Document governance
The four kinds of document an ISMS keeps, how each one is tested at audit, and the single lifecycle all four share.
Audience: ISMS Admin.
Where: SharePoint holds the files. The Certaria app holds the records. Your people only ever see SharePoint, and need no licence to do so.
An ISMS is not only policies. ISO 27001:2022 Clause 7.5 covers documented information, and in practice that arrives as four different kinds of document with four different readers. Certaria keeps all four, publishes all four to your people, and asks for confirmation on all four in the same way.
The four kinds, and why the distinction is not cosmetic
Section titled “The four kinds, and why the distinction is not cosmetic”They are separated because an auditor tests them differently, not because they are written differently.
| Kind | What it does | Who it is for | What an auditor asks |
|---|---|---|---|
| Policies | States management intent and the rules everyone must follow | Everybody | Was it approved by leadership, and reviewed this year? |
| Procedures | Sets out the operational workflow: who does what, and when | Technical and operations staff | Is it followed consistently, and can you show it was? |
| Guides and standards | Gives practical instruction and technical advice | End users, administrators | Is it usable, and has anyone been trained on it? |
| Plans | Frameworks for responding to a named event | Incident and recovery teams | When did you last rehearse this, and what happened? |
Each name in that first column opens the page for that kind. Two of them carry real consequences if you file them in the wrong place.
Plans have to have been exercised. The auditor asks for the test schedule and the results, so a plan buried in a list of policies is a plan nobody scheduled a test for. Plans covers what is asked and where the evidence lives.
Guides are advice, not obligation. Filed among your binding rules, a suggestion gets read as a requirement, and an auditor sampling “your policies” is handed something nobody ever approved. Guides and standards covers both halves of that.
Where they are in the app
Section titled “Where they are in the app”The Certaria app groups them under Document Governance, one entry per kind, in the order above. Acknowledgements and Change Log sit directly beneath them, because they record what happened to the documents rather than being documents themselves.
Each entry opens its own filtered list. If your organisation has no guides or plans yet, those lists open empty, which is normal on a new install rather than a fault.
Your registers and your reports are deliberately not in this group. A register such as the risk register or the Statement of Applicability is a live record you update continuously, with no approval and no version in force. Keeping them apart from documents that are approved, published and acknowledged is what makes the distinction legible at audit.
What ships, and what does not
Section titled “What ships, and what does not”Certaria ships 38 templates: 21 policies, 10 procedures, 2 plans, 2 guides, and 3 templates in the everyday sense of a form you fill in, such as a confidentiality agreement or an onboarding checklist.
Two of the ten procedures apply to every organisation, because ISO 27001 requires them of everyone, and the remaining eight follow your applicability decisions. Procedures names the two, and the controls the other eight govern.
No guides or plans ship. Those two lists begin empty on every install and stay empty until you create something. That is not an oversight: a guide is specific to how your organisation actually works, and a plan is worthless unless it names your people and your systems.
One lifecycle, all four kinds
Section titled “One lifecycle, all four kinds”Whichever of the four kinds a document is, it moves through the same four stages, and each stage has a page of its own.
| Stage | What you do | Page |
|---|---|---|
| Adopt | Decide whether a control applies to you, then copy a template and personalise it | Adopt a template |
| Publish | Check the record Certaria created and set it to Approved | Publish a document |
| Revise | Change a document that is already in force, without withdrawing it | Revise a document |
| Review | Confirm each year that it still stands, whether or not it changes | The annual review cycle |
Four things worth knowing before you start
Section titled “Four things worth knowing before you start”Approval is yours and only yours. Every record Certaria creates arrives as Draft, deliberately, so that putting a file in a folder can never publish it to your organisation by accident.
Nothing publishes that Certaria cannot find. It will not publish a document whose file is missing from the root of Policy Masters, because it would be putting something in front of everybody that it cannot produce again at audit.
A document being revised stays in force. Setting it back to Draft or Under Review does not take it off the site. Only Superseded or Archived does that, because until a new approved version replaces it, the last approved version is still the one that applies.
Review and acknowledgement are two separate clocks. Reviewing a document does not by itself ask anyone to confirm it again. People are asked when the version changes, or when their own confirmation passes its expiry, whichever comes first. So a yearly review that changes nothing does not create work for your whole organisation.
What your people see
Section titled “What your people see”They read documents from the Published Documents list on your SharePoint site, and confirm them on the Certaria card in Microsoft Teams. They never open the Certaria app and need no Power Platform licence.
A procedure reaches them exactly as a policy does, and asks for confirmation in the same way. That matters most for the ones with teeth: somebody confirming the disciplinary procedure is confirming they have read the rules that would be applied to them.
Each person can see what they have already confirmed under My Acknowledgements, beneath My Compliance in the site navigation, which shows their own entries and nobody else’s. Published Documents is a list of what applies to everyone, not a personal to-do list.
Related
Section titled “Related”- Your SharePoint site covers the libraries and lists these pages refer to.
- The Statement of Applicability is where the applicability decision is recorded, and where a procedure is named as the document covering a control.
- Who can see and do what covers the permissions behind all of it.