How many documents are mandatory for ISO 27001?
Last verified 2026-08-19 · UK focus
Short answer
ISO/IEC 27001:2022 explicitly requires about 18 pieces of documented information: roughly 11 standing documents (scope, information security policy, risk assessment and treatment processes, Statement of Applicability, objectives) and 7 record types (competence evidence, monitoring results, internal audit programme and results, management review outputs, nonconformity and corrective action records). Annex A controls add further documents only where you apply them.
Key facts
- The Statement of Applicability is the only Annex A artefact named as mandatory in the main clauses.
- There is no required page count or template — 'documented information' can be a wiki page or a system record.
- Auditors sample records far more than they read policies.
- Applied Annex A controls typically add 5-15 further documents in practice.
Documented information required by ISO/IEC 27001:2022
| # | Documented item | Clause | Type |
|---|---|---|---|
| 1 | Scope of the ISMS | 4.3 | Document |
| 2 | Information security policy | 5.2 | Document |
| 3 | Information security risk assessment process | 6.1.2 | Document |
| 4 | Information security risk treatment process | 6.1.3 | Document |
| 5 | Statement of Applicability | 6.1.3 d) | Document |
| 6 | Information security objectives and plans | 6.2 | Document |
| 7 | Evidence of competence | 7.2 | Record |
| 8 | Documented information determined as necessary | 7.5.1 b) | Document |
| 9 | Evidence of operational planning and control | 8.1 | Record |
| 10 | Results of information security risk assessments | 8.2 | Record |
| 11 | Results of information security risk treatment | 8.3 | Record |
| 12 | Evidence of monitoring and measurement results | 9.1 | Record |
| 13 | Internal audit programme | 9.2.2 | Document |
| 14 | Internal audit results | 9.2.2 | Record |
| 15 | Results of management reviews | 9.3.3 | Record |
| 16 | Nonconformities and actions taken | 10.2 | Record |
| 17 | Results of corrective actions | 10.2 | Record |
| 18 | Continual improvement evidence | 10.1 | Record |
Caveats
- Counts published elsewhere vary between 16 and 22 because sources group clause 7.5 and 10.2 items differently.
- The 2022 revision removed several prescriptive documents present in the 2013 edition's Annex A.
Sources
- ISO/IEC 27001:2022, clauses 4-10 (documented information requirements). International Organization for Standardization, 2022-10-25.
Check your own position
Run the free ISO 27001 gap analysis for an instant score against clauses 4-10 and Annex A, then manage risks, controls, owners and evidence in one workspace.
