ISO 27001 Required Documents and Records (Complete List)

Quick Answer: ISO 27001 requires two types of documentation: mandatory documents (policies, plans, and procedures you must create) and mandatory records (evidence that your system is actually working). There are roughly 12 mandatory documents and 12 mandatory records under ISO 27001:2022. Miss any of them and your certification audit will fail — it's that straightforward.


Key Takeaways

  • ISO 27001:2022 has both mandatory documents and mandatory records — they're different things and you need both
  • The Statement of Applicability (SoA) is widely considered the most critical single document in your entire ISMS
  • Records prove your system is operating — documents prove it exists
  • Auditors will check for every item on this list during your Stage 2 audit
  • You can add more documents than the minimum, but you cannot have fewer
  • Document control itself is a requirement — your documents must be version-controlled and accessible
  • Getting the documentation right from the start saves significant rework later

What's the Difference Between Documents and Records in ISO 27001?

Documents and records serve different purposes, and ISO 27001 treats them differently.

Documents are the policies, procedures, and plans you create to define how your Information Security Management System (ISMS) works. They're living files — you update them as your business changes.

Records are the evidence that your ISMS is actually running. Audit reports, meeting minutes, training logs — these prove to an auditor that you're not just writing policies and filing them away. Records are typically kept as-is and not altered after the fact.

Think of it this way: your Information Security Policy is a document. The minutes from your management review meeting where you discussed that policy? That's a record.


The ISO 27001 Required Documents and Records (Complete List): Mandatory Documents

Every organisation pursuing ISO 27001 certification must produce these documents. There are no optional ones in this list — all are explicitly required by the standard.

The 12 Mandatory Documents

#DocumentWhat It Covers
1ISMS Scope DocumentDefines the boundaries of your information security system — what's in, what's out
2Information Security PolicyYour top-level commitment to information security, signed off by leadership
3Risk Assessment ProcessThe methodology you use to identify and evaluate risks
4Risk Treatment ProcessHow you decide what to do about the risks you've found
5Statement of Applicability (SoA)Lists all 93 Annex A controls, which apply to you, which don't, and why
6Risk Treatment PlanThe specific actions you'll take to address identified risks
7Information Security ObjectivesMeasurable goals for your ISMS for the period ahead
8Competence RequirementsWhat skills and knowledge your people need for security-related roles
9Documented ProceduresSpecific procedures required by the controls you've selected in your SoA
10Asset InventoryA register of information assets within your ISMS scope
11Acceptable Use PolicyRules for how staff can use company information and systems
12Access Control PolicyHow access to systems and data is granted, managed, and revoked

Here's the truth about the Statement of Applicability: It's not just a checkbox exercise. Your SoA needs to justify every control you've excluded — and auditors read it carefully. A weak SoA is one of the most common reasons businesses struggle at Stage 2. If you're unsure how to approach it, ISO Adviser's implementation support can help you get it right first time.


The ISO 27001 Required Documents and Records (Complete List): Mandatory Records

Records are your evidence trail. Without them, you have policies that exist only on paper — and auditors know the difference.

The 12 Mandatory Records

#RecordWhat It Proves
1Risk Assessment ResultsThat you've actually conducted risk assessments, not just written a process for them
2Risk Treatment ResultsEvidence of decisions made about how to treat each identified risk
3Training and Competency RecordsProof that staff have received appropriate security training
4Monitoring and Measurement ResultsEvidence that you're tracking ISMS performance against your objectives
5Internal Audit ProgrammeYour schedule and plan for internal audits
6Internal Audit ReportsThe actual results of those audits
7Management Review MinutesRecords of leadership meetings where ISMS performance was reviewed
8Corrective Action RecordsDocumentation of non-conformities found and what you did about them
9Evidence of CompetenceCVs, certificates, training records — proof people have the skills they claim
10Supplier Security RecordsEvidence of how you've assessed and managed third-party security risks
11Incident LogA record of information security incidents and how they were handled
12Business Continuity Test RecordsEvidence that continuity plans have been tested (if applicable to your scope)

Common mistake: Many businesses create the documents but neglect the records. An auditor visiting your site doesn't just want to see your policies — they want to see proof you're living by them. Records are that proof.

For a detailed look at what auditors actually check during your certification visit, see our guide on what happens during an ISO certification audit.


Which Documents Are Truly Non-Negotiable?

All of them — but some carry more weight than others.

If you had to prioritise, focus on these first:

  • ISMS Scope — without a defined scope, nothing else makes sense
  • Statement of Applicability — auditors consider this the spine of your ISMS
  • Risk Assessment and Treatment documentation — the heart of ISO 27001
  • Information Security Policy — your public commitment, signed by top management

Get these four right and the rest becomes much more manageable. To understand how documentation fits into the broader ISO 27001 certification process, it helps to see the full picture before you start writing.


Do You Need Additional Documents Beyond the Mandatory List?

Yes — and this is where many businesses underestimate the work involved.

The 93 Annex A controls in ISO 27001:2022 often require supporting documentation beyond the mandatory list. For example:

  • A clear desk and clear screen policy if you've selected that control
  • Cryptography procedures if you use encryption
  • Change management procedures for IT systems
  • Supplier agreements with security clauses

The controls you select in your SoA determine which additional documents you'll need. This is why the SoA isn't just an admin exercise — it drives your entire documentation structure.

If you're not sure where your current documentation stands, a gap analysis will tell you exactly what you have, what you're missing, and what needs improving before your audit.


FAQ

How many documents does ISO 27001 actually require?
ISO 27001:2022 requires approximately 12 mandatory documents and 12 mandatory records as a minimum. Additional documents are typically needed depending on which Annex A controls you select in your Statement of Applicability.

What is the most important ISO 27001 document?
The Statement of Applicability (SoA) is widely considered the most critical document. It lists all 93 Annex A controls, confirms which apply to your organisation, and justifies any exclusions. Auditors scrutinise it closely.

Can I use templates for ISO 27001 documentation?
Yes, templates are a legitimate starting point. But they must be customised to reflect your actual business, risks, and controls — not left as generic placeholders. Auditors can spot a template that hasn't been adapted.

What's the difference between a document and a record in ISO 27001?
Documents define how your ISMS works (policies, procedures, plans). Records provide evidence that it's actually working (audit reports, training logs, meeting minutes). You need both.

Do small businesses need the same documents as large ones?
Yes — the mandatory list is the same regardless of size. However, smaller businesses can often produce simpler, shorter documents that still satisfy the requirements. ISO 27001 doesn't mandate length or complexity, just completeness.

How long do you need to keep ISO 27001 records?
The standard doesn't specify exact retention periods for most records. Your organisation should define retention periods in your document control procedure, taking into account legal and contractual requirements.

What happens if you're missing a mandatory document at your audit?
Missing mandatory documentation results in a major non-conformity, which means you won't receive certification until it's resolved. This is why preparation matters — see our audit preparation guide for a 90-day plan.

Is the risk assessment a document or a record?
Both. The risk assessment process is a document (how you'll do it). The risk assessment results are records (what you found when you did it). You need both.


Conclusion

Getting your ISO 27001 documentation right isn't glamorous work, but it's the foundation everything else rests on. Miss a mandatory document and your audit fails. Produce records that don't reflect real activity and auditors will see straight through it.

Here's what to do next:

  1. Download or create a documentation checklist using the tables above as your starting point
  2. Complete your Statement of Applicability — this determines what additional documents you'll need
  3. Run a gap analysis to identify what you have versus what you need
  4. Build your records system before your audit, not during it

If you'd rather not navigate this alone, ISO Adviser works with businesses across the UK to build documentation that satisfies auditors and actually serves your business. No unnecessary paperwork, no generic templates — just practical support that gets you certified.


✅ ISO 27001 Documentation Readiness Checker

Tick each item as you complete it. Switch between mandatory documents and records using the tabs below.

0 of 0 completed 0%