Skip to main content
Category: Management System Governance

Documented Information

Also known as: Records, Policies, and Procedures
Simply put

Documented information refers to the records, policies, and procedures that an organization is expected to create, manage, and keep under control as part of a management system. It can serve to communicate a message and to provide evidence that planned activities have actually been carried out. The specific term is used in ISO management system standards, and its exact scope depends on the standard in question.

Formal definition

In ISO management system standards (for example, ISO 9001 for quality management and ISO 27001 for information security management), "documented information" typically encompasses the records, policies, and procedures an organization must maintain and control to demonstrate conformity. As commonly defined, it serves dual functions: communication of a message and provision of evidence that what was planned has actually been done (conformity evidence). In quality management contexts it is described as contributing to management system effectiveness by enabling process evaluation, facilitating corrective actions, and supporting related activities. Where documented information is retained as evidence of conformity, control measures typically address protection against unauthorized alteration or tampering. Note that the precise definition, required scope, and control requirements are standard-specific (for instance, requirements framed under ISO 9001 Clause 7.5 differ in application from those under ISO 27001), and this entry does not resolve those differences.

Why it matters

Documented information is the mechanism by which an organization can demonstrate, rather than merely assert, that its management system operates as intended. In ISO management system standards, it serves two distinct functions: communicating a message (for example, conveying policies and procedures to those who must follow them) and providing evidence that what was planned has actually been done. For compliance officers, auditors, and model risk professionals, this dual role matters because governance and control claims that cannot be evidenced are difficult to substantiate during audit, certification, or regulatory review.

The practical significance is heightened where documented information is retained specifically as evidence of conformity. In that role, its integrity becomes a concern: records used to demonstrate that activities occurred are of limited value if they can be altered or tampered with after the fact. Control measures that protect such records help preserve their evidentiary reliability. This is why professionals treat the control of documented information as a discipline in its own right, distinct from simply generating documents.

It is important not to overstate what documented information achieves. Maintaining records, policies, and procedures supports the evaluation of processes and facilitates corrective actions, but the required scope and the specific control obligations differ by standard—requirements framed under ISO 9001 differ in application from those under ISO 27001. Documented information does not by itself guarantee conformity or eliminate risk; it provides the evidentiary and communicative basis on which conformity can be assessed and improvement can be pursued.

Who it's relevant to

Compliance Officers
Compliance officers rely on documented information to demonstrate conformity with the management system standard in scope. Because required scope and control obligations differ between standards such as ISO 9001 and ISO 27001, they must map documentation requirements to the specific standard the organization is pursuing rather than assuming a single universal requirement.
Auditors
Auditors treat documented information as the primary evidence base for assessing whether planned activities have actually been done. Where records are retained as evidence of conformity, auditors are concerned with whether controls protect those records from tampering, since altered records undermine their evidentiary value.
Model Risk and AI Governance Professionals
For those managing AI-related management systems, documented information provides the records, policies, and procedures needed to communicate governance expectations and to evidence that controls were applied as planned. Professionals should note that the specific scope depends on the standard in question and should not assume documentation practices from one standard transfer unchanged to another.
Quality and Information Security Managers
In quality management contexts, documented information contributes to management system effectiveness by enabling process evaluation, facilitating corrective actions, and supporting related activities. Information security managers, working under a different standard, face their own scope and control requirements, so managers should treat the applicable standard as authoritative for their context.

Inside Documented Information

Recorded content requiring control
Information that an organization must maintain and control to demonstrate the operation of its management system or processes. As commonly framed in ISO management system standards (including ISO/IEC 42001), 'documented information' replaces the older distinction between 'documents' and 'records' with a single term.
Information the organization determines is necessary
Content the organization itself identifies as needed for the effectiveness of its management system, alongside content that a specific standard or applicable requirement mandates. The scope typically varies by organization size, activities, and complexity.
Format and medium neutrality
Documented information may exist in any format (text, diagrams, data) and on any medium (electronic, paper), and may come from any source, as management system standards generally treat it independently of its carrier.
Evidence of conformity and operation
Records that provide evidence that planned activities were carried out and that requirements were met—for example, evidence supporting AI governance activities, model oversight, or process execution. This function is where documented information often intersects with model risk management evidence needs, though the two are not equivalent.

Common questions

Answers to the questions practitioners most commonly ask about Documented Information.

Does 'documented information' mean the same thing as traditional documents and records?
Not exactly. The phrasing 'documented information' is used in many management system standards to combine what older frameworks separated into 'documents' (which typically set out how something is to be done and are meant to be maintained and updated) and 'records' (which typically provide evidence that something was done and are meant to be retained as they are). Treating the two as identical is a common error, because the distinction still matters in practice: one is generally maintained and revised over time, while the other is retained as evidence. Use the term with an awareness of both aspects rather than assuming it collapses the older distinction entirely.
Does documented information have to be a formal paper or word-processed document?
No. A frequent misconception is that documented information must take the form of a formal written document in a specific format. As commonly defined, documented information can exist in any medium and from any source, including electronic records, databases, logs, images, or other formats. The emphasis is typically on the information being controlled and available rather than on its particular form. Fixating on a single required format is a pitfall; the focus should be on control, accessibility, and fitness for purpose.
How do we decide what documented information actually needs to be created and controlled?
This is generally driven by a combination of what a given framework or standard requires and what your organization determines is necessary for the effectiveness of its processes and controls. In many frameworks the extent of documented information can vary with the size of the organization, the complexity of its activities, and the competence of its people. It is worth distinguishing information that is required to be maintained (typically kept current) from information required to be retained (typically kept as evidence), and scoping each accordingly. Beyond what a standard mandates, treat the decision as a risk-informed judgment rather than assuming more documentation is always better.
What controls are typically expected over documented information once it exists?
Common expectations include ensuring documented information is available and suitable for use where and when it is needed, and that it is adequately protected, for example against loss of confidentiality, improper use, or loss of integrity. Control activities frequently addressed include distribution, access, retrieval, storage, preservation, control of changes such as version control, and retention and disposition. The specific controls appropriate to your organization depend on the framework you are applying and your own risk assessment, so treat these as commonly cited categories rather than a fixed universal checklist.
How should we handle documented information that originates outside the organization?
Documented information of external origin that your organization determines is necessary should generally be identified as such and brought under appropriate control, as it is in many management system approaches. This does not mean you rewrite or reformat it, but rather that you manage its access, version, and use so that people rely on the correct external material. The practical point is to distinguish externally sourced information within your control processes rather than treating all documented information as internally generated.
How do version control and retention differ in the way we manage documented information?
These serve different purposes and should not be blurred. Version control typically applies to information that is maintained, meaning it is kept current and revised over time, so the concern is ensuring people use the latest approved version and that changes are managed. Retention typically applies to information that is retained as evidence of what occurred, so the concern is preserving it unchanged for a defined period and controlling its eventual disposition. In practice a given item may need one, the other, or both, so it is useful to classify each type of documented information by whether it is primarily maintained, retained, or both, and then apply the appropriate handling.

Common misconceptions

'Documented information' is just another word for a policy manual or a set of written procedures.
In many management system standards the term is broader, encompassing both the information needed to run processes and the records generated as evidence of their operation. It is not limited to policy documents, and it spans multiple formats and media.
Maintaining documented information demonstrates that an AI system is well governed or low risk.
Documentation is a control that supports and evidences governance and oversight; it does not by itself establish that risks are managed or that a model performs adequately. Governance documentation and model risk management evidence are related but distinct, and neither eliminates risk.
There is a single, fixed list of documents every organization must keep.
Requirements typically combine what a given standard mandates with what the organization determines it needs based on its context. The precise set is not universal and varies by organization, sector, and applicable framework.

Best practices

Distinguish documented information created to operate a process from records retained as evidence of conformity, and manage each according to its purpose rather than treating all documentation identically.
Define, for each document type, controls for identification, review, approval, version control, retention, and disposition so that the correct and current version is available where needed.
Scope your documented information to what the applicable standard requires plus what your organization determines is necessary, and record the rationale for inclusions and exclusions.
Keep documented information format- and medium-neutral in policy, but ensure access, protection, and retrievability controls apply consistently across electronic and paper media.
Align governance documentation with, but do not substitute it for, the distinct evidence needed for model risk activities such as validation, monitoring, and performance review.
Periodically review documented information for currency and accuracy so it continues to reflect actual processes, since outdated documentation weakens its value as evidence.