Skip to main content
Category: Audit Process

Documentation Review

Also known as: Document Review, Documentation Assessment
Simply put

Documentation review is the process of examining an organization's written records, such as policies, procedures, and other supporting materials, to evaluate their content and adequacy. In a compliance context, it is one of the ways an auditor or assessor gathers evidence about how an organization operates. On its own, it typically confirms what is written down rather than proving how consistently those practices are carried out in day-to-day operations.

Formal definition

Documentation review is an evidence-gathering and evaluation method involving the structured examination of records and documents that describe a program, system, or set of controls. Depending on scope, it may take the form of a quick reading or a more formal, staged review in which reviewers examine materials, provide feedback, and require amendments before acceptance. In audit and assessment work it is commonly used to assess the design and adequacy of documented policies and procedures; because it addresses documented artifacts rather than operating behavior, it is typically combined with other procedures (such as inquiry, observation, or testing) where operating effectiveness must be evaluated. The specific documents reviewed, the depth of review, and its role within an engagement vary by scope, methodology, and the reviewer.

Why it matters

Documentation review is often the starting point of an audit or assessment because it establishes what an organization intends to do. Written policies and procedures describe the controls an organization claims to operate, and reviewers examine these artifacts to evaluate whether the documented approach is coherent, adequate, and aligned with the applicable criteria. In a SOC 2 examination, for example, reviewing documented policies contributes to assessing the suitability of design of controls; in an ISO 27001 certification audit, documented artifacts such as the Statement of Applicability and ISMS procedures are central inputs. Without adequate documentation, an assessor typically cannot form a view on how controls are intended to function.

The limitation of documentation review is equally important to understand. Examining what is written down confirms the existence and content of a record, but it does not by itself demonstrate that the described practices are carried out consistently in day-to-day operations. A well-drafted policy that is not followed provides little assurance. For this reason, documentation review is typically one input among several rather than a complete basis for a conclusion. In engagements where operating effectiveness must be evaluated, such as a SOC 2 Type II examination, which assesses operating effectiveness over a defined review period, documentation review is combined with procedures such as inquiry, observation, and testing.

Because documentation review addresses documented artifacts rather than observed behavior, over-reliance on it can create a gap between what an organization records and what it actually does. Recognizing this boundary helps compliance teams scope engagements appropriately and helps readers of a report or certificate understand what the underlying procedures did and did not cover.

Who it's relevant to

Compliance and GRC Managers
Compliance managers prepare and maintain the policies and procedures that reviewers examine. Understanding that documentation review confirms what is written, but not how consistently it is followed, helps them ensure documented practices align with actual operations before an engagement begins.
Auditors and Assessors
Auditors use documentation review as one evidence-gathering method to assess the design and adequacy of documented controls. Because it addresses documented artifacts rather than operating behavior, they typically combine it with inquiry, observation, or testing when operating effectiveness must be evaluated.
Security Engineers
Security engineers often supply the technical procedures and configuration standards that reviewers assess. Ensuring these documents accurately reflect implemented practices helps reduce gaps between what is recorded and what is actually operated.
Report and Certificate Readers
Customers and stakeholders relying on a SOC 2 report or ISO 27001 certificate benefit from understanding that documentation review alone confirms the existence and content of records. It does not, on its own, demonstrate consistent operation, which is why other procedures are typically applied alongside it.

Inside Documentation Review

Policy and Procedure Examination
The review of written policies, procedures, and standards that describe how controls are intended to operate. In a SOC 2 examination, this supports the CPA firm's evaluation of the suitability of design of controls; in an ISO 27001 audit, it supports the certification body's assessment of the ISMS documented information required under clauses 4 through 10.
Evidence of Control Operation
For a SOC 2 Type II engagement, documentation review extends to records demonstrating that controls operated over the defined review period, whereas a SOC 2 Type I engagement typically focuses on documentation supporting design at a point in time. The specific evidence examined depends on scope and the criteria selected.
Statement of Applicability and Risk Assessment Records (ISO 27001)
In an ISO 27001 audit, reviewers examine the Statement of Applicability, which documents the selection and justification of Annex A reference controls, along with risk assessment and risk treatment documentation that informs those selections.
Scope-Defining Documentation
Documentation that establishes the boundaries of what is being assessed, such as the described system and Trust Services Criteria selected for a SOC 2 report, or the defined ISMS scope for an ISO 27001 certificate. Review confirms alignment between documented scope and the controls examined.

Common questions

Answers to the questions practitioners most commonly ask about Documentation Review.

Does a documentation review by itself prove that controls are operating effectively?
No. A documentation review evaluates whether policies, procedures, and other artifacts exist and are appropriately designed, but reviewing documentation alone does not demonstrate operating effectiveness. In a SOC 2 Type II examination, operating effectiveness is assessed through additional testing over the defined review period, and in an ISO 27001 audit, evidence beyond documents is typically examined. Documentation review is generally one input among several rather than conclusive evidence on its own.
Is a documentation review the same activity in a SOC 2 examination and an ISO 27001 audit?
Not exactly. While both frameworks involve examining documentation, the purpose and context differ. In a SOC 2 examination performed by a CPA firm under SSAE 18, documentation review supports the auditor's assessment of the suitability of design (and, for Type II, operating effectiveness) of controls against the applicable Trust Services Criteria. In an ISO 27001 certification audit conducted by an accredited certification body, documentation review supports assessment of conformity to the ISMS requirements in clauses 4 through 10 and the controls selected in the Statement of Applicability. The activities are analogous but tied to different objectives, and satisfying one does not automatically satisfy the other.
What kinds of documents are typically examined during a documentation review?
The specific documents depend on scope and the applicable criteria, but they commonly include policies, procedures, and records that describe how controls are designed and intended to operate. For an ISO 27001 audit this often includes ISMS-related documentation such as the Statement of Applicability and risk assessment outputs, while for a SOC 2 examination it typically includes documentation supporting the controls mapped to the selected Trust Services Criteria. The exact set is determined by the auditor or certification body and the defined scope.
When in the engagement does documentation review usually occur?
Documentation review is typically performed early in an engagement, as it helps the auditor or certification body understand the environment and assess the design of controls before or alongside other testing. In many engagements it informs subsequent activities such as inquiry, observation, and, for a SOC 2 Type II, testing of operating effectiveness over the review period. The precise timing varies by auditor, methodology, and scope.
How should an organization prepare its documentation ahead of a review?
In most engagements, organizations benefit from ensuring documentation is current, approved, and consistent with actual practice, and that it aligns with the controls or ISMS requirements in scope. Because outcomes depend on the auditor, certification body, scope, and applicable criteria, it is generally advisable to confirm expectations with the assessing party rather than assuming any single format or artifact is required, unless the standard itself calls for it.
What are the limitations of a documentation review?
A documentation review addresses only the documents examined and the scope covered, and it does not by itself confirm that controls operated as described or guarantee freedom from breaches. Findings depend on the completeness and accuracy of the materials provided and on the reviewer's judgment. It is generally most meaningful when combined with other procedures, and its conclusions apply only within the boundaries of the defined engagement scope.

Common misconceptions

A thorough documentation review alone confirms that controls are working effectively.
Reviewing documentation typically supports an assessment of the design of controls, but demonstrating operating effectiveness generally requires additional evidence over a period, as in a SOC 2 Type II engagement. Documentation review by itself does not establish that controls operated as intended.
Passing a documentation review means the organization is free from breaches or security failures.
Documentation review is one input to an examination or audit that attests only to the controls and, where applicable, the period covered within the defined scope. A SOC 2 report does not guarantee freedom from breaches, and an ISO 27001 certificate covers only the defined scope of the ISMS.
The same documentation set satisfies both SOC 2 and ISO 27001 reviews interchangeably.
Mapping between the frameworks is possible but partial. SOC 2 documentation is reviewed against the Trust Services Criteria under the AICPA SSAE 18 standard, while ISO 27001 documentation is reviewed against the ISMS requirements in clauses 4 through 10 and Annex A reference controls. Satisfying one review does not automatically satisfy the other.

Best practices

Maintain documentation that clearly links each policy and procedure to the specific criteria or clauses it addresses, so reviewers can trace design intent to the applicable framework.
For SOC 2 Type II engagements, retain records that evidence control operation throughout the defined review period, since the period length is set by scoping decisions rather than fixed.
Keep the Statement of Applicability and supporting risk assessment records current for ISO 27001, documenting the justification for including or excluding each Annex A reference control and specifying the version of the standard being applied.
Confirm that documented scope aligns with the controls and, for SOC 2, the Trust Services Criteria actually selected, remembering that Security (the Common Criteria) is required while other categories are optional.
Version-control documentation and record review dates so evolving policies can be evaluated against the correct point in time or review period.
Where pursuing both frameworks, document mappings explicitly but treat them as partial, since satisfying one framework's documentation review does not automatically satisfy the other.