Quick Answer: ISO 27001 requires two types of documentation: mandatory documents (policies, plans, and procedures you must create) and mandatory records (evidence that your system is actually working). There are roughly 12 mandatory documents and 12 mandatory records under ISO 27001:2022. Miss any of them and your certification audit will fail — it's that straightforward.
Key Takeaways
- ISO 27001:2022 has both mandatory documents and mandatory records — they're different things and you need both
- The Statement of Applicability (SoA) is widely considered the most critical single document in your entire ISMS
- Records prove your system is operating — documents prove it exists
- Auditors will check for every item on this list during your Stage 2 audit
- You can add more documents than the minimum, but you cannot have fewer
- Document control itself is a requirement — your documents must be version-controlled and accessible
- Getting the documentation right from the start saves significant rework later
What's the Difference Between Documents and Records in ISO 27001?
Documents and records serve different purposes, and ISO 27001 treats them differently.
Documents are the policies, procedures, and plans you create to define how your Information Security Management System (ISMS) works. They're living files — you update them as your business changes.
Records are the evidence that your ISMS is actually running. Audit reports, meeting minutes, training logs — these prove to an auditor that you're not just writing policies and filing them away. Records are typically kept as-is and not altered after the fact.
Think of it this way: your Information Security Policy is a document. The minutes from your management review meeting where you discussed that policy? That's a record.
The ISO 27001 Required Documents and Records (Complete List): Mandatory Documents
Every organisation pursuing ISO 27001 certification must produce these documents. There are no optional ones in this list — all are explicitly required by the standard.
The 12 Mandatory Documents
| # | Document | What It Covers |
|---|---|---|
| 1 | ISMS Scope Document | Defines the boundaries of your information security system — what's in, what's out |
| 2 | Information Security Policy | Your top-level commitment to information security, signed off by leadership |
| 3 | Risk Assessment Process | The methodology you use to identify and evaluate risks |
| 4 | Risk Treatment Process | How you decide what to do about the risks you've found |
| 5 | Statement of Applicability (SoA) | Lists all 93 Annex A controls, which apply to you, which don't, and why |
| 6 | Risk Treatment Plan | The specific actions you'll take to address identified risks |
| 7 | Information Security Objectives | Measurable goals for your ISMS for the period ahead |
| 8 | Competence Requirements | What skills and knowledge your people need for security-related roles |
| 9 | Documented Procedures | Specific procedures required by the controls you've selected in your SoA |
| 10 | Asset Inventory | A register of information assets within your ISMS scope |
| 11 | Acceptable Use Policy | Rules for how staff can use company information and systems |
| 12 | Access Control Policy | How access to systems and data is granted, managed, and revoked |
Here's the truth about the Statement of Applicability: It's not just a checkbox exercise. Your SoA needs to justify every control you've excluded — and auditors read it carefully. A weak SoA is one of the most common reasons businesses struggle at Stage 2. If you're unsure how to approach it, ISO Adviser's implementation support can help you get it right first time.
The ISO 27001 Required Documents and Records (Complete List): Mandatory Records
Records are your evidence trail. Without them, you have policies that exist only on paper — and auditors know the difference.
The 12 Mandatory Records
| # | Record | What It Proves |
|---|---|---|
| 1 | Risk Assessment Results | That you've actually conducted risk assessments, not just written a process for them |
| 2 | Risk Treatment Results | Evidence of decisions made about how to treat each identified risk |
| 3 | Training and Competency Records | Proof that staff have received appropriate security training |
| 4 | Monitoring and Measurement Results | Evidence that you're tracking ISMS performance against your objectives |
| 5 | Internal Audit Programme | Your schedule and plan for internal audits |
| 6 | Internal Audit Reports | The actual results of those audits |
| 7 | Management Review Minutes | Records of leadership meetings where ISMS performance was reviewed |
| 8 | Corrective Action Records | Documentation of non-conformities found and what you did about them |
| 9 | Evidence of Competence | CVs, certificates, training records — proof people have the skills they claim |
| 10 | Supplier Security Records | Evidence of how you've assessed and managed third-party security risks |
| 11 | Incident Log | A record of information security incidents and how they were handled |
| 12 | Business Continuity Test Records | Evidence that continuity plans have been tested (if applicable to your scope) |
Common mistake: Many businesses create the documents but neglect the records. An auditor visiting your site doesn't just want to see your policies — they want to see proof you're living by them. Records are that proof.
For a detailed look at what auditors actually check during your certification visit, see our guide on what happens during an ISO certification audit.
Which Documents Are Truly Non-Negotiable?
All of them — but some carry more weight than others.
If you had to prioritise, focus on these first:
- ISMS Scope — without a defined scope, nothing else makes sense
- Statement of Applicability — auditors consider this the spine of your ISMS
- Risk Assessment and Treatment documentation — the heart of ISO 27001
- Information Security Policy — your public commitment, signed by top management
Get these four right and the rest becomes much more manageable. To understand how documentation fits into the broader ISO 27001 certification process, it helps to see the full picture before you start writing.
Do You Need Additional Documents Beyond the Mandatory List?
Yes — and this is where many businesses underestimate the work involved.
The 93 Annex A controls in ISO 27001:2022 often require supporting documentation beyond the mandatory list. For example:
- A clear desk and clear screen policy if you've selected that control
- Cryptography procedures if you use encryption
- Change management procedures for IT systems
- Supplier agreements with security clauses
The controls you select in your SoA determine which additional documents you'll need. This is why the SoA isn't just an admin exercise — it drives your entire documentation structure.
If you're not sure where your current documentation stands, a gap analysis will tell you exactly what you have, what you're missing, and what needs improving before your audit.
FAQ
How many documents does ISO 27001 actually require?
ISO 27001:2022 requires approximately 12 mandatory documents and 12 mandatory records as a minimum. Additional documents are typically needed depending on which Annex A controls you select in your Statement of Applicability.
What is the most important ISO 27001 document?
The Statement of Applicability (SoA) is widely considered the most critical document. It lists all 93 Annex A controls, confirms which apply to your organisation, and justifies any exclusions. Auditors scrutinise it closely.
Can I use templates for ISO 27001 documentation?
Yes, templates are a legitimate starting point. But they must be customised to reflect your actual business, risks, and controls — not left as generic placeholders. Auditors can spot a template that hasn't been adapted.
What's the difference between a document and a record in ISO 27001?
Documents define how your ISMS works (policies, procedures, plans). Records provide evidence that it's actually working (audit reports, training logs, meeting minutes). You need both.
Do small businesses need the same documents as large ones?
Yes — the mandatory list is the same regardless of size. However, smaller businesses can often produce simpler, shorter documents that still satisfy the requirements. ISO 27001 doesn't mandate length or complexity, just completeness.
How long do you need to keep ISO 27001 records?
The standard doesn't specify exact retention periods for most records. Your organisation should define retention periods in your document control procedure, taking into account legal and contractual requirements.
What happens if you're missing a mandatory document at your audit?
Missing mandatory documentation results in a major non-conformity, which means you won't receive certification until it's resolved. This is why preparation matters — see our audit preparation guide for a 90-day plan.
Is the risk assessment a document or a record?
Both. The risk assessment process is a document (how you'll do it). The risk assessment results are records (what you found when you did it). You need both.
Conclusion
Getting your ISO 27001 documentation right isn't glamorous work, but it's the foundation everything else rests on. Miss a mandatory document and your audit fails. Produce records that don't reflect real activity and auditors will see straight through it.
Here's what to do next:
- Download or create a documentation checklist using the tables above as your starting point
- Complete your Statement of Applicability — this determines what additional documents you'll need
- Run a gap analysis to identify what you have versus what you need
- Build your records system before your audit, not during it
If you'd rather not navigate this alone, ISO Adviser works with businesses across the UK to build documentation that satisfies auditors and actually serves your business. No unnecessary paperwork, no generic templates — just practical support that gets you certified.
✅ ISO 27001 Documentation Readiness Checker
Tick each item as you complete it. Switch between mandatory documents and records using the tabs below.
