Skip to content

Document governance

The four kinds of document an ISMS keeps, how each one is tested at audit, and the single lifecycle all four share.

Audience: ISMS Admin.

Where: SharePoint holds the files. The Certaria app holds the records. Your people only ever see SharePoint, and need no licence to do so.

An ISMS is not only policies. ISO 27001:2022 Clause 7.5 covers documented information, and in practice that arrives as four different kinds of document with four different readers. Certaria keeps all four, publishes all four to your people, and asks for confirmation on all four in the same way.

The four kinds, and why the distinction is not cosmetic

Section titled “The four kinds, and why the distinction is not cosmetic”

They are separated because an auditor tests them differently, not because they are written differently.

KindWhat it doesWho it is forWhat an auditor asks
PoliciesStates management intent and the rules everyone must followEverybodyWas it approved by leadership, and reviewed this year?
ProceduresSets out the operational workflow: who does what, and whenTechnical and operations staffIs it followed consistently, and can you show it was?
Guides and standardsGives practical instruction and technical adviceEnd users, administratorsIs it usable, and has anyone been trained on it?
PlansFrameworks for responding to a named eventIncident and recovery teamsWhen did you last rehearse this, and what happened?

Each name in that first column opens the page for that kind. Two of them carry real consequences if you file them in the wrong place.

Plans have to have been exercised. The auditor asks for the test schedule and the results, so a plan buried in a list of policies is a plan nobody scheduled a test for. Plans covers what is asked and where the evidence lives.

Guides are advice, not obligation. Filed among your binding rules, a suggestion gets read as a requirement, and an auditor sampling “your policies” is handed something nobody ever approved. Guides and standards covers both halves of that.

The Certaria app groups them under Document Governance, one entry per kind, in the order above. Acknowledgements and Change Log sit directly beneath them, because they record what happened to the documents rather than being documents themselves.

Each entry opens its own filtered list. If your organisation has no guides or plans yet, those lists open empty, which is normal on a new install rather than a fault.

Your registers and your reports are deliberately not in this group. A register such as the risk register or the Statement of Applicability is a live record you update continuously, with no approval and no version in force. Keeping them apart from documents that are approved, published and acknowledged is what makes the distinction legible at audit.

Certaria ships 38 templates: 21 policies, 10 procedures, 2 plans, 2 guides, and 3 templates in the everyday sense of a form you fill in, such as a confidentiality agreement or an onboarding checklist.

Two of the ten procedures apply to every organisation, because ISO 27001 requires them of everyone, and the remaining eight follow your applicability decisions. Procedures names the two, and the controls the other eight govern.

No guides or plans ship. Those two lists begin empty on every install and stay empty until you create something. That is not an oversight: a guide is specific to how your organisation actually works, and a plan is worthless unless it names your people and your systems.

Whichever of the four kinds a document is, it moves through the same four stages, and each stage has a page of its own.

StageWhat you doPage
AdoptDecide whether a control applies to you, then copy a template and personalise itAdopt a template
PublishCheck the record Certaria created and set it to ApprovedPublish a document
ReviseChange a document that is already in force, without withdrawing itRevise a document
ReviewConfirm each year that it still stands, whether or not it changesThe annual review cycle

Four things worth knowing before you start

Section titled “Four things worth knowing before you start”

Approval is yours and only yours. Every record Certaria creates arrives as Draft, deliberately, so that putting a file in a folder can never publish it to your organisation by accident.

Nothing publishes that Certaria cannot find. It will not publish a document whose file is missing from the root of Policy Masters, because it would be putting something in front of everybody that it cannot produce again at audit.

A document being revised stays in force. Setting it back to Draft or Under Review does not take it off the site. Only Superseded or Archived does that, because until a new approved version replaces it, the last approved version is still the one that applies.

Review and acknowledgement are two separate clocks. Reviewing a document does not by itself ask anyone to confirm it again. People are asked when the version changes, or when their own confirmation passes its expiry, whichever comes first. So a yearly review that changes nothing does not create work for your whole organisation.

They read documents from the Published Documents list on your SharePoint site, and confirm them on the Certaria card in Microsoft Teams. They never open the Certaria app and need no Power Platform licence.

A procedure reaches them exactly as a policy does, and asks for confirmation in the same way. That matters most for the ones with teeth: somebody confirming the disciplinary procedure is confirming they have read the rules that would be applied to them.

Each person can see what they have already confirmed under My Acknowledgements, beneath My Compliance in the site navigation, which shows their own entries and nobody else’s. Published Documents is a list of what applies to everyone, not a personal to-do list.