Chapter 17
17Documented Information: What Is Written Endures
“A document nobody reads is more dangerous than none at all, because it gives false confidence.”
The standard requires “documented information” in many places: the scope, the policy, the risk methodology, the Statement of Applicability, objectives, competence records and audit results. The practical question is: how do we document enough without drowning the team in paperwork?


Text in this figure
Policies · Why? · one page per topic · Procedures · Who does what, when? · Instructions, templates · How, step by step? · Records and evidence · What actually happened? · Version control applies to all: documents, code, models and data · Figure 22
The Documentation Pyramid
- Policies: At the top: few and short, stating “what” and “why”, and approved by leadership.
- Procedures: Stating “how”: the steps for handling an incident, onboarding a new employee or offboarding a leaver.
- Instructions and templates: Checklists and ready-made forms that make implementation easy.
- Records: At the base: evidence that what was written was actually done, such as review minutes, access logs and incident reports.
Managing Documents
- Identification: A title, date, owner and version number for every document.
- Review and approval: Before publication and after every significant change.
- Availability and protection: Available to those who need it, protected from unauthorised change and loss.
- Retention and disposal: A defined period for each type of record, then secure deletion.
From the Field
Write the procedure as it is actually carried out, not as you wish it were. The auditor compares the document with reality, and the gap between them is the first finding in their report.
2026 Update
AI can speed up first drafts of policies and procedures, but an uncustomised generated document looks generic and an auditor spots it quickly. Use it for structure and wording, and write the reality yourself: system names, real roles and the decisions you have made.
Document as much as you need to repeat success and prove it; no more, no less.
Lessons Learned
- 1Documentation is a pyramid: policies, procedures, instructions and records.
- 2Every document has an owner, a version and a review date.
- 3Records are the evidence of implementation.
- 4A document describes reality, not aspiration.
Tip: use ← → to move between sections.

