ISO/IEC 27001:2022

ISO 27001 Mandatory Documents and Records

One of the most common questions during ISO 27001 implementation is: what documents and records are actually required?

This guide explains the mandatory documented information required by ISO/IEC 27001:2022, plus the common supporting documents organizations typically maintain for effective ISMS implementation and certification readiness.

10 min read ISMS Documentation Guide

Key Takeaways

  • ISO 27001 requires specific documented information to be maintained and retained.
  • The ISMS scope, Information Security Policy, risk assessment process, risk treatment process and SoA are key mandatory documents.
  • Records such as risk assessment results, internal audit results, management review results and corrective actions must be retained.
  • Additional operational documents are often needed to demonstrate effective implementation.
  • A practical ISMS should avoid both under-documentation and unnecessary paperwork.

In This Article

What is Documented Information? Mandatory ISO 27001 Documents and Records Documents vs Records Common Supporting ISMS Documents Recommended ISMS Document Structure Common Documentation Mistakes What Auditors Look For FAQ

What is Documented Information in ISO 27001?

ISO/IEC 27001 uses the term documented information to refer to documents and records required to establish, implement, maintain and continually improve the Information Security Management System.

In simple terms, documented information includes both the documents that describe how the ISMS operates and the records that prove the ISMS has been implemented.

Maintained Information

Documents such as policies, scope, procedures, methodologies, plans and standards.

Retained Information

Records such as completed registers, audit reports, management review minutes and corrective action records.

Mandatory ISO 27001 Documents and Records

The table below summarizes the key documented information required by ISO/IEC 27001:2022.

Clause Mandatory Documented Information Typical Document / Record
4.3 Scope of the ISMS ISMS Scope Statement / ISMS Manual
5.2 Information Security Policy Approved Information Security Policy
6.1.2 Information security risk assessment process Risk Assessment Methodology / Procedure
6.1.2 Information security risk assessment results Risk Assessment Register
6.1.3 Information security risk treatment process Risk Treatment Methodology / Procedure
6.1.3 Statement of Applicability Statement of Applicability (SoA)
6.1.3 Information security risk treatment plan Risk Treatment Plan
6.2 Information security objectives Information Security Objectives Register
7.2 Evidence of competence Competency / Training Records
8.2 Results of information security risk assessment Updated Risk Assessment Records
8.3 Results of information security risk treatment Risk Treatment Progress / Completion Records
9.1 Monitoring and measurement results Monitoring & Measurement Register
9.2 Internal audit programme and audit results Audit Programme, Plan, Checklist and Report
9.3 Management review results Management Review Minutes
10.1 Nonconformities and corrective actions Corrective Action Records / NC Register

Documents vs Records in ISO 27001

Documents

  • Describe what shall be done.
  • Provide direction, requirements or guidance.
  • Examples include policy, procedures, plans and standards.

Records

  • Provide evidence of what has been done.
  • Show implementation and results.
  • Examples include registers, logs, reports and completed forms.

Common Supporting ISMS Documents

In addition to mandatory documented information, most organizations maintain supporting documents and records to make the ISMS workable, auditable and easier to implement.

Context & Governance

Clause 4 and 5 Support

  • Internal & External Issues Register
  • Interested Parties Register
  • Roles, Responsibilities & Authorities Matrix
  • ISMS Manual
Risk & Assets

Clause 6 and 8 Support

  • Information Asset Register
  • Information Classification Register
  • Risk Assessment Register
  • Risk Treatment Plan
Operations

Control Implementation Support

  • User Access Records
  • Backup and Restoration Records
  • Supplier Security Evaluation
  • Incident Reports
Evaluation

Audit and Improvement Support

  • Internal Audit Programme
  • Internal Audit Checklist
  • Management Review Minutes
  • Corrective Action Records

Download Free ISO 27001 Starter Pack

Includes ISO 27001 implementation checklist, documented information list, information asset register sample and risk assessment sample.

Download Starter Pack

Recommended ISMS Document Structure

A practical ISO 27001 documentation structure can be organized into four levels.

Level Purpose Typical Documents
Level 1 Defines ISMS framework and direction ISMS Manual, Information Security Policy
Level 2 Defines key ISMS procedures Risk Management, Asset Management, Access Control, Incident Management
Level 3 Provides operational guidance Password Standard, Backup Guideline, Incident Response Plan, BYOD Guideline
Level 4 Provides implementation evidence Forms, registers, checklists, logs, audit records and review minutes

Common ISO 27001 Documentation Mistakes

  • Creating too many procedures without actual implementation.
  • Completing a risk assessment without linking it to the Risk Treatment Plan.
  • Preparing a Statement of Applicability without clear justification.
  • Failing to maintain evidence of competence and awareness.
  • Using generic templates without customization.
  • Not updating documented information after incidents, changes or audits.
  • Keeping records for audit only instead of operational use.

What Auditors Look For

Is the ISMS scope clearly defined and appropriate?
Is the Information Security Policy approved and communicated?
Is the risk assessment methodology defined and consistently applied?
Are risk assessment results retained and updated?
Is the Statement of Applicability complete and justified?
Are operational controls supported by evidence?
Are internal audit and management review records available?
Are nonconformities and corrective actions properly closed?

Frequently Asked Questions (FAQ)

No. ISO/IEC 27001:2022 does not specifically require an ISMS Manual. However, many organizations use one to consolidate scope, context, responsibilities and clause-aligned system structure.

Yes. The Statement of Applicability is mandatory and must identify applicable controls, justification for inclusion or exclusion, and implementation status.

ISO 27001 does not prescribe a fixed list of named procedures. However, procedures are commonly maintained to define how risk assessment, risk treatment, access control, incident management, internal audit and improvement are controlled.

Yes. ISO 27001 documentation should be appropriate to the organization's size, complexity, information security risks and operational needs. Small organizations can use a lean but complete documentation structure.

Need a Complete ISO 27001 Document Kit?

Access a complete ISO/IEC 27001:2022 Level 1–4 document kit with ISMS manual, policy, procedures, operational guides, Statement of Applicability, risk registers, internal audit templates and management review records.

View ISO 27001 Document Kit