Exemplar Global Certified Courses from USD 119. Ending Soon!

Documented Information in an ISMS: What Clause 7.5 Requires

AW

Team @ Audit Workshop

15 min read
Documented Information in an ISMS: What Clause 7.5 Requires

Why Documented Information Matters in an ISMS

When organisations implement ISO 27001, they often focus their energy on risk assessments, Annex A controls, and the Statement of Applicability. Documented information tends to get treated as an afterthought, something to sort out before the certification audit. That approach creates problems.

Clause 7.5 of ISO 27001 is not just a housekeeping requirement. It is the mechanism that makes everything else in your Information Security Management System verifiable. Without properly controlled documented information, an auditor cannot confirm that your ISMS is operating as intended. Policies exist only if they are documented and accessible. Risk decisions are only defensible if they are recorded. Controls are only auditable if there is evidence they are being applied.

This article walks through what Clause 7.5 actually requires, how the three subclauses work together, what auditors look for when they review documented information, and the most common gaps organisations leave in their systems.

The Structure of Clause 7.5

Clause 7.5 is divided into three subclauses, each addressing a different aspect of documented information management.

  • Clause 7.5.1 covers the general requirement to maintain and retain documented information.
  • Clause 7.5.2 covers creating and updating documented information, including identification, format, and review and approval.
  • Clause 7.5.3 covers the control of documented information, including availability, protection, distribution, access, storage, and disposition.

Together, these three subclauses form a complete document control framework. They tell you what to have, how to create and maintain it, and how to manage it throughout its lifecycle.

Clause 7.5.1: The General Requirement

Clause 7.5.1 states that the ISMS shall include documented information required by the standard, as well as documented information determined by the organisation to be necessary for the effectiveness of the ISMS.

There are two categories here, and both matter.

Documented Information Required by ISO 27001

ISO 27001 specifies documented information that is mandatory in various clauses. These are non-negotiable. If the standard says you shall retain documented information as evidence of something, you need that evidence. Common examples include:

  • The scope of the ISMS (Clause 4.3)
  • The information security policy (Clause 5.2)
  • The information security risk assessment process and results (Clause 6.1.2)
  • The risk treatment plan (Clause 6.1.3)
  • The Statement of Applicability (Clause 6.1.3)
  • Information security objectives (Clause 6.2)
  • Evidence of competence (Clause 7.2)
  • Results of monitoring, measurement, analysis and evaluation (Clause 9.1)
  • Internal audit programme and results (Clause 9.2)
  • Management review results (Clause 9.3)
  • Evidence of nonconformities and corrective actions (Clause 10.2)

This is not an exhaustive list. Throughout the standard, you will find the phrases shall maintain documented information and shall retain documented information as evidence. Every time you see those phrases, there is a mandatory document or record requirement attached.

Documented Information Determined by the Organisation

Beyond what the standard mandates, your organisation must also maintain documented information that it determines is necessary for the ISMS to work effectively. This is where professional judgement comes in.

If your organisation has a process for managing user access, and that process is not documented, there is a real risk that it will be applied inconsistently. If you have a procedure for responding to information security incidents, and it exists only in one person's head, it is not a reliable control. Documented information captures how things are actually supposed to work, so that the system functions consistently regardless of who is doing the work.

The standard does not prescribe a fixed list beyond its mandatory requirements. Your organisation decides what additional documented information is needed based on the complexity of your operations, the risks you face, and the controls you have implemented.

Clause 7.5.2: Creating and Updating Documented Information

Once you know what documented information you need, Clause 7.5.2 sets out how it must be created and updated. The requirements cover three areas: identification, format, and review and approval.

Identification

Documented information must be identified. In practice, this means each document or record needs enough identifying information to distinguish it from other documents and to confirm it is the current version. This typically includes a document title, a unique identifier or reference number, a version number or date, and the name of the author or owner.

The standard does not require a specific format for identification. What it requires is that the identification is sufficient to ensure the right document is being used at the right time.

Format and Media

Clause 7.5.2 also addresses format and media. Documented information can exist in any format and on any media. Paper documents, electronic files, databases, intranet pages, and even video recordings can all qualify as documented information, provided they meet the other requirements of the clause.

The format must be appropriate for its purpose. A procedure that needs to be followed step by step on a factory floor might need to be printed and laminated. A risk register that is updated regularly by multiple people is better suited to a shared electronic system. The format should support the actual use of the documented information, not just its storage.

Review and Approval

Documented information must be reviewed and approved for suitability and adequacy. This is a critical control. It means that someone with appropriate authority and knowledge must sign off on documented information before it is used, and again when it is updated.

In practice, this means your organisation needs a defined process for who can approve which documents, and evidence that approvals have actually occurred. An undated signature on a policy from three years ago, with no record of subsequent review, is unlikely to satisfy an auditor that the document is current and approved.

Clause 7.5.3: Control of Documented Information

Clause 7.5.3 is the most operationally demanding subclause. It requires that documented information be controlled to ensure it is available and suitable for use where and when it is needed, and that it is adequately protected.

Availability and Suitability

Documented information must be available to the people who need it, at the time they need it, in a form that is usable. This sounds straightforward, but it creates practical challenges.

Consider a situation where your incident response procedure is stored in a shared drive that is inaccessible during a network outage. During a security incident, the people who need that procedure cannot get to it. That is a control failure. Availability means the document can actually be accessed and used when the situation demands it.

Suitability means the document is in a condition where it can be used. A procedure that is out of date, unclear, or missing critical steps is not suitable for use, even if it is technically accessible.

Protection

Documented information must be adequately protected. For an ISMS, this is particularly significant. Your risk register, for example, contains sensitive information about your organisation's vulnerabilities. Your incident records contain details of past security failures. These documents need access controls, and those controls need to be appropriate to the sensitivity of the information.

Protection also covers integrity. Documented information must be protected from unintended alteration. If anyone can edit the risk assessment without authorisation, the integrity of that record is compromised.

Distribution, Access, Retrieval and Use

The standard requires that the organisation address distribution, access, retrieval, and use of documented information. This means deciding who gets access to which documents, how documents are distributed when they are updated, and how people retrieve the documents they need.

In most organisations, this is managed through a document management system, whether that is a purpose-built platform, a SharePoint site, or a structured folder system. The key requirement is that the system is controlled. People must be able to find the current version of a document quickly, and must not be able to inadvertently use an old version.

Storage, Preservation and Retention

Documented information must be stored and preserved appropriately. For records that serve as evidence of ISMS activities, this includes defining how long they will be retained. The standard does not specify retention periods. Your organisation must determine appropriate periods based on legal and regulatory requirements, contractual obligations, and the operational needs of the ISMS.

Preservation addresses the ongoing integrity and readability of stored information. Electronic records stored in obsolete formats may become unreadable over time. Paper records stored in poor conditions may deteriorate. Preservation means actively managing the condition of stored documented information so it remains usable for its intended retention period.

Control of Externally Originated Documents

Clause 7.5.3 also requires that documented information of external origin be identified as necessary and controlled. In an ISMS context, this includes things like supplier security policies, relevant legislation, industry standards, and contractual security requirements. These external documents need to be identified, kept current, and made available to the people who need them.

Disposition

Finally, the clause addresses disposition, which means what happens to documented information when it is no longer needed. Obsolete documents must be prevented from unintended use. Sensitive records must be disposed of securely. This is particularly important in an information security context. Disposing of a risk assessment by leaving it in an unsecured recycling bin is not adequate.

What Auditors Actually Look For

When an auditor reviews your documented information under Clause 7.5, they are not just checking whether documents exist. They are checking whether your document control system is functional and whether it is actually being used.

Here are the things that commonly attract scrutiny.

Mandatory Documents That Are Missing

The first check is whether all the documented information required by the standard is present. Missing mandatory documents are straightforward nonconformities. If you cannot produce a documented risk assessment process, a Statement of Applicability, or evidence of management review, the auditor will raise a finding.

Documents That Are Out of Date

Policies and procedures that have not been reviewed for several years are a common issue. If your information security policy was last approved in 2019 and nothing has changed in your business since then, that might be defensible. But if your organisation has grown, changed its technology environment, or faced new risks, and the policy has not been updated to reflect those changes, that is a problem.

Version Control Failures

Finding multiple versions of the same document in circulation is a version control failure. If one team is using version 2 of a procedure and another team is using version 3, there is a breakdown in document control. Auditors will often ask staff to show them where they access documented information, specifically to check whether they are using current versions.

Approval Without Evidence

A document that says it was approved but has no record of who approved it, when, or in what capacity is not demonstrably approved. Auditors look for evidence of approval, not just an approval field on a template.

Records That Cannot Be Produced

If the standard requires you to retain documented information as evidence of an activity, and you cannot produce that evidence when asked, the auditor will conclude that the activity either did not happen or was not recorded. Both outcomes are findings. Common examples include training records, audit records, and evidence of monitoring activities.

Access Controls on Sensitive Documents

In an ISMS audit, auditors may check whether sensitive documented information is appropriately protected. If your risk register is accessible to everyone in the organisation without restriction, that may be appropriate or it may not, depending on the sensitivity of the information and the controls documented in your system.

Common Nonconformities Under Clause 7.5

Based on real audit experience, these are the documented information issues that come up most frequently in ISMS audits.

  • No documented process for creating, reviewing, and approving documents
  • Policies approved by people without the authority to approve them
  • Risk assessment records that are not retained or are incomplete
  • No defined retention periods for ISMS records
  • Obsolete documents still accessible in shared drives or intranet sites
  • Externally originated documents not identified or controlled
  • No evidence of document review at planned intervals
  • Incident records that are incomplete or not retained

Most of these issues are not difficult to fix once they are identified. The challenge is that organisations often do not realise these gaps exist until an auditor finds them. That is why internal audits of your document control processes are so valuable. For practical guidance on how to approach this, the article on auditing documented information using a Clause 7.5 checklist approach is worth reading alongside this one.

Practical Advice for Getting Clause 7.5 Right

Here is what actually works in practice, based on experience across multiple ISMS implementations and audits.

Start with a Document Register

Maintain a register of all documented information in your ISMS. Include the document title, reference number, current version, date of last review, next review date, owner, and approval status. This register becomes your master control list and makes it easy to identify documents that are overdue for review.

Define Your Review Cycle

Set a review frequency for each type of document. Policies might be reviewed annually. Procedures might be reviewed every two years or when a significant change occurs. Risk assessments should be reviewed at planned intervals and whenever significant changes occur. Whatever frequency you choose, document it and stick to it.

Control Access to the Document System

Only authorised people should be able to create or modify documents in your system. Everyone who needs to use documents should be able to access current versions easily. Obsolete versions should be archived or deleted, not left in accessible locations.

Train People on Document Control

Document control only works if the people responsible for creating and maintaining documents understand the requirements. This is particularly important for new staff who take on document ownership responsibilities. Make sure they understand what review and approval actually means, and what records need to be kept.

Link Records to the Activities They Evidence

When you define an ISMS activity, identify at the same time what records will be retained as evidence of that activity. This connection between activities and their evidence is what makes your ISMS auditable. If you cannot identify what record will demonstrate that an activity occurred, that is a signal that the activity may not be well defined.

For anyone building or auditing a broader information security management system, understanding how Clause 7.5 connects to the rest of the standard is important. The article on Clause 7 of ISO 27001 covering resources, competence, awareness and communication provides useful context for how documented information fits within the broader support requirements.

Documented Information in an Integrated System

Many organisations run ISO 27001 alongside other management system standards such as ISO 9001, ISO 14001, or ISO 45001. The documented information requirements in Clause 7.5 are consistent across all of these standards because they share the same harmonised structure. This means a single document control procedure can serve all your management systems, provided it addresses the requirements of each standard.

Integration does not mean merging every document into a single file. It means having a coherent approach to document control that applies consistently across all your systems. A shared document register, a consistent naming and versioning convention, and a single approval process are all practical ways to integrate document control without creating unnecessary complexity.

If you are working across multiple standards, the article on auditing ISMS operations under Clause 8 is a useful companion for understanding how documented information supports operational controls in practice.

Preparing for an ISMS Audit: Document Control Readiness

Before a certification or surveillance audit of your ISMS, run a specific check on your documented information. Go through the list of mandatory documented information required by ISO 27001 and confirm that each item exists, is current, and is approved. Then review your document register to check that all documents have been reviewed within their defined review cycle.

Ask yourself whether you could produce any record required by the standard within a reasonable time if an auditor asked for it. If the answer is no for any record, that is a gap to address before the audit.

Also check that your document control procedure itself is current and that the people responsible for document control understand their responsibilities. Document control is one of those areas where the system can drift over time if it is not actively managed.

Building Auditor Competence in Documented Information

For internal auditors and those preparing for lead auditor roles, documented information is an area where practical competence really matters. Knowing what the standard requires is one thing. Being able to assess whether a document control system is genuinely effective is another.

Effective auditors do not just check whether documents exist. They trace the lifecycle of a document from creation through to disposal. They check whether the approval process was followed. They verify that the people using documents are actually using current versions. They look at whether records are complete and whether they genuinely evidence the activities they are supposed to evidence.

This kind of practical auditing skill is built through training and experience. If you are working towards an ISO 27001 internal auditor or lead auditor credential, Audit Workshop offers training that covers documented information requirements in the context of real audit scenarios, not just clause-by-clause theory. The courses are designed by practitioners who have conducted hundreds of external certification audits and understand what auditors actually look for.

Frequently Asked Questions

Maintained documented information refers to documents that are kept current and updated over time, such as policies, procedures, and the risk register. Retained documented information refers to records that are kept as evidence of activities that have occurred, such as audit reports, training records, and management review minutes. Both types are required by ISO 27001, and the distinction matters because they are managed differently. Documents need version control and regular review. Records need to be kept intact and accessible for their defined retention period.
Start Learning

Ready to Build Real Audit Skills?

Join practitioners training with ISO auditors who've conducted 500+ external certification audits.

ISO 9001:2026 Lead Auditor Training Course
Launching on 22 Sept 20265+ enrolled
View Details
Exemplar Global certified
ISO 9001:2026 Lead Auditor Training Course badge
ISO 9001:2026 Lead Auditor

Quality Management Systems (QMS)

Lead AuditorSelf-Paced OnlineDigital BadgeVideo Lessons
USD 299USD 789
ISO 45001:2018 Lead Auditor Training Course
15+ enrolled
View Details
Exemplar Global certified
ISO 45001:2018 Lead Auditor Training Course badge
ISO 45001:2018 Lead Auditor

Occupational Health and Safety Management Systems (OHSMS)

Lead AuditorSelf-Paced OnlineDigital BadgeVideo Lessons
USD 249USD 789
ISO 14001:2026 Lead Auditor Training Course
10+ enrolled
View Details
Exemplar Global certified
ISO 14001:2026 Lead Auditor Training Course badge
ISO 14001:2026 Lead Auditor

Environmental Management Systems (EMS)

Lead AuditorSelf-Paced OnlineDigital BadgeVideo Lessons
USD 249USD 789
Exemplar Global Recognised Training Provider digital badge

Audit Workshop is an Exemplar Global Recognised Training Provider

Globally Recognised, Certified Training

Pass an Exemplar Global Certified course and you earn a Certificate of Attainment and an Exemplar Global digital badge. Audit Workshop graduates can apply for third-party Personnel Certification through Exemplar Global.

  • 12 months of Graduate certification
  • Access to Exemplar Global Community
  • Digital badges and a certificate
  • Access to webinars, events, and online resources

Learn Anytime

No fixed schedule. Start, pause, and pick up exactly where you left off.

Practical Content

Every lesson is built from real-world ISO auditing experience.

Instant Certificate

Download your digital certificate the moment you complete the course.

Lifetime Access

Course materials are yours to keep and revisit long after you complete.