One of the most common questions during ISO 27001 implementation is: what documents and records are actually required?
This guide explains the mandatory documented information required by ISO/IEC 27001:2022, plus the common supporting documents organizations typically maintain for effective ISMS implementation and certification readiness.
ISO/IEC 27001 uses the term documented information to refer to documents and records required to establish, implement, maintain and continually improve the Information Security Management System.
In simple terms, documented information includes both the documents that describe how the ISMS operates and the records that prove the ISMS has been implemented.
Documents such as policies, scope, procedures, methodologies, plans and standards.
Records such as completed registers, audit reports, management review minutes and corrective action records.
The table below summarizes the key documented information required by ISO/IEC 27001:2022.
| Clause | Mandatory Documented Information | Typical Document / Record |
|---|---|---|
| 4.3 | Scope of the ISMS | ISMS Scope Statement / ISMS Manual |
| 5.2 | Information Security Policy | Approved Information Security Policy |
| 6.1.2 | Information security risk assessment process | Risk Assessment Methodology / Procedure |
| 6.1.2 | Information security risk assessment results | Risk Assessment Register |
| 6.1.3 | Information security risk treatment process | Risk Treatment Methodology / Procedure |
| 6.1.3 | Statement of Applicability | Statement of Applicability (SoA) |
| 6.1.3 | Information security risk treatment plan | Risk Treatment Plan |
| 6.2 | Information security objectives | Information Security Objectives Register |
| 7.2 | Evidence of competence | Competency / Training Records |
| 8.2 | Results of information security risk assessment | Updated Risk Assessment Records |
| 8.3 | Results of information security risk treatment | Risk Treatment Progress / Completion Records |
| 9.1 | Monitoring and measurement results | Monitoring & Measurement Register |
| 9.2 | Internal audit programme and audit results | Audit Programme, Plan, Checklist and Report |
| 9.3 | Management review results | Management Review Minutes |
| 10.1 | Nonconformities and corrective actions | Corrective Action Records / NC Register |
In addition to mandatory documented information, most organizations maintain supporting documents and records to make the ISMS workable, auditable and easier to implement.
Includes ISO 27001 implementation checklist, documented information list, information asset register sample and risk assessment sample.
Download Starter PackA practical ISO 27001 documentation structure can be organized into four levels.
| Level | Purpose | Typical Documents |
|---|---|---|
| Level 1 | Defines ISMS framework and direction | ISMS Manual, Information Security Policy |
| Level 2 | Defines key ISMS procedures | Risk Management, Asset Management, Access Control, Incident Management |
| Level 3 | Provides operational guidance | Password Standard, Backup Guideline, Incident Response Plan, BYOD Guideline |
| Level 4 | Provides implementation evidence | Forms, registers, checklists, logs, audit records and review minutes |
No. ISO/IEC 27001:2022 does not specifically require an ISMS Manual. However, many organizations use one to consolidate scope, context, responsibilities and clause-aligned system structure.
Yes. The Statement of Applicability is mandatory and must identify applicable controls, justification for inclusion or exclusion, and implementation status.
ISO 27001 does not prescribe a fixed list of named procedures. However, procedures are commonly maintained to define how risk assessment, risk treatment, access control, incident management, internal audit and improvement are controlled.
Yes. ISO 27001 documentation should be appropriate to the organization's size, complexity, information security risks and operational needs. Small organizations can use a lean but complete documentation structure.
Access a complete ISO/IEC 27001:2022 Level 1–4 document kit with ISMS manual, policy, procedures, operational guides, Statement of Applicability, risk registers, internal audit templates and management review records.
View ISO 27001 Document Kit