iso27001partnersUK certification, costed Get a cost estimate

ISO 27001 checklist: the documented information and evidence each audit looks for

Written from the standards themselves · Editor-reviewed · Checked against the current editions on 30 September 2026
By the iso27001partners.co.uk editorial team · Published 30 September 2026 · Last reviewed 30 September 2026 · 9 min read
4 primary sources cited on this page. How we check what is on this site
Stage 1 starts here Your documented information

ISO/IEC 17021-1: Stage 1 must “review the client’s management system documented information”.

Most ISO 27001 checklists are someone's list. This one is built from the texts: ISO/IEC 27001 itself where its wording can be read, the harmonized-structure text it is built on for clauses 7 to 10, and the accreditation standard that tells the certification body what each audit must look at. Every line says where it comes from.

Documented information, clause by clause

Documented information ISO/IEC 27001 requires, with the wording and where it comes from
ClauseWhatWordingText
4.3The scope of the ISMS“The scope shall be available as documented information.”ISO/IEC 27001:2022
5.2The information security policy“be available as documented information”ISO/IEC 27001:2022
6.1.2The risk assessment process“retain documented information about the information security risk assessment process”ISO/IEC 27001:2022
6.1.3The risk treatment process“retain documented information about the information security risk treatment process”ISO/IEC 27001:2022
6.1.3 d)The Statement of Applicability“produce a Statement of Applicability”ISO/IEC 27001:2022
6.1.3 e)The risk treatment plan“formulate an information security risk treatment plan”ISO/IEC 27001:2022
6.2The information security objectives“retain documented information on the information security objectives”ISO/IEC 27001:2022
7.2Evidence of competence“Appropriate documented information shall be available as evidence of competence.”Harmonized structure
7.5.1 b)Whatever else you decide is needed“documented information determined by the organization as being necessary for the effectiveness of the [information security] management system”Harmonized structure
8.1Operational records“Documented information shall be available to the extent necessary to have confidence that the processes have been carried out as planned.”Harmonized structure
8.2, 8.3Results of risk assessment and treatmentNot quoted: the clause titles are ‘information security risk assessment’ and ‘information security risk treatment’; we have not read their textISO/IEC 27001:2022 contents
9.1Monitoring and measurement results“Documented information shall be available as evidence of the results.”Harmonized structure
9.2.2Audit programme and results“Documented information shall be available as evidence of the implementation of the audit programme(s) and the audit results.”Harmonized structure
9.3.3Management review results“Documented information shall be available as evidence of the results of management reviews.”Harmonized structure
10.2Nonconformities and corrective action“Documented information shall be available as evidence of: the nature of the nonconformities and any subsequent actions taken; the results of any corrective action”Harmonized structure

Why two different texts

The official preview of ISO/IEC 27001:2022 runs to clause 6.3, so clauses 4 to 6 are quoted from the standard. Clauses 7 to 10 are quoted from the harmonized structure, the common text every ISO management system standard applies. Where both can be read, we measured 79–100% of the common wording appearing in the standard; the standard may add to it.

The list is not the ceiling

Clause 7.5.1 b) adds whatever you decide is needed for the system to work. And the common text notes that the extent of documented information can differ from one organisation to another, depending on:

What the extent of documented information depends on (harmonized structure 7.5.1 NOTE, verbatim)
Factor
the size of organization and its type of activities, processes, products and services
the complexity of processes and their interactions
the competence of persons

Before Stage 1

Stage 1 has seven objectives. Three of them are the ones a checklist can prepare for:

Stage 1 objectives (ISO/IEC 17021-1:2015 9.3.1.2.2, verbatim) and what to have ready (our reading)
Stage 1 mustHave ready
areview the client’s management system documented informationEvery item in the documented-information table above exists and is current
dobtain necessary information regarding the scope of the management system, including: the client’s site(s); processes and equipment used; levels of controls established (particularly in case of multisite clients); applicable statutory and regulatory requirementsYour scope names the sites, processes and legal requirements
gevaluate if the internal audits and management reviews are being planned and performed, and that the level of implementation of the management system substantiates that the client is ready for stage 2At least one internal audit and one management review are done or scheduled

The other four, and what Stage 1 can lead to, are on Stage 1 and Stage 2.

Before Stage 2

“The purpose of stage 2 is to evaluate the implementation, including effectiveness, of the client’s management system. The stage 2 shall take place at the site(s) of the client.” It must include the auditing of:

Stage 2 must audit (ISO/IEC 17021-1:2015 9.3.1.3, verbatim) and the evidence that answers it (our reading)
Stage 2 shall includeEvidence
ainformation and evidence about conformity to all requirements of the applicable management system standard or other normative documentsEvidence for every clause, and for each control the Statement of Applicability says is implemented
bperformance monitoring, measuring, reporting and reviewing against key performance objectives and targetsObjectives with measures, and results against them
cthe client’s management system ability and its performance regarding meeting of applicable statutory, regulatory and contractual requirementsThe legal, regulatory and contract requirements you listed, and how you meet them
doperational control of the client’s processesControls operating as the procedures say
einternal auditing and management reviewThe internal audit report and management review minutes
fmanagement responsibility for the client’s policiesThe policy, signed off and communicated

Annex A goes through the Statement of Applicability

Controls are not audited from a generic list. Clause 6.1.3 d) requires a Statement of Applicability that contains “the necessary controls (see 6.1.3 b) and c)); justification for their inclusion; whether the necessary controls are implemented or not; and the justification for excluding any of the Annex A controls”. The auditor samples controls from it. See Statement of Applicability.

Before each surveillance audit

Each surveillance audit must include:

What every surveillance audit shall include (ISO/IEC 17021-1:2015 9.6.2.2, verbatim)
Item
ainternal audits and management review
ba review of actions taken on nonconformities identified during the previous audit
ccomplaints handling
deffectiveness of the management system with regard to achieving the certified client’s objectives and the intended results of the respective management system (s)
eprogress of planned activities aimed at continual improvement
fcontinuing operational control
greview of any changes
huse of marks and/or any other reference to certification

Items (b) and (g) mean the checklist changes after certification: last time's findings and anything that has changed come first. See surveillance audits.

What a checklist cannot do

It cannot show effectiveness

Stage 2 evaluates “implementation, including effectiveness”. A document that exists but is not followed is a finding waiting to happen, however complete the list. See nonconformities.

It is not your internal audit

Clause 9.2 needs a programme, criteria and scope for each audit, and objective auditors. A checklist can be a tool within it. See internal audit.

Use it in this order

Documented information first (Stage 1 reads it), then evidence that it is followed (Stage 2 samples it), then the surveillance items every year after.

We do not audit, certify or consult, and are paid the same fixed fee per enquiry whichever firm you use. Requirements are quoted from ISO/IEC 27001, the harmonized structure and ISO/IEC 17021-1; the right-hand columns are our reading.

Where this fits

Common questions

Is there an official ISO 27001 checklist?

No. ISO/IEC 27001 states requirements; it does not publish a checklist. A checklist is someone's reading of the requirements. This one is built from the texts the certification body works to, and says which text each line comes from.

What documents are required for ISO 27001?

In clauses 4 to 6: the scope, the information security policy, documented information about the risk assessment and risk treatment processes, the Statement of Applicability, the risk treatment plan and the information security objectives. Clauses 7 to 10 add evidence of competence, operational records, monitoring results, audit programme and results, management review results and nonconformity records, in the common text the standard is built on.

What does the auditor check at Stage 1?

Among other things, Stage 1 must “review the client’s management system documented information” and “evaluate if the internal audits and management reviews are being planned and performed, and that the level of implementation of the management system substantiates that the client is ready for stage 2”.

What does the auditor check at Stage 2?

Stage 2 must include auditing of “information and evidence about conformity to all requirements of the applicable management system standard or other normative documents”, and five further items including “internal auditing and management review”.

Is an ISO 27001 internal audit checklist enough for the internal audit?

No. The requirement is an audit programme with defined objectives, criteria and scope for each audit, objective auditors and reported results, with evidence kept. A checklist is a tool for one audit, not the programme. See the internal audit page.

How much documentation does ISO 27001 need?

The common text says the extent can differ from one organisation to another, depending on the organisation's size and activities, the complexity of its processes, and “the competence of persons”.

Sources cited on this page

  1. ISO/IEC 27001:2022, official preview (clauses 1 to 6.3 and contents), read first-hand
  2. ISO/IEC Harmonized structure for MSS with guidance for use (formerly Annex SL Appendix 2 of the ISO/IEC Directives, Part 1), approved 30 July 2025
  3. BS EN ISO/IEC 17021-1:2015, clauses 9.3.1.2–9.3.1.4 (initial certification audit), full text
  4. BS EN ISO/IEC 17021-1:2015, clauses 9.1.3, 9.5.4 and 9.6 (audit programme, surveillance, recertification, suspension), full text

Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.

Preparing for Stage 1?

Say your size, your deadline, and which items on this list you do not have yet.

Step 1 of 6
What has made this a live question?

Almost nobody certifies for its own sake. Whatever is pushing this usually also sets the deadline, so it is worth saying first.

When do you need the certificate in your hand?

Stage 1 and Stage 2 are separate visits with a gap between them, so the certificate always lands some weeks after the last audit day. A date inside three months is a different piece of work from a date inside a year.

How many people would be inside the scope?

Not your whole payroll — everyone doing work under your control inside the certified scope, contractors included. This is the number the audit-day table in ISO/IEC 27006-1 runs on, so it decides the audit fee before anything else does.

What exists already?

There is no wrong answer here and nothing to be embarrassed about. Most enquiries are at the first option.

How do you want the work done?

The three routes cost very different amounts and suit very different teams. If you have not decided, say so — that is a useful answer too.

Where should the consultancy reach you?

This is the only step that asks you to type anything.

By clicking “Send my enquiry” I agree that iso27001partners.co.uk may pass the details above to up to three ISO 27001 consultancies that advertise for my sector, so that they can contact me at the business details I have given. Consent is not a condition of anything — every page, table and calculator on this site works without it. You can withdraw consent at any time by replying to any message you receive, or by writing to us through the enquiry form on any page. We are not a certification body, not an accreditation body and not a consultancy; the disclaimer linked in the footer sets out the whole arrangement.

  • Your details go to consultancies only, and to no more than three
  • Free to you — consultancies pay us a fixed fee per enquiry, set in advance
  • No obligation, and no certification body is involved at this stage

Your enquiry is ready to send

Here is what happens after you submit:

  1. Your answers go to ISO 27001 consultancies that advertise for your sector.
  2. No more than three of them may contact you, using the details you gave.
  3. You decide who, if anyone, you speak to. You are committed to nothing.

We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.

Free enquiryFive clicks · no obligation Start now