7.5.1 — General
There is no fixed list of required documents — the standard tells you the categories, your own ISMS decides the rest.
In plain language
In plain language: 7.5.1 says your ISMS has to include two categories of documented information: whatever this standard explicitly requires (the SoA, the risk assessment, internal audit results, and so on), plus anything else your own organization has decided is necessary for the ISMS to actually be effective.
Position in the standard
Why this requirement exists
The standard deliberately does not hand you a fixed checklist of documents, because a one-size-fits-all list would either be too heavy for a small company or too light for a complex one. This sub-clause exists to make that flexibility explicit: it is not that documentation is optional, it is that the exact set has to be right-sized to your organization.
Scenario: a company copies a 40-document template pack designed for a 2,000-person enterprise onto a 15-person business. Most of the documents are never actually used or kept current, because nobody sized them to the organization’s real complexity. 7.5.1 is the reminder that the goal is a right-sized set of documents that gets maintained, not the biggest possible pile.
What the standard expects
The standard expects the ISMS to include documented information required by the standard itself, and documented information the organization has determined to be necessary for the effectiveness of the ISMS — with an explicit acknowledgment that the extent of documented information can differ from one organization to another, depending on factors like organizational size, the complexity of its processes, and the competence of its people.
In practice
- Start from the documents the standard names explicitly (scope, policy, risk assessment/treatment, SoA, objectives, competence evidence, audit programme and results, management review results, nonconformities) — that is your mandatory floor.
- Add anything beyond that only if it genuinely helps the ISMS run — a document that exists purely to look thorough for an auditor tends to go stale fast.
Evidence the auditor will ask for
- A document inventory or list mapping each required document to where it lives.
Related requirements
7.5.2 Creating and updating
How each document on this list actually gets made.
6.1.3 Risk treatment
The SoA required here is one of the most important documents named by 7.5.1.
Parent link: 7.5 Documented information
Frequently asked questions
Is there an official list of mandatory ISO 27001 documents?
Know exactly what documents your ISMS actually needs.
Sentrix maps every clause’s documented-information requirement to a live checklist, so nothing required goes missing and nothing unnecessary piles up.