The ISO 27701 mandatory documents are of two kinds, and a document list that mixes them up produces either a PIMS with gaps or one with forty policies nobody reads. The first kind is what the standard’s clauses 4 to 10 require as documented information — the same harmonized-structure items every ISO management system standard demands: scope, policy, objectives, the risk process and its results, competence evidence, operational planning, monitoring results, internal audit, management review and nonconformities.
The second kind is what the Annex A controls generate when they operate — records of processing, consent records, privacy notices, data subject request logs, processor instructions, transfer records, breach records — which are mandatory for the controls the organisation has declared applicable and not otherwise. Since ISO/IEC 27701:2025 became a standalone standard, both kinds live in the PIMS itself rather than being borrowed from an ISO 27001 ISMS.
This guide lists the ISO 27701 mandatory documents by clause, the records the controller and processor controls require, the information security records that came inside with Annex A.3, how to structure the set so that an auditor finds each item once, and the documents that are commonly produced and are not required at all.

ISO 27701 mandatory documents by clause
| Clause | Documented information required | What it is in practice |
|---|---|---|
| 4.3 Scope | The scope of the PIMS | A scope statement: organisational units, locations, processing activities, roles (controller, processor or both), jurisdictions |
| 5.2 Policy | The privacy (PIMS) policy | A top-level policy with commitment to requirements and continual improvement |
| 6.1 Risk | The privacy risk assessment process and the risk treatment process; the results of assessments and treatment; the risk treatment plan | A documented method, a risk register of privacy risks to PII principals and to the organisation, and a treatment plan |
| 6.1 Applicability | The statement of applicability for the Annex A controls | Which controller, processor and security controls apply, which do not, and why |
| 6.2 Objectives | The privacy objectives | Measurable objectives with owners, resources and dates |
| 7.2 Competence | Evidence of competence | Training and qualification records for roles in the PIMS |
| 7.5 Documented information | The information the standard requires and what the organisation decides is necessary; control of creation, update, distribution, retention | A document control procedure and a register |
| 8.1 Operational planning and control | Documented information to the extent necessary to have confidence the processes are carried out as planned | Procedures for the privacy processes and evidence they ran |
| 8.2 / 8.3 Risk in operation | Results of privacy risk assessments performed at planned intervals or on change; results of treatment | Dated assessment records and treatment updates |
| 9.1 Monitoring | Evidence of the results of monitoring and measurement | Metrics and their records |
| 9.2 Internal audit | The audit programme and the audit results | Programme, plans, reports, findings |
| 9.3 Management review | The results of management reviews | Minutes with decisions and actions |
| 10 Improvement | The nature of nonconformities and actions taken; the results of corrective action | A nonconformity and corrective action register |
These are the items an auditor will ask for by clause number at stage 1. Our guide to ISO 27701:2025 vs 2019 covers why the clauses are now the standard’s own rather than ISO 27001’s.
ISO 27701 mandatory documents from Annex A: the records the controls require
The Annex A controls are mandatory where the statement of applicability declares them applicable, and each operating control produces records. The list below is organised by the three Annex A tables; the exact control identifiers are in the copy of the standard you certify against.
| Table | Record | Why it exists |
|---|---|---|
| A.1 PII controllers | Records of processing: purposes, categories of PII and principals, recipients, transfers, retention, security measures | The controller’s inventory — also GDPR Article 30 |
| Lawful basis register and, where consent is the basis, consent records with the ability to evidence withdrawal | Basis for each processing activity | |
| Privacy notices and the record of what was provided to whom and when | Information to PII principals | |
| Privacy impact assessment reports | Assessment of new or changed processing | |
| Data subject request log: request, identity verification, response, timing | Handling PII principals’ rights | |
| Retention schedule and disposal records | Storage limitation | |
| Sharing, transfer and onward-transfer records, with the basis for each transfer between jurisdictions | Disclosure and transfer controls | |
| Agreements with processors and joint controllers | Supplier and joint-controller controls | |
| A.2 PII processors | Documented customer instructions and the record of processing per customer | Processing only on instruction |
| Sub-processor register and customer authorisations | Sub-processor engagement | |
| Records of assistance to the customer: requests, breaches, impact assessments | Customer obligations | |
| Return, transfer and disposal records at contract end | Return and disposal of PII | |
| A.3 Information security (both roles) | Asset inventory of PII and systems; access control records; logging; incident records including breach notifications and timings; supplier security agreements; backup and cryptography records | The security controls that came inside the standard in 2025 so a standalone PIMS has them |
A processor that is not a controller does not produce A.1 records, and the reverse; a hybrid organisation produces both, scoped to the processing where each role applies. Our guide to ISO 27701 controls covers the three tables.
Structuring the ISO 27701 mandatory documents
- One PIMS manual, short. Scope, policy, roles, the clause-by-clause map to where each required document lives. It is the auditor’s index.
- One register per record type, not one document per processing activity: a records-of-processing register, a request log, a breach log, a transfer register, a sub-processor register.
- Procedures only where clause 8.1 needs confidence. Request handling, breach response, impact assessment, consent management, supplier onboarding and processor instruction are the processes that need written procedures; a procedure for everything is not required.
- Integrate with ISO 27001 where it exists. One risk method, one document control procedure, one internal audit programme, one management review — with the PIMS items identifiable within them. Where it does not exist, A.3 records are the PIMS’s own. Our guide to ISO 27001 vs ISO 27701 covers the integration.
- Map the legal register once. GDPR, UK GDPR, CCPA and other regimes as requirements against the same controls, so the statement of applicability and the notices answer every jurisdiction in scope.
- Date and version everything. Clause 7.5 is the clause auditors test on every other document.
ISO 27701 mandatory documents that are not, in fact, required
- A separate policy per control. The standard requires a PIMS policy and documented information “to the extent necessary”; forty control-level policies are a choice, not a requirement.
- A DPO appointment — unless the GDPR or another law requires one; the standard requires roles and responsibilities, not a DPO.
- A DPIA for every activity. Impact assessments are for new or changed processing that presents risk; a register recording the decision not to assess is the evidence for the rest.
- Printed privacy notices on file for every recipient. The record is of what notice was in force and how it was provided.
- An ISO 27001 certificate — not since October 2025.
Our guide to ISO 27701 implementation covers the order in which the documents are produced.
Frequently asked questions
What documents does ISO 27701 require?
Two kinds: the management-system documented information of clauses 4–10 — scope, policy, objectives, risk process and results, statement of applicability, competence evidence, operational procedures, monitoring results, internal audit programme and results, management review results, nonconformity and corrective action records — and the records generated by the Annex A controls declared applicable: records of processing, consent, notices, impact assessments, request logs, processor instructions, sub-processor registers, transfer and breach records, and the A.3 security records.
Does ISO 27701:2025 require a statement of applicability?
Yes. As a standalone standard with its own Annex A, the 2025 edition requires the organisation to determine and document which controller, processor and security controls apply, with justification, in the same way ISO 27001 does.
Do processors need the controller records?
No. A pure processor produces the A.2 records — customer instructions, sub-processor register, assistance records, return and disposal — plus the A.3 security records. A.1 records apply where the organisation acts as a controller.
Can we reuse ISO 27001 documents?
Yes, where an ISMS exists: the risk method, document control, internal audit, management review and corrective action procedures can be shared with the PIMS items identified within them. Without an ISMS, the 2025 edition’s A.3 controls mean the PIMS carries its own security records.
How many documents is that?
A workable PIMS for a single-role organisation typically runs to a manual, a policy, five to eight procedures, six to ten registers and the audit, review and corrective action records — under thirty documents, most of them registers. The count rises with roles, jurisdictions and processing complexity, not with the standard.
Where this leaves you
Build the ISO 27701 mandatory documents as an index plus registers: the clause 4–10 items the auditor asks for by number, the Annex A records for the controls you declared applicable, and procedures only where clause 8.1 needs confidence — integrated with ISO 27001 where you have it, self-contained where you do not.
References
- ISO/IEC 27701:2025 — Privacy information management systems — Requirements and guidance — Clauses 4–10 documented information requirements and Annex A.
- Regulation (EU) 2016/679 — Article 30, records of processing activities (EUR-Lex) — The legal record the A.1 and A.2 records-of-processing controls correspond to.
More on ISO 27701
- ISO 27701 mandatory documents — you are here
- ISO 27701: the complete guide
- ISO 27701 controls: the three Annex A tables
- ISO 27701 implementation: eight steps
- ISO 27701:2025 vs 2019
- GDPR documentation requirements
The PIMS manual, the privacy policy, the statement of applicability, the records of processing register, the request and breach logs, the processor instruction and sub-processor templates and the internal audit and management review records are in the ISO 27701 Toolkit, or start with the free templates.