ISO 27001 Documentation Kit – What You Actually Need (With Real Examples)

When people search for an “ISO 27001 documentation kit”, what they usually get is either a long list of generic templates or a vague explanation of the standard.

Neither of those actually helps when you’re trying to put something workable in place.

What you really need is a clear understanding of what documents are expected, how they fit together, and what an auditor will actually look for when they review them.

What documents are actually required for ISO 27001?

At its core, ISO 27001 is not about producing documents for the sake of it. It’s about demonstrating that your information security management system (ISMS) is defined, implemented, and working in practice.

That said, there are some key documents that every organisation ends up needing.

These typically include:

  • Scope of the ISMS
  • Information Security Policy
  • Risk Assessment Methodology
  • Risk Register
  • Statement of Applicability
  • Internal Audit Programme
  • Management Review Records
  • Corrective Action Process

On paper, that doesn’t look too complicated. And this is where a lot of businesses underestimate what’s involved. Because the challenge isn’t creating each document individually - it’s making sure they all align.

Example ISO 27001 legal register image showing applicable legislation, supporting compliance records and a structured view of legal and regulatory obligations.

What auditors actually look for (this is where most systems fall down)

From an audit perspective, documents are never reviewed in isolation.

An auditor will typically follow a trail like this:

If those pieces don’t line up, it doesn’t matter how “good” each individual document looks.

This is why downloading a set of disconnected templates often leads to problems later in the process.

Example: how these documents link together

Take something simple like access control.

Your risk assessment might identify:

“Unauthorised access to company systems”

Your Statement of Applicability then selects controls relating to access management.

From there, you would expect to see:

  • A defined access control policy
  • User access reviews
  • Evidence of onboarding/offboarding processes
  • Logs or records showing access is managed

If any part of that chain is missing, it creates a gap that will be picked up during an audit.

Where most “ISO 27001 template packs” go wrong

Most template packs focus on volume rather than usability.

You’ll often see:

  • Dozens of documents with no clear structure
  • Generic wording that doesn’t reflect how your business operates
  • No linkage between risk, controls, and processes
  • No guidance on how to actually implement what’s written

This leads to a situation where you have “documentation”, but not a working management system.

And that’s the difference auditors care about.

What a usable ISO 27001 documentation system should look like

In practice, a working system should:

  • Be simple enough to maintain
  • Clearly link risk → controls → processes → evidence
  • Reflect what your business actually does
  • Be structured so updates don’t break everything else

This is where most of the effort goes - not in writing documents, but in making them coherent.

A quick reality check before you start building this yourself

It’s completely possible to build an ISO 27001 system from scratch using individual templates.

But what most businesses find is that:

  • They spend far more time linking everything together than expected
  • Version control becomes difficult
  • Documents drift out of sync
  • Preparing for audit becomes a manual exercise

That’s usually the point where people start looking for something more structured.

If you want a complete, working system rather than disconnected templates

This is exactly the gap The Compliance Companion is designed to fill.

Instead of providing isolated documents, it gives you a structured, interlinked system that:

  • covers the full set of ISO 27001 requirements
  • aligns risk assessment, controls, and processes
  • is designed to be implemented in a practical way (not just sit on a shelf)

It’s built around how audits actually work, so you’re not trying to piece everything together yourself.

If you’ve already started building documentation and are finding it harder than expected, it’s worth taking a look.