is needed


These records demonstrate that the organization understands its risk environment and makes informed decisions.


Risk treatment plan


The risk treatment plan explains what the organization will do about unacceptable risks. It connects risk assessment results to planned actions.


The plan should show:


  • Selected treatment option

  • Control or action to be implemented

  • Responsible owner

  • Target completion date

  • Current status

  • Residual risk after treatment

  • Approval of residual risk where needed


Common treatment options include reducing the risk with controls, accepting the risk, avoiding the activity, or sharing the risk through contracts or insurance. Any acceptance decision should be documented and approved at the right level.


Statement of Applicability


The Statement of Applicability, often called the SoA, is one of the most important ISO 27001 documents.


It lists the Annex A controls and explains whether each control applies to the organization. For each applicable control, it should identify implementation status and reference related policies, procedures, or evidence. For controls that do not apply, it should give a clear justification.


The SoA matters because it connects risk treatment decisions to the control set in Annex A. It also gives auditors a practical map for testing the ISMS.


The Statement of Applicability should not be treated as a checkbox list. It should explain why controls were selected and how they support risk treatment.

Close-up of a printed risk matrix with colored rating cells on a neutral workbench
Risk assessment records show how security decisions were made.

Policies and procedures explain how the ISMS operates


Policies set expectations. Procedures explain how work is done. Together, they make the ISMS repeatable.


The exact set of policies and procedures depends on the organization’s scope, risks, legal requirements, and selected Annex A controls. ISO 27001 does not require every organization to use identical document titles.


Still, most certification-ready ISMS documentation includes the following.


Document

Purpose

How it supports the ISMS

Access control policy

Defines rules for user access, privileged access, and access reviews

Reduces unauthorized access risk

Asset management procedure

Identifies and manages information assets

Helps protect systems, data, and services based on value and risk

Acceptable use policy

Sets rules for use of company systems, devices, and information

Guides staff behavior and reduces misuse

Incident management procedure

Explains how incidents are reported, assessed, handled, and learned from

Supports fast response and evidence of control

Supplier security procedure

Defines security checks and ongoing oversight for suppliers

Manages third-party risk

Change management procedure

Controls changes to systems, applications, and infrastructure

Reduces disruption and security gaps

Backup and recovery procedure

Sets backup frequency, responsibilities, and recovery checks

Supports availability and recovery planning

Business continuity or ICT readiness procedure

Defines response and recovery arrangements for disruption

Helps maintain critical operations

Document control procedure

Manages creation, approval, review, version control, and retention

Keeps ISMS documents accurate and current

Internal audit procedure

Explains how audits are planned, performed, reported, and followed up

Supports independent checking of the ISMS

Corrective action procedure

Defines how nonconformities are investigated and resolved

Drives improvement and prevents repeat issues


For ISO 27001 certification, ISO 27001 MANUALS are optional. Some organizations still create an ISMS manual because it gives a simple overview of scope, processes, documents, and responsibilities. If used, keep it short and useful. Do not turn it into a duplicate of every policy and procedure.


Annex A control documents


ISO/IEC 27001:2022 Annex A contains controls across organizational, people, physical, and technological themes. The SoA determines which controls apply.


Many Annex A controls can be supported by existing documents. For example:


  • Screening and confidentiality agreements may sit with HR records

  • Physical security rules may sit with facilities procedures

  • Logging and monitoring may sit with IT operations procedures

  • Secure development rules may sit with engineering standards

  • Data retention may sit with privacy or records management procedures


This is acceptable as long as the documents are controlled, current, and available to the people who need them.


Records prove that the ISMS is working


A policy says what should happen. A record proves what did happen.


During a certification audit, auditors will sample records to confirm that the ISMS operates in practice. Weak records are one of the most common reasons organizations receive findings.


Core ISO 27001 records usually include:


  • Risk assessment results

  • Risk treatment results

  • Evidence of competence, training, and awareness

  • Monitoring and measurement results

  • Internal audit program and audit results

  • Management review results

  • Nonconformities and corrective actions

  • Evidence of control operation, such as access reviews, incident logs, backup test results, supplier reviews, and change approvals


Training and awareness records


Training records show that people performing ISMS-related work are competent and aware of their responsibilities.


Records may include attendance logs, learning platform reports, role-based training evidence, phishing simulation results, or signed acknowledgments of key policies.


The focus should be practical. A system administrator needs different training from a sales employee handling customer information.


Monitoring and performance records


ISO 27001 requires organizations to evaluate ISMS performance. Records may include metrics, dashboards, reports, or meeting notes.


Useful measures may include:


  • Status of risk treatment actions

  • Number and type of security incidents

  • Timeliness of access reviews

  • Backup success and recovery test results

  • Internal audit findings

  • Corrective action status

  • Supplier review results


Choose measures that support decisions. Avoid collecting data only because it looks impressive.


Internal audit and management review records


Internal audits check whether the ISMS conforms to ISO 27001, the organization’s own requirements, and planned arrangements. Audit records should include the audit program, scope, criteria, findings, evidence reviewed, and follow-up actions.


Management review records show that leadership evaluates ISMS performance and makes decisions. They should capture inputs such as audit results, risk status, incidents, objectives, changes affecting the ISMS, and opportunities for improvement.


These records are important because they show top management involvement, not just technical activity.


Eye-level view of a locked metal records cabinet with neatly labeled folders
Records provide evidence that ISMS controls operate in practice.

How to create and maintain ISO 27001 documents effectively


The best documentation is clear, controlled, and used. It does not need to be complicated.


Start with the standard and the risk assessment


Build documents around actual requirements and real risks. Avoid downloading a large template library and filling in company names without understanding the content.


A good sequence is:


  1. Define the ISMS scope

  2. Approve the information security policy

  3. Define the risk assessment and treatment process

  4. Complete the risk assessment

  5. Build the Statement of Applicability

  6. Create needed policies and procedures based on selected controls

  7. Generate records by operating the ISMS

  8. Audit, review, and improve the system


This sequence keeps the documentation connected to the ISMS rather than separate from it.


Use simple document control


Every controlled document should have a clear owner, version, approval date, and review cycle. Staff should know where to find the current version.


At minimum, document control should cover:


  • Creation and approval

  • Version history

  • Access and distribution

  • Periodic review

  • Change approval

  • Obsolete document handling

  • Record retention


This prevents an auditor from finding three different versions of the same access control policy in use.


Write for the people who will use the document


A policy should be short enough for staff to understand. A procedure should be specific enough for someone to follow.


Use plain language. Define terms only where needed. Replace vague instructions such as “review access regularly” with clear expectations such as “system owners review privileged access every quarter.”


Also avoid over-documenting. If a team cannot realistically follow a procedure, either improve the process or simplify the document.


Keep records as work happens


Do not wait until the certification audit to gather evidence. Build records into normal work.


For example:


  • Save access review approvals when the review is completed

  • Record incident decisions during the incident process

  • Update the risk treatment plan when actions change status

  • Keep management review minutes at the time of the review

  • Store audit evidence with the audit report


This approach reduces audit stress and improves trust in the ISMS.


Review documents after meaningful change


Annual review is common, but it should not be the only trigger. Update documents when there are major changes to systems, services, laws, suppliers, risks, or organizational structure.


A practical ISMS document review should ask:


  • Is the document still accurate?

  • Does it match how the process works today?

  • Are responsibilities still correct?

  • Do records show the process is being followed?

  • Did incidents, audits, or corrective actions reveal gaps?


ISO 27001 DOCUMENTATION should support decision-making and control. If a document does not help someone operate, verify, or improve the ISMS, revise it or consider whether it is needed.


Overhead view of a version-controlled document checklist clipped to a metal board
A controlled checklist helps keep certification documents current.

Frequently asked questions


Does ISO 27001 require a formal ISMS manual?


No. ISO/IEC 27001:2022 does not require a document titled “ISMS manual.” Some organizations create one as a helpful summary, but certification depends on meeting the standard’s documented information requirements and proving the ISMS works.


What is the most important ISO 27001 document?


The Statement of Applicability is often the most important because it links Annex A controls to risk treatment decisions. The risk assessment, risk treatment plan, scope, and information security policy are also central.


Can small businesses have simple ISO 27001 documents?


Yes. Documentation should match the size, complexity, and risk profile of the organization. A small business can use concise documents if they clearly define requirements and produce reliable records.


How often should ISO 27001 documents be reviewed?


Many organizations review key ISMS documents at least once a year. They should also be reviewed after major changes, incidents, audit findings, new legal requirements, or significant changes in risk.


Are templates enough for certification?


Templates can help, but they are not enough by themselves. Documents must reflect the organization’s real scope, risks, controls, responsibilities, and evidence. Auditors will test whether the documents match actual practice.


The practical path to certification-ready documentation


ISO 27001 documentation is not paperwork for its own sake. It is the structure that shows how the ISMS is planned, operated, monitored, and improved.


Start with the required foundation documents. Build risk and control documents from real assessments. Create procedures that people can follow. Keep records as evidence of daily operation. Review and improve documents as the business changes.


For a clear walkthrough of the certification process, watch this guide on ISO 27001 Certification Explained - Complete Process from Documentation to Certification


A well-documented ISMS gives leadership, employees, customers, and auditors confidence that information security is managed with discipline, not guesswork.



Comments


bottom of page