Skip to content

Evidence and documentation for ISO 27001

Documentation describes agreed arrangements; operational evidence shows what happened. Connect both to the scope, period, responsible person and requirement being supported.

Book an informal conversation

ISO Ready helps you align policy, risk, and evidence, without endless document churn.

Run the ISO 27001 readiness scan

What does a document demonstrate?

An approved policy shows which arrangements the organisation has adopted. By itself, it does not prove that those arrangements are followed. An operational record may demonstrate an activity, but without context it says little about the wider process. Use both kinds of information to build a traceable connection between an agreement and its implementation. ISO/IEC 27001 contains management system requirements; the structure below is a practical working method.

Three types of information with different functions

TypeWhat it showsExample
ArrangementHow the organisation intends to workApproved change procedure
ImplementationWhat happened in a specific caseReviewed change and deployment record
EvaluationHow the result was assessedCheck with outcome and follow-up

One system can combine these functions, provided their meaning remains clear. An automatically generated report is not automatically a human assessment. Record who reviewed the result where review is part of the agreed process.

Assess the context of evidence

Check which service, environment and period the record concerns. A screenshot from a test environment does not necessarily support a claim about production. A current export shows the present situation but may not demonstrate a previous state. Identify the source and limitations. Set retention periods by information type, purpose and applicable obligations; do not assume one universal retention period for every audit record.

Fictional example: an access review

A fictional business exports a user list. The export shows which accounts existed at that time. To support a completed access review, the owner adds the assessment and decisions. Removal actions link to their implementation. This makes it possible to trace who reviewed access, what needed to change and whether the change happened. A list without an assessment would show only the starting position.

Keep the evidence set usable

Make records findable through a short index and clear references. Avoid unnecessary copies of personal data or customer content; arrange controlled viewing where suitable. Preserve relevant context when redacting information. Describe missing evidence accurately and address gaps through the appropriate improvement process. Read evidence management for maintaining the index and the audit checklist for questions that help assess records.

Primary sources for this topic

Frequently asked questions

Is a screenshot sufficient audit evidence?
That depends on the claim being assessed. A screenshot may show a setting but lack information about the environment, date, owner or earlier operation. Add the necessary context and combine it with other records where appropriate. Check whether the evidence answers the specific question, and avoid drawing a broader conclusion than the available material supports.
Must audit evidence always be copied into a separate folder?
No. A clear reference to a controlled source can be more useful than an extra copy that later becomes outdated. Ensure authorised reviewers can access the information and relevant versions or periods remain available. Use an export when the purpose requires one, record its source and date, and avoid unnecessary distribution of confidential or personal information.

Need help with the next step?

Explore support for your next step at ISO Ready. ISO Ready and this knowledge base are operated by Oosterwal Consultancy.

Explore your next step at ISO Ready

isocertificering.org is operated by Oosterwal Consultancy (oosterwal.com). ISO Ready (iso-ready.nl) has the same owner. Links to ISO Ready refer to our own commercial offering. About us (Dutch)

AI reading guide (llms.txt)