· Reference · 8 min read

ISO 27001 Required Documents and Records

Understand ISO 27001 required documented information, distinguish clause evidence from selected controls, and organise records for reliable audits.


ISO/IEC 27001:2022 requires organisations to maintain and retain particular documented information, but it rarely dictates a filename or format. A compliant information security management system (ISMS) can use policies, registers, workflow records, reports, tickets and system evidence as long as required content is present, controlled and reliable.

The most important distinction is between management-system information required directly by clauses 4–10 and documentation needed because the organisation selected particular controls or created its own requirements.

This reference provides an original AuditPrepared structure. It summarises requirements without reproducing ISO text; organisations should use a licensed copy of the standard for authoritative wording.

Maintain versus retain

In practical terms:

  • Maintain means keep information current and available for use, such as a policy or defined process.
  • Retain means preserve evidence of what happened, such as audit results or competence records.

One item can serve both purposes. A risk register may describe current risks and also retain dated assessment decisions. The organisation should make clear which version is authoritative and which history must be preserved.

Core documented information from clauses 4–10

The following table is a practical summary, not ISO text.

ISMS areaDocumented information to controlEvidence purpose
ScopeDefined ISMS boundaries and applicabilityShows what the management system covers
Information security policyApproved direction and commitmentsDemonstrates leadership direction and communication
Risk assessment processDefined, repeatable risk method and criteriaShows how consistent risk decisions are made
Risk treatment processMethod for selecting and managing treatmentConnects risks to treatment choices
Statement of ApplicabilityNecessary controls, reasoning and implementation statusExplains control inclusion and exclusion
Risk treatment planActions, responsibilities and approvalsShows how treatment will be delivered and accepted
Information security objectivesObjectives and planning informationEnables monitoring and accountability
Competence evidenceRecords supporting competence of relevant peopleDemonstrates qualification for assigned work
Operational evidenceRecords sufficient to show planned processes occurredSupports confidence in controlled operation
Risk assessment resultsDated outputs from assessmentsShows risks were evaluated as planned
Risk treatment resultsRecords of treatment performedShows approved treatment was carried out
Monitoring and measurement resultsResults from defined evaluation activitiesSupports performance conclusions
Internal audit programme and resultsPlanning and completed audit evidenceDemonstrates independent evaluation
Management review resultsDecisions and actions from top-management reviewShows leadership evaluation and direction
Nonconformity and corrective actionIssue, response and result recordsDemonstrates controlled improvement

Confirm exact applicability and wording in the licensed ISO/IEC 27001:2022 publication. ISO’s official page identifies the current standard and its purpose.

Scope evidence

The scope should identify organisational and technical boundaries clearly enough to understand included activities, services, locations and interfaces. Supporting records may include process maps, architecture, legal entities and dependency analysis.

Do not maintain different scope descriptions across the certificate, sales material, policy and risk register. If summaries are needed, designate one approved statement as authoritative.

Policy evidence

The information security policy should be approved at the right level, appropriate to the organisation and available to intended audiences. Evidence can include approval, communication and review records.

A policy alone proves direction, not operation. Audit trails should connect it to objectives, responsibilities, risk decisions and performance.

Risk assessment and treatment evidence

The organisation needs defined processes and retained results. Keep the method separate from the latest results so changes to one do not erase the history of the other.

Useful evidence includes:

  • assessment scope and date;
  • risk scenario, owner and affected objectives;
  • likelihood, consequence and evaluation;
  • existing controls and evidence considered;
  • treatment decision and approver;
  • action owner and due date;
  • residual risk and acceptance authority; and
  • reassessment or change history.

The Clause 6.1.2 risk assessment guide explains how to make the method repeatable and auditable.

Statement of Applicability and treatment plan

The Statement of Applicability is not just an Annex A status table. It should communicate which controls are necessary, why they are included, why Annex A controls are excluded and whether necessary controls are implemented.

The treatment plan turns decisions into accountable work. Link actions to risks, owners, timing, resources, completion evidence and remaining acceptance.

Use the Statement of Applicability builder to structure decisions, then validate the output against the organisation’s licensed standard and approved risk method.

Objectives and evaluation records

Objectives should be capable of evaluation and connected to accountable work. Retain results produced by the organisation’s monitoring and measurement arrangements.

An objective such as “improve security awareness” is difficult to evaluate. A better record defines the intended outcome, measure, source, frequency, owner and target or decision threshold.

Keep data-quality limitations visible. A dashboard can be controlled documented information, but an attractive chart is not reliable evidence if its population and calculation are unknown.

Competence records

Competence evidence may include education, training, experience, witnessed performance, work review and authorisation. Retain only necessary personal information and protect access.

Professional credentials can support a decision but do not replace role-specific evaluation. See using professional credentials as competence evidence for a proportionate method.

Internal audit records

Retain enough information to show the audit programme was planned and audits were performed. Depending on the organisation, evidence may include:

  • programme, objectives, scope and criteria;
  • auditor selection and competence;
  • plans and sampling records;
  • working evidence and interview notes;
  • findings and conclusions;
  • reports and distribution;
  • correction and corrective-action tracking; and
  • effectiveness follow-up.

Protect confidential evidence and avoid retaining unnecessary copies of sensitive operational data.

Management review records

The record should show that top management considered required inputs and made decisions concerning the ISMS. Attendance slides alone are weak evidence.

Retain the information reviewed, material discussion, conclusions, decisions, action owner, due date and follow-up. Our guide to effective ISO 27001 management review provides an evidence-driven structure.

Corrective-action records

Evidence should distinguish immediate correction, cause analysis, extent review, corrective action and effectiveness evaluation. Keep links to the finding, affected process, owner and dates.

Closing a record after updating a document may be premature if the issue concerned operation over time.

Documentation arising from selected controls

Annex A is a reference set used during risk treatment. The organisation determines necessary controls, records decisions in the Statement of Applicability and establishes the information needed to operate those controls.

Depending on selection and design, controlled information may address:

  • asset ownership and acceptable use;
  • identity, access and privileged activity;
  • supplier requirements and monitoring;
  • incident reporting, assessment, response and learning;
  • backup, recovery and continuity;
  • change, configuration and vulnerability management;
  • secure development and testing;
  • physical security and environmental protection;
  • logging and monitoring;
  • legal, regulatory and contractual obligations; and
  • documented operating procedures.

Do not claim that every possible policy is mandatory. The need depends on clause requirements, selected controls, risk, obligations and the organisation’s own rules.

The Annex A control selection and evidence guide explains this risk-based relationship.

Organisation-created requirements

Once an organisation approves a procedure, frequency or form as part of the ISMS, auditors may use it as a criterion. Avoid writing unnecessary promises such as “all access is reviewed monthly” if risk-based frequencies differ.

Review internally created requirements for relevance, feasibility and consistency. Simplifying a redundant rule through authorised document control is better than repeatedly violating it.

Control documented information

For each important item, define:

  • title or identifier;
  • owner and approval authority;
  • current version and effective date;
  • storage and access;
  • change control;
  • review trigger or frequency;
  • retention and disposal where applicable;
  • protection of confidentiality and integrity; and
  • treatment of external documents.

System records need control too. Confirm time sources, role permissions, audit logs, export integrity and retention. A ticketing platform does not make evidence reliable automatically.

One source of truth, several views

Avoid copying the same information into multiple files. A central risk record can feed a management dashboard and audit report while remaining the authoritative source.

Use stable identifiers and links. If information is exported for an audit, record the source, extraction time, filters and responsible person. This protects traceability when the live system changes later.

An evidence register can organise locations, owners and periods without moving every record into one repository.

Pass, partial and fail examples

Pass: Required information was identifiable, current and controlled. Sampled records connected requirements to authorised decisions and operating evidence across the audit period.

Partial: Core documents existed and processes operated, but several system exports lacked population or extraction details, limiting confidence in completeness.

Fail: The organisation presented generic policies but could not produce risk treatment results, internal audit evidence, management review decisions or current control records.

These examples illustrate evidence maturity, not predetermined certification classifications.

Common weaknesses

Organisations often:

  • confuse document titles with required content;
  • copy clause wording without explaining operation;
  • treat all Annex A documents as universally required;
  • maintain current records but erase necessary history;
  • keep several conflicting versions;
  • collect excessive personal or security-sensitive evidence;
  • store screenshots without source or date; or
  • prepare records only before an external visit.

Use the ISO 27001 readiness checker to identify evidence gaps and then confirm each requirement against the licensed standard.

The practical conclusion

ISO 27001 documented information should make the ISMS governable and verifiable. Maintain current direction and methods; retain reliable evidence of decisions, operation, evaluation and improvement.

Organise information around purpose and ownership rather than filenames. Distinguish direct clause requirements from selected-control and organisation-created needs, control the authoritative source and preserve enough history for a defensible audit trail.

The subject perspective was informed by Advisera’s ISO 27001:2022 documented-information overview, with the standard edition and management-system purpose checked against ISO.