Skip to content

Procedures

Tier two: who does what and when, including the two procedures ISO 27001 requires of every organisation.

Audience: ISMS Admin.

Where: SharePoint holds the files. The Certaria app holds the records.

A procedure sets out the execution, not the rule

Section titled “A procedure sets out the execution, not the rule”

A procedure is the operational workflow: who does what, and when. Its readers are the technical and operations staff who carry the work out, so it is written for them rather than for the whole organisation.

Where a policy states the rule, a procedure sets out how the rule is met. The Policies page carries the test that tells the two apart, and it works in this direction too: a document on this tier that names no system, no screen and no sequence of steps has not yet told an operator anything they can follow.

Ten of the thirty-four templates Certaria ships are procedures

Section titled “Ten of the thirty-four templates Certaria ships are procedures”

They arrive exactly as the policies do, as templates in the Certaria app, awaiting an applicability decision and personalisation once adopted. A template is never in force and never publishes.

Adopt a template is the catalogue of all thirty-four. This page covers what is different about these ten.

Two of them apply to you whatever your applicability decisions say

Section titled “Two of them apply to you whatever your applicability decisions say”

ISO 27001 requires two procedures of every organisation:

  • the Document Control Procedure, required by Clause 7.5
  • the Internal Audit Procedure, required by Clause 9.2

Neither is conditional, and there is no justification that excludes either. They sit outside the applicability question rather than under it: the Statement of Applicability records your decisions about Annex A controls, and these two are clause requirements. If you find yourself weighing whether they apply, the question was never open.

The other eight follow your applicability decisions, and several are named in them

Section titled “The other eight follow your applicability decisions, and several are named in them”

The remaining eight depend on what your organisation actually does, and you decide each one as you would a policy. Several are the governing document for a control an auditor asks about directly: information transfer (A.5.14), the data protection impact assessment procedure (A.5.34), personnel screening (A.6.1), the disciplinary procedure (A.6.4), and secure disposal and re-use (A.7.14).

That is why this tier has an entry of its own rather than sitting among the policies. An administrator who cannot find a procedure cannot maintain it, review it on time, or evidence that it was ever approved. Worse, the Statement of Applicability may name that procedure as the document covering a control, which makes it one of the first things the auditor asks to see.

An auditor does not ask whether a procedure was approved

Section titled “An auditor does not ask whether a procedure was approved”

Approval is necessary and it is not the test. The question asked about a procedure is whether it is followed consistently, and whether you can show that it was.

That is the sharpest difference between this tier and the one above it. A policy is tested on its approval and its review. A procedure is tested on its execution. For a policy, a named approver and a review date largely answer the question. For a procedure, the document is only the claim: the evidence is whatever the work itself leaves behind.

The uncomfortable consequence is that an accurate procedure describing work nobody performs is worse than no procedure at all. It documents the gap in your own words, signed off by a named person on a recorded date.

Your people are asked to confirm a procedure exactly as they confirm a policy

Section titled “Your people are asked to confirm a procedure exactly as they confirm a policy”

Publishing a procedure reaches everybody, exactly as publishing a policy does: the same list, the same confirmation, the same reminders. A procedure written for your operations team still goes in front of the whole organisation, and everybody is asked to confirm it.

That is worth a second thought on the ones with teeth. Somebody confirming the disciplinary procedure is confirming they have read the rules that would be applied to them, which is exactly the evidence you want and exactly why the wording deserves a careful read before you approve it.

Your people read it from the Published Documents list on your SharePoint site and confirm it on the Certaria card in Microsoft Teams. They never open the Certaria app, and they need no Power Platform licence.

This tier has no part of the lifecycle to itself

Section titled “This tier has no part of the lifecycle to itself”

Adoption, publication, revision and review are identical for a procedure and a policy. No step is added here and none is skipped, so these four pages are the whole of it.