Sentrix

ISO 27001 guide · Clause 7

7.5.1 — General

Clause 7.5.1 states that the ISMS includes the documented information the standard requires plus whatever the organization deems necessary for effectiveness.

By Sentrix · Published 2026-07-16

There is no fixed list of required documents—the standard tells you the categories, your own ISMS decides the rest.

Mandatory requirement · Documented information required: no

In plain language

7.5.1 says your ISMS has to include two categories of documented information: whatever this standard explicitly requires (the SoA, the risk assessment, internal audit results, and so on), plus anything else your own organization has decided is necessary for the ISMS to actually be effective.

Why this requirement exists

The standard deliberately does not hand you a fixed checklist of documents, because a one-size-fits-all list would either be too heavy for a small company or too light for a complex one. This sub-clause exists to make that flexibility explicit: it is not that documentation is optional, it is that the exact set has to be right-sized to your organization.

Scenario: a company copies a 40-document template pack designed for a 2,000-person enterprise onto a 15-person business. Most of the documents are never actually used or kept current, because nobody sized them to the organization’s real complexity. 7.5.1 is the reminder that the goal is a right-sized set of documents that gets maintained, not the biggest possible pile.

What the standard expects

The standard expects the ISMS to include documented information required by the standard itself, and documented information the organization has determined to be necessary for the effectiveness of the ISMS—with an explicit acknowledgment that the extent of documented information can differ from one organization to another, depending on factors like organizational size, the complexity of its processes, and the competence of its people.

In practice

  • Start from the documents the standard names explicitly (scope, policy, risk assessment and treatment, SoA, objectives, competence evidence, audit programme and results, management review results, nonconformities)—that is your mandatory floor.
  • Add anything beyond that only if it genuinely helps the ISMS run—a document that exists purely to look thorough for an auditor tends to go stale fast.

Evidence the auditor will ask for

  • A document inventory or list mapping each required document to where it lives.

Related requirements

Sources

Frequently asked questions

Is there an official list of mandatory ISO 27001 documents?
The standard names several explicitly throughout clauses 4 to 10—scope, policy, risk assessment and treatment, SoA, objectives, competence evidence, audit programme and results, management review results, nonconformities—but it does not publish a single master checklist. The exact set is derived by reading each clause’s documented-information requirement.
Should we adopt a complete template pack?
No. The standard explicitly acknowledges that the extent of documented information differs from one organization to another depending on its size, the complexity of its processes, and the competence of its people. A pack designed for a large enterprise, copied onto a small business, produces documents that are never used or kept current. The goal is a right-sized, maintained set.
What evidence will the auditor ask for under 7.5.1?
A document inventory or list mapping each required document to where it lives. That inventory shows you know the mandatory floor the standard names and that anything beyond it exists because it genuinely helps the ISMS run, not to look thorough for an auditor.

Let's talk about your compliance program.

Last updated: 2026-09-17