Skip to content

The documented information ISO 27001 requires

By Sam Rivera, Founder, SentinelPanda · June 19, 2026 · 1 min read · ISO 27001

ISO 27001 names the documents you must keep — fewer than people fear. The trap is producing documentation the standard never asked for.

Documents vs records

ISO 27001 distinguishes documented information that defines the system (documents — your scope, policy, procedures) from evidence that it ran (records — audit results, review minutes, logs). Both are "documented information" in the standard's language, but they serve different purposes.

The mandatory documents

  • ISMS scope; the information security policy; the risk assessment and risk treatment methodology.
  • The Statement of Applicability; the risk treatment plan; security objectives.
  • Any procedures the standard or your own controls require to operate consistently.

The mandatory records

  • Evidence of competence/training; results of monitoring and measurement.
  • Internal audit programme and results; management review minutes.
  • Nonconformities and corrective actions taken.

Avoid the binder trap

The failure mode is generating documentation the standard never asked for — pages of procedures nobody follows — because it feels like compliance. The standard wants the listed documents plus whatever your controls genuinely need to run; more than that is overhead an auditor neither needs nor rewards. SentinelPanda holds the mandatory documents and records in one place, current and linked to the controls.

ISO 27001 clauses 4 to 10 Security policies auditors accept ISO 27001 Statement of Applicability

Run your compliance program in one workspace.