ISO 27001 checklist: the documented information and evidence each audit looks for
ISO/IEC 17021-1: Stage 1 must “review the client’s management system documented information”.
Most ISO 27001 checklists are someone's list. This one is built from the texts: ISO/IEC 27001 itself where its wording can be read, the harmonized-structure text it is built on for clauses 7 to 10, and the accreditation standard that tells the certification body what each audit must look at. Every line says where it comes from.
Documented information, clause by clause
| Clause | What | Wording | Text |
|---|---|---|---|
| 4.3 | The scope of the ISMS | “The scope shall be available as documented information.” | ISO/IEC 27001:2022 |
| 5.2 | The information security policy | “be available as documented information” | ISO/IEC 27001:2022 |
| 6.1.2 | The risk assessment process | “retain documented information about the information security risk assessment process” | ISO/IEC 27001:2022 |
| 6.1.3 | The risk treatment process | “retain documented information about the information security risk treatment process” | ISO/IEC 27001:2022 |
| 6.1.3 d) | The Statement of Applicability | “produce a Statement of Applicability” | ISO/IEC 27001:2022 |
| 6.1.3 e) | The risk treatment plan | “formulate an information security risk treatment plan” | ISO/IEC 27001:2022 |
| 6.2 | The information security objectives | “retain documented information on the information security objectives” | ISO/IEC 27001:2022 |
| 7.2 | Evidence of competence | “Appropriate documented information shall be available as evidence of competence.” | Harmonized structure |
| 7.5.1 b) | Whatever else you decide is needed | “documented information determined by the organization as being necessary for the effectiveness of the [information security] management system” | Harmonized structure |
| 8.1 | Operational records | “Documented information shall be available to the extent necessary to have confidence that the processes have been carried out as planned.” | Harmonized structure |
| 8.2, 8.3 | Results of risk assessment and treatment | Not quoted: the clause titles are ‘information security risk assessment’ and ‘information security risk treatment’; we have not read their text | ISO/IEC 27001:2022 contents |
| 9.1 | Monitoring and measurement results | “Documented information shall be available as evidence of the results.” | Harmonized structure |
| 9.2.2 | Audit programme and results | “Documented information shall be available as evidence of the implementation of the audit programme(s) and the audit results.” | Harmonized structure |
| 9.3.3 | Management review results | “Documented information shall be available as evidence of the results of management reviews.” | Harmonized structure |
| 10.2 | Nonconformities and corrective action | “Documented information shall be available as evidence of: the nature of the nonconformities and any subsequent actions taken; the results of any corrective action” | Harmonized structure |
Why two different texts
The official preview of ISO/IEC 27001:2022 runs to clause 6.3, so clauses 4 to 6 are quoted from the standard. Clauses 7 to 10 are quoted from the harmonized structure, the common text every ISO management system standard applies. Where both can be read, we measured 79–100% of the common wording appearing in the standard; the standard may add to it.
The list is not the ceiling
Clause 7.5.1 b) adds whatever you decide is needed for the system to work. And the common text notes that the extent of documented information can differ from one organisation to another, depending on:
| Factor |
|---|
| the size of organization and its type of activities, processes, products and services |
| the complexity of processes and their interactions |
| the competence of persons |
Before Stage 1
Stage 1 has seven objectives. Three of them are the ones a checklist can prepare for:
| Stage 1 must | Have ready | |
|---|---|---|
| a | review the client’s management system documented information | Every item in the documented-information table above exists and is current |
| d | obtain necessary information regarding the scope of the management system, including: the client’s site(s); processes and equipment used; levels of controls established (particularly in case of multisite clients); applicable statutory and regulatory requirements | Your scope names the sites, processes and legal requirements |
| g | evaluate if the internal audits and management reviews are being planned and performed, and that the level of implementation of the management system substantiates that the client is ready for stage 2 | At least one internal audit and one management review are done or scheduled |
The other four, and what Stage 1 can lead to, are on Stage 1 and Stage 2.
Before Stage 2
“The purpose of stage 2 is to evaluate the implementation, including effectiveness, of the client’s management system. The stage 2 shall take place at the site(s) of the client.” It must include the auditing of:
| Stage 2 shall include | Evidence | |
|---|---|---|
| a | information and evidence about conformity to all requirements of the applicable management system standard or other normative documents | Evidence for every clause, and for each control the Statement of Applicability says is implemented |
| b | performance monitoring, measuring, reporting and reviewing against key performance objectives and targets | Objectives with measures, and results against them |
| c | the client’s management system ability and its performance regarding meeting of applicable statutory, regulatory and contractual requirements | The legal, regulatory and contract requirements you listed, and how you meet them |
| d | operational control of the client’s processes | Controls operating as the procedures say |
| e | internal auditing and management review | The internal audit report and management review minutes |
| f | management responsibility for the client’s policies | The policy, signed off and communicated |
Annex A goes through the Statement of Applicability
Controls are not audited from a generic list. Clause 6.1.3 d) requires a Statement of Applicability that contains “the necessary controls (see 6.1.3 b) and c)); justification for their inclusion; whether the necessary controls are implemented or not; and the justification for excluding any of the Annex A controls”. The auditor samples controls from it. See Statement of Applicability.
Before each surveillance audit
Each surveillance audit must include:
| Item | |
|---|---|
| a | internal audits and management review |
| b | a review of actions taken on nonconformities identified during the previous audit |
| c | complaints handling |
| d | effectiveness of the management system with regard to achieving the certified client’s objectives and the intended results of the respective management system (s) |
| e | progress of planned activities aimed at continual improvement |
| f | continuing operational control |
| g | review of any changes |
| h | use of marks and/or any other reference to certification |
Items (b) and (g) mean the checklist changes after certification: last time's findings and anything that has changed come first. See surveillance audits.
What a checklist cannot do
It cannot show effectiveness
Stage 2 evaluates “implementation, including effectiveness”. A document that exists but is not followed is a finding waiting to happen, however complete the list. See nonconformities.
It is not your internal audit
Clause 9.2 needs a programme, criteria and scope for each audit, and objective auditors. A checklist can be a tool within it. See internal audit.
Use it in this order
Documented information first (Stage 1 reads it), then evidence that it is followed (Stage 2 samples it), then the surveillance items every year after.
We do not audit, certify or consult, and are paid the same fixed fee per enquiry whichever firm you use. Requirements are quoted from ISO/IEC 27001, the harmonized structure and ISO/IEC 17021-1; the right-hand columns are our reading.
Where this fits
Common questions
Is there an official ISO 27001 checklist?
No. ISO/IEC 27001 states requirements; it does not publish a checklist. A checklist is someone's reading of the requirements. This one is built from the texts the certification body works to, and says which text each line comes from.
What documents are required for ISO 27001?
In clauses 4 to 6: the scope, the information security policy, documented information about the risk assessment and risk treatment processes, the Statement of Applicability, the risk treatment plan and the information security objectives. Clauses 7 to 10 add evidence of competence, operational records, monitoring results, audit programme and results, management review results and nonconformity records, in the common text the standard is built on.
What does the auditor check at Stage 1?
Among other things, Stage 1 must “review the client’s management system documented information” and “evaluate if the internal audits and management reviews are being planned and performed, and that the level of implementation of the management system substantiates that the client is ready for stage 2”.
What does the auditor check at Stage 2?
Stage 2 must include auditing of “information and evidence about conformity to all requirements of the applicable management system standard or other normative documents”, and five further items including “internal auditing and management review”.
Is an ISO 27001 internal audit checklist enough for the internal audit?
No. The requirement is an audit programme with defined objectives, criteria and scope for each audit, objective auditors and reported results, with evidence kept. A checklist is a tool for one audit, not the programme. See the internal audit page.
How much documentation does ISO 27001 need?
The common text says the extent can differ from one organisation to another, depending on the organisation's size and activities, the complexity of its processes, and “the competence of persons”.
Sources cited on this page
- ISO/IEC 27001:2022, official preview (clauses 1 to 6.3 and contents), read first-hand
- ISO/IEC Harmonized structure for MSS with guidance for use (formerly Annex SL Appendix 2 of the ISO/IEC Directives, Part 1), approved 30 July 2025
- BS EN ISO/IEC 17021-1:2015, clauses 9.3.1.2–9.3.1.4 (initial certification audit), full text
- BS EN ISO/IEC 17021-1:2015, clauses 9.1.3, 9.5.4 and 9.6 (audit programme, surveillance, recertification, suspension), full text
Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.
Preparing for Stage 1?
Say your size, your deadline, and which items on this list you do not have yet.
Your enquiry is ready to send
Here is what happens after you submit:
- Your answers go to ISO 27001 consultancies that advertise for your sector.
- No more than three of them may contact you, using the details you gave.
- You decide who, if anyone, you speak to. You are committed to nothing.
We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.