The requirements of ISO 27001 fall into two parts: the mandatory management-system clauses (4 to 10), which every certified organisation must meet, and the Annex A controls, which you select based on your risks. This guide covers the mandatory requirements and gives you a practical checklist to get certification-ready.

The mandatory clauses (4-10)
- Clause 4 (Context): define your organisation’s issues, interested parties and the scope of your ISMS.
- Clause 5 (Leadership): top-management commitment, an information security policy, and clear roles and responsibilities.
- Clause 6 (Planning): risk assessment and treatment, the Statement of Applicability, and security objectives.
- Clause 7 (Support): resources, competence, awareness (see our clause 7.3 awareness training guide), communication and documented information.
- Clause 8 (Operation): actually running your risk treatment and controls day to day.
- Clause 9 (Performance evaluation): monitoring, internal audit and management review.
- Clause 10 (Improvement): handling nonconformities and continually improving the system.
The documents you must have
ISO 27001 requires certain documented information. At a minimum, a certification auditor will expect to see:
- ISMS scope
- Information security policy and objectives
- Risk assessment and risk treatment process and results
- Statement of Applicability (your selected Annex A controls and justifications)
- Evidence of competence, awareness and operational controls
- Internal audit programme and results
- Management review records and corrective actions
A practical readiness checklist
- Scope defined and agreed
- Risk assessment completed and treatment decided
- Statement of Applicability prepared
- Policies and procedures written and in use
- Selected controls implemented and generating records
- Staff aware and trained
- One full internal audit completed
- Management review held
Then select your Annex A controls
On top of the mandatory clauses, you choose the technical and organisational controls that treat your risks, from the 93 in Annex A. Our guide to ISO 27001 controls explains the four themes and how the Statement of Applicability works.
Frequently asked questions
What documents are mandatory for ISO 27001?
The scope, information security policy, risk assessment and treatment, Statement of Applicability, objectives, and records of internal audit and management review are the core mandatory items. Most organisations also maintain supporting policies and procedures.
Can we build the system ourselves?
Yes, and many do, increasingly with AI tools. Where DIY systems fall down is risk, context and evidence. We can mentor your team and provide the independent internal audit that confirms your system will certify.
Speak with an experienced ISO auditor
Want a clear path to meeting the ISO 27001 requirements? Email hello@streamline.business or call us:
- Brisbane 07 3667 8280
- Sydney 02 8315 7780
- Melbourne 03 9034 3990
Stay in the Loop
Get an email when we post an article. Your email address will not be used for marketing, and you can unsubscribe at any time.
We handle your details in line with our privacy policy.











