Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 27001 mandatory documents checklist including scope, policy, risk assessment and SoA

ISO 27001 Mandatory Documents Checklist (2022)

Knowing the ISO 27001 mandatory documents is one of the fastest ways to demystify certification. The standard requires a defined set of documented information, and auditors will expect to see each item. This guide lists the documents ISO 27001 requires, the records that support them, and how to produce them efficiently.

ISO 27001 mandatory documents checklist including scope, policy, risk assessment and SoA

For the wider context, see our complete ISO 27001 guide.

Why documented information matters

ISO 27001 is evidence-based. Your Information Security Management System is judged not by intentions but by the documented information you can produce — policies that set direction, procedures that describe how things are done, and records that prove they were done. Getting this documentation right is the core of a successful certification, which is why a structured template set is so valuable.

The core ISO 27001 mandatory documents

The following documented information is required by ISO 27001:2022 and forms the backbone of your ISMS:

  • ISMS scope — the boundaries of your management system.
  • Information security policy — top-level direction approved by leadership.
  • Information security risk assessment process — how you identify and evaluate risks.
  • Information security risk treatment process — how you decide to treat them.
  • Statement of Applicability (SoA) — which Annex A controls apply, and why.
  • Risk treatment plan — how selected controls will be implemented.
  • Information security objectives — measurable goals for the ISMS.

The mandatory records you must keep

Alongside the documents above, ISO 27001 requires records that evidence the ISMS in operation:

  • Evidence of competence and training.
  • Results of the risk assessment and risk treatment.
  • Monitoring and measurement results.
  • Internal audit programme and results.
  • Management review results.
  • Records of nonconformities and corrective actions.

These records demonstrate that the system is not just documented but genuinely working — which is precisely what a Stage 2 audit tests.

Commonly expected supporting documents

While not always strictly mandatory, auditors typically expect supporting policies and procedures such as access control, acceptable use, incident management, business continuity, supplier security, and secure development. These operationalise your Annex A controls. Preparing them upfront avoids gaps during the audit and gives your team clear, usable guidance.

How to produce the documents efficiently

Authoring every policy, procedure, and record from a blank page is the slowest part of ISO 27001. The efficient approach is to start from a mapped template set aligned to the 2022 standard, then tailor each document to your organization. This turns a multi-month documentation project into a structured review-and-adapt exercise, and ensures nothing on the mandatory list is missed.

Every required document, ready to adapt.

Our ISO 27001 Toolkit includes the scope, policy, risk assessment, Statement of Applicability, and every supporting procedure and record — mapped to ISO 27001:2022 and editable in Word and Excel.

Get the ISO 27001 Toolkit →

Frequently asked questions

What are the ISO 27001 mandatory documents?

They include the ISMS scope, information security policy, risk assessment and risk treatment processes, Statement of Applicability, risk treatment plan, and security objectives — plus mandatory records such as audit and management-review results.

Is the Statement of Applicability mandatory?

Yes. The Statement of Applicability records which Annex A controls you apply and your justification, and it is a central document auditors examine.

How many documents does ISO 27001 require?

There is a defined set of mandatory documents and records, supplemented by the policies and procedures needed to operate your selected Annex A controls — the exact number depends on your scope and risks.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.