Documented information register
The controlled master list of every document your ISMS depends on, the ISO 27001 Clause 7.5 requirement, with owners, versions, classification, review cadence, and retention.
| Document | Owner | Version | Classification | Review |
|---|---|---|---|---|
| ISMS scope | Security lead | v1.3 | Internal | Current |
| Risk methodology | Security lead | v2.0 | Internal | Current |
| Supplier register | Ops | v1.1 | Confidential | Due |
| Access matrix | IT lead | v1.0 | Restricted | Overdue |
ISO 27001 Clause 7.5 asks you to identify the documented information your ISMS needs and keep it controlled: approved before use, versioned, protected by classification, available where it’s needed, and reviewed on a cadence. Keel gives you the controlled master list for exactly that: every policy, procedure, work instruction, form, and record with an owner, an approver, a classification, a version, where the controlled copy lives, a review schedule, and a retention rule.
Document control lives in a folder called “QMS”
For most teams the “document register” is a shared drive and a memory of which file is current. Clause 7.5 asks for more: a controlled list where every document has an owner, an approved version, a classification, and a review date, so nothing is out of date, unapproved, or unprotected when the auditor asks to see the master list.
What documented information register does
One controlled master list
Register every controlled document (policy, procedure, work instruction, form, record, plan, or manual) with a document code and version, so there’s a single source of truth for what exists and which revision is current.
Ownership and approval
Each document carries an owner and an approver, and moves through a lifecycle (draft, in review, approved, published, under revision, obsolete, withdrawn), so “approved before use” (Clause 7.5.2) is on the record.
Classification and protection
Tag each document public, internal, confidential, or restricted, and note its distribution, the Clause 7.5.3 requirement that documented information is available and adequately protected.
Review cadence with overdue flags
Set a review interval and a next-review date, and Keel flags anything overdue or due within 30 days, on the register and on each document. Mark a document reviewed and the next date rolls forward automatically, so control never quietly lapses.
Retention and controlled-copy location
Record where the controlled copy lives (a link or system) and its retention rule, the disposition half of Clause 7.5, so you can show how long each record is kept and where to find it.
Awareness & acknowledgment
Require named readers to acknowledge a document, the Clause 7.3 awareness expectation, and track who’s acknowledged the current version. Publish a new version and every reader resets to pending, so people must confirm they’ve read the revision.
Why it matters
- Prove ISO 27001 Clause 7.5 document control with a real master list
- Know which version is current, who owns it, and how it’s classified
- Catch documents due for review before they go stale
- Show that the right people acknowledged each revision (Clause 7.3)
- Complements the Policies module, which holds your authored policy bodies
Get audit-ready, and prove it
Documented information register is one module of a full GRC platform: controls crosswalked across every framework, so you collect evidence once and comply everywhere. Start free, no credit card, no sales call.
Start freeFrequently asked questions
What does ISO 27001 Clause 7.5 require?
That you identify the documented information your ISMS needs, control its creation and update (approval, version, format), and control its availability, protection, distribution, retention, and disposition. Keel’s register captures each of those attributes per document.
How is this different from the Policies module?
The Policies module holds your authored policy bodies with their own version history. The documented information register is the master index of every controlled document wherever it lives (including procedures, work instructions, forms, and records that aren’t authored inside Keel), so you have one Clause 7.5 list across the whole ISMS.
How does the review cadence work?
Set a review interval in months and a next-review date. Keel flags documents that are overdue or due within 30 days. When you mark a document reviewed, it stamps the review date and rolls the next-review date forward by the cadence.
Who can edit the register?
Owners and admins in the workspace. Other members can view it, so the whole team can find the current, approved version of any controlled document.
Related features: Policy management · Internal audits · Management reviews
Works with: ISO/IEC 27001