The documented information ISO 27001 requires
By Sam Rivera, Founder, SentinelPanda · June 19, 2026 · 1 min read · ISO 27001
ISO 27001 names the documents you must keep — fewer than people fear. The trap is producing documentation the standard never asked for.
Documents vs records
ISO 27001 distinguishes documented information that defines the system (documents — your scope, policy, procedures) from evidence that it ran (records — audit results, review minutes, logs). Both are "documented information" in the standard's language, but they serve different purposes.
The mandatory documents
- ISMS scope; the information security policy; the risk assessment and risk treatment methodology.
- The Statement of Applicability; the risk treatment plan; security objectives.
- Any procedures the standard or your own controls require to operate consistently.
The mandatory records
- Evidence of competence/training; results of monitoring and measurement.
- Internal audit programme and results; management review minutes.
- Nonconformities and corrective actions taken.
Avoid the binder trap
The failure mode is generating documentation the standard never asked for — pages of procedures nobody follows — because it feels like compliance. The standard wants the listed documents plus whatever your controls genuinely need to run; more than that is overhead an auditor neither needs nor rewards. SentinelPanda holds the mandatory documents and records in one place, current and linked to the controls.