ISO 27001 guide · Clause 7
7.5.2 — Creating and updating
Clause 7.5.2 requires that every time an ISMS document is created or updated it is clearly identified, appropriately formatted, then reviewed and approved.
By Sentrix · Published 2026-07-16
Three simple checks that stop an unapproved draft from quietly becoming the document everyone relies on.
Mandatory requirement · Documented information required: no
In plain language
7.5.2 requires that every time you create or update an ISMS document, you handle three things properly: label it clearly enough to identify it, format it appropriately for how it will be used, and have someone review and approve it before it counts as official.
Why this requirement exists
Without a defined creation process, documents accumulate informally—a draft policy gets emailed around, someone starts using it, and it becomes the de facto standard without anyone having actually reviewed it for accuracy or approved it for use. This sub-clause exists to put a gate in front of that drift.
Scenario: an incident response plan gets drafted, shared in a chat channel for feedback, and then referenced during a real incident six months later—except the version people are using was never formally approved, and a critical contact detail was fixed in a later draft that never got distributed. A defined review-and-approval step would have caught that before it mattered.
What the standard expects
The standard expects that, when creating and updating documented information, the organization ensures appropriate identification and description (such as a title, date, author, or reference number); appropriate format (such as language, software version, or graphics) and media (such as paper or electronic); and appropriate review and approval for suitability and adequacy.
In practice
- Use a consistent header or metadata block on every document: title, version number, date, author, and approver.
- Assign a named approver for each document type, and do not treat a draft as official until that approval is recorded.
- Pick a format appropriate to the audience—a technical procedure for engineers can look different from a policy meant for all staff.
Evidence the auditor will ask for
- Documents showing consistent identification metadata (title, version, date, author).
- Approval records—sign-off, an approval workflow, or meeting minutes—for key documents.
Common pitfalls
- A document in active use that was never formally approved by anyone.
- Inconsistent versioning across documents, making it unclear which one is current.
Related requirements
- 7.5.1 General—what documents this creation process applies to.
- 7.5.3 Control of documented information—what happens to a document after it is created and approved.
- Parent clause: 7.5 Documented information.
Sources
Frequently asked questions
- Who can approve a document?
- The standard does not name a specific role. It just has to be someone with the authority and knowledge to judge the document’s suitability and adequacy, defined consistently for each document type. Assign a named approver per document type and do not treat a draft as official until that approval is recorded.
- What metadata should an ISMS document carry?
- Appropriate identification and description: the standard cites a title, date, author, or reference number. In practice, a consistent header or metadata block on every document—title, version number, date, author, and approver—is enough, and it is exactly what the auditor will examine to check that versioning is consistent.
- Does every document need the same format?
- No. The standard asks for an appropriate format (language, software version, graphics) and appropriate media (paper or electronic), chosen for how the document will be used. A technical procedure for engineers can look different from a policy meant for all staff; what matters is that the format serves its audience.
Related pages
ISO 27001 guide · Clause 7
7.5 — Documented information
Clause 7.5 requires you to know what documented information the ISMS needs, to create and approve it consistently, and then to control it throughout its life.
ISO 27001 guide · Clause 7
7.5.1 — General
Clause 7.5.1 states that the ISMS includes the documented information the standard requires plus whatever the organization deems necessary for effectiveness.
ISO 27001 guide · Clause 7
7.5.3 — Control of documented information
Clause 7.5.3 requires that once a document exists it stays available, protected and managed: distribution, access, storage, versions, retention and disposal.
Let's talk about your compliance program.
Last updated: 2026-09-17
