ISO27001:2022 – A5.37 – Documented operating procedures

Introduction to ISO 27001 – A5.37

Unlike many ISO27001 controls that require some interpretation, ISO 27001 – A5.37 is refreshingly clear. If you want to secure your business, you need consistent procedures—and that means documenting them properly.

What does the standard require?

“Operating procedures for information processing facilities shall be documented and made available to personnel who need them.”
(ISO 27001 – A5.37 – Documented Operating Procedures)

This doesn’t just apply to your technical infrastructure. It also includes physical processes related to your premises and facilities. Think beyond IT—think HVAC, alarms, access controls, and more.

Why is this required?

ISO27001 is about doing the right things. Documented procedures make sure you do those things consistently. Without documentation, you’re relying on individuals to remember and execute procedures correctly every time—which is a recipe for inconsistency and error.

For example, when onboarding new staff or configuring a new device, how do you ensure everyone applies the same security controls if you don’t have a documented checklist or guide?

What the auditor is looking for

The auditor doesn’t expect a procedure for everything—this isn’t ISO9001. But they will expect documented processes in areas that have a material impact on information security. Keep in mind that where a policy is in place/required, your procedures need to provide further support on HOW the policy is adopted.

Examples include:

If a process affects the confidentiality, integrity or availability of information, document it.

What do you need to do?

Start by identifying key processes in your organisation that support your information processing facilities—especially those that affect how secure, available, or resilient your systems are. Speak to process owners and walk through each step.

Document the steps clearly—either as written instructions, flowcharts, or process maps—whatever format suits your team best. The goal is that anyone with the appropriate background should be able to follow the steps and get a consistent result.

Q & A

How many procedures do I need?

That depends on your size and complexity. Begin with processes that carry higher risk or require precision, then expand as needed. You’re aiming for consistency and accountability—not bureaucracy.

Can I use diagrams or flowcharts instead of documents?

Yes. As long as the process is clear and accessible to those who need it, the format is up to you. Visuals like process maps or decision trees often improve clarity and reduce training time.

Difficulty Rating

2 out of 5 – While not technically difficult, this control does require talking to technical and operational staff, validating what they tell you, and documenting it in a usable way. Strong communication and basic technical understanding will go a long way here.

Final Tip

Don’t go overboard. You don’t need to create a manual for every click. Focus on security-relevant procedures that ensure consistent execution. Keep them accurate and accessible, and update them when the process changes.

 We are ISO 27001 Consultants who provide ‘Compliance without Complexity’® and we know we can help you… we even wrote a book about it. For more information on how to implement ISO 27001, written by ISO 27001 consultants like us, you should buy our book… “The Real Easy Guide to ISO27001” covers these areas in depth and is available on Amazon now.

ISO 27001 – A5.37