Sentrix

ISO 27001 guide · Clause 7

7.5 — Documented information

Clause 7.5 requires you to know what documented information the ISMS needs, to create and approve it consistently, and then to control it throughout its life.

By Sentrix · Published 2026-07-16

Every other clause in the standard eventually points here—this is where all of it has to actually live, stay current, and be findable.

Mandatory requirement

In plain language

7.5 requires you to know exactly what documented information your ISMS needs to exist, create and approve it consistently, and control it afterward so it stays accurate, findable, and protected throughout its life.

How these requirements fit together

7.5.1 sets the boundary: what belongs in the ISMS as documented information in the first place, whether mandated by the standard (the SoA, the risk assessment, internal audit results) or added because the organization finds it useful. 7.5.2 governs how each piece gets made—identified, formatted, reviewed, and approved before anyone relies on it. 7.5.3 governs what happens for the rest of its life—who can access it, how versions are tracked, how long it is kept, and how it is eventually disposed of. Skip 7.5.2 and you get documents nobody approved; skip 7.5.3 and you get approved documents nobody can find the current version of.

Going further

Need hands-on support structuring your document control? See our ISO 27001 certification support service. Parent clause: Clause 7 Support.

Sources

Frequently asked questions

What is the difference between 7.5.2 and 7.5.3?
7.5.2 governs how a document is created and approved in the first place: identification, format, review. 7.5.3 governs what happens to it afterward: access, storage, version control, and retention. Skip the first and you get documents nobody approved; skip the second and you get approved documents nobody can find the current version of.
What does 7.5.1 set?
The boundary: what belongs in the ISMS as documented information in the first place. That includes what the standard explicitly requires—the SoA, the risk assessment, internal audit results—and what the organization adds because it finds it necessary for the ISMS to be effective. The extent of that set varies with the size and complexity of the organization.
Why is 7.5 central at audit?
Because every other clause produces something that has to be created, reviewed, and controlled as documented information: the risk register, the SoA, policies, audit reports, management review minutes. An auditor who finds document control is undisciplined will start doubting whether anything else in the file is current or approved, however good it is.

Let's talk about your compliance program.

Last updated: 2026-09-17