Documented Information
Documented information refers to the records, policies, and procedures that an organization is expected to create, manage, and keep under control as part of a management system. It can serve to communicate a message and to provide evidence that planned activities have actually been carried out. The specific term is used in ISO management system standards, and its exact scope depends on the standard in question.
In ISO management system standards (for example, ISO 9001 for quality management and ISO 27001 for information security management), "documented information" typically encompasses the records, policies, and procedures an organization must maintain and control to demonstrate conformity. As commonly defined, it serves dual functions: communication of a message and provision of evidence that what was planned has actually been done (conformity evidence). In quality management contexts it is described as contributing to management system effectiveness by enabling process evaluation, facilitating corrective actions, and supporting related activities. Where documented information is retained as evidence of conformity, control measures typically address protection against unauthorized alteration or tampering. Note that the precise definition, required scope, and control requirements are standard-specific (for instance, requirements framed under ISO 9001 Clause 7.5 differ in application from those under ISO 27001), and this entry does not resolve those differences.
Why it matters
Documented information is the mechanism by which an organization can demonstrate, rather than merely assert, that its management system operates as intended. In ISO management system standards, it serves two distinct functions: communicating a message (for example, conveying policies and procedures to those who must follow them) and providing evidence that what was planned has actually been done. For compliance officers, auditors, and model risk professionals, this dual role matters because governance and control claims that cannot be evidenced are difficult to substantiate during audit, certification, or regulatory review.
The practical significance is heightened where documented information is retained specifically as evidence of conformity. In that role, its integrity becomes a concern: records used to demonstrate that activities occurred are of limited value if they can be altered or tampered with after the fact. Control measures that protect such records help preserve their evidentiary reliability. This is why professionals treat the control of documented information as a discipline in its own right, distinct from simply generating documents.
It is important not to overstate what documented information achieves. Maintaining records, policies, and procedures supports the evaluation of processes and facilitates corrective actions, but the required scope and the specific control obligations differ by standard—requirements framed under ISO 9001 differ in application from those under ISO 27001. Documented information does not by itself guarantee conformity or eliminate risk; it provides the evidentiary and communicative basis on which conformity can be assessed and improvement can be pursued.
Who it's relevant to
Inside Documented Information
Common questions
Answers to the questions practitioners most commonly ask about Documented Information.