
ISO 27001 Documents Required: A Practical 2026 List
ISO 27001:2022 names sixteen pieces of documented information you must be able to produce, running from the ISMS scope in clause 4.3 through to corrective action records in clause 10.2. Annex A adds roughly ten more where the relevant controls apply, such as an asset inventory and an access control policy. A small Australian business can usually deliver the whole set as about eight documents plus six registers, because the standard requires the information to exist, not a separate file for each requirement.
This guide lists every required item by clause, shows which ones can be combined, and sets out what the Stage 1 and Stage 2 auditors ask for.

Which documents does ISO 27001 actually require?
ISO 27001:2022 requires sixteen items of documented information across clauses 4 to 10. In Australia the standard is adopted as AS/NZS ISO/IEC 27001:2023, which is the 2022 international edition with an Australian and New Zealand cover. The clause numbers below are identical in both.
| Clause | Documented information | What it is |
|---|---|---|
| 4.3 | ISMS scope | The boundary: which people, systems, sites and services are inside |
| 5.2 | Information security policy | The top level statement of intent, approved by management |
| 6.1.2 | Risk assessment process | How you identify, analyse and evaluate risk, written down |
| 6.1.3 | Risk treatment process | How you decide what to do about each risk |
| 6.1.3 d | Statement of Applicability | Every Annex A control, whether it applies, and why |
| 6.1.3 e | Risk treatment plan | Who is fixing what, by when |
| 6.2 | Information security objectives | Measurable goals, with a plan to reach them |
| 7.2 | Evidence of competence | Proof the people doing security work are capable of it |
| 7.5.1 b | Other documented information | Anything else you decide the ISMS needs |
| 8.1 | Operational planning and control | Evidence processes ran as planned |
| 8.2 | Risk assessment results | The completed risk register, at a point in time |
| 8.3 | Risk treatment results | Evidence the treatment plan was carried out |
| 9.1 | Monitoring and measurement results | What you measured and what it showed |
| 9.2 | Internal audit programme and results | The schedule, plus reports from audits actually done |
| 9.3 | Management review results | Minutes or a record of the leadership review |
| 10.2 | Nonconformity and corrective action records | What went wrong, and what you did about it |
Annex A adds more where the control applies to you. The ones that come up in almost every Australian implementation are an inventory of information assets (A.5.9), rules for acceptable use (A.5.10), an access control policy (A.5.15), supplier security requirements (A.5.19 to A.5.22), incident management procedures (A.5.24 to A.5.28), continuity plans (A.5.29 and A.5.30), a register of legal and contractual requirements (A.5.31), documented operating procedures (A.5.37) and secure development rules (A.8.25).
What is the ISO 27001 document hierarchy?
The ISO 27001 document hierarchy has three layers: policies that record what the business has decided, procedures that record how those decisions are carried out, and records that prove the procedures actually ran. The standard does not use the word hierarchy, but every certification auditor reads documentation this way.

The common failure in small Australian businesses is a thick stack of polished policies and almost no records. Policies take a week to write and prove nothing. Records take a year to accumulate and are the only evidence that the management system exists. If you are choosing what to start first, start the registers.
Which ISO 27001 documents can a small team safely combine?
ISO 27001 requires documented information, not individual files, so most requirements can be merged into a smaller set of documents as long as every requirement is addressed and findable. A team of twenty people does not need twenty five separate policies, and an auditor will not thank you for producing them.
| Combine these | Into one document | Keep separate because |
|---|---|---|
| Risk assessment process, risk treatment process, risk criteria | A single risk management procedure | Nothing. Auditors expect these together |
| Acceptable use, access control, password rules, remote work, mobile devices | One information security policy with named sections | Nothing, if the sections are clearly headed |
| Supplier security requirements and the supplier register | One supplier management procedure with an attached register | Nothing |
| Incident response, breach assessment, notification steps | One incident management procedure | Nothing, though the Privacy Act steps deserve their own section |
| Statement of Applicability | Its own document | Auditors and customers ask for it by name and read it on its own |
| ISMS scope | Its own short document | It is the first thing Stage 1 checks, and it changes on its own cycle |
| Internal audit reports and management review minutes | Separate records | They are evidence of two different clauses, dated differently |
The practical target for a business of 10 to 100 staff is about eight documents and six registers. The registers are risk, assets, suppliers, incidents, legal and contractual requirements, and corrective actions. Our guide to ISO 27001 for small business in Australia covers how that scales with headcount.
Which documents does the Stage 1 audit ask for first?
The Stage 1 audit is a documentation review, so it asks for the written layer: scope, policy, risk method, Statement of Applicability, risk treatment plan, internal audit report and management review minutes. Stage 2 then asks for the records that prove those documents have been in use.

Two items surprise first time applicants. You must have completed an internal audit and a management review before Stage 1, not after, because clauses 9.2 and 9.3 require them and the auditor checks for the records. Guides to running a useful internal audit and to what to expect at Stage 1 and Stage 2 cover both in detail.
The Statement of Applicability is the document auditors spend the most time on, because it is where a weak implementation shows itself. Controls marked as applicable with no supporting evidence are the fastest route to a nonconformity. See how to write a Statement of Applicability for the format certification bodies expect.
How long does the ISO 27001 documentation take to produce?
For a business of 10 to 100 staff, expect roughly six to ten weeks of part time effort to draft the document set, and a further three to six months before the records exist in the quantity Stage 2 wants to see. The writing is not the long part. The waiting is.
| Item | Typical drafting effort | Earliest it can be finished |
|---|---|---|
| ISMS scope | Half a day | Week 1 |
| Information security policy set | 1 to 2 weeks | Week 3 |
| Risk management procedure and first risk assessment | 1 to 2 weeks | Week 4 |
| Statement of Applicability | 3 to 5 days, after the risk assessment | Week 5 |
| Risk treatment plan | 2 to 3 days | Week 6 |
| Registers populated with real entries | Ongoing | Month 4 onwards |
| Internal audit report | 2 to 4 days, once controls are running | Month 4 to 6 |
| Management review minutes | Half a day, after the internal audit | Month 5 to 6 |
Do you need a documentation toolkit or software?
No. ISO 27001 has no tooling requirement, and plenty of Australian businesses have certified with a shared drive, a naming convention and a spreadsheet index. Tooling buys you structure and a tidier handover to the auditor, not compliance.
If you do want structure, there are three honest options. A shared drive with document templates costs nothing and works well below about fifty staff. A consultant can draft the set with you, which is faster and more expensive. Or a self-service platform: CertAssist lays out every control with editable policy and evidence templates and read-only auditor access, at a list price of US$375 a month, and connects to no systems at all. Enterprise platforms such as Vanta and Drata trade that simplicity for deep integrations and automated evidence collection.
Whichever you pick, the certification body still audits your organisation, not your tool. Our post on whether you need a consultant if you already use a platform covers where the gap usually sits, and ISO 27001 certification cost in Australia covers what the audit itself involves.
How often do ISO 27001 documents need updating?
Review every document at least annually, and immediately after any change that makes it wrong. The standard sets no fixed interval in clause 7.5, but certification bodies expect to see a review date, an owner and a version on each document, and surveillance audits check that the dates are not two years old.
- Annually. Every policy and procedure, with the review recorded even when nothing changed.
- On change. A new office, a new cloud platform, a new product line or a merger all move the ISMS scope, and the scope drives everything else.
- After an incident. Incident records feed corrective actions, which often change a procedure.
- Before each surveillance audit. Check that registers have entries for the last twelve months, not just the certification push.
Common questions
How many documents are mandatory for ISO 27001?
Sixteen items of documented information are named in clauses 4 to 10 of ISO 27001:2022, plus roughly ten more that Annex A requires where the control applies. That is a count of requirements, not files. Most small Australian businesses satisfy all of them with about eight documents and six registers.
What is the difference between a document and a record in ISO 27001?
A document says what you intend to do and is updated over time, such as a policy or a procedure. A record is evidence that something happened at a point in time and is never edited afterwards, such as an internal audit report or a training log. ISO 27001:2022 calls both documented information, but auditors treat them differently.
Is an ISMS manual required for ISO 27001 certification?
No. An ISMS manual is not required by ISO 27001:2022 and has not been required since the 2013 revision. Some consultants still produce one as a navigation aid that points to where each clause is addressed. It is optional, and an auditor will not ask for it by name.
Can one document cover multiple ISO 27001 controls?
Yes, and it usually should. The standard requires the information to exist and be available, not that each requirement has its own file. One information security policy with clearly headed sections can satisfy acceptable use, access control, remote working and mobile device requirements at once, provided the sections are findable.
How often do I need to update my ISO 27001 documents?
At least annually, with the review recorded even when nothing changes, and immediately after any change that makes a document inaccurate. Certification bodies look for an owner, a version and a review date on each document, and stale dates at a surveillance audit are a common observation.
What happens if an auditor finds my documentation lacking?
Missing or inadequate documented information is usually raised as a minor nonconformity, with a corrective action due inside a set period, commonly 30 to 90 days. A missing mandatory item such as the Statement of Applicability or the internal audit record can be raised as a major nonconformity, which must be closed before a certificate is issued.
Getting the document set right the first time
Most of the wasted effort in ISO 27001 comes from writing documents nobody asked for while the registers stay empty. Start with scope, then the risk method, then the registers, and let the policies follow what you actually decided.
Siege Cyber helps Australian businesses build an ISMS that passes audit without drowning the team in paperwork. Learn more about our ISO 27001 certification support or get in touch to talk through where you are up to.