ISO27K

ISO 27001 mandatory documents and records

The standard asks for far less paper than the people selling template packs suggest. Everything beyond the required set is a document you have chosen to be audited against, which is a choice worth making deliberately.

Last reviewed 2026-09-01Written by Jacob Masse, TrazTech Inc.

Clauses 4 to 10 of ISO/IEC 27001:2022 name fewer than twenty pieces of documented information: seven documents you maintain, and around ten sets of records you retain as evidence that the system ran. Annex A adds more, but only for the controls you determined applicable, and the count depends entirely on your own Statement of Applicability. A working set for a Canadian company under 100 staff lands between 15 and 25 documents. Template packs commonly sell 50 to 60, and every one of those is a document an auditor can hold you to.

Fewer than 20 Pieces of documented information named in clauses 4 to 10

What documents does ISO 27001 actually require

The standard distinguishes between documented information you maintain, which is a living document, and documented information you retain, which is a record of something that happened. Auditors treat them differently: a document is checked for currency and approval, a record is sampled for existence across a period.

Documented information required by clauses 4 to 10 of ISO/IEC 27001:2022
ItemClauseType
Scope of the information security management system4.3Document
Information security policy5.2Document
Risk assessment process6.1.2Document
Risk treatment process6.1.3Document
Statement of Applicability6.1.3 d)Document
Information security objectives6.2Document
Operational planning and control, to the extent needed for confidence that processes ran as planned8.1Document and record
Results of the risk assessment6.1.2, 8.2Record
Results of risk treatment, including the risk treatment plan and risk owner acceptance6.1.3, 8.3Record
Evidence of competence7.2Record
Monitoring and measurement results9.1Record
Internal audit program and audit results9.2Record
Results of management review9.3Record
Nature of nonconformities, actions taken and results of corrective action10.2Record

Clause 7.5 is not on that list because it is not a document. It is the rule about documents: they need identification, a format, review and approval, version control, and controlled distribution. A single page describing how you control documented information satisfies it, and most companies fold it into their information security policy rather than writing a separate procedure.

0 of 0 of the maintained documents in place ยท

What does Annex A add

Annex A controls are written as outcomes rather than as documents, so the paperwork they generate depends on which controls you selected and how you chose to satisfy them. Several controls name documented information explicitly or are impossible to evidence without it. The ones that reliably produce a document for a Canadian software company are these.

  • Topic-specific policies, A.5.1. The standard expects policies below the main one, on subjects your risks justify. Access control, acceptable use, cryptography, secure development, supplier security, incident response and continuity is a normal set. Seven documents, not twenty.
  • Inventories and registers. The asset and information inventory under A.5.9, the supplier register behind A.5.19 to A.5.22, and the register of legal, statutory, regulatory and contractual requirements under A.5.31, which in Canada is where PIPEDA, PHIPA and Quebec Law 25 get written down as obligations you have identified.
  • Procedures people follow. Documented operating procedures under A.5.37, incident management planning under A.5.24, change management under A.8.32, and configuration standards under A.8.9.
  • Employment paperwork. Terms and conditions under A.6.2, confidentiality agreements under A.6.6, and the screening and training records behind A.6.1 and A.6.3, which are records rather than documents and are the most commonly sampled evidence at stage 2.

The Statement of Applicability decides your document list

Do not build the document set first. Work out which controls are applicable, then write only what those controls require. Building the folder structure before the Statement of Applicability exists is how companies end up with a data masking policy they do not need and no register of legal obligations, which they do. The Annex A page covers what each theme expects to see.

Why a 60 document pack is a liability

The pitch is that a pack saves months, and it does save the blank page problem. What it does not save is the work, because every document in the pack becomes a commitment you are audited against. This is the part nobody selling one mentions.

An auditor does not audit you against the standard alone. Clause 10.2 and the whole management system logic mean they audit you against your own documents too. If your access control policy says access reviews happen monthly because that is what the template said, and yours happen quarterly, that is a nonconformity against a promise you never intended to make. Multiply that by sixty documents written by somebody who has never seen your company, and the pack has created a surface area of self-inflicted findings.

The second cost is currency. Every one of those documents needs review, approval and a version history under clause 7.5, and a surveillance auditor who finds forty documents all last reviewed on the same day two years ago has learned something about whether the management system operates. Fifteen documents that are genuinely maintained read far better than sixty that are not.

What a working set looks like for a 40 person company

Between 15 and 25 documents, plus the records that accumulate as the system runs. The seven required maintained documents, six or seven topic-specific policies, three or four registers, and a small number of procedures where the work is genuinely procedural. Everything else belongs in the tools where the work happens: change management in your ticket system, access reviews as recorded output rather than a policy, onboarding as a checklist in your people system.

Records are a different matter and there is no way to keep them small, because they are the point. A stage 2 auditor samples access reviews, screening records, training completions, supplier reviews, backup restore tests, incident tickets, internal audit reports and management review minutes. The stage 2 audit is largely an exercise in producing records on request, and companies that fail it usually have adequate documents and thin records.

When buying a template pack is the right call

There is an honest case for it. If nobody in the company has written a policy before, a pack gives you the vocabulary and the structure, and rewriting a bad draft is faster than facing an empty document. It is also reasonable when a deadline is fixed and the alternative is nothing at all.

Buy one on two conditions. Delete everything that does not map to a control you marked applicable, before you approve any of it, and expect to delete a third to a half. And read every operational commitment out loud and change it to what you will actually do, particularly frequencies, timelines and role names. A pack used that way is a starting draft, which is worth $500 to $2,000 CAD. A pack approved as it arrived is a set of promises about a company that does not exist, and it is the reason gap assessments so often find complete documentation sitting beside no evidence.

Get the document set sized properly

Tell us your scope and what you already have written, and we will match you with Canadian firms that will cut the list rather than add to it.

Get matched

Common questions

How many documents does ISO 27001 require?

Clauses 4 to 10 name seven documents you maintain and around ten sets of records you retain. Annex A adds documents only where a control you selected needs them, which for a typical Canadian software company means six or seven topic-specific policies and three or four registers. A working set of 15 to 25 documents is normal and satisfies the standard completely.

Is there a mandatory list of ISO 27001 policies?

Only one policy is named: the information security policy at clause 5.2. Control A.5.1 then expects topic-specific policies below it, but the standard does not list them, because which ones you need follows from your risks and your applicable controls. Any list you are shown of twenty mandatory policies is somebody's template contents page rather than a requirement.

Do the documents have to be in a particular format?

No. Clause 7.5 requires identification, description, format and media to be appropriate, and review and approval for suitability. It says nothing about templates, headers or numbering schemes. A policy in a wiki with a version history and an approval record satisfies it as fully as a signed PDF, and it is more likely to stay current.

Do documents need to be in French for Quebec?

If you have Quebec employees, French-language documentation obligations apply to what those employees have to read and follow, independently of anything ISO requires, and audits with Quebec personnel in scope can involve French-language interviews. This is a real cost line rather than a formality, and it is set out on certifying with Quebec in scope.

How long do we have to keep the records?

The standard does not set retention periods, so you set them and then meet them. What matters at an audit is that the retention you wrote down is the retention you practise. Practically, keep everything from the current certification cycle available, because a recertification auditor can look back across the whole three years, and keep enough history that the trend in your monitoring results under clause 9.1 is visible.

Can we use a compliance platform instead of documents?

Partly. A platform at $8,000 to $30,000 CAD a year is good at collecting records and evidence automatically, which is the half of this that is laborious. It does not write your scope statement, your risk method or your Statement of Applicability, and platform-generated policies carry exactly the same liability as a template pack if you approve them unread. Buy one for the evidence, not for the documents.