ISO 27001 Documentation Kit – What You Actually Need (With Real Examples)
When people search for an “ISO 27001 documentation kit”, what they usually get is either a long list of generic templates or a vague explanation of the standard.
Neither of those actually helps when you’re trying to put something workable in place.
What you really need is a clear understanding of what documents are expected, how they fit together, and what an auditor will actually look for when they review them.
What documents are actually required for ISO 27001?
At its core, ISO 27001 is not about producing documents for the sake of it. It’s about demonstrating that your information security management system (ISMS) is defined, implemented, and working in practice.
That said, there are some key documents that every organisation ends up needing.
These typically include:
- Scope of the ISMS
- Information Security Policy
- Risk Assessment Methodology
- Risk Register
- Statement of Applicability
- Internal Audit Programme
- Management Review Records
- Corrective Action Process
On paper, that doesn’t look too complicated. And this is where a lot of businesses underestimate what’s involved. Because the challenge isn’t creating each document individually - it’s making sure they all align.



What auditors actually look for (this is where most systems fall down)
From an audit perspective, documents are never reviewed in isolation.
An auditor will typically follow a trail like this:
- Risks identified in your risk assessment
- Controls selected in your Statement of Applicability
- Evidence those controls are actually implemented
- Records showing the system is reviewed and improved
If those pieces don’t line up, it doesn’t matter how “good” each individual document looks.
This is why downloading a set of disconnected templates often leads to problems later in the process.
Example: how these documents link together
Take something simple like access control.
Your risk assessment might identify:
“Unauthorised access to company systems”
Your Statement of Applicability then selects controls relating to access management.
From there, you would expect to see:
- A defined access control policy
- User access reviews
- Evidence of onboarding/offboarding processes
- Logs or records showing access is managed
If any part of that chain is missing, it creates a gap that will be picked up during an audit.
Where most “ISO 27001 template packs” go wrong
Most template packs focus on volume rather than usability.
You’ll often see:
- Dozens of documents with no clear structure
- Generic wording that doesn’t reflect how your business operates
- No linkage between risk, controls, and processes
- No guidance on how to actually implement what’s written
This leads to a situation where you have “documentation”, but not a working management system.
And that’s the difference auditors care about.
What a usable ISO 27001 documentation system should look like
In practice, a working system should:
- Be simple enough to maintain
- Clearly link risk → controls → processes → evidence
- Reflect what your business actually does
- Be structured so updates don’t break everything else
This is where most of the effort goes - not in writing documents, but in making them coherent.
A quick reality check before you start building this yourself
It’s completely possible to build an ISO 27001 system from scratch using individual templates.
But what most businesses find is that:
- They spend far more time linking everything together than expected
- Version control becomes difficult
- Documents drift out of sync
- Preparing for audit becomes a manual exercise
That’s usually the point where people start looking for something more structured.
If you want a complete, working system rather than disconnected templates
This is exactly the gap The Compliance Companion is designed to fill.
Instead of providing isolated documents, it gives you a structured, interlinked system that:
- covers the full set of ISO 27001 requirements
- aligns risk assessment, controls, and processes
- is designed to be implemented in a practical way (not just sit on a shelf)
It’s built around how audits actually work, so you’re not trying to piece everything together yourself.
If you’ve already started building documentation and are finding it harder than expected, it’s worth taking a look.