Documented Information Evaluation Criteria
In an ISO/IEC 27001 audit, documented information evaluation criteria are the benchmarks a lead auditor uses to judge whether an organization's ISMS documentation is adequate, effective, and conforms to the standard. The evaluation usually begins during the Stage 1 audit and continues during Stage … In an ISO/IEC 27001 audit, documented information evaluation criteria are the benchmarks a lead auditor uses to judge whether an organization's ISMS documentation is adequate, effective, and conforms to the standard. The evaluation usually begins during the Stage 1 audit and continues during Stage 2, where auditors check that documented processes are actually implemented. The criteria come mainly from ISO/IEC 27001 clause 7.5 (Documented Information) and from ISO 19011 clause 6.3.1, which guides auditors in reviewing documentation. ISO 19011 identifies four core criteria. Completeness means all expected content is present, including mandatory items such as the ISMS scope, information security policy, risk assessment and risk treatment processes, Statement of Applicability, information security objectives, and evidence of competence, monitoring, internal audits, management reviews, and corrective actions. Correctness means the content is accurate and matches reliable sources such as the risk register and actual practice. Consistency means documents agree with each other and with related records. For example, controls marked as applicable in the Statement of Applicability should appear in risk treatment plans. Currentness means the content is up to date and reflects the organization's present context, risks, and technology. From clause 7.5, auditors also check several further criteria. Documents should have proper identification and description, such as a title, date, author, and reference number. They should use an appropriate format and media. Evidence should show that documents have been reviewed and approved for suitability and adequacy. Auditors also examine control of documented information: availability where needed, protection of confidentiality and integrity, distribution, access, storage, version control, retention, and disposal. Documents of external origin, such as legal requirements and supplier contracts, must also be identified and controlled. Auditors consider whether the extent of documentation suits the organization's size, complexity, and risks, since ISO/IEC 27001 does not demand excessive documentation. Weaknesses found are recorded as potential nonconformities or areas of concern. These findings help determine Stage 2 readiness and shape the audit plan and sampling strategy, giving an objective, evidence-based conclusion on the ISMS.
Documented Information Evaluation Criteria in ISO/IEC 27001 Audits: A Complete Lead Auditor Guide
Introduction
In an ISO/IEC 27001 audit, documented information is the backbone of objective evidence. Before an auditor can judge whether an Information Security Management System (ISMS) conforms to requirements and is effectively implemented, they must first evaluate the documented information the organization keeps. Documented Information Evaluation Criteria are the standards, questions and benchmarks a lead auditor uses to decide whether documented information is adequate, complete, controlled, current and fit for purpose. This guide explains what the criteria are, why they matter, how they are applied during an audit, and how to answer exam questions on the topic with confidence.
1. What Is Documented Information?
ISO/IEC 27001:2022 (and the 2013 version) uses the term documented information to replace the older terms 'documents' and 'records'. ISO/IEC 27000 defines it as information required to be controlled and maintained by an organization, and the medium on which it is contained. It can exist in any format or medium, such as paper, electronic files, databases, video or intranet pages, and from any source.
Two broad types exist:
Documented information to be maintained (traditionally 'documents'). Examples are the ISMS scope, the information security policy, the risk assessment process, the risk treatment process, the Statement of Applicability (SoA) and information security objectives.
Documented information to be retained (traditionally 'records'). Examples are results of risk assessments, risk treatment results, evidence of competence, monitoring and measurement results, internal audit programmes and results, management review results, and nonconformities with their corrective actions.
Clause 7.5 of ISO/IEC 27001 sets the requirements for documented information:
7.5.1 General: the ISMS shall include documented information required by the standard and documented information the organization determines as necessary for the effectiveness of the ISMS.
7.5.2 Creating and updating: appropriate identification and description (title, date, author, reference number), format and media, and review and approval for suitability and adequacy.
7.5.3 Control of documented information: it must be available and suitable for use where and when needed, and adequately protected (from loss of confidentiality, improper use or loss of integrity). It also addresses distribution, access, retrieval and use; storage and preservation, including legibility; control of changes (version control); retention and disposition; and control of documented information of external origin.
2. What Are Documented Information Evaluation Criteria?
Evaluation criteria are the reference points against which the auditor assesses documented information. ISO 19011:2018 (Guidelines for auditing management systems), clause 6.3.1, says the auditee's relevant documented information should be reviewed to gather information to prepare audit activities and applicable work documents. It should also be reviewed to establish an overview of the extent of the documented information, so the auditor can detect possible gaps.
ISO 19011 suggests documented information should be evaluated for whether it is:
Complete: all expected content is present.
Correct: content conforms to other reliable sources such as standards and regulations.
Consistent: the document is consistent with itself and with related documents.
Current: content is up to date.
In addition, a lead auditor typically checks whether the documented information:
Covers the audit scope and provides enough information to support the audit objectives.
Is adequate (suitable): it meets the requirements of ISO/IEC 27001 and the organization's own needs.
Is controlled: it is identified, approved, versioned, distributed, protected, retained and disposed of as required by clause 7.5.
Is accessible and available to the people who need it, at the point of use.
Is appropriately protected in line with the classification and confidentiality of its content.
Is traceable: records can be linked to processes, risks, controls and activities.
Is proportionate: the extent of documentation fits the organization's size, type of activities, complexity of processes and competence of personnel (clause 7.5.1 note).
Is aligned with practice: what is written matches what is actually done. This is verified on site.
3. Why Is This Important?
Foundation of objective evidence: audit findings must be based on verifiable evidence. Documented information is a major source of that evidence. Without evaluating its quality, conclusions may rest on unreliable data.
Determines audit readiness: in a certification audit, the Stage 1 audit focuses heavily on documented information. It confirms the ISMS is designed properly and that the organization is ready for Stage 2. Major gaps found here may delay Stage 2.
Efficient planning: reviewing documents early helps the audit team understand the ISMS, identify risk areas, prepare checklists and sampling plans, and allocate time sensibly.
Conformity determination: ISO/IEC 27001 explicitly mandates certain documented information. Missing mandatory items, such as the SoA, risk assessment results or internal audit results, are clear nonconformities.
Effectiveness insight: well-controlled, current and consistent documentation usually shows a mature ISMS. Outdated, contradictory or unapproved documents signal weak governance.
Risk-based auditing: evaluation criteria help the auditor focus on high-risk documents, such as the risk treatment plan or access control policy, rather than treating all documents equally.
4. How It Works in Practice
Step 1: Request documented information before the audit. The lead auditor asks for key documents during preparation. These include scope, policy, risk methodology, risk assessment and treatment reports, SoA, objectives, internal audit reports, management review minutes and key procedures. ISO 19011 notes that documents may be reviewed off-site or during the opening phase, depending on the audit method.
Step 2: Check for mandatory documented information. The auditor compares the documents against the list required by ISO/IEC 27001. This includes clauses 4.3, 5.2, 6.1.2, 6.1.3, 6.2, 6.3 (in a sense), 7.2, 8.1, 8.2, 8.3, 9.1, 9.2, 9.3 and 10.2, plus controls in Annex A that the SoA declares applicable and that need documentation (for example, documented operating procedures in A.5.37).
Step 3: Apply the evaluation criteria. For each document, the auditor asks questions such as these:
- Is it complete for its purpose?
- Is it approved by an appropriate authority?
- Is it the current version, and is there version control?
- Is it consistent with other documents? For example, does the SoA match the risk treatment plan? Does the scope in the policy match the scope document?
- Is it correct relative to legal, regulatory and contractual requirements?
- Is it protected according to its classification?
- Is external documentation, such as supplier contracts or legal texts, identified and controlled?
Step 4: Identify gaps and concerns. The auditor records gaps that could be classified as nonconformities. In Stage 1 these are often described as areas of concern. The auditor also notes items to verify on site.
Step 5: Verify implementation on site. Documented information is only half the story. During Stage 2 or surveillance, the auditor confirms through interviews, observation and record sampling that practice reflects documentation. A beautifully written access control procedure that staff do not follow results in a nonconformity of implementation, not of documentation.
Step 6: Report. Findings regarding documented information are reported with references to the requirement (for example, clause 7.5.3) and the objective evidence (for example, 'Version 2.1 of the backup procedure in use at the data centre differed from approved version 3.0 on the document management system').
5. Common Findings Related to Documented Information
- The SoA lacks justification for inclusion or exclusion of controls, or does not state implementation status.
- Risk assessment results are not retained, or are not updated after significant changes.
- Obsolete versions of procedures are in use at the point of use.
- Documents have no evidence of approval or review date.
- Competence records are missing for staff in key security roles.
- Internal audit results are not retained, or the audit programme is not documented.
- External documents, such as legal and regulatory requirements, are not identified or controlled.
- Sensitive documents, such as network diagrams, are accessible to unauthorized staff (a 7.5.3 protection failure).
- Inconsistencies exist between the scope statement, policy and SoA.
6. Key Distinctions to Remember
Excessive documentation is not a requirement: ISO/IEC 27001 does not require a quality-manual style document or specific procedures for every control. Auditors should not raise nonconformities simply because a document they would like to see does not exist. This applies only when the standard requires it, the organization's own ISMS requires it, or its absence affects effectiveness.
Format is flexible: a wiki page, a ticketing system or a video can be valid documented information if it is controlled.
Documentation review versus implementation audit: Stage 1 focuses on design and documentation. Stage 2 focuses on implementation and effectiveness.
Auditor confidentiality: auditors must protect the auditee's documented information they receive, per ISO 19011 principles and ISO/IEC 27006 requirements.
Exam Tips: Answering Questions on Documented Information Evaluation Criteria
1. Memorize the ISO 19011 criteria. Exam questions often ask how documented information should be evaluated. Recall the four Cs: Complete, Correct, Consistent, Current. Also remember the requirement to cover the audit scope and support audit objectives.
2. Know the mandatory documented information list. Be ready to identify which items ISO/IEC 27001 explicitly requires. Many scenario questions describe a missing document and ask whether this is a nonconformity. If the standard says 'shall retain documented information' or 'shall be available as documented information', its absence is a nonconformity.
3. Distinguish 'maintain' from 'retain'. 'Maintain' means a living document (policy, procedure, SoA). 'Retain' means evidence or records (results, minutes, competence evidence). Questions may test whether you can classify an item correctly.
4. Reference clause 7.5 precisely. When writing findings in essay or scenario questions, cite the specific sub-clause. Use 7.5.2 for approval, identification and format issues. Use 7.5.3 for availability, protection, version control, retention and external documents.
5. Link documents to each other. Examiners like consistency checks. Examples: the SoA versus the risk treatment plan, the scope versus the policy, and objectives versus monitoring results. If a scenario shows contradictions, the expected answer usually identifies a nonconformity or a concern about consistency.
6. Remember: documented does not mean implemented. If a question describes a perfect procedure that is not followed, the finding relates to the operational clause (for example, 8.1 or an Annex A control), not to clause 7.5. Show the examiner that you understand the difference between documentation adequacy and implementation effectiveness.
7. Avoid over-auditing. If a scenario describes an auditor raising a nonconformity because a non-mandatory procedure is missing, and nothing shows that effectiveness is affected, the correct answer is usually that it is not a valid nonconformity. It may be an opportunity for improvement instead. Remember the proportionality note in clause 7.5.1.
8. Understand the Stage 1 versus Stage 2 context. Questions may ask when documented information is primarily reviewed. Documentation review is central to Stage 1, which assesses readiness and design. Stage 2 verifies implementation, though documents and records are also sampled there.
9. Write evidence-based findings. In scenario answers, structure a finding as follows:
- the requirement (clause);
- the evidence (what was seen: document name, version, date, location);
- the nonconformity statement (what was not met).
Vague statements like 'documentation is poor' lose marks.
10. Consider protection and confidentiality. ISO/IEC 27001 is about information security, so documented information itself must be protected. Exam scenarios may hide a clue, such as risk assessment reports stored on a public share. Recognize this as a 7.5.3 issue.
11. Watch for keywords in multiple-choice questions. Answer options containing 'any format and media', 'determined by the organization as necessary', 'appropriate', or 'controlled' tend to reflect the standard's flexible but controlled approach. Be wary of options stating that documentation 'must be on paper', 'must include a manual', or 'must have a procedure for every control'.
12. Time management. In long scenario exams, scan the case for document-related clues first. Look for version numbers, dates, approval signatures, missing records and inconsistencies. These are often the quickest marks to secure.
Summary
Documented Information Evaluation Criteria give the lead auditor a structured way to judge whether an ISMS's documentation is complete, correct, consistent, current, adequate, controlled and protected. Applying these criteria supports efficient audit planning, reliable objective evidence and fair conformity decisions. In the exam, combine knowledge of ISO 19011 guidance with ISO/IEC 27001 clause 7.5 and the mandatory documented information list. Always distinguish documentation issues from implementation issues, and write precise, evidence-based findings.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!