Skip to content
TB
TeamBenchResources

ISO 27001 Documentation Review for Singapore Organisations

ISO 27001 certification requires extensive documentation. Here's how to review your ISMS documentation for certification readiness and ongoing compliance in Singapore.

TeamBench· Content Quality PlatformFebruary 9, 202614 min read

ISO 27001 is the international standard for Information Security Management Systems (ISMS). In Singapore, ISO 27001 certification is increasingly expected — not just for technology companies, but for any organisation handling sensitive data. MAS-regulated financial institutions often use ISO 27001 as the foundation for their technology risk management. Government contractors frequently require it. And enterprise clients across Southeast Asia view it as a baseline for vendor security assurance.

The standard is documentation-intensive. ISO 27001 requires a documented ISMS with policies, procedures, risk assessments, control implementations, internal audits, and management reviews. Certification auditors evaluate your documentation before they evaluate your controls — if the documentation is incomplete, inconsistent, or outdated, the audit fails before it really begins.

For Singapore organisations pursuing or maintaining ISO 27001 certification, this guide covers what the standard requires, where documentation most commonly fails, and how to build a review process that keeps your ISMS audit-ready.

What ISO 27001 Documentation Requires

Mandatory Documents

ISO 27001:2022 requires the following documented information as a minimum:

DocumentClausePurpose
ISMS scope4.3Defines the boundaries of the ISMS — what's in scope and what's excluded
Information security policy5.2Top-level policy statement approved by management
Risk assessment methodology6.1.2How risks are identified, analysed, and evaluated
Risk assessment results6.1.2Output of the risk assessment process
Risk treatment plan6.1.3How identified risks will be treated (mitigate, accept, transfer, avoid)
Statement of Applicability (SoA)6.1.3dLists all Annex A controls, states whether each is applicable, and justifies exclusions
Information security objectives6.2Measurable security objectives aligned with the policy
Evidence of competence7.2Training records, qualifications, experience records
Operational planning and control8.1Documented processes for managing security operations
Risk assessment results8.2Periodic risk assessment outputs
Risk treatment results8.3Evidence that risk treatment plans are implemented
Monitoring and measurement results9.1Evidence of security performance monitoring
Internal audit programme and results9.2Audit schedule, audit reports, findings
Management review results9.3Minutes of management review meetings
Corrective actions10.1Records of nonconformities and corrective actions taken

Annex A Controls Documentation

ISO 27001:2022 Annex A contains 93 controls across four themes. Each applicable control needs documented implementation:

ThemeControlsExamples of Documentation
Organisational (37 controls)Information security roles, acceptable use, access control, supplier relationshipsPolicies, role descriptions, agreements, risk assessments
People (8 controls)Screening, training, disciplinary process, terminationHR procedures, training records, NDA templates
Physical (14 controls)Physical security perimeters, equipment security, clear deskPhysical security policy, access logs, equipment registers
Technological (34 controls)Endpoint security, access rights, cryptography, secure developmentTechnical standards, configuration baselines, encryption policy

The Statement of Applicability (SoA)

The SoA is the single most important document in your ISMS. It:

  • Lists all 93 Annex A controls
  • States whether each is applicable or not applicable
  • Provides justification for any exclusion
  • References the implementing document or procedure for each applicable control
  • Shows the current implementation status

Common failure: SoAs that list controls as "applicable" but don't reference the implementing document. The auditor asks "show me your implementation of A.8.9 (Configuration Management)" — you need to point to a specific document, not say "we do that."

Where Organisations Fail ISO 27001 Documentation

1. Risk Assessment Gaps

The risk assessment is the foundation of the ISMS. Common failures:

  • Methodology too vague — "We assess risks qualitatively" without defining the criteria, scales, or process
  • Asset-based but incomplete — risk assessment covers servers and applications but misses people, processes, and physical locations
  • Point-in-time only — risk assessment conducted once for certification but not updated when the environment changes
  • Risk treatment not linked to controls — risks identified but no clear mapping to the Annex A controls that mitigate them
  • Residual risk not documented — risks treated but the remaining (residual) risk not formally assessed and accepted

2. Policy-Procedure-Practice Gaps

Three-layer misalignment:

  • Policy says one thing — "Access reviews are conducted quarterly"
  • Procedure says another — access review procedure describes an annual process
  • Practice does a third — the last access review was 7 months ago

Auditors trace from policy through procedure to evidence of practice. Any gap at any layer is a nonconformity.

3. Incomplete Operational Documentation

Annex A controls that are "implemented" but not documented:

  • Cryptographic controls in use but no encryption policy documenting what's encrypted, with what algorithm, and how keys are managed
  • Change management practiced informally but no documented process
  • Incident response handled ad hoc — no documented plan, no incident register
  • Backup performed automatically but no documented backup policy, no restoration testing records
  • Vulnerability scanning conducted but no documented vulnerability management procedure

4. Internal Audit Deficiencies

ISO 27001 requires internal audits of the ISMS. Common failures:

  • Audit schedule doesn't cover all ISMS requirements over the audit cycle
  • Auditors not independent of the area being audited
  • Audit reports that describe the area reviewed but don't identify nonconformities or observations
  • Audit findings not tracked to corrective action completion
  • No evidence that audit results are reported to management

5. Management Review Gaps

Management review is a mandatory ISMS process. Common failures:

  • Management review conducted but not documented (no minutes)
  • Minutes that don't cover all required inputs (audit results, feedback, risk assessment changes, improvement opportunities)
  • No documented decisions or actions from the review
  • Actions from previous reviews not followed up
  • Review conducted by operational staff, not top management

6. Corrective Action Failures

When nonconformities are identified (through audits, incidents, or reviews), corrective actions must be documented:

  • Nonconformity identified but root cause not analysed
  • Corrective action defined but not implemented
  • Implementation not verified (was the action effective?)
  • Similar nonconformities recurring — suggesting the corrective action didn't address the root cause
  • No register or tracking mechanism for corrective actions

Building an ISO 27001 Documentation Review Process

Step 1: Document Register

Maintain a master register of all ISMS documents:

DocumentClause/ControlVersionLast ReviewedOwnerStatus
ISMS Scope4.33.0January 2026CISO✅ Current
Information Security Policy5.24.0November 2025CEO/CISO✅ Current
Risk Assessment Methodology6.1.22.0September 2025Risk Manager✅ Current
Risk Assessment Report8.2CurrentJanuary 2026Risk Manager✅ Current
Statement of Applicability6.1.3d5.0January 2026CISO✅ Current
Access Control PolicyA.5.153.0August 2025IT Manager⚠️ Needs review
Incident Response PlanA.5.262.0March 2025Security Lead❌ Overdue
Encryption PolicyA.8.241.0June 2024IT Manager❌ 18 months old
Internal Audit Programme9.2CurrentOctober 2025Internal Audit✅ Current
Management Review Minutes9.3LatestDecember 2025CISO✅ Current

Step 2: Pre-Audit Readiness Check

Before a certification or surveillance audit, verify:

Mandatory documents:

  • All 15+ mandatory documents exist and are current
  • Documents are version-controlled with review dates
  • Risk assessment has been conducted/updated within the past year
  • Statement of Applicability references implementing documents for all applicable controls
  • Internal audits have covered all ISMS areas in the cycle
  • Management review has been conducted with documented inputs and outputs
  • Corrective actions from previous audits are completed and verified

Annex A control documentation:

  • Each applicable control has a documented implementation
  • Documentation reflects actual practice (no policy-practice gaps)
  • Evidence of control effectiveness is available (logs, records, test results)

Records and evidence:

  • Training records for all ISMS roles
  • Incident register with investigation and resolution records
  • Access review records
  • Change management records
  • Backup and restoration test records
  • Vulnerability scan and penetration test reports

Step 3: Implement Ongoing Review

ActivityFrequency
Policy and procedure reviewAnnually (or on significant change)
Risk assessment reviewAnnually (or on significant change)
SoA review and updateAnnually (or when controls change)
Internal audit cycleFull ISMS coverage over audit cycle (typically 1-3 years)
Management reviewAt least annually (many organisations do semi-annually)
Corrective action trackingMonthly (check status of open items)
Document currency checkQuarterly (flag overdue reviews)

Step 4: Cross-Document Consistency

  • SoA vs. risk treatment plan — do the controls in the SoA map to the risks in the treatment plan?
  • Policies vs. procedures — do procedures implement what policies commit to?
  • Risk assessment vs. SoA — has every identified risk been addressed by at least one Annex A control?
  • Internal audit findings vs. corrective actions — has every audit nonconformity been addressed?
  • Management review inputs vs. outputs — have all required inputs been discussed, and have decisions been documented?

ISO 27001:2022 vs. 2013 — Documentation Changes

If you're transitioning from ISO 27001:2013 to 2022:

ChangeDocumentation Impact
Annex A restructured114 controls (14 domains) → 93 controls (4 themes). SoA must be completely rebuilt.
New controls added11 new controls including threat intelligence (A.5.7), cloud security (A.5.23), data masking (A.8.11), and monitoring activities (A.8.16). New documentation needed.
Merged controlsSome 2013 controls merged. Documentation may need consolidation.
AttributesControls now have attributes (control types, security properties, cybersecurity concepts, operational capabilities, security domains). Optional but useful for documentation organisation.

Transition deadline: Organisations certified to 2013 must transition to 2022 by 31 October 2025. If you haven't transitioned, this is urgent.

Using AI to Review ISMS Documentation

What AI Can Check

  • Completeness — verify all mandatory documents exist and contain required elements
  • Consistency — cross-reference policies, procedures, and the SoA for contradictions
  • Currency — flag documents past their review date, references to superseded standards
  • SoA validation — check that all 93 controls are listed, applicable controls reference implementing documents, and exclusions are justified
  • Policy-procedure alignment — verify procedures implement what policies commit to
  • Terminology — check correct use of ISO 27001 terminology (nonconformity, corrective action, risk treatment, etc.)

What AI Cannot Replace

  • Information security risk assessment (requires human judgement about threats, vulnerabilities, and business impact)
  • Internal audit (requires auditor competence and independence)
  • Management review (requires top management involvement)
  • Assessment of whether controls are effectively implemented (requires testing)
  • Certification audit (only accredited certification bodies can certify)

Practical Example

In TeamBench, you could configure a reviewer:

Reviewer name: ISO 27001 ISMS Documentation Reviewer

System prompt:

You are an ISO 27001:2022 ISMS documentation reviewer. Review policies, procedures, risk assessments, Statements of Applicability, internal audit reports, and management review minutes against ISO 27001:2022 requirements. Check for: completeness (all mandatory documents and Annex A control documentation present), consistency (no contradictions between policies, procedures, and the SoA), currency (documents within review period, references to ISO 27001:2022 not 2013), SoA accuracy (all 93 controls listed, applicable controls reference implementing documents, exclusions justified), and traceability (risks → controls → procedures → evidence). Flag specific gaps with the ISO 27001 clause reference. Use Singapore English where applicable.

Evaluation criteria:

  • Completeness (weight: 3) — All mandatory documents and Annex A documentation present
  • Consistency (weight: 3) — No contradictions across the ISMS documentation
  • Currency (weight: 2) — All documents within review period, current standard referenced
  • Traceability (weight: 2) — Clear links from risks to controls to evidence
  • Structure (weight: 1) — Professional presentation, version control, clear ownership

Quality gate: Minimum score: 85.

Upload the ISO 27001:2022 standard (Annex A control list), your ISMS scope document, and your current SoA into a Knowledge Base.

Frequently Asked Questions

How long does ISO 27001 certification take?

Typical timeline for a mid-sized organisation: 6-12 months from ISMS implementation start to Stage 2 audit. This includes: scoping and gap analysis (1-2 months), ISMS implementation and documentation (3-6 months), internal audit and management review (1 month), and certification audit (Stage 1 + Stage 2, 1-2 months). Organisations with existing security frameworks (e.g., MAS TRM compliant) may be faster.

What's the difference between Stage 1 and Stage 2 audits?

Stage 1 (documentation review): The auditor reviews your ISMS documentation for completeness and conformity with ISO 27001 requirements. This is primarily a documentation audit. Stage 2 (implementation audit): The auditor verifies that your documented ISMS is implemented and effective. This includes interviews, observations, and evidence review. Both stages must pass for certification.

How often are surveillance audits?

After initial certification, surveillance audits occur annually (some certification bodies do them at 6-month and 18-month marks). The full ISMS is re-assessed every 3 years through a recertification audit. Surveillance audits cover a subset of the ISMS — the full scope is covered over the 3-year certification cycle.

Can we use ISO 27001 to satisfy MAS TRM requirements?

ISO 27001 provides a strong foundation for MAS TRM compliance, with approximately 70-80% overlap. However, MAS TRM has financial-sector-specific requirements that ISO 27001 doesn't cover (e.g., specific requirements for online financial services, payment systems, and customer authentication). Most Singapore financial institutions use ISO 27001 as the base and layer MAS-specific controls on top.

What's the cost of ISO 27001 certification in Singapore?

Certification audit fees vary by organisation size and scope: SGD 15,000-50,000 for the initial certification audit, plus annual surveillance audit fees. Implementation costs (consulting, tools, staff time) are typically 2-5x the audit fees. Total investment for a mid-sized organisation: SGD 50,000-200,000 over the first year, with lower ongoing costs.

How many documents do we actually need?

ISO 27001 mandates approximately 15-20 specific documents. However, documenting all applicable Annex A controls typically requires 30-60 additional documents (policies, procedures, records). The total depends on your scope and complexity. Focus on quality over quantity — a well-written 5-page access control policy is better than a 30-page document nobody reads.

Can we integrate ISO 27001 with other management systems?

Yes — ISO 27001 follows the Annex SL high-level structure shared by ISO 9001 (quality), ISO 22301 (business continuity), and ISO 27701 (privacy). Integrated management systems reduce documentation burden by sharing common elements (context, leadership, planning, support, performance evaluation, improvement).

Key Takeaways

  • ISO 27001 certification lives and dies on documentation — auditors evaluate your documented ISMS before they evaluate your controls.
  • 15+ mandatory documents are required, plus documentation for all applicable Annex A controls. The Statement of Applicability is the single most important document.
  • Common failures include risk assessment gaps, policy-procedure-practice misalignment, incomplete operational documentation, internal audit deficiencies, and management review gaps.
  • ISO 27001:2022 restructured Annex A from 114 controls in 14 domains to 93 controls in 4 themes, with 11 new controls. If transitioning from 2013, your SoA needs a complete rebuild.
  • Cross-document consistency is critical — SoA, risk treatment plan, policies, procedures, and evidence must all align.
  • Internal audits and management reviews are mandatory — both must be documented with findings tracked to corrective action completion.
  • AI-assisted review can check completeness, consistency, currency, and traceability across your ISMS documentation, but cannot replace risk assessment, internal audits, or the certification process.
  • Singapore organisations can use ISO 27001 as a foundation for MAS TRM compliance, with additional financial-sector-specific controls layered on top.

This article provides general information about ISO 27001 documentation requirements and is not certification advice. Always refer to the ISO 27001:2022 standard directly and work with an accredited certification body for your certification audit.

iso-27001ismsinformation-securitycertificationdocumentationsingapore

Need consistent content quality across your team?

TeamBench lets you create custom AI reviewers that score content against your specific criteria. Submit content, get instant scored feedback, and improve with one click.

  • Create custom AI reviewers for your brand
  • Score content against your specific criteria
  • Instant feedback, one-click improvement
  • Free to start — no credit card required