ISO 27001 documents required, Siege Cyber guide to the mandatory documentation list
Blog

ISO 27001 Documents Required: A Practical 2026 List

ISO 27001:2022 names sixteen pieces of documented information you must be able to produce, running from the ISMS scope in clause 4.3 through to corrective action records in clause 10.2. Annex A adds roughly ten more where the relevant controls apply, such as an asset inventory and an access control policy. A small Australian business can usually deliver the whole set as about eight documents plus six registers, because the standard requires the information to exist, not a separate file for each requirement.

This guide lists every required item by clause, shows which ones can be combined, and sets out what the Stage 1 and Stage 2 auditors ask for.

ISO 27001 documents required, Siege Cyber guide to the mandatory documentation list
The standard requires documented information, not a filing cabinet. The distinction saves small teams weeks.

Which documents does ISO 27001 actually require?

ISO 27001:2022 requires sixteen items of documented information across clauses 4 to 10. In Australia the standard is adopted as AS/NZS ISO/IEC 27001:2023, which is the 2022 international edition with an Australian and New Zealand cover. The clause numbers below are identical in both.

ClauseDocumented informationWhat it is
4.3ISMS scopeThe boundary: which people, systems, sites and services are inside
5.2Information security policyThe top level statement of intent, approved by management
6.1.2Risk assessment processHow you identify, analyse and evaluate risk, written down
6.1.3Risk treatment processHow you decide what to do about each risk
6.1.3 dStatement of ApplicabilityEvery Annex A control, whether it applies, and why
6.1.3 eRisk treatment planWho is fixing what, by when
6.2Information security objectivesMeasurable goals, with a plan to reach them
7.2Evidence of competenceProof the people doing security work are capable of it
7.5.1 bOther documented informationAnything else you decide the ISMS needs
8.1Operational planning and controlEvidence processes ran as planned
8.2Risk assessment resultsThe completed risk register, at a point in time
8.3Risk treatment resultsEvidence the treatment plan was carried out
9.1Monitoring and measurement resultsWhat you measured and what it showed
9.2Internal audit programme and resultsThe schedule, plus reports from audits actually done
9.3Management review resultsMinutes or a record of the leadership review
10.2Nonconformity and corrective action recordsWhat went wrong, and what you did about it
The sixteen documented items ISO 27001:2022 requires, by clause.

Annex A adds more where the control applies to you. The ones that come up in almost every Australian implementation are an inventory of information assets (A.5.9), rules for acceptable use (A.5.10), an access control policy (A.5.15), supplier security requirements (A.5.19 to A.5.22), incident management procedures (A.5.24 to A.5.28), continuity plans (A.5.29 and A.5.30), a register of legal and contractual requirements (A.5.31), documented operating procedures (A.5.37) and secure development rules (A.8.25).

What is the ISO 27001 document hierarchy?

The ISO 27001 document hierarchy has three layers: policies that record what the business has decided, procedures that record how those decisions are carried out, and records that prove the procedures actually ran. The standard does not use the word hierarchy, but every certification auditor reads documentation this way.

ISO 27001 document hierarchy showing policies, procedures and records as three layers
Policies, procedures and records. Small teams over-invest in the top layer and under-invest in the bottom one.

The common failure in small Australian businesses is a thick stack of polished policies and almost no records. Policies take a week to write and prove nothing. Records take a year to accumulate and are the only evidence that the management system exists. If you are choosing what to start first, start the registers.

Which ISO 27001 documents can a small team safely combine?

ISO 27001 requires documented information, not individual files, so most requirements can be merged into a smaller set of documents as long as every requirement is addressed and findable. A team of twenty people does not need twenty five separate policies, and an auditor will not thank you for producing them.

Combine theseInto one documentKeep separate because
Risk assessment process, risk treatment process, risk criteriaA single risk management procedureNothing. Auditors expect these together
Acceptable use, access control, password rules, remote work, mobile devicesOne information security policy with named sectionsNothing, if the sections are clearly headed
Supplier security requirements and the supplier registerOne supplier management procedure with an attached registerNothing
Incident response, breach assessment, notification stepsOne incident management procedureNothing, though the Privacy Act steps deserve their own section
Statement of ApplicabilityIts own documentAuditors and customers ask for it by name and read it on its own
ISMS scopeIts own short documentIt is the first thing Stage 1 checks, and it changes on its own cycle
Internal audit reports and management review minutesSeparate recordsThey are evidence of two different clauses, dated differently
What can be merged, and the four items that are worth keeping standalone.

The practical target for a business of 10 to 100 staff is about eight documents and six registers. The registers are risk, assets, suppliers, incidents, legal and contractual requirements, and corrective actions. Our guide to ISO 27001 for small business in Australia covers how that scales with headcount.

Which documents does the Stage 1 audit ask for first?

The Stage 1 audit is a documentation review, so it asks for the written layer: scope, policy, risk method, Statement of Applicability, risk treatment plan, internal audit report and management review minutes. Stage 2 then asks for the records that prove those documents have been in use.

Which ISO 27001 documents the Stage 1 and Stage 2 certification audits ask for
Stage 1 reads what you decided. Stage 2 asks for proof you have been doing it since.

Two items surprise first time applicants. You must have completed an internal audit and a management review before Stage 1, not after, because clauses 9.2 and 9.3 require them and the auditor checks for the records. Guides to running a useful internal audit and to what to expect at Stage 1 and Stage 2 cover both in detail.

The Statement of Applicability is the document auditors spend the most time on, because it is where a weak implementation shows itself. Controls marked as applicable with no supporting evidence are the fastest route to a nonconformity. See how to write a Statement of Applicability for the format certification bodies expect.

How long does the ISO 27001 documentation take to produce?

For a business of 10 to 100 staff, expect roughly six to ten weeks of part time effort to draft the document set, and a further three to six months before the records exist in the quantity Stage 2 wants to see. The writing is not the long part. The waiting is.

ItemTypical drafting effortEarliest it can be finished
ISMS scopeHalf a dayWeek 1
Information security policy set1 to 2 weeksWeek 3
Risk management procedure and first risk assessment1 to 2 weeksWeek 4
Statement of Applicability3 to 5 days, after the risk assessmentWeek 5
Risk treatment plan2 to 3 daysWeek 6
Registers populated with real entriesOngoingMonth 4 onwards
Internal audit report2 to 4 days, once controls are runningMonth 4 to 6
Management review minutesHalf a day, after the internal auditMonth 5 to 6
Indicative effort for a first ISO 27001 document set in a business of 10 to 100 people.

Do you need a documentation toolkit or software?

No. ISO 27001 has no tooling requirement, and plenty of Australian businesses have certified with a shared drive, a naming convention and a spreadsheet index. Tooling buys you structure and a tidier handover to the auditor, not compliance.

If you do want structure, there are three honest options. A shared drive with document templates costs nothing and works well below about fifty staff. A consultant can draft the set with you, which is faster and more expensive. Or a self-service platform: CertAssist lays out every control with editable policy and evidence templates and read-only auditor access, at a list price of US$375 a month, and connects to no systems at all. Enterprise platforms such as Vanta and Drata trade that simplicity for deep integrations and automated evidence collection.

Whichever you pick, the certification body still audits your organisation, not your tool. Our post on whether you need a consultant if you already use a platform covers where the gap usually sits, and ISO 27001 certification cost in Australia covers what the audit itself involves.

How often do ISO 27001 documents need updating?

Review every document at least annually, and immediately after any change that makes it wrong. The standard sets no fixed interval in clause 7.5, but certification bodies expect to see a review date, an owner and a version on each document, and surveillance audits check that the dates are not two years old.

  • Annually. Every policy and procedure, with the review recorded even when nothing changed.
  • On change. A new office, a new cloud platform, a new product line or a merger all move the ISMS scope, and the scope drives everything else.
  • After an incident. Incident records feed corrective actions, which often change a procedure.
  • Before each surveillance audit. Check that registers have entries for the last twelve months, not just the certification push.

Common questions

How many documents are mandatory for ISO 27001?

Sixteen items of documented information are named in clauses 4 to 10 of ISO 27001:2022, plus roughly ten more that Annex A requires where the control applies. That is a count of requirements, not files. Most small Australian businesses satisfy all of them with about eight documents and six registers.

What is the difference between a document and a record in ISO 27001?

A document says what you intend to do and is updated over time, such as a policy or a procedure. A record is evidence that something happened at a point in time and is never edited afterwards, such as an internal audit report or a training log. ISO 27001:2022 calls both documented information, but auditors treat them differently.

Is an ISMS manual required for ISO 27001 certification?

No. An ISMS manual is not required by ISO 27001:2022 and has not been required since the 2013 revision. Some consultants still produce one as a navigation aid that points to where each clause is addressed. It is optional, and an auditor will not ask for it by name.

Can one document cover multiple ISO 27001 controls?

Yes, and it usually should. The standard requires the information to exist and be available, not that each requirement has its own file. One information security policy with clearly headed sections can satisfy acceptable use, access control, remote working and mobile device requirements at once, provided the sections are findable.

How often do I need to update my ISO 27001 documents?

At least annually, with the review recorded even when nothing changes, and immediately after any change that makes a document inaccurate. Certification bodies look for an owner, a version and a review date on each document, and stale dates at a surveillance audit are a common observation.

What happens if an auditor finds my documentation lacking?

Missing or inadequate documented information is usually raised as a minor nonconformity, with a corrective action due inside a set period, commonly 30 to 90 days. A missing mandatory item such as the Statement of Applicability or the internal audit record can be raised as a major nonconformity, which must be closed before a certificate is issued.

Getting the document set right the first time

Most of the wasted effort in ISO 27001 comes from writing documents nobody asked for while the registers stay empty. Start with scope, then the risk method, then the registers, and let the policies follow what you actually decided.

Siege Cyber helps Australian businesses build an ISMS that passes audit without drowning the team in paperwork. Learn more about our ISO 27001 certification support or get in touch to talk through where you are up to.