Clause 7 · Support

7.5.1 — General

There is no fixed list of required documents — the standard tells you the categories, your own ISMS decides the rest.

Mandatory requirementDocumented information required: No

In plain language

In plain language: 7.5.1 says your ISMS has to include two categories of documented information: whatever this standard explicitly requires (the SoA, the risk assessment, internal audit results, and so on), plus anything else your own organization has decided is necessary for the ISMS to actually be effective.

Position in the standard

Clause 7 · Support
7.5.1 · General ← you are here
See also: 7.5.2 · 7.5.3

Why this requirement exists

The standard deliberately does not hand you a fixed checklist of documents, because a one-size-fits-all list would either be too heavy for a small company or too light for a complex one. This sub-clause exists to make that flexibility explicit: it is not that documentation is optional, it is that the exact set has to be right-sized to your organization.

Scenario: a company copies a 40-document template pack designed for a 2,000-person enterprise onto a 15-person business. Most of the documents are never actually used or kept current, because nobody sized them to the organization’s real complexity. 7.5.1 is the reminder that the goal is a right-sized set of documents that gets maintained, not the biggest possible pile.

What the standard expects

The standard expects the ISMS to include documented information required by the standard itself, and documented information the organization has determined to be necessary for the effectiveness of the ISMS — with an explicit acknowledgment that the extent of documented information can differ from one organization to another, depending on factors like organizational size, the complexity of its processes, and the competence of its people.

In practice

  • Start from the documents the standard names explicitly (scope, policy, risk assessment/treatment, SoA, objectives, competence evidence, audit programme and results, management review results, nonconformities) — that is your mandatory floor.
  • Add anything beyond that only if it genuinely helps the ISMS run — a document that exists purely to look thorough for an auditor tends to go stale fast.

Evidence the auditor will ask for

  • A document inventory or list mapping each required document to where it lives.

Related requirements

Parent link: 7.5 Documented information

Frequently asked questions

Is there an official list of mandatory ISO 27001 documents?
The standard names several explicitly throughout clauses 4-10 (scope, policy, SoA, objectives, and more), but it does not publish a single master checklist — the exact set is derived by reading each clause’s documented-information requirement.

Know exactly what documents your ISMS actually needs.

Sentrix maps every clause’s documented-information requirement to a live checklist, so nothing required goes missing and nothing unnecessary piles up.