Blog

ISO 27001 Documentation: What Is Actually Mandatory

ISO 27001:2022 names roughly twenty pieces of documented information you must hold, not the hundred-plus document packs sold online. The mandatory set splits in two: documents required by the management clauses, which every certified organisation needs, and documents required by Annex A controls, which you only need where you declared that control applicable. Anything beyond those two groups is optional, and for a small Australian business most of it is a liability rather than an asset.

That distinction is the whole game. Below is what the standard actually requires, what your Statement of Applicability decides for you, and what an auditor will not ask for no matter how many templates told you otherwise.

What documents does ISO 27001 actually require?

ISO 27001 uses the phrase “documented information” rather than “document” or “policy”, and that wording matters. It means recorded evidence in any form. A ticketing system export, a spreadsheet, a wiki page or a signed PDF can all satisfy the same requirement. The standard almost never dictates format, length or title.

The documented information ISO 27001 management clauses require, listed by clause number
The documents and records required by the ISO 27001 management clauses, with their clause references.

Note that the ISMS scope statement sits at the top of that list. It is the document every other requirement depends on, because it determines what the rest of your ISMS applies to. Defining your ISMS boundary is worth settling before you write anything else.

Two things on that list surprise people. First, there is no mandatory “Information Security Policy Manual” running to eighty pages. Clause 5.2 requires an information security policy, and a focused three-page document satisfies it. Second, records are mandatory documentation too. Audit results, training evidence and monitoring results are all documented information, and they are where first-time certification projects usually fall short rather than on the policy side.

Which documents depend on your Statement of Applicability?

The Annex A controls you declare applicable determine a second tier of required documents. Declare a control applicable and you must be able to show it operating, which in most cases means a documented procedure or a record. Declare it not applicable, justify that in the Statement of Applicability, and the associated documents disappear from your obligations entirely.

This is the single most effective lever on documentation workload, and it is why writing your Statement of Applicability carefully is worth the time. A business with no physical server room, no in-house development and no bring-your-own-device arrangements can legitimately exclude a meaningful number of controls, and with them a meaningful stack of paperwork.

If this is true of your businessThese documents become requiredIf not applicable
You develop your own softwareSecure development policy, secure coding rules, test data handlingExcluded with justification in the Statement of Applicability
You hold your own physical infrastructurePhysical security procedures, equipment disposal records, clear desk rulesExcluded if you are entirely cloud hosted
Staff use personal devices for workBring-your-own-device policy, mobile device controlsExcluded if you issue and manage all devices
You use suppliers who process your dataSupplier security policy, supplier agreements, monitoring recordsRarely excludable, almost every business has suppliers
You have remote or hybrid staffRemote working policy and associated controlsExcluded only if genuinely nobody works remotely
Annex A controls drive a second tier of documentation, and your Statement of Applicability decides which apply.

Be honest in these exclusions. An auditor who finds developers writing code after you excluded secure development will raise a nonconformity, and the finding will be about the integrity of your Statement of Applicability rather than the missing policy. That is a far more serious conversation.

What documentation can you safely skip?

Most commercial ISO 27001 template packs include a great deal that the standard never asks for. Extra documents are not neutral: every one of them is something you must keep current, review, and defend in an audit when reality drifts away from it.

ISO 27001 documentation commonly included in template packs that the standard does not require
Documentation that appears in most template packs but is not required, and what to do instead.

The practical test is simple. If a document is not required by a management clause, not required by an applicable Annex A control, and not something your business would maintain anyway, it is probably costing you more than it returns. A policy that describes a process nobody follows is worse than no policy, because it hands an auditor a documented standard you are visibly failing to meet.

How detailed does ISO 27001 documentation need to be?

Only detailed enough that the process can be performed consistently by the people responsible for it. ISO 27001 sets no page counts and no templates. Clause 7.5 asks that documented information is identified, in a suitable format, reviewed, approved, available where needed and protected from loss or misuse.

For an Australian business of twenty to a hundred staff, that usually means shorter documents than people expect. A good access control policy for that size of business fits comfortably on two pages. If yours runs to fifteen, it is probably describing an organisation you do not have, and every surplus paragraph is a commitment an auditor can test you against. The ISO 27001 checklist sets out where documentation fits in the wider project.

  • Write what you do, not what good practice says. The gap between the two is the most common source of audit findings.
  • Name an owner on every document. Clause 7.5 expects review and approval, and an unowned document never gets reviewed.
  • Date the review, not just the creation. An auditor checks whether the review actually happened on the cycle you committed to.
  • Keep records where the work happens. Access review evidence belongs in the system that performed it, not transcribed into a separate register.

How often does ISO 27001 documentation need to be reviewed?

ISO 27001 does not specify a frequency. It requires that documented information is reviewed and updated as necessary, and that the information security policy and the ISMS are reviewed at planned intervals. In Australian practice, annual review of policies with an out-of-cycle review after any significant change is the pattern auditors expect and accept.

The trap is committing to a shorter cycle than you can sustain. If your document control states quarterly review and your review log shows one review in eighteen months, you have created a nonconformity out of nothing. Set annual, meet annual, and review out of cycle when something changes. Your internal audit is where this gap usually surfaces, which is the right place for it to surface rather than at Stage 2.

Common questions about ISO 27001 documentation

How many mandatory documents does ISO 27001 have?

Around twenty pieces of documented information are required by the management clauses, depending on how you count combined documents, plus a variable number driven by the Annex A controls you declared applicable. There is no single official numbered list published by ISO, which is why different consultancies quote different totals. What matters for your audit is not the number but whether every clause requirement and every applicable control is evidenced.

What are the ISO 27001 documentation requirements in clause 7.5?

Clause 7.5 covers creating, updating and controlling documented information. It requires appropriate identification such as a title, date, author or reference number, a suitable format and medium, and review and approval for suitability. It also requires that documents are available where needed, adequately protected, and controlled through distribution, access, retrieval, storage, version control and retention. It does not require a particular document management system.

Is ISO 27001 mandatory in Australia?

No. ISO 27001 is a voluntary standard with no general legal force in Australia. Businesses pursue it because a customer, a tender or a sector expectation requires it, or because they want the structure it provides. Specific obligations can make it effectively necessary in practice, particularly in government-adjacent supply chains, but the standard itself is not law. You can buy the standard through Standards Australia as AS ISO/IEC 27001.

Can we use ISO 27001 document templates?

Yes, as a starting structure, and most organisations do. The failure mode is adopting them unedited. Auditors read a great many template packs and recognise them immediately, and a policy describing procedures your business does not perform is a finding waiting to happen. Treat a template as a checklist of what to consider, then rewrite each document to describe your actual process, your actual systems and your actual people.

Who needs to approve ISO 27001 documents?

The standard requires review and approval for suitability and adequacy without naming roles, so you decide and record it. In most Australian SMBs the information security policy is approved by the business owner or managing director, because clause 5 places responsibility for the ISMS with top management, while operational procedures are approved by whoever owns that process. What an auditor checks is that your stated approval process is the one that actually happened.

Getting your documentation right the first time

Start from the clauses and your Statement of Applicability, not from a template pack. Write down the clause-mandated items, add the documents your applicable Annex A controls require, and stop there. That list is your scope of work, and for most Australian businesses it is considerably shorter and more achievable than the stack of files sold as an ISO 27001 toolkit.

Then write short, write true, and name an owner. Certification bodies accredited through the International Accreditation Forum and its members are assessing whether your management system works, not whether your documents are impressive. A lean set of accurate documents passes an audit that a beautiful set of aspirational ones fails. Stage 1 is largely a documentation review, so this is the work that determines how that day goes.

Siege Cyber helps Australian businesses build ISO 27001 documentation that reflects how they actually operate, then get it through certification. See our ISO 27001 services or get in touch to talk through your scope.