Documented Information Review
In an ISO/IEC 27001 audit, documented information review is the auditor's examination of the auditee's ISMS documents and records. ISO 19011 (clause 6.3.1) frames it as part of preparing audit activities. ISO/IEC 27006 frames it as a core element of the Stage 1 audit in certification. Its purpose i… In an ISO/IEC 27001 audit, documented information review is the auditor's examination of the auditee's ISMS documents and records. ISO 19011 (clause 6.3.1) frames it as part of preparing audit activities. ISO/IEC 27006 frames it as a core element of the Stage 1 audit in certification. Its purpose is to judge whether the documented ISMS conforms to the standard's requirements and is adequate to support the audit objectives, before or alongside on-site evidence gathering. The Lead Auditor checks that the documented information required by ISO/IEC 27001:2022 exists, is current and is controlled under clause 7.5. Key items include: - the ISMS scope (4.3) - the information security policy (5.2) - the risk assessment and risk treatment processes (6.1.2, 6.1.3) - the Statement of Applicability, including justifications for inclusions and exclusions of Annex A controls - the risk treatment plan - information security objectives (6.2) - evidence of competence (7.2) - operational planning and control records (8.1) - risk assessment and treatment results (8.2, 8.3) - monitoring and measurement results (9.1) - internal audit programme and results (9.2) - management review results (9.3) - nonconformities and corrective actions (10.2) The auditor evaluates three things: - **Completeness:** are all required elements present? - **Correctness:** do the documents accurately reflect requirements and the organization's context? - **Consistency:** do the scope, risk assessment, SoA and policies align with each other? The auditor also considers document control: version identification, approval, availability, protection, retention and disposition. The review informs audit planning. It reveals areas of concern, the organization's readiness for Stage 2, and where sampling should focus. It also helps auditors prepare checklists and identify key processes and locations. If documents are inadequate, the Lead Auditor decides whether the audit can continue, should be postponed, or requires the auditee to resolve issues. Any concerns are communicated to the audit client and auditee. Documented information review is not limited to the opening stages. Throughout the audit, auditors compare documents against actual practice through interviews and observation. The aim is to verify that the ISMS is implemented and effective, not merely written. A well-documented system that is not followed constitutes a nonconformity.
Documented Information Review in ISO/IEC 27001 Audits: A Complete Guide for Lead Auditors
Introduction
Documented information review is one of the first substantive activities in any ISO/IEC 27001 audit. Before an auditor interviews staff or observes controls, they examine the organization's documented Information Security Management System (ISMS). This review shows whether the ISMS, as written, is adequate to meet the audit criteria. It also shapes the audit plan, the sampling approach and the questions asked on site.
This guide covers what documented information review is, why it matters, how it is performed under ISO 19011, ISO/IEC 27007 and ISO/IEC 17021-1, and how to answer exam questions on the topic.
1. What Is Documented Information Review?
ISO/IEC 27001 defines documented information as information that an organization must control and maintain, together with the medium that contains it. The term replaced the older words 'documents' and 'records'. It covers two kinds of material:
• Documented information to be maintained, traditionally called documents. Examples are the ISMS scope, the information security policy and the risk assessment methodology.
• Documented information to be retained, traditionally called records. Examples are risk assessment results, internal audit results, management review outputs and evidence of competence.
Documented information review is the auditor's systematic examination of this material to:
• judge whether the management system documentation conforms to the audit criteria;
• gather information to prepare audit activities and audit work documents;
• understand the context, scope, processes and risks of the auditee.
ISO 19011:2018 (clause 6.3.1) says the review should take into account the organization's context, including its size, nature and complexity, and its related risks and opportunities. It should also consider the audit scope, criteria and objectives.
2. Why Is Documented Information Review Important?
• It establishes adequacy. It answers the question: is the ISMS designed to meet ISO/IEC 27001 requirements? A system cannot be implemented effectively if its design is missing or flawed.
• It drives audit planning. What the auditor learns about processes, locations, risks and controls feeds directly into the audit plan, team assignments, time allocation and sampling.
• It reveals readiness. In certification audits, the Stage 1 review helps the certification body decide whether the organization is ready for Stage 2.
• It shows risk areas. Gaps, inconsistencies or weak justifications, for example in the Statement of Applicability, point to areas that need closer testing on site.
• It saves time and cost. Finding major documentation gaps early avoids wasted on-site effort. It can also lead to the audit being postponed until the gaps are fixed.
• It provides a baseline for verification. Later, auditors compare what is written with what is actually done. This comparison is the core of testing implementation.
3. Key Documented Information Required by ISO/IEC 27001:2022
A lead auditor should know the mandatory documented information well:
• Clause 4.3: Scope of the ISMS
• Clause 5.2: Information security policy
• Clause 6.1.2: Information security risk assessment process
• Clause 6.1.3: Information security risk treatment process
• Clause 6.1.3 d): Statement of Applicability (SoA). It lists necessary controls, justifies inclusions and exclusions, and states implementation status.
• Clause 6.2: Information security objectives
• Clause 7.2: Evidence of competence
• Clause 7.5.1 b): Documented information the organization has determined to be necessary for ISMS effectiveness
• Clause 8.1: Documented information showing that processes have been carried out as planned
• Clause 8.2: Results of information security risk assessments
• Clause 8.3: Results of information security risk treatment
• Clause 9.1: Evidence of monitoring and measurement results
• Clause 9.2.2: Evidence of the audit programme(s) and audit results
• Clause 9.3.3: Evidence of management review results
• Clause 10.2: Evidence of the nature of nonconformities, actions taken and results of corrective actions
Several Annex A controls also imply documentation. Examples are 5.1 (policies for information security), 5.37 (documented operating procedures) and 5.31 (legal, statutory, regulatory and contractual requirements).
Note: ISO/IEC 27001 does not require specific documented procedures, and it does not require a manual. The extent of documentation depends on the organization's size, activities, process complexity and the competence of its people (clause 7.5.1 Note).
4. How Documented Information Review Works
4.1 Timing
• Before the audit (preparation): The auditor reviews documented information to prepare the audit plan and work documents, such as checklists and sampling plans.
• Stage 1 of a certification audit: Under ISO/IEC 17021-1, Stage 1 reviews the client's documented management system. It also evaluates site conditions, readiness for Stage 2, understanding of requirements, scope, internal audits and management review.
• During the audit: Review continues throughout. Records are sampled and checked against interviews and observations to verify implementation.
4.2 Steps in the Review
Step 1: Request the documentation. The audit team leader asks the auditee for relevant documented information through the agreed channel. If the auditee refuses access, or the material is too sensitive to release off site, the auditor may review it on site.
Step 2: Check completeness. Is all mandatory documented information present? Is anything missing, for example the SoA or risk treatment plan?
Step 3: Check correctness and conformity. Does each item address the relevant ISO/IEC 27001 requirement? For example:
• Does the risk assessment process define criteria for risk acceptance and for performing assessments?
• Does the SoA justify every exclusion?
• Are the objectives measurable and consistent with the policy?
Step 4: Check consistency. Do the documents agree with each other? Typical checks:
• Does the scope match the SoA?
• Do risk treatment decisions match the controls marked as applicable?
• Do the policy and objectives align?
Step 5: Check currency and control (clause 7.5.2 and 7.5.3).
• Are documents identified, versioned, reviewed and approved?
• Are they available where needed and protected?
• Are obsolete versions controlled?
• Is external documentation managed?
Step 6: Understand context and risk. Use the documents to understand interfaces, dependencies, outsourced processes and critical assets. These shape the audit focus.
Step 7: Record observations. Note gaps, concerns and areas to verify on site. In Stage 1, significant issues are usually reported as areas of concern that could be classified as nonconformities at Stage 2.
Step 8: Decide whether to proceed. If the documentation is inadequate, the team leader informs the audit client and the auditee. The audit may be postponed or its plan adjusted, as decided by the audit client.
4.3 The Four Cs Mnemonic
A useful memory aid for review criteria is the 4 Cs:
• Completeness: all expected content is present
• Correctness: content conforms to standards and regulations
• Consistency: internally and with other documents
• Currency: content is up to date
4.4 Documents Versus Records in the Audit
• Documents show what the organization intends to do. Reviewing them tests adequacy of design.
• Records show what the organization has actually done. Reviewing them tests implementation and effectiveness.
For example, a documented access review procedure shows design. Signed quarterly access review records show implementation.
4.5 Practical Considerations
• Format: Documentation may be in any format or medium, including wikis, ticketing systems and tools. Auditors must not insist on paper manuals.
• Confidentiality: ISMS documentation is sensitive, so auditors must protect it. Some organizations restrict off-site access, especially to risk registers and vulnerability reports.
• Sampling: Not every record can be reviewed. Use judgmental or statistical sampling based on risk.
• Objectivity: Assess documents against the criteria, not against personal preference for style or length.
5. Common Findings During Documented Information Review
• The SoA does not justify excluded Annex A controls, or does not state implementation status.
• The ISMS scope does not define boundaries, interfaces or dependencies.
• The risk acceptance criteria are not defined.
• Objectives are not measurable or have no plan for achieving them (clause 6.2).
• The policy is not approved by top management or not communicated.
• Documents have no version control or approval evidence.
• No internal audit or management review has been performed before the certification audit.
• Risk treatment plan approval and residual risk acceptance by risk owners are missing.
6. Exam Tips: Answering Questions on Documented Information Review
Tip 1: Know the purpose. If a question asks why documents are reviewed, the best answer combines two ideas: determining conformity of the system as documented with the audit criteria, and gathering information to prepare the audit. Avoid answers that say the review alone proves effectiveness.
Tip 2: Separate adequacy from implementation. Document review tests adequacy, meaning design. On-site activities test implementation and effectiveness. If an option claims document review alone confirms that controls work, it is usually wrong.
Tip 3: Remember the Stage 1 and Stage 2 distinction. Stage 1 focuses on documentation and readiness. Stage 2 evaluates implementation and effectiveness. Stage 1 concerns are typically reported as areas of concern, not formal nonconformities.
Tip 4: Know the inadequate-documentation response. If documentation is inadequate, the audit team leader informs the audit client (and auditee). The audit client then decides whether the audit continues, is postponed, or is changed. Auditors do not write or fix documents for the auditee, because that would breach independence and become consultancy.
Tip 5: Memorize mandatory documented information. Expect questions such as 'Which is NOT mandatory?' Watch for distractors like a 'documented procedure for internal audit', a 'quality manual' or a 'business continuity plan document'. These are not explicitly mandated by ISO/IEC 27001 clauses. The SoA, scope, policy, risk processes, objectives and evidence records are mandated.
Tip 6: Focus on the SoA. The SoA is a favorite exam topic. It must contain the necessary controls, justification for their inclusion, whether they are implemented, and justification for excluding Annex A controls.
Tip 7: Apply the 4 Cs in scenario questions. When a scenario describes a document, check it for completeness, correctness, consistency and currency. For example, a policy approved three years ago with no review evidence raises a currency and control concern.
Tip 8: Accept any format. If a scenario says documentation is held in an online tool, a wiki or a ticketing system, that is acceptable as long as it is controlled. Do not choose answers that demand printed, signed manuals.
Tip 9: Link findings to clauses. In essay or scenario questions, cite the relevant clause, for example 'clause 6.1.3 d) requires justification for exclusions'. Then state the evidence and explain the requirement not met. This mirrors how a well-written nonconformity is structured: requirement, evidence and statement of nonconformity.
Tip 10: Respect confidentiality and access limits. If the auditee will not release sensitive documents off site, the right response is to review them on site under controlled conditions. Do not treat it as an automatic nonconformity, and do not abandon the audit.
Tip 11: Use review results for planning. Questions may ask how review findings are used. Answers include adjusting the audit plan, focusing sampling on high-risk areas, allocating competent team members and preparing checklists.
Tip 12: Read for keywords. Words such as maintain (documents) and retain (records) signal which type of documented information is meant. 'Evidence of' in the standard always indicates retained documented information.
7. Sample Exam-Style Question
During Stage 1, the auditor finds that the SoA lists 10 Annex A controls as excluded with no justification. What should the auditor do?
Best answer: Record this as an area of concern against clause 6.1.3 d). Communicate it to the auditee in the Stage 1 report. Note that it could be graded as a nonconformity at Stage 2 if it is not addressed. Consider whether it affects readiness for Stage 2.
Wrong answers to avoid:
• Rewriting the SoA for the client.
• Ignoring the issue because controls might still be implemented.
• Immediately terminating the certification process without informing the client.
8. Summary
Documented information review is the foundation of an effective ISO/IEC 27001 audit.
• It confirms whether the ISMS is adequately designed.
• It shows readiness for certification.
• It reveals the organization's context and risks.
• It shapes the whole audit plan.
For exams, remember five things:
• the purpose of the review (conformity plus preparation);
• the list of mandatory documented information;
• the difference between adequacy and implementation;
• the Stage 1 and Stage 2 roles;
• the correct auditor response when documentation is inadequate.
Apply the 4 Cs, link findings to clauses, and keep your role independent and objective.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!